← Back to feed Patch nowZero-days

📅 New This Week

Vulnerabilities published in the last 7 days (2026-09-11 → 2026-09-18). Updated every 4 hours.

5294
Total new CVEs
548
Critical
2269
High
9
Actively exploited
1
Public PoC
CVE / IDTitleSeverityCVSSEPSSWhy urgentSourceDate
CVE-2026-85706GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1CRITICAL10.096%KEV PoC EPSS 96%ileNVD2026-09-12
CVE-2026-89308An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execCRITICAL9.387%EPSS 87%ileNVD2026-09-15
CVE-2026-58146WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the CRITICAL9.481%EPSS 81%ileNVD2026-09-16
CVE-2026-52824Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pubCRITICAL9.180%EPSS 80%ileNVD2026-09-15
CVE-2026-76461A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticCRITICAL9.880%KEV EPSS 80%ileNVD2026-09-14
CVE-2026-73172Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandCRITICAL9.377%EPSS 77%ileNVD2026-09-16
CVE-2026-90822FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command iCRITICAL9.871%EPSS 71%ileNVD2026-09-17
CVE-2026-20305A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perforCRITICAL9.171%EPSS 71%ileNVD2026-09-16
CVE-2026-20306A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform commanCRITICAL9.171%EPSS 71%ileNVD2026-09-16
CVE-2026-76675A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploiCRITICAL9.170%EPSS 70%ileNVD2026-09-15
CVE-2026-54501Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used throughCRITICAL9.467%EPSS 67%ileNVD2026-09-17
CVE-2026-58147WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password chaCRITICAL9.367%EPSS 67%ileNVD2026-09-16
CVE-2026-40855WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality CRITICAL9.365%EPSS 65%ileNVD2026-09-16
CVE-2026-76674Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways tCRITICAL9.863%EPSS 63%ileNVD2026-09-15
CVE-2026-90919LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_regCRITICAL9.362%EPSS 62%ileNVD2026-09-14
CVE-2026-51990An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary CRITICAL9.861%EPSS 61%ileNVD2026-09-16
CVE-2026-65414An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.CRITICAL9.861%EPSS 61%ileNVD2026-09-14
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote aCRITICAL9.861%EPSS 61%ileNVD2026-09-17
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.CRITICAL9.860%EPSS 60%ileNVD2026-09-14
CVE-2026-20307A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execCRITICAL9.960%EPSS 60%ileNVD2026-09-16
CVE-2026-27546An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admCRITICAL9.860%EPSS 60%ileNVD2026-09-16
CVE-2026-27565An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root prCRITICAL9.859%EPSS 59%ileNVD2026-09-16
CVE-2026-89040Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request iCRITICAL9.359%EPSS 59%ileNVD2026-09-15
CVE-2026-70416Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticaCRITICAL10.058%EPSS 58%ileNVD2026-09-16
CVE-2026-57127PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewarCRITICAL9.858%EPSS 58%ileNVD2026-09-14
CVE-2026-12351IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LCRITICAL9.857%EPSS 57%ileNVD2026-09-15
CVE-2026-76834b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array objeCRITICAL9.256%EPSS 56%ileNVD2026-09-17
CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_saCRITICAL10.056%EPSS 56%ileNVD2026-09-15
CVE-2026-90011In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for CRITICAL9.156%EPSS 56%ileNVD2026-09-16
CVE-2026-91932Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attacCRITICAL9.056%EPSS 56%ileNVD2026-09-15
CVE-2026-92937vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GCRITICAL10.055%EPSS 55%ileNVD2026-09-17
CVE-2026-76460A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypCRITICAL10.054%KEV EPSS 54%ileNVD2026-09-16
CVE-2026-61534Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use aCRITICAL9.154%EPSS 54%ileNVD2026-09-14
CVE-2026-89970In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ tearCRITICAL9.854%EPSS 54%ileNVD2026-09-16
CVE-2026-20176A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyiCRITICAL9.154%EPSS 54%ileNVD2026-09-16
CVE-2026-78006The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includingCRITICAL9.854%EPSS 54%ileNVD2026-09-12
CVE-2026-57147PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public CRITICAL9.854%EPSS 54%ileNVD2026-09-15
CVE-2026-50006Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL froCRITICAL9.154%EPSS 54%ileNVD2026-09-14
CVE-2026-78159The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includingCRITICAL9.854%EPSS 54%ileNVD2026-09-12
CVE-2026-73447A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full CRITICAL9.454%EPSS 54%ileNVD2026-09-16
CVE-2026-73453An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary cCRITICAL9.553%EPSS 53%ileNVD2026-09-16
CVE-2026-73456Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI)CRITICAL9.253%EPSS 53%ileNVD2026-09-16
CVE-2026-92934vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited hostCRITICAL9.553%EPSS 53%ileNVD2026-09-17
CVE-2026-46495OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/CRITICAL9.253%EPSS 53%ileNVD2026-09-15
CVE-2026-91104HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several CRITICAL9.352%EPSS 52%ileNVD2026-09-16
CVE-2026-80976In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_aCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89482In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_payCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89485In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-dCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89494In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler CRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89495In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handlerCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89538In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject krb5 v2 wrap tokens with oversized eCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89643In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rulCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89655In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entryCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-89712In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after droppingCRITICAL9.852%EPSS 52%ileNVD2026-09-11
CVE-2026-61560`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`CRITICAL9.852%EPSS 52%ileNVD2026-09-15
CVE-2026-89783In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr(CRITICAL9.852%EPSS 52%ileNVD2026-09-16
CVE-2026-89634In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIGN() overflow in symlink_data()CRITICAL9.152%EPSS 52%ileNVD2026-09-11
CVE-2026-54053Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implCRITICAL9.652%EPSS 52%ileNVD2026-09-17
CVE-2026-89969In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving aCRITICAL9.852%EPSS 52%ileNVD2026-09-16
CVE-2026-89846In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sensCRITICAL9.152%EPSS 52%ileNVD2026-09-16
CVE-2026-89778In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on emptyCRITICAL9.851%EPSS 51%ileNVD2026-09-16
CVE-2026-89697In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATTCRITICAL9.151%EPSS 51%ileNVD2026-09-11
CVE-2026-43790The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, CRITICAL9.151%EPSS 51%ileNVD2026-09-14
CVE-2026-89779In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's namCRITICAL9.151%EPSS 51%ileNVD2026-09-16
CVE-2026-89786In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_diCRITICAL9.151%EPSS 51%ileNVD2026-09-16
CVE-2026-89555In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_selCRITICAL9.851%EPSS 51%ileNVD2026-09-11
CVE-2026-89662In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during clieCRITICAL9.851%EPSS 51%ileNVD2026-09-11
CVE-2026-89669In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publishCRITICAL9.851%EPSS 51%ileNVD2026-09-11
CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to executeCRITICAL9.351%EPSS 51%ileNVD2026-09-14
CVE-2026-90823FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based bCRITICAL9.851%EPSS 51%ileNVD2026-09-17
CVE-2026-54617GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote CRITICAL9.851%EPSS 51%ileNVD2026-09-17
CVE-2026-89847In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCCRITICAL9.851%EPSS 51%ileNVD2026-09-16
CVE-2025-59953LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and priorCRITICAL9.851%EPSS 51%ileNVD2026-09-16
CVE-2026-89686In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on rCRITICAL9.850%EPSS 50%ileNVD2026-09-11
CVE-2026-91106HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several CRITICAL9.350%EPSS 50%ileNVD2026-09-16
CVE-2026-89649In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() CRITICAL9.150%EPSS 50%ileNVD2026-09-11
CVE-2026-89636In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() WhenCRITICAL9.850%EPSS 50%ileNVD2026-09-11
CVE-2026-61667DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1CRITICAL9.950%EPSS 50%ileNVD2026-09-15
CVE-2026-84561A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS CRITICAL9.850%EPSS 50%ileNVD2026-09-14
CVE-2026-62379Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PCRITICAL9.850%EPSS 50%ileNVD2026-09-15
CVE-2026-73807The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticaCRITICAL9.350%EPSS 50%ileNVD2026-09-15
CVE-2026-19773libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabiliCRITICAL9.850%EPSS 50%ileNVD2026-09-15
CVE-2026-86533Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a rCRITICAL9.150%EPSS 50%ileNVD2026-09-17
CVE-2026-57124PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect CRITICAL9.849%EPSS 49%ileNVD2026-09-14
CVE-2023-54398Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageSCRITICAL9.349%EPSS 49%ileNVD2026-09-15
CVE-2026-20242A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could CRITICAL9.849%EPSS 49%ileNVD2026-09-16
CVE-2026-91931Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attCRITICAL9.049%EPSS 49%ileNVD2026-09-15
CVE-2026-89526In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before reconCRITICAL9.849%EPSS 49%ileNVD2026-09-11
CVE-2026-89536In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake calCRITICAL9.849%EPSS 49%ileNVD2026-09-11
CVE-2026-89558In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix still_degraded being inverted in raiCRITICAL9.849%EPSS 49%ileNVD2026-09-11
CVE-2026-89651In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in hCRITICAL9.849%EPSS 49%ileNVD2026-09-11
CVE-2026-90012In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failuCRITICAL9.849%EPSS 49%ileNVD2026-09-16
CVE-2026-69843Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwoCRITICAL10.048%EPSS 48%ileNVD2026-09-18
CVE-2026-89857In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LSCRITICAL9.848%EPSS 48%ileNVD2026-09-16
CVE-2026-92955vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ gCRITICAL10.048%EPSS 48%ileNVD2026-09-17
CVE-2026-87719GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3CRITICAL9.948%EPSS 48%ileNVD2026-09-12
CVE-2026-16338IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbiCRITICAL9.948%EPSS 48%ileNVD2026-09-14
CVE-2026-84609A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldCRITICAL9.848%EPSS 48%ileNVD2026-09-14
CVE-2026-87796The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, CRITICAL9.848%EPSS 48%ileNVD2026-09-17
CVE-2026-89658In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 CRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-89688In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqiCRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-89703In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_stiCRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-82435Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline aCRITICAL9.848%EPSS 48%ileNVD2026-09-14
CVE-2026-89990In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS seCRITICAL9.848%EPSS 48%ileNVD2026-09-16
CVE-2026-91995pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verifCRITICAL9.348%EPSS 48%ileNVD2026-09-15
CVE-2026-80980In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharingCRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-80986In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC CRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-89492In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when rCRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-89689In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in usCRITICAL9.848%EPSS 48%ileNVD2026-09-11
CVE-2026-82311Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, CRITICAL9.848%EPSS 48%ileNVD2026-09-16
CVE-2026-76187Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidenCRITICAL9.848%EPSS 48%ileNVD2026-09-16
CVE-2026-89713In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock nCRITICAL9.148%EPSS 48%ileNVD2026-09-11
CVE-2026-78330Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authCRITICAL9.847%EPSS 47%ileNVD2026-09-14
CVE-2026-89972In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path CRITICAL9.847%EPSS 47%ileNVD2026-09-16
CVE-2026-54460OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1CRITICAL9.847%EPSS 47%ileNVD2026-09-17
CVE-2026-91939Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowingCRITICAL9.347%EPSS 47%ileNVD2026-09-15
CVE-2026-62104Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.CRITICAL10.047%EPSS 47%ileNVD2026-09-17
CVE-2026-80981In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in smCRITICAL9.847%EPSS 47%ileNVD2026-09-11
CVE-2026-89637In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_CRITICAL9.847%EPSS 47%ileNVD2026-09-11
CVE-2026-89660In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin stCRITICAL9.847%EPSS 47%ileNVD2026-09-11
CVE-2026-92946vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit reCRITICAL10.047%EPSS 47%ileNVD2026-09-17
CVE-2026-70200Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorizeCRITICAL10.047%EPSS 47%ileNVD2026-09-17
CVE-2026-92944vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally(CRITICAL9.346%EPSS 46%ileNVD2026-09-17
CVE-2026-75030Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be ablCRITICAL9.846%EPSS 46%ileNVD2026-09-14
CVE-2026-46619Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authenCRITICAL9.346%EPSS 46%ileNVD2026-09-15
CVE-2026-82232Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. CRITICAL9.846%EPSS 46%ileNVD2026-09-14
CVE-2026-77051Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. CRITICAL9.846%EPSS 46%ileNVD2026-09-14
CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issueCRITICAL9.845%EPSS 45%ileNVD2026-09-14
CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instalCRITICAL9.345%EPSS 45%ileNVD2026-09-17
CVE-2026-20211A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyiCRITICAL9.145%EPSS 45%ileNVD2026-09-16
CVE-2026-89610In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary CRITICAL9.845%EPSS 45%ileNVD2026-09-11
CVE-2026-89612In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector TheCRITICAL9.845%EPSS 45%ileNVD2026-09-11
CVE-2026-89613In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject anCRITICAL9.845%EPSS 45%ileNVD2026-09-11
CVE-2026-89635In the Linux kernel, the following vulnerability has been resolved: ksmbd: only rebind the reopened file's own oplock oCRITICAL9.845%EPSS 45%ileNVD2026-09-11
CVE-2026-54670WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contCRITICAL9.145%EPSS 45%ileNVD2026-09-17
CVE-2026-85878Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwoCRITICAL9.945%EPSS 45%ileNVD2026-09-18
CVE-2026-62263Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize apCRITICAL9.245%EPSS 45%ileNVD2026-09-15
CVE-2026-76423A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain aCRITICAL10.045%EPSS 45%ileNVD2026-09-16
CVE-2026-85500Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to CRITICAL9.145%EPSS 45%ileNVD2026-09-17
CVE-2026-55211Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fielCRITICAL9.844%EPSS 44%ileNVD2026-09-15
CVE-2026-63695Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticateCRITICAL9.844%EPSS 44%ileNVD2026-09-15
CVE-2026-92939vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed.CRITICAL9.444%EPSS 44%ileNVD2026-09-17
CVE-2026-54626SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. ICRITICAL9.844%EPSS 44%ileNVD2026-09-17
CVE-2026-85885Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorizedCRITICAL9.944%EPSS 44%ileNVD2026-09-17
CVE-2026-90945Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuraCRITICAL9.344%EPSS 44%ileNVD2026-09-14
CVE-2026-57141PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mCRITICAL9.843%EPSS 43%ileNVD2026-09-15
CVE-2026-89672In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2CRITICAL9.143%EPSS 43%ileNVD2026-09-11
CVE-2026-81002In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_CRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89478In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed scCRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89541In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks CRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89542In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tokCRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89551In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdr_buf_trim: clamp buf->len to avoid underCRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89656In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids CRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89674In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encodeCRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-89026The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HSCRITICAL9.343%EPSS 43%ileNVD2026-09-15
CVE-2026-92749SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allCRITICAL9.243%EPSS 43%ileNVD2026-09-16
CVE-2026-81642In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial CRITICAL9.143%EPSS 43%ileNVD2026-09-16
CVE-2026-93467The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execuCRITICAL9.343%EPSS 43%ileNVD2026-09-18
CVE-2026-89546In the Linux kernel, the following vulnerability has been resolved: SUNRPC: close backchannel before destroying callbacCRITICAL9.843%EPSS 43%ileNVD2026-09-11
CVE-2026-82439Description The DRPC server kept a map from function name to request queue and created an entry the first time a functiCRITICAL9.843%EPSS 43%ileNVD2026-09-14
CVE-2026-89788In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tCRITICAL9.843%EPSS 43%ileNVD2026-09-16
CVE-2026-89537In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krbCRITICAL9.143%EPSS 43%ileNVD2026-09-11
CVE-2026-87785Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWTCRITICAL9.143%EPSS 43%ileNVD2026-09-14
CVE-2026-90680A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy ofCRITICAL9.442%EPSS 42%ileNVD2026-09-14
CVE-2026-89533In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range CRITICAL9.842%EPSS 42%ileNVD2026-09-11
CVE-2026-89653In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS iCRITICAL9.842%EPSS 42%ileNVD2026-09-11
CVE-2026-90048In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_createCRITICAL9.842%EPSS 42%ileNVD2026-09-16
CVE-2026-89532In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks CRITICAL9.142%EPSS 42%ileNVD2026-09-11
CVE-2026-89650In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info vCRITICAL9.142%EPSS 42%ileNVD2026-09-11
CVE-2026-92913AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generaCRITICAL9.142%EPSS 42%ileNVD2026-09-17
CVE-2026-90558sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header valCRITICAL9.342%EPSS 42%ileNVD2026-09-12
CVE-2026-45051Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialCRITICAL9.242%EPSS 42%ileNVD2026-09-15
CVE-2026-76186Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed AirCRITICAL9.142%EPSS 42%ileNVD2026-09-16
CVE-2026-89479In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its associationCRITICAL9.842%EPSS 42%ileNVD2026-09-11
CVE-2026-13639An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-CRITICAL9.842%EPSS 42%ileNVD2026-09-18
CVE-2026-89082HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, CRITICAL9.342%EPSS 42%ileNVD2026-09-16
CVE-2026-89083HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, CRITICAL9.342%EPSS 42%ileNVD2026-09-16
CVE-2026-91843A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with rootCRITICAL9.842%EPSS 42%ileNVD2026-09-16
CVE-2026-92935vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computeCRITICAL9.542%EPSS 42%ileNVD2026-09-17
CVE-2026-69399Azure Arc Elevation of Privilege VulnerabilityCRITICAL10.041%EPSS 41%ileNVD2026-09-17
CVE-2026-85889Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges oCRITICAL10.041%EPSS 41%ileNVD2026-09-17
CVE-2026-76441As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscCRITICAL9.841%EPSS 41%ileNVD2026-09-14
CVE-2026-92957vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) CRITICAL9.441%EPSS 41%ileNVD2026-09-17
CVE-2026-90042In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffeCRITICAL9.841%EPSS 41%ileNVD2026-09-16
CVE-2026-76949Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a reCRITICAL9.141%EPSS 41%ileNVD2026-09-17
CVE-2026-89671In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_seCRITICAL9.141%EPSS 41%ileNVD2026-09-11
CVE-2026-39919Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpCRITICAL9.341%EPSS 41%ileNVD2026-09-15
CVE-2026-85192Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension foCRITICAL9.441%EPSS 41%ileNVD2026-09-14
CVE-2026-81855A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of WärCRITICAL9.341%EPSS 41%ileNVD2026-09-15
CVE-2026-83059Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL10.041%EPSS 41%ileNVD2026-09-15
CVE-2026-73956Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-73961Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions tCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-82994Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-82995Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83000Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83035Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83036Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83037Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83042Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported CRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83060Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83061Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83062Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83066Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83094Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83095Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83100Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83327Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83339Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83452Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-83462Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-87184Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.841%EPSS 41%ileNVD2026-09-15
CVE-2026-89633In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated DaCRITICAL9.841%EPSS 41%ileNVD2026-09-11
CVE-2026-86462Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate tCRITICAL9.141%EPSS 41%ileNVD2026-09-16
CVE-2026-82434Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.paylCRITICAL10.040%EPSS 40%ileNVD2026-09-14
CVE-2026-88795The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, CRITICAL9.040%EPSS 40%ileNVD2026-09-17
CVE-2026-73470Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles notCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-73579Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or ElastCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-73668Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given ReaCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-77181Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unabCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-73370Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by ReconcCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-82431Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was emptyCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-37152TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.CRITICAL9.840%EPSS 40%ileNVD2026-09-15
CVE-2026-57123PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_seCRITICAL9.840%EPSS 40%ileNVD2026-09-14
CVE-2026-68536Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affectCRITICAL9.840%EPSS 40%ileNVD2026-09-16
CVE-2026-90692A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the componCRITICAL9.440%EPSS 40%ileNVD2026-09-14
CVE-2026-90693A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings.CRITICAL9.440%EPSS 40%ileNVD2026-09-14
CVE-2026-80945In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback onCRITICAL9.140%EPSS 40%ileNVD2026-09-11
CVE-2026-70009Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacCRITICAL9.340%EPSS 40%ileNVD2026-09-17
CVE-2026-92720Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated aCRITICAL9.340%EPSS 40%ileNVD2026-09-16
CVE-2026-52630SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditoCRITICAL9.840%EPSS 40%ileNVD2026-09-11
CVE-2026-92860A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmCRITICAL9.440%EPSS 40%ileNVD2026-09-17
CVE-2026-89530In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the puCRITICAL9.839%EPSS 39%ileNVD2026-09-11
CVE-2026-89702In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_loCRITICAL9.839%EPSS 39%ileNVD2026-09-11
CVE-2026-89550In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum lenCRITICAL9.839%EPSS 39%ileNVD2026-09-11
CVE-2026-89652In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS exportCRITICAL9.839%EPSS 39%ileNVD2026-09-11
CVE-2026-90036In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked-CRITICAL9.839%EPSS 39%ileNVD2026-09-16
CVE-2026-90961The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthCRITICAL9.339%EPSS 39%ileNVD2026-09-14
CVE-2026-79752CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::caCRITICAL9.239%EPSS 39%ileNVD2026-09-17
CVE-2026-83001Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.139%EPSS 39%ileNVD2026-09-15
CVE-2026-83064Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported CRITICAL9.139%EPSS 39%ileNVD2026-09-15
CVE-2026-83260Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported versionCRITICAL9.139%EPSS 39%ileNVD2026-09-15
CVE-2026-87189Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.139%EPSS 39%ileNVD2026-09-15
CVE-2026-77866Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reacCRITICAL9.039%EPSS 39%ileNVD2026-09-15
CVE-2026-90037In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lrCRITICAL9.839%EPSS 39%ileNVD2026-09-16
CVE-2026-13684An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-6905CRITICAL9.839%EPSS 39%ileNVD2026-09-18
CVE-2026-76440As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscCRITICAL9.839%EPSS 39%ileNVD2026-09-14
CVE-2026-69865Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevCRITICAL10.039%EPSS 39%ileNVD2026-09-17
CVE-2026-83944Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.039%EPSS 39%ileNVD2026-09-17
CVE-2026-76673Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unautCRITICAL9.839%EPSS 39%ileNVD2026-09-15
CVE-2026-83020Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdCRITICAL10.038%EPSS 38%ileNVD2026-09-15
CVE-2026-83021Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported vCRITICAL10.038%EPSS 38%ileNVD2026-09-15
CVE-2026-70756Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.838%EPSS 38%ileNVD2026-09-15
CVE-2026-73940Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.838%EPSS 38%ileNVD2026-09-15
CVE-2026-73950Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.838%EPSS 38%ileNVD2026-09-15
CVE-2026-83108Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.838%EPSS 38%ileNVD2026-09-15
CVE-2026-83283Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeCRITICAL9.838%EPSS 38%ileNVD2026-09-15
CVE-2026-76669Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful explCRITICAL9.938%EPSS 38%ileNVD2026-09-15
CVE-2026-76670Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful explCRITICAL9.938%EPSS 38%ileNVD2026-09-15
CVE-2026-89675In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown AnCRITICAL9.838%EPSS 38%ileNVD2026-09-11
CVE-2026-89676In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for asyncCRITICAL9.838%EPSS 38%ileNVD2026-09-11
CVE-2026-81402The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type vCRITICAL9.838%EPSS 38%ileNVD2026-09-12
CVE-2026-92948vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on NCRITICAL9.438%EPSS 38%ileNVD2026-09-17
CVE-2026-89631In the Linux kernel, the following vulnerability has been resolved: smb: client: reject a tree connect response whose bCRITICAL9.138%EPSS 38%ileNVD2026-09-11
CVE-2026-91949FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated atCRITICAL9.238%EPSS 38%ileNVD2026-09-15
CVE-2026-47252Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE accessCRITICAL9.038%EPSS 38%ileNVD2026-09-17
CVE-2026-20329As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplCRITICAL9.938%EPSS 38%ileNVD2026-09-16
CVE-2026-21391An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID CRITICAL9.538%EPSS 38%ileNVD2026-09-14
CVE-2026-55158Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1,CRITICAL9.138%EPSS 38%ileNVD2026-09-15
CVE-2026-20194As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL9.138%EPSS 38%ileNVD2026-09-16
CVE-2026-20341A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authentiCRITICAL9.138%EPSS 38%ileNVD2026-09-16
CVE-2026-54627SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. ICRITICAL9.838%EPSS 38%ileNVD2026-09-17
CVE-2026-20324A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) SofCRITICAL9.938%EPSS 38%ileNVD2026-09-16
CVE-2026-57578DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorCRITICAL9.238%EPSS 38%ileNVD2026-09-14
CVE-2026-83103Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.138%EPSS 38%ileNVD2026-09-15
CVE-2026-83107Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.138%EPSS 38%ileNVD2026-09-15
CVE-2026-45579DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1CRITICAL9.938%EPSS 38%ileNVD2026-09-15
CVE-2026-54337Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upCRITICAL9.837%EPSS 37%ileNVD2026-09-15
CVE-2026-87701Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB alCRITICAL9.637%EPSS 37%ileNVD2026-09-17
CVE-2026-80926In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notificatCRITICAL9.837%EPSS 37%ileNVD2026-09-11
CVE-2026-89659In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegatiCRITICAL9.837%EPSS 37%ileNVD2026-09-11
CVE-2026-89708In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-frCRITICAL9.837%EPSS 37%ileNVD2026-09-11
CVE-2026-88952Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another usCRITICAL9.137%EPSS 37%ileNVD2026-09-17
CVE-2026-54333UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. PriCRITICAL9.837%EPSS 37%ileNVD2026-09-14
CVE-2026-54334UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. PriCRITICAL9.837%EPSS 37%ileNVD2026-09-14
CVE-2026-92947vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by BufferCRITICAL10.037%EPSS 37%ileNVD2026-09-17
CVE-2026-20192As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.037%EPSS 37%ileNVD2026-09-16
CVE-2026-83006Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).CRITICAL9.137%EPSS 37%ileNVD2026-09-15
CVE-2026-61594djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to CRITICAL9.136%EPSS 36%ileNVD2026-09-16
CVE-2026-92960vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbCRITICAL10.036%EPSS 36%ileNVD2026-09-17
CVE-2026-14349The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in CRITICAL9.836%EPSS 36%ileNVD2026-09-16
CVE-2026-90562LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to theCRITICAL9.236%EPSS 36%ileNVD2026-09-13
CVE-2026-54767WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.phpCRITICAL9.136%EPSS 36%ileNVD2026-09-17
CVE-2026-92938vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin CRITICAL9.436%EPSS 36%ileNVD2026-09-17
CVE-2026-55209resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata iCRITICAL9.836%EPSS 36%ileNVD2026-09-14
CVE-2026-82441Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, whiCRITICAL9.136%EPSS 36%ileNVD2026-09-14
CVE-2026-88617SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to CRITICAL9.836%EPSS 36%ileNVD2026-09-15
CVE-2026-90038In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export sCRITICAL9.836%EPSS 36%ileNVD2026-09-16
CVE-2026-53459Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and pCRITICAL9.336%EPSS 36%ileNVD2026-09-15
CVE-2026-82997Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-82998Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-82999Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-83031Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-83039Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-83056Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-83057Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.936%EPSS 36%ileNVD2026-09-15
CVE-2026-57139PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serveCRITICAL9.836%EPSS 36%ileNVD2026-09-15
CVE-2026-91998Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers withCRITICAL9.436%EPSS 36%ileNVD2026-09-15
CVE-2026-75800The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication respCRITICAL9.836%EPSS 36%ileNVD2026-09-12
CVE-2026-59178ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dCRITICAL9.836%EPSS 36%ileNVD2026-09-14
CVE-2026-53713Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayCRITICAL9.135%EPSS 35%ileNVD2026-09-14
CVE-2026-57125PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST CRITICAL9.835%EPSS 35%ileNVD2026-09-14
CVE-2026-78225A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOSCRITICAL9.535%EPSS 35%ileNVD2026-09-15
CVE-2026-79395An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia ICRITICAL9.835%EPSS 35%ileNVD2026-09-11
CVE-2026-77411RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nilCRITICAL9.535%EPSS 35%ileNVD2026-09-16
CVE-2026-77408RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte leCRITICAL9.135%EPSS 35%ileNVD2026-09-16
CVE-2026-63472Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUseCRITICAL9.135%EPSS 35%ileNVD2026-09-17
CVE-2026-89614In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the free-cluster bitmap scan to the volCRITICAL9.835%EPSS 35%ileNVD2026-09-11
CVE-2026-89654In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed dCRITICAL9.835%EPSS 35%ileNVD2026-09-11
CVE-2026-89677In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible fh_compose of wrong dentry in nfCRITICAL9.835%EPSS 35%ileNVD2026-09-11
CVE-2026-91728Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code insidCRITICAL9.635%EPSS 35%ileNVD2026-09-15
CVE-2026-83104Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83202Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87128Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87170Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87173Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87176Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.134%EPSS 34%ileNVD2026-09-15
CVE-2026-62101Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.CRITICAL9.834%EPSS 34%ileNVD2026-09-17
CVE-2026-62108Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.CRITICAL9.834%EPSS 34%ileNVD2026-09-17
CVE-2026-91039Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one iCRITICAL9.134%EPSS 34%ileNVD2026-09-17
CVE-2026-92956vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on CRITICAL10.034%EPSS 34%ileNVD2026-09-17
CVE-2026-92576HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the CRITICAL9.234%EPSS 34%ileNVD2026-09-16
CVE-2026-54618Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorizaCRITICAL9.434%EPSS 34%ileNVD2026-09-17
CVE-2026-12258Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticateCRITICAL9.234%EPSS 34%ileNVD2026-09-14
CVE-2026-82761Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holCRITICAL9.134%EPSS 34%ileNVD2026-09-17
CVE-2026-87230Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL10.034%EPSS 34%ileNVD2026-09-15
CVE-2026-20353As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscCRITICAL9.834%EPSS 34%ileNVD2026-09-14
CVE-2025-56563A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts CRITICAL9.834%EPSS 34%ileNVD2026-09-16
CVE-2026-89630In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_vaCRITICAL9.134%EPSS 34%ileNVD2026-09-11
CVE-2026-20130As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL10.034%EPSS 34%ileNVD2026-09-16
CVE-2026-76672A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. CRITICAL9.934%EPSS 34%ileNVD2026-09-15
CVE-2026-79396Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores staCRITICAL9.834%EPSS 34%ileNVD2026-09-11
CVE-2026-83040Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.634%EPSS 34%ileNVD2026-09-15
CVE-2026-83043Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiCRITICAL9.634%EPSS 34%ileNVD2026-09-15
CVE-2026-57138PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-moCRITICAL9.933%EPSS 33%ileNVD2026-09-15
CVE-2026-15639An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScripCRITICAL9.333%EPSS 33%ileNVD2026-09-16
CVE-2026-20284A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection CRITICAL9.133%EPSS 33%ileNVD2026-09-16
CVE-2026-59971MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2CRITICAL10.033%EPSS 33%ileNVD2026-09-15
CVE-2026-73948Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiCRITICAL9.933%EPSS 33%ileNVD2026-09-15
CVE-2026-76443As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscCRITICAL9.833%EPSS 33%ileNVD2026-09-14
CVE-2026-12793The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versiCRITICAL9.833%EPSS 33%ileNVD2026-09-16
CVE-2026-20326As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tCRITICAL9.833%EPSS 33%ileNVD2026-09-16
CVE-2026-73458On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configuredCRITICAL9.232%EPSS 32%ileNVD2026-09-15
CVE-2024-58385Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoCRITICAL9.332%EPSS 32%ileNVD2026-09-15
CVE-2026-77903Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a neCRITICAL9.032%EPSS 32%ileNVD2026-09-17
CVE-2026-89611In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfsCRITICAL9.832%EPSS 32%ileNVD2026-09-11
CVE-2026-89681In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference raceCRITICAL9.832%EPSS 32%ileNVD2026-09-11
CVE-2026-87217Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.132%EPSS 32%ileNVD2026-09-15
CVE-2026-92787Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypasCRITICAL9.331%EPSS 31%ileNVD2026-09-16
CVE-2026-84171The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files beforeCRITICAL9.831%EPSS 31%ileNVD2026-09-12
CVE-2026-83197Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). SupCRITICAL9.131%EPSS 31%ileNVD2026-09-15
CVE-2026-20234As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL9.931%EPSS 31%ileNVD2026-09-16
CVE-2026-92951vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses noCRITICAL9.431%EPSS 31%ileNVD2026-09-17
CVE-2026-57140PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the CRITICAL9.431%EPSS 31%ileNVD2026-09-15
CVE-2026-57148PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the pCRITICAL9.830%EPSS 30%ileNVD2026-09-15
CVE-2023-54397Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers CRITICAL9.030%EPSS 30%ileNVD2026-09-15
CVE-2026-76420A vulnerability in the internal configuration of the Apache JServ Protocol (AJP)&nbsp;connector for Cisco Secure FMC SofCRITICAL9.030%EPSS 30%ileNVD2026-09-16
CVE-2026-83099Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL10.030%EPSS 30%ileNVD2026-09-15
CVE-2026-54734Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplCRITICAL10.030%EPSS 30%ileNVD2026-09-17
CVE-2026-92717Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callCRITICAL9.330%EPSS 30%ileNVD2026-09-16
CVE-2026-55366In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead CRITICAL9.830%EPSS 30%ileNVD2026-09-15
CVE-2026-57145PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-contCRITICAL9.130%EPSS 30%ileNVD2026-09-14
CVE-2026-86863pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxCRITICAL9.330%EPSS 30%ileNVD2026-09-17
CVE-2026-92785Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist valCRITICAL9.230%EPSS 30%ileNVD2026-09-16
CVE-2026-73953Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-73963Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83054Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83098Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83151Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). SuppCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83261Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supporteCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83269Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83355Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: MeCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-87188Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.829%EPSS 29%ileNVD2026-09-15
CVE-2026-83105Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoCRITICAL9.029%EPSS 29%ileNVD2026-09-15
CVE-2026-82845The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserCRITICAL9.929%EPSS 29%ileNVD2026-09-12
CVE-2026-67100HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. wCRITICAL9.829%EPSS 29%ileNVD2026-09-18
CVE-2026-75513Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several MarteCRITICAL9.129%EPSS 29%ileNVD2026-09-16
CVE-2026-54752NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The valiCRITICAL9.629%EPSS 29%ileNVD2026-09-17
CVE-2026-84625A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, macCRITICAL9.129%EPSS 29%ileNVD2026-09-14
CVE-2024-14029Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body aCRITICAL9.029%EPSS 29%ileNVD2026-09-15
CVE-2026-83029Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). CRITICAL9.629%EPSS 29%ileNVD2026-09-15
CVE-2026-78299In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extrCRITICAL9.128%EPSS 28%ileNVD2026-09-14
CVE-2026-92805UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfCRITICAL9.328%EPSS 28%ileNVD2026-09-16
CVE-2026-90898Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that proCRITICAL9.828%EPSS 28%ileNVD2026-09-14
CVE-2026-92953vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation.CRITICAL9.328%EPSS 28%ileNVD2026-09-17
CVE-2026-92954vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises retuCRITICAL9.228%EPSS 28%ileNVD2026-09-17
CVE-2026-20325As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineerCRITICAL9.928%EPSS 28%ileNVD2026-09-16
CVE-2026-83196Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.128%EPSS 28%ileNVD2026-09-15
CVE-2026-83229Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). SupportCRITICAL9.128%EPSS 28%ileNVD2026-09-15
CVE-2026-83268Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiCRITICAL9.128%EPSS 28%ileNVD2026-09-15
CVE-2026-65381A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the proCRITICAL10.027%EPSS 27%ileNVD2026-09-14
CVE-2026-91729Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging socialCRITICAL9.627%EPSS 27%ileNVD2026-09-15
CVE-2026-91738Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execCRITICAL9.627%EPSS 27%ileNVD2026-09-15
CVE-2026-92940vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is eCRITICAL10.027%EPSS 27%ileNVD2026-09-17
CVE-2026-86709The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication CRITICAL9.827%EPSS 27%ileNVD2026-09-17
CVE-2026-20330As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplCRITICAL9.927%EPSS 27%ileNVD2026-09-16
CVE-2026-91749Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitCRITICAL9.627%EPSS 27%ileNVD2026-09-15
CVE-2026-45052Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiveCRITICAL9.327%EPSS 27%ileNVD2026-09-15
CVE-2026-92578WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as aCRITICAL9.227%EPSS 27%ileNVD2026-09-16
CVE-2026-45143Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private CRITICAL9.027%EPSS 27%ileNVD2026-09-17
CVE-2026-91718Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outsiCRITICAL9.626%EPSS 26%ileNVD2026-09-15
CVE-2026-71133Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL10.026%EPSS 26%ileNVD2026-09-15
CVE-2026-70748Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.826%EPSS 26%ileNVD2026-09-15
CVE-2026-70757Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions tCRITICAL9.826%EPSS 26%ileNVD2026-09-15
CVE-2026-70913Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions CRITICAL9.826%EPSS 26%ileNVD2026-09-15
CVE-2026-73947Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.826%EPSS 26%ileNVD2026-09-15
CVE-2026-83232Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository ExploreCRITICAL9.826%EPSS 26%ileNVD2026-09-15
CVE-2026-69204Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages cCRITICAL9.226%EPSS 26%ileNVD2026-09-15
CVE-2026-20237As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISECRITICAL9.126%EPSS 26%ileNVD2026-09-16
CVE-2026-68491An insufficient check allowed for the overwrite of arbitrary files via a symlink.CRITICAL9.426%EPSS 26%ileNVD2026-09-15
CVE-2026-48717Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler reqCRITICAL9.126%EPSS 26%ileNVD2026-09-15
CVE-2026-53952GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic fCRITICAL9.826%EPSS 26%ileNVD2026-09-11
CVE-2026-84520A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local attaCRITICAL9.826%EPSS 26%ileNVD2026-09-14
CVE-2026-87223Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.126%EPSS 26%ileNVD2026-09-15
CVE-2026-63696Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerabCRITICAL9.126%EPSS 26%ileNVD2026-09-15
CVE-2026-61568`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTCRITICAL9.626%EPSS 26%ileNVD2026-09-15
CVE-2026-59151Prowler: SAML Domain Claiming Enables Cross-Tenant Account TakeoverCRITICAL9.626%EPSS 26%ileGitHub2026-09-11
CVE-2026-92808A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unCRITICAL10.025%EPSS 25%ileNVD2026-09-16
CVE-2026-73946Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.125%EPSS 25%ileNVD2026-09-15
CVE-2026-87214Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.125%EPSS 25%ileNVD2026-09-15
CVE-2026-77972Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS respoCRITICAL9.025%EPSS 25%ileNVD2026-09-15
CVE-2026-62874Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ovCRITICAL10.025%EPSS 25%ileNVD2026-09-18
CVE-2026-62103Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.CRITICAL9.824%EPSS 24%ileNVD2026-09-11
CVE-2026-62105Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.CRITICAL9.824%EPSS 24%ileNVD2026-09-11
CVE-2026-91710Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary CRITICAL9.624%EPSS 24%ileNVD2026-09-15
CVE-2026-91716Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outsiCRITICAL9.624%EPSS 24%ileNVD2026-09-15
CVE-2026-86881A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and iCRITICAL9.124%EPSS 24%ileNVD2026-09-14
CVE-2026-73944Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-73952Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-83154Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-83201Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-87129Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-87175Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.124%EPSS 24%ileNVD2026-09-15
CVE-2026-83055Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.924%EPSS 24%ileNVD2026-09-15
CVE-2026-83058Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporCRITICAL9.924%EPSS 24%ileNVD2026-09-15
CVE-2026-87172Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.924%EPSS 24%ileNVD2026-09-15
CVE-2026-92395@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and iCRITICAL9.123%EPSS 23%ileNVD2026-09-16
CVE-2026-20332As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplCRITICAL9.923%EPSS 23%ileNVD2026-09-16
CVE-2026-93372Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbiCRITICAL9.623%EPSS 23%ileNVD2026-09-17
CVE-2026-56960In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote esCRITICAL9.823%EPSS 23%ileNVD2026-09-15
CVE-2026-73461On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated usCRITICAL9.423%EPSS 23%ileNVD2026-09-16
CVE-2026-77005The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting aCRITICAL9.623%EPSS 23%ileNVD2026-09-12
CVE-2026-11928IBM Verify Identity Access is vulnerable to a buffer overflow attack.CRITICAL9.822%EPSS 22%ileNVD2026-09-15
CVE-2026-89022BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows CRITICAL9.122%EPSS 22%ileNVD2026-09-15
CVE-2026-73945Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.921%EPSS 21%ileNVD2026-09-15
CVE-2026-83038Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). SuppoCRITICAL9.921%EPSS 21%ileNVD2026-09-15
CVE-2026-83282Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeCRITICAL9.921%EPSS 21%ileNVD2026-09-15
CVE-2026-93393A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platfCRITICAL9.221%EPSS 21%ileNVD2026-09-17
CVE-2026-15640Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.CRITICAL9.520%EPSS 20%ileNVD2026-09-16
CVE-2026-81648The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX CRITICAL10.020%EPSS 20%ileNVD2026-09-13
CVE-2026-85681The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it maCRITICAL9.820%EPSS 20%ileNVD2026-09-12
CVE-2026-86707The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is onCRITICAL9.820%EPSS 20%ileNVD2026-09-17
CVE-2026-86710The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, mCRITICAL9.820%EPSS 20%ileNVD2026-09-17
CVE-2026-73957Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportCRITICAL9.320%EPSS 20%ileNVD2026-09-15
CVE-2026-20322As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineerCRITICAL9.920%EPSS 20%ileNVD2026-09-16
CVE-2026-92943Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for CRITICAL9.220%EPSS 20%ileNVD2026-09-17
CVE-2026-54072Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authoCRITICAL9.320%EPSS 20%ileNVD2026-09-11
CVE-2026-61559`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1CRITICAL9.620%EPSS 20%ileNVD2026-09-15
CVE-2026-93374Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially exCRITICAL9.620%EPSS 20%ileNVD2026-09-17
CVE-2026-92941vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tlsCRITICAL10.019%EPSS 19%ileNVD2026-09-17
CVE-2026-67101HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionalCRITICAL9.319%EPSS 19%ileNVD2026-09-18
CVE-2026-46488motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program wCRITICAL9.119%EPSS 19%ileNVD2026-09-15
CVE-2026-73962Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.619%EPSS 19%ileNVD2026-09-15
CVE-2026-71163Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppCRITICAL9.919%EPSS 19%ileNVD2026-09-15
CVE-2026-90937froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cusCRITICAL9.418%EPSS 18%ileNVD2026-09-14
CVE-2026-87802Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.CRITICAL9.118%EPSS 18%ileNVD2026-09-14
CVE-2026-83149Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitaCRITICAL9.118%EPSS 18%ileNVD2026-09-15
CVE-2026-90456An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-knowCRITICAL9.217%EPSS 17%ileNVD2026-09-11
CVE-2026-90413In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data thaCRITICAL9.117%EPSS 17%ileNVD2026-09-17
CVE-2026-83027Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedCRITICAL9.317%EPSS 17%ileNVD2026-09-15
CVE-2026-91988atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowinCRITICAL9.217%EPSS 17%ileNVD2026-09-15
CVE-2026-12944IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) CRITICAL9.616%EPSS 16%ileNVD2026-09-14
CVE-2026-90561Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the contCRITICAL9.315%EPSS 15%ileNVD2026-09-13
CVE-2026-90943parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering CRITICAL9.315%EPSS 15%ileNVD2026-09-14
CVE-2026-93373Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary codeCRITICAL9.615%EPSS 15%ileNVD2026-09-17
CVE-2026-11921IBM Verify Identity Access containers may not apply management password change operations correctly.CRITICAL9.114%EPSS 14%ileNVD2026-09-15
CVE-2026-77405RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values witCRITICAL9.414%EPSS 14%ileNVD2026-09-16
CVE-2026-20331As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplCRITICAL9.614%EPSS 14%ileNVD2026-09-16
CVE-2026-11746Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeoverCRITICAL14%EPSS 14%ileGitHub2026-09-11
CVE-2026-84738The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import fCRITICAL9.113%EPSS 13%ileNVD2026-09-18
CVE-2026-90151In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocatiCRITICAL9.813%EPSS 13%ileNVD2026-09-17
CVE-2026-92950vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary codCRITICAL9.313%EPSS 13%ileNVD2026-09-17
CVE-2026-90999Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled teleCRITICAL9.813%EPSS 13%ileNVD2026-09-16
CVE-2026-90110In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using SCRITICAL9.412%EPSS 12%ileNVD2026-09-17
CVE-2026-90942Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /aCRITICAL9.312%EPSS 12%ileNVD2026-09-14
CVE-2026-15638An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using onCRITICAL9.110%EPSS 10%ileNVD2026-09-16
CVE-2026-90235In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks CRITICAL9.810%EPSS 10%ileNVD2026-09-17
CVE-2026-66887The affected products are missing authorization on state-changing CGIs and session checks are not performed.CRITICAL9.410%EPSS 10%ileNVD2026-09-15
CVE-2026-66890The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTCRITICAL9.410%EPSS 10%ileNVD2026-09-15
CVE-2026-87186Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporCRITICAL9.69%EPSS 9%ileNVD2026-09-15
CVE-2026-90104In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding CRITICAL9.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90173In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_freeCRITICAL9.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90711proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs ECRITICAL9.19%EPSS 9%ileNVD2026-09-15
CVE-2026-77006The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capaCRITICAL9.68%EPSS 8%ileNVD2026-09-12
CVE-2026-89930In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nestCRITICAL9.38%EPSS 8%ileNVD2026-09-16
CVE-2026-88592kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFiCRITICAL9.18%EPSS 8%ileNVD2026-09-16
CVE-2026-89914In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invCRITICAL9.38%EPSS 8%ileNVD2026-09-16
CVE-2026-89915In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter ThCRITICAL9.38%EPSS 8%ileNVD2026-09-16
CVE-2026-89916In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in MCRITICAL9.38%EPSS 8%ileNVD2026-09-16
CVE-2026-89918In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI iCRITICAL9.38%EPSS 8%ileNVD2026-09-16
CVE-2026-90414In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was CRITICAL9.18%EPSS 8%ileNVD2026-09-17
CVE-2026-89775In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR CRITICAL9.37%EPSS 7%ileNVD2026-09-16
CVE-2026-90049In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb inCRITICAL9.37%EPSS 7%ileNVD2026-09-16
CVE-2026-92489In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_outputCRITICAL9.86%EPSS 6%ileNVD2026-09-17
CVE-2026-90230In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_neCRITICAL9.16%EPSS 6%ileNVD2026-09-17
CVE-2026-61549Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_opCRITICAL9.06%EPSS 6%ileNVD2026-09-15
CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked fileCRITICAL9.46%EPSS 6%ileNVD2026-09-15
CVE-2026-89448In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enabCRITICAL9.34%EPSS 4%ileNVD2026-09-11
CVE-2026-90647ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validationCRITICAL9.14%EPSS 4%ileNVD2026-09-12
CVE-2026-15688Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control SCRITICAL9.22%EPSS 2%ileNVD2026-09-17
CVE-2026-93603vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridgeCRITICAL10.0NVD2026-09-18
CVE-2026-93605vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chiCRITICAL10.0NVD2026-09-18
CVE-2026-93606vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host APICRITICAL10.0NVD2026-09-18
CVE-2025-15399IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croCRITICAL10.0NVD2026-09-18
CVE-2026-10747IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due toCRITICAL10.0NVD2026-09-18
CVE-2025-53837XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) intCRITICAL9.9NVD2026-09-18
CVE-2026-10858IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or poteCRITICAL9.9NVD2026-09-18
CVE-2026-61682kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior tCRITICAL9.9NVD2026-09-18
CVE-2026-77240WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level securityCRITICAL9.9NVD2026-09-18
CVE-2026-75031In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick quCRITICAL9.8NVD2026-09-18
CVE-2026-84383libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF itemCRITICAL9.8NVD2026-09-18
CVE-2025-66455LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and priorCRITICAL9.8NVD2026-09-18
CVE-2026-61550Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC mesCRITICAL9.8NVD2026-09-18
USN-8725-2USN-8725-2: Linux kernel (AWS) vulnerabilitiesCRITICAL9.8Ubuntu2026-09-18
USN-8714-3USN-8714-3: Linux kernel vulnerabilitiesCRITICAL9.8Ubuntu2026-09-18
CVE-2026-28197An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crCRITICAL9.4NVD2026-09-18
CVE-2026-28198An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograpCRITICAL9.4NVD2026-09-18
CVE-2026-93659Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and aCRITICAL9.3NVD2026-09-18
CVE-2026-81321CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker wCRITICAL9.3NVD2026-09-18
CVE-2026-85497CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insuCRITICAL9.3NVD2026-09-18
USN-8781-1USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilitiesCRITICAL9.3Ubuntu2026-09-18
USN-8726-2USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilitiesCRITICAL9.3Ubuntu2026-09-18
CVE-2023-5778Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance ControlCRITICAL9.2NVD2026-09-18
CVE-2026-93762Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passesCRITICAL9.2NVD2026-09-18
CVE-2026-93019Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_paCRITICAL9.1NVD2026-09-18
CVE-2026-59163Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_CRITICAL9.1NVD2026-09-18
CVE-2026-92701trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDXCRITICAL9.1NVD2026-09-18
CVE-2026-92702Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions CRITICAL9.1NVD2026-09-18
CVE-2026-63374AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofingCRITICALGitHub2026-09-18
CVE-2026-90702A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. ThiHIGH8.586%EPSS 86%ileNVD2026-09-14
CVE-2026-90703A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrHIGH8.586%EPSS 86%ileNVD2026-09-14
CVE-2026-92398A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality oHIGH8.584%EPSS 84%ileNVD2026-09-16
CVE-2026-92397A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function ccHIGH8.582%EPSS 82%ileNVD2026-09-16
CVE-2026-27560A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendHIGH7.282%EPSS 82%ileNVD2026-09-16
CVE-2026-27561A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sendHIGH7.282%EPSS 82%ileNVD2026-09-16
CVE-2026-27562A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sendHIGH7.282%EPSS 82%ileNVD2026-09-16
CVE-2026-90847A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_seHIGH8.582%EPSS 82%ileNVD2026-09-15
CVE-2026-27547A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_infoHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27548A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_infoHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27549A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/doHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27550A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using HIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27551A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage enHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27554A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameteHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27558A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27559A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendiHIGH8.881%EPSS 81%ileNVD2026-09-16
CVE-2026-27563A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint byHIGH7.280%EPSS 80%ileNVD2026-09-16
CVE-2026-27564A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint byHIGH7.280%EPSS 80%ileNVD2026-09-16
CVE-2026-85200The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 vHIGH7.579%EPSS 79%ileNVD2026-09-12
CVE-2026-51134The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameteHIGH7.579%EPSS 79%ileNVD2026-09-15
CVE-2026-10144Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands bHIGH7.175%EPSS 75%ileNVD2026-09-15
CVE-2026-90699A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/HIGH8.675%EPSS 75%ileNVD2026-09-14
CVE-2026-18912ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, alloHIGH7.773%EPSS 73%ileNVD2026-09-18
CVE-2026-54646CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administratorHIGH7.272%EPSS 72%ileNVD2026-09-17
CVE-2026-54647CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates tHIGH7.272%EPSS 72%ileNVD2026-09-17
CVE-2026-91989atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remoteHIGH8.768%EPSS 68%ileNVD2026-09-15
CVE-2026-81476Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special ElementHIGH8.168%EPSS 68%ileNVD2026-09-17
CVE-2026-82762Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000HIGH8.766%EPSS 66%ileNVD2026-09-14
CVE-2026-82766Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If tHIGH8.766%EPSS 66%ileNVD2026-09-14
CVE-2026-82774Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2MHIGH8.766%EPSS 66%ileNVD2026-09-14
CVE-2026-82777Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PACHIGH8.766%EPSS 66%ileNVD2026-09-14
CVE-2026-92580In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClieHIGH8.764%EPSS 64%ileNVD2026-09-16
CVE-2026-84408QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged inHIGH8.763%EPSS 63%ileNVD2026-09-16
CVE-2026-18911ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolleHIGH7.563%EPSS 63%ileNVD2026-09-18
CVE-2026-77853Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 aHIGH8.762%EPSS 62%ileNVD2026-09-15
CVE-2026-82779Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM HIGH8.762%EPSS 62%ileNVD2026-09-14
CVE-2026-82791Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.HIGH8.762%EPSS 62%ileNVD2026-09-14
CVE-2026-82794SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploHIGH8.762%EPSS 62%ileNVD2026-09-14
CVE-2026-76690A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary comHIGH7.261%EPSS 61%ileNVD2026-09-15
CVE-2026-54629Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtuHIGH7.560%EPSS 60%ileNVD2026-09-14
CVE-2026-73165Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%EPSS 60%ileNVD2026-09-16
CVE-2026-73167Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%EPSS 60%ileNVD2026-09-16
CVE-2026-73176Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%EPSS 60%ileNVD2026-09-16
CVE-2026-19780Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbiHIGH8.860%EPSS 60%ileNVD2026-09-15
CVE-2026-14323The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal inHIGH7.559%EPSS 59%ileNVD2026-09-18
CVE-2026-73163Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.659%EPSS 59%ileNVD2026-09-16
CVE-2026-73164Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.659%EPSS 59%ileNVD2026-09-16
CVE-2026-42018JFrog Artifactory Improper Authentication VulnerabilityHIGH59%KEV EPSS 59%ileCISA-KEV2026-09-11
CVE-2026-16466IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.858%EPSS 58%ileNVD2026-09-14
CVE-2026-74909Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security pHIGH8.158%EPSS 58%ileNVD2026-09-16
CVE-2026-17086The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object IHIGH8.858%EPSS 58%ileNVD2026-09-18
CVE-2026-42016JFrog Artifactory Incorrect Authorization VulnerabilityHIGH58%KEV EPSS 58%ileCISA-KEV2026-09-11
CVE-2026-15815Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugHIGH8.857%EPSS 57%ileNVD2026-09-17
CVE-2026-27556A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_paramHIGH8.857%EPSS 57%ileNVD2026-09-16
CVE-2026-76689A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperHIGH7.257%EPSS 57%ileNVD2026-09-15
CVE-2026-92466zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.HIGH8.756%EPSS 56%ileNVD2026-09-16
CVE-2026-86108Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may alHIGH7.556%EPSS 56%ileNVD2026-09-16
CVE-2026-27555A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_iHIGH8.856%EPSS 56%ileNVD2026-09-16
CVE-2026-90608A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the fileHIGH8.655%EPSS 55%ileNVD2026-09-14
CVE-2026-89968In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: reject unsolicited H2CData PDUs nvmet_tHIGH7.555%EPSS 55%ileNVD2026-09-16
CVE-2026-92137Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot FrameworHIGH8.854%EPSS 54%ileNVD2026-09-16
CVE-2026-76550The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expoHIGH7.254%EPSS 54%ileNVD2026-09-16
CVE-2026-76551The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exportedHIGH7.254%EPSS 54%ileNVD2026-09-16
CVE-2026-89696In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to pHIGH7.554%EPSS 54%ileNVD2026-09-11
CVE-2026-50276dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGHIGH7.554%EPSS 54%ileNVD2026-09-14
CVE-2026-76691Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful explHIGH7.254%EPSS 54%ileNVD2026-09-15
CVE-2026-86792Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectioHIGH8.854%EPSS 54%ileNVD2026-09-16
CVE-2026-91771Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download functionHIGH8.753%EPSS 53%ileNVD2026-09-15
CVE-2026-90770Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-suppHIGH8.752%EPSS 52%ileNVD2026-09-13
CVE-2026-88765GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 befHIGH8.552%EPSS 52%ileNVD2026-09-15
CVE-2026-76678A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authenticaHIGH8.852%EPSS 52%ileNVD2026-09-15
CVE-2026-89511In the Linux kernel, the following vulnerability has been resolved: qede: Fix NULL pointer dereference in TPA fragment HIGH7.552%EPSS 52%ileNVD2026-09-11
CVE-2026-89549In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_cHIGH7.552%EPSS 52%ileNVD2026-09-11
CVE-2026-90944Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthentiHIGH8.852%EPSS 52%ileNVD2026-09-14
CVE-2026-81475Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical FunctioHIGH8.152%EPSS 52%ileNVD2026-09-17
CVE-2026-27557An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file HIGH7.552%EPSS 52%ileNVD2026-09-16
CVE-2026-82310Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivationHIGH7.252%EPSS 52%ileNVD2026-09-16
CVE-2026-89036Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write HIGH8.752%EPSS 52%ileNVD2026-09-17
CVE-2026-20340A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commandsHIGH8.852%EPSS 52%ileNVD2026-09-16
CVE-2026-82428Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from tHIGH8.851%EPSS 51%ileNVD2026-09-14
CVE-2026-14917A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is HIGH7.751%EPSS 51%ileNVD2026-09-16
CVE-2026-84869ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization VulnerabilityHIGH51%KEV EPSS 51%ileCISA-KEV2026-09-11
CVE-2026-91934Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databHIGH8.751%EPSS 51%ileNVD2026-09-15
CVE-2026-89476In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate RECHIGH7.551%EPSS 51%ileNVD2026-09-11
CVE-2026-89679In the Linux kernel, the following vulnerability has been resolved: nfsd: fix null dereference in nfsd4_setattr for delHIGH7.551%EPSS 51%ileNVD2026-09-11
CVE-2026-65364An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.551%EPSS 51%ileNVD2026-09-14
CVE-2026-84445gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() HIGH8.751%EPSS 51%ileNVD2026-09-14
CVE-2026-92355In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a patHIGH8.751%EPSS 51%ileNVD2026-09-16
CVE-2026-63126Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire proHIGH7.551%EPSS 51%ileNVD2026-09-16
CVE-2026-85893Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.HIGH8.851%EPSS 51%ileNVD2026-09-15
CVE-2026-76552The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it reHIGH8.851%EPSS 51%ileNVD2026-09-16
CVE-2026-73173Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver mHIGH8.851%EPSS 51%ileNVD2026-09-16
CVE-2026-84858ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox BypHIGH8.851%EPSS 51%ileNVD2026-09-16
CVE-2026-73166Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in theHIGH8.651%EPSS 51%ileNVD2026-09-16
CVE-2026-54504MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13HIGH8.850%EPSS 50%ileNVD2026-09-17
CVE-2026-91098HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.650%EPSS 50%ileNVD2026-09-16
CVE-2026-91105HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.650%EPSS 50%ileNVD2026-09-16
CVE-2026-89863In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: edif: Fix NULL pointer deref in RX SHIGH7.550%EPSS 50%ileNVD2026-09-16
CVE-2026-91097HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH7.050%EPSS 50%ileNVD2026-09-16
CVE-2026-85731oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked wHIGH8.850%EPSS 50%ileNVD2026-09-16
CVE-2026-76685A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malfHIGH8.150%EPSS 50%ileNVD2026-09-15
CVE-2026-14916A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKitHIGH7.750%EPSS 50%ileNVD2026-09-16
CVE-2026-69486Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a netHIGH8.850%EPSS 50%ileNVD2026-09-15
CVE-2026-93450go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatioHIGH8.750%EPSS 50%ileNVD2026-09-18
CVE-2026-92748BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authentHIGH8.750%EPSS 50%ileNVD2026-09-16
CVE-2023-45858A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.HIGH8.650%EPSS 50%ileNVD2026-09-14
CVE-2026-15579An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usernHIGH8.850%EPSS 50%ileNVD2026-09-18
CVE-2026-91948FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handliHIGH7.750%EPSS 50%ileNVD2026-09-15
CVE-2026-50285Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performsHIGH7.549%EPSS 49%ileNVD2026-09-17
CVE-2026-89680In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file leak on inter-server COPY setupHIGH7.549%EPSS 49%ileNVD2026-09-11
CVE-2026-92417A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the libHIGH7.149%EPSS 49%ileNVD2026-09-16
CVE-2026-91963FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirectiHIGH7.149%EPSS 49%ileNVD2026-09-15
CVE-2026-12728IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.849%EPSS 49%ileNVD2026-09-15
CVE-2025-14871GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, andHIGH7.549%EPSS 49%ileNVD2026-09-16
CVE-2026-1168GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, andHIGH7.549%EPSS 49%ileNVD2026-09-16
CVE-2026-89493In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate rl_used against rl_count in refcounHIGH8.849%EPSS 49%ileNVD2026-09-11
CVE-2026-88064Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstHIGH8.849%EPSS 49%ileNVD2026-09-16
CVE-2026-90778SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers wiHIGH8.749%EPSS 49%ileNVD2026-09-13
CVE-2026-90780SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when procHIGH8.749%EPSS 49%ileNVD2026-09-13
CVE-2026-89647In the Linux kernel, the following vulnerability has been resolved: ceph: do not repeat ceph_trim_dentries() if no progHIGH7.549%EPSS 49%ileNVD2026-09-11
CVE-2026-81875HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versioHIGH7.549%EPSS 49%ileNVD2026-09-16
CVE-2026-81876HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versioHIGH7.549%EPSS 49%ileNVD2026-09-16
CVE-2026-89528In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Read lists that exceed the page budHIGH7.549%EPSS 49%ileNVD2026-09-11
CVE-2026-88975Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’sHIGH7.548%EPSS 48%ileNVD2026-09-15
CVE-2026-79651A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service respoHIGH7.548%EPSS 48%ileNVD2026-09-16
CVE-2026-88616An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java compoHIGH8.848%EPSS 48%ileNVD2026-09-15
CVE-2026-89665In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range useconds in NFSv2 SETATTRHIGH8.248%EPSS 48%ileNVD2026-09-11
CVE-2026-81477Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. AHIGH7.248%EPSS 48%ileNVD2026-09-17
CVE-2026-81480Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. HIGH7.248%EPSS 48%ileNVD2026-09-17
CVE-2026-76424A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary fHIGH7.248%EPSS 48%ileNVD2026-09-16
CVE-2026-92122Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy creaHIGH8.848%EPSS 48%ileNVD2026-09-16
CVE-2026-91973Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limitiHIGH8.748%EPSS 48%ileNVD2026-09-15
CVE-2026-89648In the Linux kernel, the following vulnerability has been resolved: ceph: cap delegated inode count in ceph_parse_delegHIGH7.548%EPSS 48%ileNVD2026-09-11
CVE-2026-82399CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-overHIGH7.548%EPSS 48%ileNVD2026-09-16
CVE-2026-55416Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticatHIGH8.848%EPSS 48%ileNVD2026-09-14
CVE-2026-89554In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_JHIGH8.248%EPSS 48%ileNVD2026-09-11
CVE-2026-89586In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: fix DSM TRIM for sector sizes larHIGH8.248%EPSS 48%ileNVD2026-09-11
CVE-2026-89973In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDUHIGH8.248%EPSS 48%ileNVD2026-09-16
CVE-2026-80997In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix stalled modem TX queue after runtime HIGH7.548%EPSS 48%ileNVD2026-09-11
CVE-2026-89657In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor advHIGH7.548%EPSS 48%ileNVD2026-09-11
CVE-2026-89707In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfsHIGH7.548%EPSS 48%ileNVD2026-09-11
CVE-2026-8462SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms alloHIGH8.947%EPSS 47%ileNVD2026-09-16
CVE-2026-90689A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthHIGH8.747%EPSS 47%ileNVD2026-09-14
CVE-2026-78088The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to UnautHIGH8.847%EPSS 47%ileNVD2026-09-16
CVE-2026-91080webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticateHIGH8.747%EPSS 47%ileNVD2026-09-14
CVE-2026-76683Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allowHIGH8.147%EPSS 47%ileNVD2026-09-15
CVE-2026-78175The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all vHIGH8.847%EPSS 47%ileNVD2026-09-12
CVE-2026-11728IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.147%EPSS 47%ileNVD2026-09-15
CVE-2026-55864GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/toolHIGH7.847%EPSS 47%ileNVD2026-09-15
CVE-2026-92123Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiHIGH8.847%EPSS 47%ileNVD2026-09-16
CVE-2026-92124Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elemHIGH8.847%EPSS 47%ileNVD2026-09-16
CVE-2026-54567Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flaskHIGH7.547%EPSS 47%ileNVD2026-09-14
CVE-2026-89971In the Linux kernel, the following vulnerability has been resolved: nvme: skip the zoned limits update if the zone infoHIGH7.546%EPSS 46%ileNVD2026-09-16
CVE-2026-89084HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, HIGH8.846%EPSS 46%ileNVD2026-09-16
CVE-2026-82410Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middlewHIGH8.746%EPSS 46%ileNVD2026-09-16
CVE-2026-76686A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful explHIGH7.546%EPSS 46%ileNVD2026-09-15
CVE-2026-85756SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into HIGH7.546%EPSS 46%ileNVD2026-09-16
CVE-2026-76825RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted enHIGH8.446%EPSS 46%ileNVD2026-09-16
CVE-2026-89861In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_repoHIGH8.146%EPSS 46%ileNVD2026-09-16
CVE-2026-90946DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSoHIGH8.746%EPSS 46%ileNVD2026-09-14
CVE-2026-89547In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Check svc pool percpu counter allocation _HIGH8.146%EPSS 46%ileNVD2026-09-11
CVE-2026-89544In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs HIGH7.546%EPSS 46%ileNVD2026-09-11
CVE-2026-84549An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.546%EPSS 46%ileNVD2026-09-14
CVE-2026-91945FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to vHIGH7.146%EPSS 46%ileNVD2026-09-15
CVE-2026-13293IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.846%EPSS 46%ileNVD2026-09-14
CVE-2026-90779SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authenticatiHIGH8.746%EPSS 46%ileNVD2026-09-13
CVE-2026-50270dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGHIGH7.546%EPSS 46%ileNVD2026-09-14
CVE-2026-50277dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggagHIGH7.546%EPSS 46%ileNVD2026-09-17
CVE-2026-88263XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve tHIGH8.745%EPSS 45%ileNVD2026-09-16
CVE-2026-27552A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload endHIGH8.145%EPSS 45%ileNVD2026-09-16
CVE-2026-89028MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows reHIGH8.245%EPSS 45%ileNVD2026-09-16
CVE-2026-89483In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_diHIGH7.545%EPSS 45%ileNVD2026-09-11
CVE-2026-89059A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing HIGH7.545%EPSS 45%ileNVD2026-09-18
CVE-2026-68791Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a networkHIGH8.645%EPSS 45%ileNVD2026-09-17
CVE-2026-20342A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attackHIGH7.745%EPSS 45%ileNVD2026-09-16
CVE-2026-54135AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have aHIGH7.545%EPSS 45%ileNVD2026-09-11
CVE-2026-85917Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netwHIGH7.545%EPSS 45%ileNVD2026-09-17
CVE-2026-91964FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing SerHIGH8.745%EPSS 45%ileNVD2026-09-15
CVE-2026-20250A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwHIGH8.645%EPSS 45%ileNVD2026-09-16
CVE-2026-20295A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD SoHIGH8.645%EPSS 45%ileNVD2026-09-16
CVE-2026-54156node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonHIGH7.545%EPSS 45%ileNVD2026-09-14
CVE-2026-61554emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport accHIGH7.545%EPSS 45%ileNVD2026-09-15
CVE-2026-84997react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, ReHIGH7.545%EPSS 45%ileNVD2026-09-16
CVE-2026-28326SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. HIGH8.845%EPSS 45%ileNVD2026-09-17
CVE-2026-16428IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.844%EPSS 44%ileNVD2026-09-14
CVE-2026-34151XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinActioHIGH8.244%EPSS 44%ileNVD2026-09-14
CVE-2026-92729SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HHIGH8.844%EPSS 44%ileNVD2026-09-16
CVE-2026-93436vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode diHIGH8.744%EPSS 44%ileNVD2026-09-17
CVE-2026-54632SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the SHIGH7.544%EPSS 44%ileNVD2026-09-14
CVE-2026-63128RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP sHIGH7.544%EPSS 44%ileNVD2026-09-16
CVE-2026-79393A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon iHIGH7.544%EPSS 44%ileNVD2026-09-11
CVE-2026-76687A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authenHIGH7.544%EPSS 44%ileNVD2026-09-15
CVE-2026-87935The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1HIGH8.144%EPSS 44%ileNVD2026-09-17
CVE-2026-92980HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administratoHIGH8.644%EPSS 44%ileNVD2026-09-17
CVE-2026-84553A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mHIGH7.544%EPSS 44%ileNVD2026-09-14
CVE-2026-75516The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. HIGH8.744%EPSS 44%ileNVD2026-09-16
CVE-2026-82760Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker toHIGH8.244%EPSS 44%ileNVD2026-09-17
CVE-2026-81481Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a ResHIGH7.544%EPSS 44%ileNVD2026-09-17
CVE-2026-92604Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows dHIGH7.243%EPSS 43%ileNVD2026-09-16
CVE-2026-18212A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management HIGH7.543%EPSS 43%ileNVD2026-09-16
CVE-2026-19407Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attHIGH7.743%EPSS 43%ileNVD2026-09-15
CVE-2026-61701Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 untilHIGH8.843%EPSS 43%ileNVD2026-09-14
CVE-2026-92970HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticHIGH8.743%EPSS 43%ileNVD2026-09-17
CVE-2026-90678An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3HIGH7.543%EPSS 43%ileNVD2026-09-13
CVE-2026-92625Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/rHIGH7.543%EPSS 43%ileNVD2026-09-16
CVE-2026-92985SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dockHIGH8.643%EPSS 43%ileNVD2026-09-17
CVE-2026-80985In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in thHIGH8.243%EPSS 43%ileNVD2026-09-11
CVE-2026-76682A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticatHIGH8.243%EPSS 43%ileNVD2026-09-15
CVE-2026-45794Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS cHIGH7.743%EPSS 43%ileNVD2026-09-15
CVE-2026-54583mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dHIGH8.343%EPSS 43%ileNVD2026-09-17
CVE-2026-43692A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH8.843%EPSS 43%ileNVD2026-09-14
CVE-2026-73170Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in theHIGH8.643%EPSS 43%ileNVD2026-09-16
CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotHIGH8.843%EPSS 43%ileNVD2026-09-16
CVE-2026-91003A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of thHIGH8.543%EPSS 43%ileNVD2026-09-15
CVE-2026-89535In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_HIGH8.143%EPSS 43%ileNVD2026-09-11
CVE-2026-89667In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdowHIGH8.143%EPSS 43%ileNVD2026-09-11
CVE-2026-89704In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async COHIGH7.543%EPSS 43%ileNVD2026-09-11
CVE-2026-89706In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writebacHIGH7.543%EPSS 43%ileNVD2026-09-11
CVE-2026-76861Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an uHIGH8.742%EPSS 42%ileNVD2026-09-15
CVE-2026-89848In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing HIGH8.142%EPSS 42%ileNVD2026-09-16
CVE-2026-90777ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrHIGH8.742%EPSS 42%ileNVD2026-09-13
CVE-2026-80987In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntHIGH7.542%EPSS 42%ileNVD2026-09-11
CVE-2026-89477In the Linux kernel, the following vulnerability has been resolved: sctp: fix NULL deref on untransmitted RECONF compleHIGH7.542%EPSS 42%ileNVD2026-09-11
CVE-2026-89684In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state HIGH7.542%EPSS 42%ileNVD2026-09-11
CVE-2026-89699In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREATHIGH7.542%EPSS 42%ileNVD2026-09-11
CVE-2026-76646A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentiaHIGH7.542%EPSS 42%ileNVD2026-09-16
CVE-2026-92791Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attHIGH8.742%EPSS 42%ileNVD2026-09-16
CVE-2026-92592Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cHIGH8.742%EPSS 42%ileNVD2026-09-16
CVE-2026-71179Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used HIGH7.342%EPSS 42%ileNVD2026-09-16
CVE-2026-70658Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#validHIGH7.442%EPSS 42%ileNVD2026-09-14
CVE-2026-92469zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DEHIGH7.242%EPSS 42%ileNVD2026-09-16
CVE-2026-91972Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, reHIGH8.742%EPSS 42%ileNVD2026-09-15
CVE-2026-69217Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differingHIGH8.742%EPSS 42%ileNVD2026-09-15
CVE-2026-79993The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authentHIGH7.542%EPSS 42%ileNVD2026-09-16
CVE-2026-76409As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tHIGH8.842%EPSS 42%ileNVD2026-09-16
CVE-2026-73171Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workHIGH8.642%EPSS 42%ileNVD2026-09-16
CVE-2026-18442The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL InjectiHIGH7.542%EPSS 42%ileNVD2026-09-18
CVE-2026-86043Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWiHIGH7.542%EPSS 42%ileNVD2026-09-16
CVE-2026-12756IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attaHIGH7.142%EPSS 42%ileNVD2026-09-14
CVE-2026-12752IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attaHIGH7.142%EPSS 42%ileNVD2026-09-15
CVE-2026-90606A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpHIGH8.641%EPSS 41%ileNVD2026-09-14
CVE-2026-65375The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mHIGH7.541%EPSS 41%ileNVD2026-09-14
CVE-2026-93452snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wrHIGH8.741%EPSS 41%ileNVD2026-09-18
CVE-2026-46623Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updaHIGH7.441%EPSS 41%ileNVD2026-09-15
CVE-2026-92971InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop thaHIGH8.741%EPSS 41%ileNVD2026-09-17
CVE-2026-92566DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that aHIGH8.841%EPSS 41%ileNVD2026-09-16
CVE-2026-63506Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized aHIGH8.841%EPSS 41%ileNVD2026-09-16
CVE-2026-89664In the Linux kernel, the following vulnerability has been resolved: nfsd: release OPEN-decoded posix ACLs via op_releasHIGH7.541%EPSS 41%ileNVD2026-09-11
CVE-2026-89695In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cosHIGH7.541%EPSS 41%ileNVD2026-09-11
CVE-2026-78501Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business HIGH7.441%EPSS 41%ileNVD2026-09-17
CVE-2026-54612Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 untilHIGH8.841%EPSS 41%ileNVD2026-09-17
CVE-2026-19667If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw inHIGH7.541%EPSS 41%ileNVD2026-09-16
CVE-2026-81736If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, theHIGH7.541%EPSS 41%ileNVD2026-09-16
CVE-2026-80274If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valHIGH7.541%EPSS 41%ileNVD2026-09-16
CVE-2026-18405The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulHIGH7.241%EPSS 41%ileNVD2026-09-18
CVE-2026-84860ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints bHIGH8.841%EPSS 41%ileNVD2026-09-16
CVE-2026-91001A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp ofHIGH8.641%EPSS 41%ileNVD2026-09-15
CVE-2025-43936Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthentHIGH8.141%EPSS 41%ileNVD2026-09-16
CVE-2026-50275The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtHIGH7.541%EPSS 41%ileNVD2026-09-17
CVE-2026-73464On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requHIGH8.741%EPSS 41%ileNVD2026-09-16
CVE-2026-85469A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/dockeHIGH8.041%EPSS 41%ileNVD2026-09-16
CVE-2026-54343Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version HIGH8.741%EPSS 41%ileNVD2026-09-17
CVE-2026-77692An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(HIGH7.540%EPSS 40%ileNVD2026-09-16
CVE-2026-81563A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may faHIGH7.540%EPSS 40%ileNVD2026-09-16
CVE-2026-19666On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a speciHIGH7.540%EPSS 40%ileNVD2026-09-16
CVE-2026-76163If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of HIGH7.540%EPSS 40%ileNVD2026-09-16
CVE-2026-90776Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser componenHIGH8.740%EPSS 40%ileNVD2026-09-13
CVE-2026-91925Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-sideHIGH8.740%EPSS 40%ileNVD2026-09-15
CVE-2026-85887Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informatHIGH7.740%EPSS 40%ileNVD2026-09-18
CVE-2026-59960Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controHIGH7.540%EPSS 40%ileNVD2026-09-14
CVE-2026-73455On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafteHIGH8.940%EPSS 40%ileNVD2026-09-16
CVE-2026-44236rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersHIGH7.140%EPSS 40%ileNVD2026-09-17
CVE-2026-82685Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticatedHIGH7.640%EPSS 40%ileNVD2026-09-17
CVE-2026-87915The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress HIGH7.240%EPSS 40%ileNVD2026-09-18
CVE-2026-89266stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation sHIGH8.840%EPSS 40%ileNVD2026-09-12
CVE-2026-56825Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectiHIGH8.140%EPSS 40%ileNVD2026-09-15
CVE-2026-56827Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/AtHIGH8.140%EPSS 40%ileNVD2026-09-15
CVE-2026-56829Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStoHIGH8.140%EPSS 40%ileNVD2026-09-15
CVE-2026-59974Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languageHIGH7.840%EPSS 40%ileNVD2026-09-16
CVE-2026-54446NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensiHIGH8.140%EPSS 40%ileNVD2026-09-17
CVE-2026-90607A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the fileHIGH8.640%EPSS 40%ileNVD2026-09-14
CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an itemHIGH8.040%EPSS 40%ileNVD2026-09-16
CVE-2026-80998In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits earlHIGH7.540%EPSS 40%ileNVD2026-09-11
CVE-2026-89687In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a HIGH7.540%EPSS 40%ileNVD2026-09-11
CVE-2026-57579Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, anHIGH7.540%EPSS 40%ileNVD2026-09-14
CVE-2026-90605A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilterHIGH8.640%EPSS 40%ileNVD2026-09-14
CVE-2026-44203Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authHIGH8.340%EPSS 40%ileNVD2026-09-15
CVE-2026-69210Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength rejeHIGH7.540%EPSS 40%ileNVD2026-09-15
CVE-2026-76821OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0HIGH7.140%EPSS 40%ileNVD2026-09-15
CVE-2026-46352Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. StHIGH7.539%EPSS 39%ileNVD2026-09-16
CVE-2026-76854Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgHIGH7.139%EPSS 39%ileNVD2026-09-15
CVE-2026-84829The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an HIGH8.839%EPSS 39%ileNVD2026-09-16
CVE-2026-76684Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentiallyHIGH8.139%EPSS 39%ileNVD2026-09-15
CVE-2026-58483mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83082Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-83112Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal OperatiHIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-83188Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-83195Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-83298Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported HIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-83344Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database ApplicatHIGH7.239%EPSS 39%ileNVD2026-09-15
CVE-2026-81445Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilitHIGH7.239%EPSS 39%ileNVD2026-09-17
CVE-2026-93468The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit RHIGH8.739%EPSS 39%ileNVD2026-09-18
CVE-2026-86831Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before vHIGH8.739%EPSS 39%ileNVD2026-09-16
CVE-2026-69203Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled throuHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-69218Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83183Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83228Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83280Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versioHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83281Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions thaHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83330Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are afHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83333Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83349Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-83350Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-87138Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-87277Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-87289Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). SupportHIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-84512A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SequoiHIGH8.839%EPSS 39%ileNVD2026-09-14
CVE-2026-82770Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request HIGH8.739%EPSS 39%ileNVD2026-09-14
CVE-2026-82772Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to HIGH8.739%EPSS 39%ileNVD2026-09-14
CVE-2026-52484An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary codeHIGH8.839%EPSS 39%ileNVD2026-09-15
CVE-2026-12954The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and includingHIGH8.839%EPSS 39%ileNVD2026-09-18
CVE-2026-20135A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauHIGH8.639%EPSS 39%ileNVD2026-09-16
CVE-2026-89663In the Linux kernel, the following vulnerability has been resolved: nfsd: revoke copy-notify stateids before dropping tHIGH8.839%EPSS 39%ileNVD2026-09-11
CVE-2026-90932LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CHIGH8.639%EPSS 39%ileNVD2026-09-14
CVE-2026-92792OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing HIGH8.739%EPSS 39%ileNVD2026-09-16
CVE-2026-92596Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows reHIGH8.739%EPSS 39%ileNVD2026-09-16
CVE-2026-80218Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for oHIGH7.639%EPSS 39%ileNVD2026-09-17
CVE-2026-91955FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, alHIGH8.239%EPSS 39%ileNVD2026-09-15
CVE-2026-12354IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.539%EPSS 39%ileNVD2026-09-15
CVE-2026-17526Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with theHIGH7.239%EPSS 39%ileNVD2026-09-16
CVE-2026-20343A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downlHIGH7.538%EPSS 38%ileNVD2026-09-16
CVE-2026-91950FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigHIGH7.138%EPSS 38%ileNVD2026-09-15
CVE-2026-89711In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_cheHIGH8.238%EPSS 38%ileNVD2026-09-11
CVE-2026-71198In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to HIGH7.038%EPSS 38%ileNVD2026-09-14
CVE-2026-44793Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a nonHIGH7.038%EPSS 38%ileNVD2026-09-15
CVE-2026-93435redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious HIGH8.738%EPSS 38%ileNVD2026-09-17
CVE-2026-92129Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods HIGH7.538%EPSS 38%ileNVD2026-09-16
CVE-2026-90896Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checkoHIGH8.238%EPSS 38%ileNVD2026-09-14
CVE-2026-92761WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform priHIGH8.738%EPSS 38%ileNVD2026-09-16
CVE-2026-54182backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH8.138%EPSS 38%ileNVD2026-09-14
CVE-2026-57129PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts fHIGH7.538%EPSS 38%ileNVD2026-09-14
CVE-2026-91731Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary codHIGH8.838%EPSS 38%ileNVD2026-09-15
CVE-2026-91741Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary coHIGH8.838%EPSS 38%ileNVD2026-09-15
CVE-2026-65831ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with langHIGH7.738%EPSS 38%ileNVD2026-09-15
CVE-2026-91960FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allowHIGH7.138%EPSS 38%ileNVD2026-09-15
CVE-2026-90018In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow iHIGH8.838%EPSS 38%ileNVD2026-09-16
CVE-2026-53659http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZHIGH7.538%EPSS 38%ileNVD2026-09-14
CVE-2026-53752docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSXHIGH7.538%EPSS 38%ileNVD2026-09-14
CVE-2026-69202Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is repHIGH7.538%EPSS 38%ileNVD2026-09-15
CVE-2026-73960Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported HIGH7.538%EPSS 38%ileNVD2026-09-15
CVE-2026-87222Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.538%EPSS 38%ileNVD2026-09-15
CVE-2026-43815A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS SonomaHIGH8.838%EPSS 38%ileNVD2026-09-14
CVE-2026-85234A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a nHIGH7.538%EPSS 38%ileNVD2026-09-15
CVE-2026-92784@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source coHIGH7.738%EPSS 38%ileNVD2026-09-16
CVE-2026-57133PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tHIGH8.837%EPSS 37%ileNVD2026-09-15
CVE-2026-59739Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can disHIGH7.537%EPSS 37%ileNVD2026-09-16
CVE-2026-86003CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-overHIGH7.537%EPSS 37%ileNVD2026-09-16
CVE-2026-83308Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.137%EPSS 37%ileNVD2026-09-15
CVE-2026-83314Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions tHIGH8.137%EPSS 37%ileNVD2026-09-15
CVE-2026-83457Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.137%EPSS 37%ileNVD2026-09-15
CVE-2026-76866Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSHIGH8.637%EPSS 37%ileNVD2026-09-15
CVE-2026-76869Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscHIGH8.637%EPSS 37%ileNVD2026-09-15
CVE-2026-89685In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_reHIGH7.537%EPSS 37%ileNVD2026-09-11
CVE-2026-89692In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation rHIGH7.537%EPSS 37%ileNVD2026-09-11
CVE-2026-89561In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rplHIGH7.537%EPSS 37%ileNVD2026-09-11
CVE-2026-84544An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqHIGH7.537%EPSS 37%ileNVD2026-09-14
CVE-2026-87743A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalHIGH7.537%EPSS 37%ileNVD2026-09-18
CVE-2026-83117Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions HIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83176Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management FrameHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83273Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83322Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83325Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83328Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83440Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-83442Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-87207Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-87239Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-87244Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-87246Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.237%EPSS 37%ileNVD2026-09-15
CVE-2026-85569The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to itHIGH7.237%EPSS 37%ileNVD2026-09-16
CVE-2026-57577DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a routHIGH8.237%EPSS 37%ileNVD2026-09-14
CVE-2026-52827Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verifHIGH7.137%EPSS 37%ileNVD2026-09-15
CVE-2026-79394An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP CamerHIGH7.537%EPSS 37%ileNVD2026-09-11
CVE-2026-82028Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API servHIGH8.736%EPSS 36%ileNVD2026-09-14
CVE-2026-78472The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it HIGH8.636%EPSS 36%ileNVD2026-09-16
CVE-2026-83248Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.236%EPSS 36%ileNVD2026-09-15
CVE-2026-13260IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of HIGH7.536%EPSS 36%ileNVD2026-09-14
CVE-2026-91946FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU HIGH7.136%EPSS 36%ileNVD2026-09-15
CVE-2026-92467zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/passHIGH8.736%EPSS 36%ileNVD2026-09-16
CVE-2026-83266Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). SuppHIGH8.236%EPSS 36%ileNVD2026-09-15
CVE-2026-85385Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output enHIGH7.736%EPSS 36%ileNVD2026-09-16
CVE-2026-16673IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.836%EPSS 36%ileNVD2026-09-14
CVE-2026-68904node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using thHIGH7.036%EPSS 36%ileNVD2026-09-16
CVE-2026-89025Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to miHIGH8.736%EPSS 36%ileNVD2026-09-15
CVE-2026-63443Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10HIGH8.336%EPSS 36%ileNVD2026-09-15
CVE-2026-91940crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untHIGH8.736%EPSS 36%ileNVD2026-09-15
CVE-2026-92719Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing atHIGH8.736%EPSS 36%ileNVD2026-09-16
CVE-2026-91953FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that failHIGH7.136%EPSS 36%ileNVD2026-09-15
CVE-2026-76677A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-92952vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. HIGH8.936%EPSS 36%ileNVD2026-09-17
CVE-2026-91200DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. AttackHIGH8.736%EPSS 36%ileNVD2026-09-14
CVE-2026-83285Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).HIGH8.336%EPSS 36%ileNVD2026-09-15
CVE-2026-83307Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.336%EPSS 36%ileNVD2026-09-15
CVE-2026-16335IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, orHIGH8.136%EPSS 36%ileNVD2026-09-14
CVE-2026-84516An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH8.136%EPSS 36%ileNVD2026-09-14
CVE-2026-73959Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versiHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83008Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83032Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83033Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83086Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83148Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitaHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83160Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83163Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / FileHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83180Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83194Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83208Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions thatHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83271Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83306Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). SuppHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83315Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83348Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83454Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-83456Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-87150Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). SupporteHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-87155Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-87163Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions HIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-87179Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-87180Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.836%EPSS 36%ileNVD2026-09-15
CVE-2026-91752GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function thHIGH8.736%EPSS 36%ileNVD2026-09-15
CVE-2026-76860Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenizHIGH8.736%EPSS 36%ileNVD2026-09-15
CVE-2026-76862Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launcHIGH8.736%EPSS 36%ileNVD2026-09-15
CVE-2026-92593Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirecHIGH8.736%EPSS 36%ileNVD2026-09-16
CVE-2026-83270Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI PlatformHIGH7.536%EPSS 36%ileNVD2026-09-15
CVE-2026-83326Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versiHIGH7.536%EPSS 36%ileNVD2026-09-15
CVE-2026-83341Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClonHIGH7.536%EPSS 36%ileNVD2026-09-15
CVE-2026-44300OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoHIGH8.835%EPSS 35%ileNVD2026-09-15
CVE-2026-54916NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abseHIGH8.835%EPSS 35%ileNVD2026-09-17
CVE-2026-90930File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplHIGH7.635%EPSS 35%ileNVD2026-09-14
CVE-2026-89480In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few byHIGH7.535%EPSS 35%ileNVD2026-09-11
CVE-2026-89616In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress HIGH7.535%EPSS 35%ileNVD2026-09-11
CVE-2026-55451gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2HIGH8.335%EPSS 35%ileNVD2026-09-14
CVE-2026-87779Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard lengthHIGH7.535%EPSS 35%ileNVD2026-09-14
CVE-2026-73178Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequHIGH7.535%EPSS 35%ileNVD2026-09-14
CVE-2026-78336Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query fHIGH7.535%EPSS 35%ileNVD2026-09-14
CVE-2026-54671WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arraHIGH8.835%EPSS 35%ileNVD2026-09-17
CVE-2026-91990Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart daHIGH8.735%EPSS 35%ileNVD2026-09-15
CVE-2026-92986SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. AttackHIGH8.635%EPSS 35%ileNVD2026-09-17
CVE-2026-56668ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token ExchangeHIGH8.135%EPSS 35%ileGitHub2026-09-14
CVE-2026-89481In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a rHIGH7.535%EPSS 35%ileNVD2026-09-11
CVE-2026-77403RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-adHIGH8.935%EPSS 35%ileNVD2026-09-16
CVE-2026-77410RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the messaHIGH8.935%EPSS 35%ileNVD2026-09-16
CVE-2026-77412RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-arHIGH8.935%EPSS 35%ileNVD2026-09-16
CVE-2026-77406RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCountHIGH8.235%EPSS 35%ileNVD2026-09-16
CVE-2026-77409RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confHIGH8.235%EPSS 35%ileNVD2026-09-16
CVE-2026-75983The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to PrivileHIGH7.535%EPSS 35%ileNVD2026-09-15
CVE-2026-63460Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticaHIGH7.535%EPSS 35%ileNVD2026-09-17
CVE-2026-85715ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF HIGH7.535%EPSS 35%ileNVD2026-09-17
CVE-2026-91965WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/caleHIGH8.735%EPSS 35%ileNVD2026-09-15
CVE-2026-50125MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoHIGH7.535%EPSS 35%ileNVD2026-09-17
CVE-2026-61598djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.135%EPSS 35%ileNVD2026-09-16
CVE-2026-19248QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted inputHIGH7.135%EPSS 35%ileNVD2026-09-16
CVE-2026-59160Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts itHIGH8.835%EPSS 35%ileNVD2026-09-15
CVE-2026-87178Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.735%EPSS 35%ileNVD2026-09-15
CVE-2026-52836OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). PriorHIGH8.735%EPSS 35%ileNVD2026-09-17
CVE-2026-54354MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tranHIGH8.235%EPSS 35%ileNVD2026-09-17
CVE-2026-54547Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, AuHIGH7.435%EPSS 35%ileNVD2026-09-15
CVE-2026-86688Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier HIGH7.435%EPSS 35%ileNVD2026-09-17
CVE-2026-91709Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary cHIGH8.835%EPSS 35%ileNVD2026-09-15
CVE-2026-69208Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes HIGH7.535%EPSS 35%ileNVD2026-09-15
CVE-2026-92815changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attacHIGH8.735%EPSS 35%ileNVD2026-09-16
CVE-2026-54076ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check oHIGH8.135%EPSS 35%ileNVD2026-09-15
CVE-2026-77614Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versHIGH8.834%EPSS 34%ileNVD2026-09-17
CVE-2026-20154A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive SecurityHIGH8.634%EPSS 34%ileNVD2026-09-16
CVE-2026-20352A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attHIGH8.634%EPSS 34%ileNVD2026-09-16
CVE-2026-82717In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memorHIGH8.434%EPSS 34%ileNVD2026-09-16
CVE-2026-87105Tanium addressed a SQL injection vulnerability in Threat Response.HIGH8.834%EPSS 34%ileNVD2026-09-16
CVE-2026-54520AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior HIGH8.134%EPSS 34%ileNVD2026-09-17
CVE-2026-87791A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress DesHIGH8.734%EPSS 34%ileNVD2026-09-15
CVE-2026-20249A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2)&nbsp;for Cisco SeHIGH8.634%EPSS 34%ileNVD2026-09-16
CVE-2026-55149Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in HIGH7.534%EPSS 34%ileNVD2026-09-15
CVE-2026-87193Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.534%EPSS 34%ileNVD2026-09-15
CVE-2026-87205Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.534%EPSS 34%ileNVD2026-09-15
CVE-2026-87211Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.534%EPSS 34%ileNVD2026-09-15
CVE-2026-87221Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.534%EPSS 34%ileNVD2026-09-15
CVE-2026-90688A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBinHIGH7.134%EPSS 34%ileNVD2026-09-14
CVE-2026-92760Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restrHIGH7.134%EPSS 34%ileNVD2026-09-16
CVE-2026-83302Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supportedHIGH8.534%EPSS 34%ileNVD2026-09-15
CVE-2026-89682In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose sHIGH8.134%EPSS 34%ileNVD2026-09-11
CVE-2026-28960A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.HIGH7.534%EPSS 34%ileNVD2026-09-14
CVE-2026-90997A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics bHIGH7.434%EPSS 34%ileNVD2026-09-17
CVE-2026-83173Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). SupportedHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83237Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83259Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83300Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions thaHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83345Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions thaHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-83352Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions thaHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87126Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported HIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-87191Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.134%EPSS 34%ileNVD2026-09-15
CVE-2026-69205Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensitiHIGH8.734%EPSS 34%ileNVD2026-09-15
CVE-2026-15955IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writHIGH7.534%EPSS 34%ileNVD2026-09-14
CVE-2026-62997Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.PHIGH7.734%EPSS 34%ileNVD2026-09-16
CVE-2026-47426Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authenticaHIGH7.634%EPSS 34%ileNVD2026-09-15
CVE-2026-65390An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iHIGH8.833%EPSS 33%ileNVD2026-09-14
CVE-2026-65391An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6HIGH8.833%EPSS 33%ileNVD2026-09-14
CVE-2026-83023Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedHIGH8.633%EPSS 33%ileNVD2026-09-15
CVE-2026-83093Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoHIGH8.633%EPSS 33%ileNVD2026-09-15
CVE-2026-83034Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). SupportedHIGH7.533%EPSS 33%ileNVD2026-09-15
CVE-2026-83051Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH7.533%EPSS 33%ileNVD2026-09-15
CVE-2026-83075Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH7.533%EPSS 33%ileNVD2026-09-15
CVE-2026-83110Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH7.533%EPSS 33%ileNVD2026-09-15
CVE-2026-77615Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in OpHIGH8.733%EPSS 33%ileNVD2026-09-17
CVE-2026-76154A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor roleHIGH7.333%EPSS 33%ileNVD2026-09-17
CVE-2026-78252GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1HIGH8.233%EPSS 33%ileNVD2026-09-16
CVE-2026-83174Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application FrameworHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83177Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). SupportedHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83297Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83412Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83432Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). SHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83439Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). SHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83446Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83447Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-83455Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-87152Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). SupporHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-87153Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-87154Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-87157Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-87166Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions HIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-84629This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visioHIGH7.533%EPSS 33%ileNVD2026-09-14
CVE-2026-89063The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct ObjeHIGH7.533%EPSS 33%ileNVD2026-09-16
CVE-2026-93014RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing HIGH7.133%EPSS 33%ileNVD2026-09-17
CVE-2026-65374A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SeqHIGH8.833%EPSS 33%ileNVD2026-09-14
CVE-2026-83946Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthoriHIGH8.233%EPSS 33%ileNVD2026-09-18
CVE-2026-16141OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force thHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-57136PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-71047Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions HIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-73942Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported HIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-73949Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83005Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83009Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83013Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83017Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). SHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83090Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83119Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). SupporHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83120Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versioHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83121Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83122Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). SupportHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83124Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83168Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics InterHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83189Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). SuppHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83205Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83301Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service AdmHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83329Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83331Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83335Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics SHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83338Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics InterHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83340Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versiHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-87204Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-87224Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-87227Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.833%EPSS 33%ileNVD2026-09-15
CVE-2026-83019Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versionHIGH8.133%EPSS 33%ileNVD2026-09-15
CVE-2026-55253LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-HIGH7.733%EPSS 33%ileNVD2026-09-14
CVE-2026-92000adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncomHIGH8.733%EPSS 33%ileNVD2026-09-15
CVE-2026-65410The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macHIGH7.533%EPSS 33%ileNVD2026-09-14
CVE-2026-91721Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbHIGH8.832%EPSS 32%ileNVD2026-09-15
CVE-2026-12358IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of HIGH7.532%EPSS 32%ileNVD2026-09-15
CVE-2026-87976Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using gHIGH7.232%EPSS 32%ileNVD2026-09-16
CVE-2026-13285IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.132%EPSS 32%ileNVD2026-09-14
CVE-2026-13287IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.132%EPSS 32%ileNVD2026-09-14
CVE-2026-83143Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versioHIGH8.132%EPSS 32%ileNVD2026-09-15
CVE-2026-83422Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported HIGH8.132%EPSS 32%ileNVD2026-09-15
CVE-2026-63671MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuHIGH8.132%EPSS 32%ileNVD2026-09-16
CVE-2026-90774rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowiHIGH8.732%EPSS 32%ileNVD2026-09-13
CVE-2026-81478Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulneraHIGH8.132%EPSS 32%ileNVD2026-09-17
CVE-2026-54175backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH7.632%EPSS 32%ileNVD2026-09-14
CVE-2026-92919admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to HIGH7.232%EPSS 32%ileNVD2026-09-17
CVE-2026-86106An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions withHIGH8.732%EPSS 32%ileNVD2026-09-16
CVE-2026-86830Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution beforHIGH8.632%EPSS 32%ileNVD2026-09-14
CVE-2026-91985Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, alloHIGH8.732%EPSS 32%ileNVD2026-09-15
CVE-2026-86864pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pHIGH8.732%EPSS 32%ileNVD2026-09-17
CVE-2026-83425Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: InteHIGH8.532%EPSS 32%ileNVD2026-09-15
CVE-2026-12355IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.132%EPSS 32%ileNVD2026-09-15
CVE-2026-87225Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.132%EPSS 32%ileNVD2026-09-15
CVE-2026-87236Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.132%EPSS 32%ileNVD2026-09-15
CVE-2026-83357Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppoHIGH8.132%EPSS 32%ileNVD2026-09-15
CVE-2026-92134Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confiHIGH8.032%EPSS 32%ileNVD2026-09-16
CVE-2026-92135Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configuratHIGH8.032%EPSS 32%ileNVD2026-09-16
CVE-2026-92136Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the HIGH8.032%EPSS 32%ileNVD2026-09-16
CVE-2026-85386Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload questHIGH7.332%EPSS 32%ileNVD2026-09-16
CVE-2026-91941Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allHIGH8.732%EPSS 32%ileNVD2026-09-15
CVE-2026-83305Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.632%EPSS 32%ileNVD2026-09-15
CVE-2026-57126PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blockHIGH8.532%EPSS 32%ileNVD2026-09-14
CVE-2026-19290IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker HIGH7.532%EPSS 32%ileNVD2026-09-14
CVE-2026-28935The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS SequoiHIGH7.532%EPSS 32%ileNVD2026-09-14
CVE-2026-61599djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH8.832%EPSS 32%ileNVD2026-09-16
CVE-2026-81442Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilitHIGH8.132%EPSS 32%ileNVD2026-09-17
CVE-2026-61595djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.732%EPSS 32%ileNVD2026-09-16
CVE-2026-83128Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). SupporteHIGH7.532%EPSS 32%ileNVD2026-09-15
CVE-2026-92772Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permHIGH7.132%EPSS 32%ileNVD2026-09-16
CVE-2026-69197Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public AcceHIGH8.732%EPSS 32%ileNVD2026-09-17
CVE-2026-59973FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 aHIGH8.532%EPSS 32%ileNVD2026-09-15
CVE-2026-19499Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied ouHIGH7.732%EPSS 32%ileNVD2026-09-14
CVE-2026-84598A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSHIGH7.532%EPSS 32%ileNVD2026-09-14
CVE-2026-92961vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, alloHIGH8.731%EPSS 31%ileNVD2026-09-17
CVE-2026-47253Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functiHIGH7.331%EPSS 31%ileNVD2026-09-14
CVE-2026-76855Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-15275The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searcHIGH7.531%EPSS 31%ileNVD2026-09-18
CVE-2026-73494blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.HIGH7.431%EPSS 31%ileNVD2026-09-14
CVE-2026-68953The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclosHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-73951Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportHIGH8.131%EPSS 31%ileNVD2026-09-15
CVE-2026-83169Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). HIGH8.131%EPSS 31%ileNVD2026-09-15
CVE-2026-83191Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.131%EPSS 31%ileNVD2026-09-15
CVE-2026-83256Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.131%EPSS 31%ileNVD2026-09-15
CVE-2026-91930Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowiHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-54077ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/querHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-20344A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote HIGH8.831%EPSS 31%ileNVD2026-09-16
CVE-2026-93426SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, HIGH8.431%EPSS 31%ileNVD2026-09-17
CVE-2026-86040libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unautheHIGH7.531%EPSS 31%ileNVD2026-09-17
CVE-2026-66269Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to SelecHIGH7.331%EPSS 31%ileNVD2026-09-17
CVE-2026-55072Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objecHIGH8.531%EPSS 31%ileNVD2026-09-14
CVE-2026-83116Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). HIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83287Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: PresentatioHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83313Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83319Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported versiHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83485Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versionHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83486Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versionHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-83487Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versionHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-87124Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-87151Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). SupporteHIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-91144ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoiHIGH8.731%EPSS 31%ileNVD2026-09-14
CVE-2026-47094SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers toHIGH8.731%EPSS 31%ileNVD2026-09-16
CVE-2025-66974An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attackeHIGH7.531%EPSS 31%ileNVD2026-09-15
CVE-2026-88065`tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions HIGH7.531%EPSS 31%ileNVD2026-09-15
CVE-2026-92619The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11HIGH7.231%EPSS 31%ileNVD2026-09-18
CVE-2026-43686A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iHIGH8.831%EPSS 31%ileNVD2026-09-14
CVE-2026-91987atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zeroHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-92783Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with rHIGH7.231%EPSS 31%ileNVD2026-09-16
CVE-2026-73247Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadataHIGH8.631%EPSS 31%ileGitHub2026-09-17
CVE-2026-83088Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3HIGH7.731%EPSS 31%ileNVD2026-09-15
CVE-2026-55178GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.HIGH7.531%EPSS 31%ileNVD2026-09-15
CVE-2026-70469Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests thHIGH7.531%EPSS 31%ileNVD2026-09-16
CVE-2026-91968vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeplHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-91970Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aHIGH7.131%EPSS 31%ileNVD2026-09-15
CVE-2026-68489Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticHIGH8.730%EPSS 30%ileNVD2026-09-14
CVE-2026-89418google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a smallHIGH8.730%EPSS 30%ileNVD2026-09-17
CVE-2026-92983InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions becHIGH8.730%EPSS 30%ileNVD2026-09-17
CVE-2026-81446Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerabHIGH7.430%EPSS 30%ileNVD2026-09-17
CVE-2026-92468zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center serviceHIGH7.130%EPSS 30%ileNVD2026-09-16
CVE-2026-91996lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackerHIGH8.730%EPSS 30%ileNVD2026-09-15
CVE-2026-83152Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). SHIGH8.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83428Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83429Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations)HIGH8.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83430Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.130%EPSS 30%ileNVD2026-09-15
CVE-2026-92626Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintHIGH7.530%EPSS 30%ileNVD2026-09-16
CVE-2026-92087@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single routeHIGH8.130%EPSS 30%ileNVD2026-09-16
CVE-2026-13107IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XHIGH7.130%EPSS 30%ileNVD2026-09-14
CVE-2026-41573Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() HIGH7.130%EPSS 30%ileNVD2026-09-15
CVE-2026-12667IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83044Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions thaHIGH7.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83046Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH7.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83224Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.130%EPSS 30%ileNVD2026-09-15
CVE-2026-83284Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.630%EPSS 30%ileNVD2026-09-15
CVE-2026-69213Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames tHIGH7.530%EPSS 30%ileNVD2026-09-15
CVE-2026-57137PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loopHIGH8.830%EPSS 30%ileNVD2026-09-15
CVE-2026-82787Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, anHIGH8.730%EPSS 30%ileNVD2026-09-14
CVE-2026-81236Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%EPSS 30%ileNVD2026-09-15
CVE-2026-81239Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%EPSS 30%ileNVD2026-09-15
CVE-2026-81240Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vHIGH8.630%EPSS 30%ileNVD2026-09-15
CVE-2026-87266Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported veHIGH8.230%EPSS 30%ileNVD2026-09-15
CVE-2026-89999In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_HIGH8.130%EPSS 30%ileNVD2026-09-16
CVE-2026-57119PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversingHIGH7.530%EPSS 30%ileNVD2026-09-14
CVE-2026-92456yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerContrHIGH7.130%EPSS 30%ileNVD2026-09-16
CVE-2026-87792The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_gHIGH8.730%EPSS 30%ileNVD2026-09-15
CVE-2026-83203Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areHIGH8.630%EPSS 30%ileNVD2026-09-15
CVE-2026-55692The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH7.530%EPSS 30%ileNVD2026-09-15
CVE-2026-53554SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datHIGH7.330%EPSS 30%ileNVD2026-09-17
CVE-2026-54178backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH8.130%EPSS 30%ileNVD2026-09-14
CVE-2026-85530The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value HIGH8.130%EPSS 30%ileNVD2026-09-16
CVE-2026-83450Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). SupporteHIGH8.030%EPSS 30%ileNVD2026-09-15
CVE-2026-83483Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis)HIGH8.030%EPSS 30%ileNVD2026-09-15
CVE-2026-55091flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.HIGH7.529%EPSS 29%ileNVD2026-09-14
CVE-2026-81634In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap bHIGH7.529%EPSS 29%ileNVD2026-09-16
CVE-2026-76693A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a HIGH7.029%EPSS 29%ileNVD2026-09-15
CVE-2026-89678In the Linux kernel, the following vulnerability has been resolved: nfsd: fix partial-write detection in nfsd_direct_wrHIGH7.529%EPSS 29%ileNVD2026-09-11
CVE-2026-47424Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an aHIGH7.529%EPSS 29%ileNVD2026-09-15
CVE-2026-89849In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fHIGH8.829%EPSS 29%ileNVD2026-09-16
CVE-2026-54519AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior HIGH8.829%EPSS 29%ileNVD2026-09-17
CVE-2026-92916Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.dHIGH8.729%EPSS 29%ileNVD2026-09-17
CVE-2026-92918admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain eventsHIGH8.729%EPSS 29%ileNVD2026-09-17
CVE-2026-83215Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.229%EPSS 29%ileNVD2026-09-15
CVE-2026-83265Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). SHIGH8.229%EPSS 29%ileNVD2026-09-15
CVE-2026-83343Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SysHIGH8.229%EPSS 29%ileNVD2026-09-15
CVE-2026-13210GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1HIGH7.729%EPSS 29%ileNVD2026-09-15
CVE-2026-83304Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics WHIGH8.929%EPSS 29%ileNVD2026-09-15
CVE-2026-72524Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and accessHIGH8.829%EPSS 29%ileNVD2026-09-14
CVE-2026-83144Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management).HIGH8.729%EPSS 29%ileNVD2026-09-15
CVE-2026-83145Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management).HIGH8.729%EPSS 29%ileNVD2026-09-15
CVE-2026-83310Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.729%EPSS 29%ileNVD2026-09-15
CVE-2026-92987roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits onHIGH8.729%EPSS 29%ileNVD2026-09-17
CVE-2026-53534JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'HIGH7.529%EPSS 29%ileNVD2026-09-17
CVE-2026-90017In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_framHIGH7.129%EPSS 29%ileNVD2026-09-16
CVE-2026-83014Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). SupporteHIGH8.129%EPSS 29%ileNVD2026-09-15
CVE-2026-82768Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may beHIGH8.629%EPSS 29%ileNVD2026-09-14
CVE-2026-82793Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB ConvertHIGH8.629%EPSS 29%ileNVD2026-09-14
CVE-2026-86107The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betweeHIGH8.229%EPSS 29%ileNVD2026-09-16
CVE-2026-76442As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and CiscHIGH7.529%EPSS 29%ileNVD2026-09-14
CVE-2026-89729In the Linux kernel, the following vulnerability has been resolved: HID: sensor-hub: Fix out-of-bounds write in sensor_HIGH8.829%EPSS 29%ileNVD2026-09-11
CVE-2026-92006Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.829%EPSS 29%ileNVD2026-09-15
CVE-2026-90559snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) HIGH8.729%EPSS 29%ileNVD2026-09-12
CVE-2026-83030Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). HIGH8.329%EPSS 29%ileNVD2026-09-15
CVE-2026-69209Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unboHIGH7.529%EPSS 29%ileNVD2026-09-15
CVE-2026-85721The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTHIGH7.529%EPSS 29%ileNVD2026-09-17
CVE-2026-92779Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helHIGH7.229%EPSS 29%ileNVD2026-09-16
CVE-2026-89626In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix field sysfs group cleanup HIGH8.829%EPSS 29%ileNVD2026-09-11
CVE-2026-90000In the Linux kernel, the following vulnerability has been resolved: HID: rmi: fix OOB access with undersized RMI reportHIGH8.829%EPSS 29%ileNVD2026-09-16
CVE-2026-83072Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. AdHIGH8.129%EPSS 29%ileNVD2026-09-15
CVE-2026-83089Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versioHIGH8.129%EPSS 29%ileNVD2026-09-15
CVE-2026-83132Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions thHIGH8.129%EPSS 29%ileNVD2026-09-15
CVE-2026-89601In the Linux kernel, the following vulnerability has been resolved: ext2: Fix lost inode updates for IS_SYNC inodes exHIGH8.828%EPSS 28%ileNVD2026-09-11
CVE-2026-91936Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_diHIGH8.328%EPSS 28%ileNVD2026-09-15
CVE-2026-91938Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer HIGH7.628%EPSS 28%ileNVD2026-09-15
CVE-2026-78425Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a tickeHIGH7.628%EPSS 28%ileNVD2026-09-17
CVE-2026-83123Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). SupportHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-83011Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdHIGH8.128%EPSS 28%ileNVD2026-09-15
CVE-2026-83286Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH8.128%EPSS 28%ileNVD2026-09-15
CVE-2026-83299Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics WHIGH8.128%EPSS 28%ileNVD2026-09-15
CVE-2026-87231Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.128%EPSS 28%ileNVD2026-09-15
CVE-2026-40530An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation ManageHIGH8.028%EPSS 28%ileNVD2026-09-18
CVE-2026-90445An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validHIGH7.128%EPSS 28%ileNVD2026-09-11
CVE-2026-57130PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/emaHIGH8.128%EPSS 28%ileNVD2026-09-14
CVE-2026-92299@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMeHIGH7.128%EPSS 28%ileNVD2026-09-16
CVE-2026-90938LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/pHIGH8.828%EPSS 28%ileNVD2026-09-14
CVE-2026-91751Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowingHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-91951FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_currHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-91952FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decodingHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-91954FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface BitsHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-91956FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function thaHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-91959FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway tHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-91961FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails HIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-89951In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged fragHIGH8.828%EPSS 28%ileNVD2026-09-16
CVE-2026-79410Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attaHIGH8.128%EPSS 28%ileNVD2026-09-15
CVE-2026-90775PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befoHIGH7.128%EPSS 28%ileNVD2026-09-13
CVE-2026-93453SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing uHIGH8.728%EPSS 28%ileNVD2026-09-18
CVE-2026-82432Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalancHIGH8.128%EPSS 28%ileNVD2026-09-14
CVE-2026-76857Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_liHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-76859Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi cHIGH7.128%EPSS 28%ileNVD2026-09-15
CVE-2026-92463yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreHIGH7.128%EPSS 28%ileNVD2026-09-16
CVE-2026-92942vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside theHIGH8.728%EPSS 28%ileNVD2026-09-17
CVE-2026-54628Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtuHIGH8.628%EPSS 28%ileNVD2026-09-14
CVE-2026-16432IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attackeHIGH7.728%EPSS 28%ileNVD2026-09-14
CVE-2026-71646An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attackeHIGH7.528%EPSS 28%ileNVD2026-09-11
CVE-2026-16482The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection vHIGH7.528%EPSS 28%ileNVD2026-09-12
CVE-2026-49846libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP reHIGH7.528%EPSS 28%ileNVD2026-09-11
CVE-2026-92603ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint thatHIGH7.128%EPSS 28%ileNVD2026-09-16
CVE-2026-87171Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.728%EPSS 28%ileNVD2026-09-15
CVE-2026-87143Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.428%EPSS 28%ileNVD2026-09-15
CVE-2026-92570reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows anyHIGH7.128%EPSS 28%ileNVD2026-09-16
CVE-2026-79708GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3HIGH8.528%EPSS 28%ileNVD2026-09-16
CVE-2026-83041Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). SupportHIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-83048Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-83084Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-83134Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions thHIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-83166Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).HIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-87257Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: SDK). The supported version that is aHIGH7.728%EPSS 28%ileNVD2026-09-15
CVE-2026-89569In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: serialize security confirmation HIGH8.828%EPSS 28%ileNVD2026-09-11
CVE-2026-54596ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versiHIGH8.128%EPSS 28%ileNVD2026-09-17
CVE-2026-73966Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions thHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-83063Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). SupporHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-83453Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: InternaHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-83481Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-83482Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH7.228%EPSS 28%ileNVD2026-09-15
CVE-2026-91736Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code insideHIGH8.827%EPSS 27%ileNVD2026-09-15
CVE-2026-91737Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code insideHIGH8.827%EPSS 27%ileNVD2026-09-15
CVE-2026-91745Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside HIGH8.827%EPSS 27%ileNVD2026-09-15
CVE-2026-89180EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attaHIGH8.727%EPSS 27%ileNVD2026-09-14
CVE-2026-92599joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression deHIGH8.727%EPSS 27%ileNVD2026-09-16
CVE-2026-76679Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conducHIGH8.627%EPSS 27%ileNVD2026-09-15
CVE-2026-87196Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.227%EPSS 27%ileNVD2026-09-15
CVE-2026-87197Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.227%EPSS 27%ileNVD2026-09-15
CVE-2026-886191024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AHIGH8.127%EPSS 27%ileNVD2026-09-15
CVE-2026-87133Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.627%EPSS 27%ileNVD2026-09-15
CVE-2026-83222Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.527%EPSS 27%ileNVD2026-09-15
CVE-2026-83225Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.527%EPSS 27%ileNVD2026-09-15
CVE-2026-83276Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versioHIGH7.527%EPSS 27%ileNVD2026-09-15
CVE-2026-87148Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.527%EPSS 27%ileNVD2026-09-15
CVE-2026-81515Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicatiHIGH7.527%EPSS 27%ileNVD2026-09-17
CVE-2026-81516Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicatiHIGH7.527%EPSS 27%ileNVD2026-09-17
CVE-2026-68523`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In veHIGH7.527%EPSS 27%ileNVD2026-09-17
CVE-2026-68537`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In veHIGH7.527%EPSS 27%ileNVD2026-09-17
CVE-2026-83186Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications CalHIGH7.127%EPSS 27%ileNVD2026-09-15
CVE-2026-80989In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when briHIGH8.827%EPSS 27%ileNVD2026-09-11
CVE-2026-89844In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map updateHIGH8.827%EPSS 27%ileNVD2026-09-16
CVE-2026-89860In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at sHIGH8.827%EPSS 27%ileNVD2026-09-16
CVE-2026-83461Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH8.227%EPSS 27%ileNVD2026-09-15
CVE-2026-91969vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpHIGH7.127%EPSS 27%ileNVD2026-09-15
CVE-2026-91971Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authHIGH7.127%EPSS 27%ileNVD2026-09-15
CVE-2026-91979Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial oHIGH7.127%EPSS 27%ileNVD2026-09-15
CVE-2026-92759SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer thatHIGH7.127%EPSS 27%ileNVD2026-09-16
CVE-2026-90460An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 cHIGH7.627%EPSS 27%ileNVD2026-09-11
CVE-2026-85705The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST APIHIGH7.527%EPSS 27%ileNVD2026-09-18
CVE-2026-90560zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructHIGH8.827%EPSS 27%ileNVD2026-09-12
CVE-2026-82780Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploHIGH8.727%EPSS 27%ileNVD2026-09-14
CVE-2026-92794OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verifHIGH8.727%EPSS 27%ileNVD2026-09-16
CVE-2026-91724Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderHIGH8.327%EPSS 27%ileNVD2026-09-15
CVE-2026-73195Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet HIGH7.327%EPSS 27%ileNVD2026-09-14
CVE-2026-92460yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any HIGH7.127%EPSS 27%ileNVD2026-09-16
CVE-2026-92567TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update HIGH7.127%EPSS 27%ileNVD2026-09-16
CVE-2026-86801The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress anHIGH8.827%EPSS 27%ileNVD2026-09-17
CVE-2026-92762Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather HIGH8.727%EPSS 27%ileNVD2026-09-16
CVE-2026-83047Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH8.227%EPSS 27%ileNVD2026-09-15
CVE-2026-83078Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.227%EPSS 27%ileNVD2026-09-15
CVE-2026-54339Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passeHIGH7.727%EPSS 27%ileNVD2026-09-17
CVE-2026-15891The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record afterHIGH7.527%EPSS 27%ileNVD2026-09-13
CVE-2026-73236Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm HIGH7.527%EPSS 27%ileNVD2026-09-14
CVE-2026-92925A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packetHIGH7.127%EPSS 27%ileNVD2026-09-17
CVE-2026-92917Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and HIGH8.727%EPSS 27%ileNVD2026-09-17
CVE-2026-83178Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported HIGH8.027%EPSS 27%ileNVD2026-09-15
CVE-2026-84543An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, HIGH7.527%EPSS 27%ileNVD2026-09-14
CVE-2026-84563A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSHIGH7.527%EPSS 27%ileNVD2026-09-14
CVE-2026-53660Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializesHIGH7.427%EPSS 27%ileNVD2026-09-15
CVE-2026-92972SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefiHIGH8.827%EPSS 27%ileNVD2026-09-17
CVE-2026-90668The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which alHIGH8.727%EPSS 27%ileNVD2026-09-13
CVE-2026-73439On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gNHIGH7.727%EPSS 27%ileNVD2026-09-16
CVE-2026-87742A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DHIGH7.527%EPSS 27%ileNVD2026-09-17
CVE-2026-61590djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.427%EPSS 27%ileNVD2026-09-16
CVE-2026-89058A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's OriHIGH7.427%EPSS 27%ileNVD2026-09-18
CVE-2026-81568Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-HIGH8.726%EPSS 26%ileNVD2026-09-15
CVE-2026-92770Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentiHIGH7.126%EPSS 26%ileNVD2026-09-16
CVE-2026-52727lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publicaHIGH7.226%EPSS 26%ileNVD2026-09-17
CVE-2026-92765ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticateHIGH7.126%EPSS 26%ileNVD2026-09-16
CVE-2026-88262Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClickHIGH8.726%EPSS 26%ileNVD2026-09-15
CVE-2026-89709In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsvHIGH8.126%EPSS 26%ileNVD2026-09-11
CVE-2026-54180backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH7.626%EPSS 26%ileNVD2026-09-14
CVE-2026-53966XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live DaHIGH7.126%EPSS 26%ileNVD2026-09-15
CVE-2026-92914AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares HIGH8.626%EPSS 26%ileNVD2026-09-17
CVE-2026-90451An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication coHIGH8.226%EPSS 26%ileNVD2026-09-11
CVE-2026-91929Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resourHIGH7.626%EPSS 26%ileNVD2026-09-15
CVE-2026-91933Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenHIGH7.626%EPSS 26%ileNVD2026-09-15
CVE-2026-81901In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce paHIGH7.226%EPSS 26%ileNVD2026-09-14
CVE-2026-19774BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent aHIGH7.126%EPSS 26%ileNVD2026-09-15
CVE-2026-54155node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authenticHIGH7.726%EPSS 26%ileNVD2026-09-14
CVE-2026-73496MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, thHIGH7.726%EPSS 26%ileNVD2026-09-14
CVE-2026-87147Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-79425An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allowsHIGH8.126%EPSS 26%ileNVD2026-09-15
CVE-2026-83012Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-83068Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: CoreHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-83070Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise PortHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-83129Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versioHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-83141Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). SupporteHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-83142Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2026-87256Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported veHIGH7.726%EPSS 26%ileNVD2026-09-15
CVE-2023-50461An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backenHIGH8.826%EPSS 26%ileNVD2026-09-14
CVE-2026-91715Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary cHIGH8.826%EPSS 26%ileNVD2026-09-15
CVE-2026-80491The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL quHIGH8.626%EPSS 26%ileNVD2026-09-12
CVE-2026-87963The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before uHIGH8.626%EPSS 26%ileNVD2026-09-17
CVE-2026-87199Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-87215Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-54716Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earliHIGH7.526%EPSS 26%ileNVD2026-09-17
CVE-2026-21586This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9HIGH7.126%EPSS 26%ileNVD2026-09-15
CVE-2026-21587This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management DataHIGH7.126%EPSS 26%ileNVD2026-09-15
CVE-2026-83025Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedHIGH8.726%EPSS 26%ileNVD2026-09-15
CVE-2026-92616FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attHIGH7.626%EPSS 26%ileNVD2026-09-16
CVE-2026-83102Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoHIGH7.426%EPSS 26%ileNVD2026-09-15
CVE-2026-83184Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported HIGH7.426%EPSS 26%ileNVD2026-09-15
CVE-2025-39964Linux Kernel Race Condition VulnerabilityHIGH26%KEV EPSS 26%ileCISA-KEV2026-09-18
CVE-2026-79954NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receivHIGH8.726%EPSS 26%ileNVD2026-09-18
CVE-2026-83002Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppHIGH8.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83272Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.HIGH8.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83182Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported veHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83204Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Internal Operations). Supported verHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83262Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).HIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83289Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics WHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83295Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: PresentatioHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83318Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions thHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-83489Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: OnboardingHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-87140Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-87190Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.526%EPSS 26%ileNVD2026-09-15
CVE-2026-20247A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affeHIGH7.526%EPSS 26%ileNVD2026-09-16
CVE-2026-89898In the Linux kernel, the following vulnerability has been resolved: media: cec: extron-da-hd-4k-plus: add sanity check HIGH8.825%EPSS 25%ileNVD2026-09-16
CVE-2026-89995In the Linux kernel, the following vulnerability has been resolved: dma-direct: return struct page from dma_direct_alloHIGH8.825%EPSS 25%ileNVD2026-09-16
CVE-2026-76412A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attHIGH8.525%EPSS 25%ileNVD2026-09-16
CVE-2026-76413A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC SoftwHIGH8.225%EPSS 25%ileNVD2026-09-16
CVE-2026-92601Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-54507Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5HIGH8.425%EPSS 25%ileNVD2026-09-17
CVE-2026-83181Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions thHIGH8.225%EPSS 25%ileNVD2026-09-15
CVE-2026-54544Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbouHIGH7.225%EPSS 25%ileNVD2026-09-15
CVE-2026-77884Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. TheHIGH7.125%EPSS 25%ileNVD2026-09-14
CVE-2026-83010Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.125%EPSS 25%ileNVD2026-09-15
CVE-2026-40856WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-92771Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing HIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-87125Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal OperatioHIGH8.325%EPSS 25%ileNVD2026-09-15
CVE-2026-89632In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLenHIGH8.225%EPSS 25%ileNVD2026-09-11
CVE-2026-83408Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppoHIGH8.125%EPSS 25%ileNVD2026-09-15
CVE-2026-87195Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.425%EPSS 25%ileNVD2026-09-15
CVE-2026-87206Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.425%EPSS 25%ileNVD2026-09-15
CVE-2026-87235Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.425%EPSS 25%ileNVD2026-09-15
CVE-2026-80937In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM addressHIGH8.825%EPSS 25%ileNVD2026-09-11
CVE-2026-89774In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready HIGH8.825%EPSS 25%ileNVD2026-09-16
CVE-2026-83303Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-87265Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions HIGH8.125%EPSS 25%ileNVD2026-09-15
CVE-2026-6205An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-HIGH8.125%EPSS 25%ileNVD2026-09-18
CVE-2026-64761A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. AHIGH7.525%EPSS 25%ileNVD2026-09-14
CVE-2026-83484Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal OperationHIGH7.125%EPSS 25%ileNVD2026-09-15
CVE-2026-46498Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-suppliedHIGH7.625%EPSS 25%ileNVD2026-09-15
CVE-2026-77705The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing aHIGH7.225%EPSS 25%ileNVD2026-09-12
CVE-2026-77752The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary HIGH7.225%EPSS 25%ileNVD2026-09-12
CVE-2026-11934IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to iHIGH7.225%EPSS 25%ileNVD2026-09-15
CVE-2026-92600Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-62102Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.HIGH8.825%EPSS 25%ileNVD2026-09-11
CVE-2026-62106Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.HIGH8.825%EPSS 25%ileNVD2026-09-11
CVE-2026-87238Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.825%EPSS 25%ileNVD2026-09-15
CVE-2026-80494The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a fileHIGH8.625%EPSS 25%ileNVD2026-09-12
CVE-2026-82765Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is HIGH8.625%EPSS 25%ileNVD2026-09-14
CVE-2026-83172Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions HIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83267Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported versHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83309Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that aHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83311Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versiHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83321Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics AHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83490Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-87177Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83115Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClonHIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83167Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported HIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83213Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports). Supported versions that areHIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83235Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-83424Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported veHIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-87136Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.525%EPSS 25%ileNVD2026-09-15
CVE-2026-82035PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_oHIGH7.125%EPSS 25%ileNVD2026-09-14
CVE-2026-83332Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). SupHIGH7.125%EPSS 25%ileNVD2026-09-15
CVE-2026-87135Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.125%EPSS 25%ileNVD2026-09-15
CVE-2026-87156Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH7.125%EPSS 25%ileNVD2026-09-15
CVE-2026-87158Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). HIGH7.125%EPSS 25%ileNVD2026-09-15
CVE-2026-74926The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one ofHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-20333As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplHIGH8.825%EPSS 25%ileNVD2026-09-16
CVE-2026-20360As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tHIGH8.825%EPSS 25%ileNVD2026-09-16
CVE-2026-83135Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions thHIGH8.725%EPSS 25%ileNVD2026-09-15
CVE-2026-91733Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised HIGH8.325%EPSS 25%ileNVD2026-09-15
CVE-2026-92457yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpointHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-92459yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoinHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-92462yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowingHIGH7.125%EPSS 25%ileNVD2026-09-16
CVE-2026-54597ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versiHIGH8.324%EPSS 24%ileNVD2026-09-17
CVE-2026-81003In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingreHIGH8.124%EPSS 24%ileNVD2026-09-11
CVE-2026-86865Tanium addressed a SQL injection vulnerability in Asset.HIGH7.224%EPSS 24%ileNVD2026-09-16
CVE-2026-76870Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation roHIGH7.124%EPSS 24%ileNVD2026-09-15
CVE-2026-83418Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle CommunicatHIGH8.224%EPSS 24%ileNVD2026-09-15
CVE-2026-85410The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & TemplateHIGH8.124%EPSS 24%ileNVD2026-09-18
CVE-2026-11926IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of HIGH7.524%EPSS 24%ileNVD2026-09-15
CVE-2026-83241Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.524%EPSS 24%ileNVD2026-09-15
CVE-2026-81564Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP PHIGH7.024%EPSS 24%ileNVD2026-09-14
CVE-2023-46273Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer oveHIGH8.824%EPSS 24%ileNVD2026-09-14
CVE-2026-91943Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_HIGH8.324%EPSS 24%ileNVD2026-09-15
CVE-2026-79411Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated baHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-92716Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint thaHIGH8.624%EPSS 24%ileNVD2026-09-16
CVE-2026-92605IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, aHIGH7.124%EPSS 24%ileNVD2026-09-16
CVE-2026-91711Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-91722Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitraHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-91735Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised tHIGH8.324%EPSS 24%ileNVD2026-09-15
CVE-2026-81440Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerabilityHIGH7.324%EPSS 24%ileNVD2026-09-17
CVE-2026-14805The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This HIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-87233Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.624%EPSS 24%ileNVD2026-09-15
CVE-2026-12384Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. HIGH8.824%EPSS 24%ileNVD2026-09-18
CVE-2026-92773Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding itHIGH7.124%EPSS 24%ileNVD2026-09-16
CVE-2026-18119Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page CHIGH7.024%EPSS 24%ileNVD2026-09-14
CVE-2026-43789An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS SHIGH7.524%EPSS 24%ileNVD2026-09-14
CVE-2026-65342A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1HIGH7.524%EPSS 24%ileNVD2026-09-14
CVE-2026-65378An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS HIGH7.524%EPSS 24%ileNVD2026-09-14
CVE-2026-57135PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-HIGH7.624%EPSS 24%ileNVD2026-09-15
CVE-2026-87024Tanium addressed a SQL injection vulnerability in Asset.HIGH7.224%EPSS 24%ileNVD2026-09-16
CVE-2026-83053Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83069Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). SuppoHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83153Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83164Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).HIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83199Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83209Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions thatHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83210Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83212Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported HIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83410Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83444Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83445Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: InteHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83479Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported veHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-87162Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-87165Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-87181Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-87185Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.824%EPSS 24%ileNVD2026-09-15
CVE-2026-83334Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).HIGH7.424%EPSS 24%ileNVD2026-09-15
CVE-2026-83171Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). SupportedHIGH7.124%EPSS 24%ileNVD2026-09-15
CVE-2026-13673An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM)HIGH8.824%EPSS 24%ileNVD2026-09-18
CVE-2026-57134PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcHIGH8.224%EPSS 24%ileNVD2026-09-15
CVE-2026-43697An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.124%EPSS 24%ileNVD2026-09-14
CVE-2026-82789An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI HIGH8.723%EPSS 23%ileNVD2026-09-14
CVE-2026-93292SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints thaHIGH8.423%EPSS 23%ileNVD2026-09-17
CVE-2026-56839PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass HIGH7.323%EPSS 23%ileNVD2026-09-14
CVE-2026-18111Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero ImageHIGH8.523%EPSS 23%ileNVD2026-09-15
CVE-2026-76820OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0HIGH7.723%EPSS 23%ileNVD2026-09-15
CVE-2026-92465Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega MeHIGH7.623%EPSS 23%ileNVD2026-09-16
CVE-2026-91994Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddlewaHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-90016In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wmHIGH7.123%EPSS 23%ileNVD2026-09-16
CVE-2026-92775Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetchesHIGH7.123%EPSS 23%ileNVD2026-09-16
CVE-2026-92789Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate afterHIGH7.123%EPSS 23%ileNVD2026-09-16
CVE-2026-84606A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS HIGH7.523%EPSS 23%ileNVD2026-09-14
CVE-2026-87194Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83113Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-83449Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.523%EPSS 23%ileNVD2026-09-15
CVE-2026-76688Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that couldHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83238Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-83436Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported vHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-87192Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-54571ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3HIGH8.723%EPSS 23%ileNVD2026-09-17
CVE-2026-54451Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attackHIGH8.223%EPSS 23%ileNVD2026-09-17
CVE-2026-83106Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83114Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83292Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83296Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).HIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-83415Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-87203Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-87237Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-87254Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The suHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-90928File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads eHIGH7.123%EPSS 23%ileNVD2026-09-14
CVE-2026-92602TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigControHIGH7.123%EPSS 23%ileNVD2026-09-16
CVE-2026-91947FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a cHIGH7.723%EPSS 23%ileNVD2026-09-15
CVE-2026-90474MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server wherHIGH7.623%EPSS 23%ileNVD2026-09-12
CVE-2026-90929File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resHIGH7.223%EPSS 23%ileNVD2026-09-14
CVE-2026-73941Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppHIGH8.623%EPSS 23%ileNVD2026-09-15
CVE-2026-83074Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.623%EPSS 23%ileNVD2026-09-15
CVE-2026-83133Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions thHIGH7.523%EPSS 23%ileNVD2026-09-15
CVE-2026-25275Transient DOS when processing authentication frames with invalid FILS information element header lengths.HIGH7.523%EPSS 23%ileNVD2026-09-17
CVE-2026-83448Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.123%EPSS 23%ileNVD2026-09-15
CVE-2026-87159Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.123%EPSS 23%ileNVD2026-09-15
CVE-2026-87167Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions HIGH8.123%EPSS 23%ileNVD2026-09-15
CVE-2026-87168Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions HIGH8.123%EPSS 23%ileNVD2026-09-15
CVE-2026-89897In the Linux kernel, the following vulnerability has been resolved: media: cec: Serialize exclusive follower delivery HIGH7.523%EPSS 23%ileNVD2026-09-16
CVE-2026-40854WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session HIGH8.723%EPSS 23%ileNVD2026-09-16
CVE-2026-92801cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactivHIGH8.723%EPSS 23%ileNVD2026-09-16
CVE-2026-54087EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFieHIGH7.623%EPSS 23%ileNVD2026-09-14
CVE-2026-58502githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow rHIGH7.123%EPSS 23%ileNVD2026-09-15
CVE-2026-90041In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure sHIGH8.822%EPSS 22%ileNVD2026-09-16
CVE-2026-14850The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the useHIGH8.822%EPSS 22%ileNVD2026-09-17
CVE-2026-93377Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to HIGH8.822%EPSS 22%ileNVD2026-09-17
CVE-2026-49250Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From HIGH8.722%EPSS 22%ileNVD2026-09-14
CVE-2026-73454On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a speciallyHIGH8.622%EPSS 22%ileNVD2026-09-16
CVE-2026-87234Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-48977OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() proHIGH7.722%EPSS 22%ileNVD2026-09-17
CVE-2026-76425A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks HIGH7.622%EPSS 22%ileNVD2026-09-16
CVE-2026-55690The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH7.522%EPSS 22%ileNVD2026-09-15
CVE-2026-55691The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for emHIGH8.622%EPSS 22%ileNVD2026-09-15
CVE-2026-90555vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticHIGH7.122%EPSS 22%ileNVD2026-09-12
CVE-2026-76681A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low privHIGH8.522%EPSS 22%ileNVD2026-09-15
CVE-2026-87200Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.222%EPSS 22%ileNVD2026-09-15
CVE-2026-83561The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via CommHIGH7.222%EPSS 22%ileNVD2026-09-18
CVE-2026-83252Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.022%EPSS 22%ileNVD2026-09-15
CVE-2026-54251netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0HIGH8.722%EPSS 22%ileNVD2026-09-15
CVE-2026-63459Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/HIGH8.722%EPSS 22%ileNVD2026-09-17
CVE-2026-83435Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.222%EPSS 22%ileNVD2026-09-15
CVE-2026-83438Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported HIGH8.222%EPSS 22%ileNVD2026-09-15
CVE-2026-73958Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83101Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83192Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83245Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83246Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83254Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83255Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83258Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83351Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3HIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83464Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH8.122%EPSS 22%ileNVD2026-09-15
CVE-2026-61592djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.422%EPSS 22%ileNVD2026-09-16
CVE-2026-20300A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affectHIGH7.122%EPSS 22%ileNVD2026-09-16
CVE-2026-89413The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.HIGH8.122%EPSS 22%ileNVD2026-09-18
CVE-2026-83207Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). SupporteHIGH7.622%EPSS 22%ileNVD2026-09-15
CVE-2026-89974In the Linux kernel, the following vulnerability has been resolved: nvme-fc: fix double free of fabrics options when nvHIGH7.522%EPSS 22%ileNVD2026-09-16
CVE-2026-83003Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.522%EPSS 22%ileNVD2026-09-15
CVE-2026-83049Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). SuppoHIGH8.522%EPSS 22%ileNVD2026-09-15
CVE-2026-83083Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions thatHIGH8.522%EPSS 22%ileNVD2026-09-15
CVE-2026-59965Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-pluHIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-57132PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accHIGH8.222%EPSS 22%ileNVD2026-09-14
CVE-2026-92812decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix HIGH7.622%EPSS 22%ileNVD2026-09-16
CVE-2026-87842The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the sHIGH7.522%EPSS 22%ileNVD2026-09-12
CVE-2026-21588This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9HIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83092Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). SupporteHIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-83179Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications CalHIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-87209Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-87249Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.122%EPSS 22%ileNVD2026-09-15
CVE-2026-62107Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.HIGH8.822%EPSS 22%ileNVD2026-09-11
CVE-2026-11729IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.522%EPSS 22%ileNVD2026-09-15
CVE-2026-89034TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low EnHIGH7.122%EPSS 22%ileNVD2026-09-16
CVE-2026-70915Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions HIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83125Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). SupportHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83136Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83137Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83165Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface).HIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83411Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-83423Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported vHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-87201Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-87202Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-87226Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-76680Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low priviHIGH8.521%EPSS 21%ileNVD2026-09-15
CVE-2026-28938A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be aHIGH7.521%EPSS 21%ileNVD2026-09-14
CVE-2026-0171In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remoHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-56882In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remotHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-56920In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code.HIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-80217Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and acceHIGH8.721%EPSS 21%ileNVD2026-09-15
CVE-2026-92763Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archHIGH8.621%EPSS 21%ileNVD2026-09-16
CVE-2026-83126Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-83320Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions thHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-87131Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-87132Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-87137Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-87144Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.621%EPSS 21%ileNVD2026-09-15
CVE-2026-92780KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticatedHIGH8.721%EPSS 21%ileNVD2026-09-16
CVE-2026-92788Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's HIGH8.721%EPSS 21%ileNVD2026-09-16
CVE-2026-92796Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL reHIGH8.721%EPSS 21%ileNVD2026-09-16
CVE-2026-53714Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayHIGH7.421%EPSS 21%ileNVD2026-09-14
CVE-2026-20361As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering tHIGH8.821%EPSS 21%ileNVD2026-09-16
CVE-2026-83146Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-83243Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-83312Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: E-Business Suite - XDO). Supported verHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-83356Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security). TheHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-83437Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported veHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-87127Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions HIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-87134Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-87141Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.721%EPSS 21%ileNVD2026-09-15
CVE-2026-20335As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplHIGH8.121%EPSS 21%ileNVD2026-09-16
CVE-2026-83477Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versHIGH8.121%EPSS 21%ileNVD2026-09-15
CVE-2026-87886Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin HIGH7.821%KEV EPSS 21%ileNVD2026-09-17
CVE-2026-83087Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.221%EPSS 21%ileNVD2026-09-15
CVE-2026-47701The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocatoHIGH7.721%EPSS 21%ileNVD2026-09-14
CVE-2026-86895An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 2HIGH7.521%EPSS 21%ileNVD2026-09-14
CVE-2026-0200In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escaHIGH8.821%EPSS 21%ileNVD2026-09-15
CVE-2026-62109Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.HIGH7.621%EPSS 21%ileNVD2026-09-11
CVE-2026-62112Editor SQL Injection in Amelia <= 2.4.9 versions.HIGH7.621%EPSS 21%ileNVD2026-09-11
CVE-2026-66618Administrator SQL Injection in WP Maps <= 4.9.9 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66619Administrator SQL Injection in Newsletters <= 4.18 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66624Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66625Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66626Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66628Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66630Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-66631Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.HIGH7.621%EPSS 21%ileNVD2026-09-17
CVE-2026-76871Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.jsonHIGH7.121%EPSS 21%ileNVD2026-09-15
CVE-2026-92256NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_sHIGH7.121%EPSS 21%ileNVD2026-09-15
CVE-2026-82993Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). SuHIGH8.520%EPSS 20%ileNVD2026-09-15
CVE-2026-83007Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH8.520%EPSS 20%ileNVD2026-09-15
CVE-2026-92958vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard togeHIGH8.420%EPSS 20%ileNVD2026-09-17
CVE-2026-17467IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due tHIGH8.220%EPSS 20%ileNVD2026-09-14
CVE-2026-83067Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). SupporteHIGH8.120%EPSS 20%ileNVD2026-09-15
CVE-2026-83434Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.120%EPSS 20%ileNVD2026-09-15
CVE-2026-83161Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). SHIGH7.120%EPSS 20%ileNVD2026-09-15
CVE-2026-83187Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications CalHIGH7.120%EPSS 20%ileNVD2026-09-15
CVE-2026-54524Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HIGH7.120%EPSS 20%ileNVD2026-09-17
CVE-2026-92015Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FiHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-91937Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within HIGH8.720%EPSS 20%ileNVD2026-09-15
CVE-2026-89524In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: clamp assoc request/response lengths HIGH8.120%EPSS 20%ileNVD2026-09-11
CVE-2026-92804Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token HIGH7.120%EPSS 20%ileNVD2026-09-16
CVE-2026-52851Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an obHIGH7.120%EPSS 20%ileNVD2026-09-17
CVE-2026-81742The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets toHIGH8.820%EPSS 20%ileNVD2026-09-12
CVE-2026-88793The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actionsHIGH8.820%EPSS 20%ileNVD2026-09-13
CVE-2026-85130The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for tHIGH8.820%EPSS 20%ileNVD2026-09-17
CVE-2026-87786The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputtHIGH8.820%EPSS 20%ileNVD2026-09-17
CVE-2026-88792The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding oHIGH8.820%EPSS 20%ileNVD2026-09-17
CVE-2026-58201Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2HIGH8.720%EPSS 20%ileNVD2026-09-15
CVE-2026-92007Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92008Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92009Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92010Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92011Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92012Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92013Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability wasHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-92020Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-91935Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect HIGH8.720%EPSS 20%ileNVD2026-09-15
CVE-2026-83218Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.420%EPSS 20%ileNVD2026-09-15
CVE-2026-87130Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.420%EPSS 20%ileNVD2026-09-15
CVE-2026-73926Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). SuppHIGH8.720%EPSS 20%ileNVD2026-09-15
CVE-2026-74933The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAHIGH8.820%EPSS 20%ileNVD2026-09-13
CVE-2026-81899Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > GHIGH7.320%EPSS 20%ileNVD2026-09-15
CVE-2026-88817An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exiHIGH8.720%EPSS 20%ileNVD2026-09-16
CVE-2026-67102HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a loHIGH8.120%EPSS 20%ileNVD2026-09-18
CVE-2026-50013Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddHIGH7.520%EPSS 20%ileNVD2026-09-11
CVE-2026-16140OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an eHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-68070The affected products are missing authentication for a critical function, which could allow an attacker to run as root aHIGH8.720%EPSS 20%ileNVD2026-09-15
CVE-2026-85077Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 respoHIGH8.220%EPSS 20%ileNVD2026-09-17
CVE-2026-73954Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). SuHIGH8.120%EPSS 20%ileNVD2026-09-15
CVE-2026-65388A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attaHIGH7.520%EPSS 20%ileNVD2026-09-16
CVE-2026-0159In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote codeHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-0170In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This cHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-55331In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead toHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-56942In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could HIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-56974In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. ThHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-56997In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This cHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-58683In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead toHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-58710In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. ThHIGH8.820%EPSS 20%ileNVD2026-09-15
CVE-2026-89583In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_datHIGH8.120%EPSS 20%ileNVD2026-09-11
CVE-2026-83080Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). SuppHIGH7.120%EPSS 20%ileNVD2026-09-15
CVE-2026-83206Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services ApplicatioHIGH7.120%EPSS 20%ileNVD2026-09-15
CVE-2026-83234Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.219%EPSS 19%ileNVD2026-09-15
CVE-2026-87174Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.219%EPSS 19%ileNVD2026-09-15
CVE-2026-18117Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because thHIGH7.319%EPSS 19%ileNVD2026-09-14
CVE-2026-81090The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate theHIGH7.219%EPSS 19%ileNVD2026-09-12
CVE-2026-92753PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that HIGH7.119%EPSS 19%ileNVD2026-09-16
CVE-2026-91923KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoinHIGH8.319%EPSS 19%ileNVD2026-09-15
CVE-2026-90447A routing rule selects between two different authentication mechanisms for the same downstream service based on the valuHIGH7.119%EPSS 19%ileNVD2026-09-11
CVE-2026-91712Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromHIGH8.319%EPSS 19%ileNVD2026-09-15
CVE-2026-84099The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that HIGH8.119%EPSS 19%ileNVD2026-09-12
CVE-2026-55306In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote denHIGH7.519%EPSS 19%ileNVD2026-09-15
CVE-2026-93381Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging socHIGH8.819%EPSS 19%ileNVD2026-09-17
CVE-2026-65838Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody fHIGH8.219%EPSS 19%ileNVD2026-09-14
CVE-2026-91197Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFaHIGH7.119%EPSS 19%ileNVD2026-09-14
CVE-2026-89725In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent out-of-bounds write on RHIGH8.819%EPSS 19%ileNVD2026-09-11
CVE-2026-53557SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated useHIGH7.719%EPSS 19%ileNVD2026-09-17
CVE-2026-86444The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attributeHIGH7.119%EPSS 19%ileNVD2026-09-16
CVE-2026-91750WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url enHIGH7.119%EPSS 19%ileNVD2026-09-15
CVE-2026-20334As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplHIGH8.419%EPSS 19%ileNVD2026-09-16
CVE-2026-92598Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domainHIGH8.319%EPSS 19%ileNVD2026-09-16
CVE-2026-12666IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH8.119%EPSS 19%ileNVD2026-09-15
CVE-2026-85129The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featuHIGH8.818%EPSS 18%ileNVD2026-09-13
CVE-2026-59148@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theftHIGH8.818%EPSS 18%ileGitHub2026-09-11
CVE-2026-84047The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it HIGH8.618%EPSS 18%ileNVD2026-09-12
CVE-2026-7848Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProduHIGH8.618%EPSS 18%ileNVD2026-09-14
CVE-2026-92053Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 15HIGH8.818%EPSS 18%ileNVD2026-09-15
CVE-2026-85921Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.HIGH8.218%EPSS 18%ileNVD2026-09-14
CVE-2026-90939novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks propHIGH7.118%EPSS 18%ileNVD2026-09-14
CVE-2026-87258Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The suHIGH7.618%EPSS 18%ileNVD2026-09-15
CVE-2026-83162Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported HIGH7.418%EPSS 18%ileNVD2026-09-15
CVE-2026-92054Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbirHIGH8.818%EPSS 18%ileNVD2026-09-15
CVE-2026-92594Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fiHIGH8.718%EPSS 18%ileNVD2026-09-16
CVE-2026-66580Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.HIGH8.518%EPSS 18%ileNVD2026-09-17
CVE-2026-83138Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.018%EPSS 18%ileNVD2026-09-15
CVE-2026-83157Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClonHIGH8.018%EPSS 18%ileNVD2026-09-15
CVE-2026-92811browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints,HIGH7.118%EPSS 18%ileNVD2026-09-16
CVE-2026-83324Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI PlatformHIGH7.118%EPSS 18%ileNVD2026-09-15
CVE-2026-83131Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File downHIGH7.718%EPSS 18%ileNVD2026-09-15
CVE-2026-83233Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.718%EPSS 18%ileNVD2026-09-15
CVE-2026-83130Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported verHIGH7.118%EPSS 18%ileNVD2026-09-15
CVE-2026-90769Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated usHIGH8.318%EPSS 18%ileNVD2026-09-13
CVE-2026-87228Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.218%EPSS 18%ileNVD2026-09-15
CVE-2026-57008In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informaHIGH7.518%EPSS 18%ileNVD2026-09-15
CVE-2026-91770IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated eHIGH7.118%EPSS 18%ileNVD2026-09-15
CVE-2026-93455django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff accHIGH7.118%EPSS 18%ileNVD2026-09-18
CVE-2026-83170Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). SupportedHIGH8.018%EPSS 18%ileNVD2026-09-15
CVE-2026-87198Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.418%EPSS 18%ileNVD2026-09-15
CVE-2026-87212Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.418%EPSS 18%ileNVD2026-09-15
CVE-2026-87242Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.418%EPSS 18%ileNVD2026-09-15
CVE-2026-80071The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membershipHIGH7.218%EPSS 18%ileNVD2026-09-13
CVE-2026-91778In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a wHIGH7.218%EPSS 18%ileNVD2026-09-15
CVE-2026-92577In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_titleHIGH8.718%EPSS 18%ileNVD2026-09-16
CVE-2026-92959vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.theHIGH7.118%EPSS 18%ileNVD2026-09-17
CVE-2026-92752metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in HIGH8.718%EPSS 18%ileNVD2026-09-16
CVE-2026-92597Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a commenHIGH8.318%EPSS 18%ileNVD2026-09-16
CVE-2026-91719Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via HIGH8.118%EPSS 18%ileNVD2026-09-15
CVE-2026-92014Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in FirHIGH8.817%EPSS 17%ileNVD2026-09-15
CVE-2026-92017Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115HIGH8.817%EPSS 17%ileNVD2026-09-15
CVE-2026-92043Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in HIGH8.817%EPSS 17%ileNVD2026-09-15
CVE-2026-92052Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed inHIGH8.817%EPSS 17%ileNVD2026-09-15
CVE-2026-92984HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies aloneHIGH8.517%EPSS 17%ileNVD2026-09-17
CVE-2026-29811CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a prHIGH7.717%EPSS 17%ileNVD2026-09-13
CVE-2026-59969Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, zHIGH7.517%EPSS 17%ileNVD2026-09-16
CVE-2026-86904A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 anHIGH7.517%EPSS 17%ileNVD2026-09-14
CVE-2026-54166Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` pHIGH7.117%EPSS 17%ileNVD2026-09-11
CVE-2026-93382Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code insHIGH8.817%EPSS 17%ileNVD2026-09-17
CVE-2026-82189Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0HIGH8.717%EPSS 17%ileNVD2026-09-15
CVE-2026-91924pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, aHIGH8.417%EPSS 17%ileNVD2026-09-15
CVE-2026-54506Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5HIGH7.617%EPSS 17%ileNVD2026-09-17
CVE-2026-81238Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulneHIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-87142Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.117%EPSS 17%ileNVD2026-09-15
CVE-2026-73468A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentiaHIGH7.117%EPSS 17%ileNVD2026-09-16
CVE-2026-90223In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and addHIGH7.117%EPSS 17%ileNVD2026-09-17
CVE-2026-83451Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). SuppHIGH8.517%EPSS 17%ileNVD2026-09-15
CVE-2026-91743Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendereHIGH8.317%EPSS 17%ileNVD2026-09-15
CVE-2026-83156Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affecteHIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-83223Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions HIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-83226Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-83227Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are HIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-83257Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-83263Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).HIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-87139Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-13275IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.117%EPSS 17%ileNVD2026-09-14
CVE-2026-92776Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to aHIGH8.617%EPSS 17%ileNVD2026-09-16
CVE-2026-92782Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated aHIGH8.617%EPSS 17%ileNVD2026-09-16
CVE-2026-92793GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated useHIGH8.617%EPSS 17%ileNVD2026-09-16
CVE-2026-45048Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session HIGH8.517%EPSS 17%ileNVD2026-09-15
CVE-2026-81896Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering HIGH8.417%EPSS 17%ileNVD2026-09-15
CVE-2026-18113In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing HIGH7.517%EPSS 17%ileNVD2026-09-15
CVE-2026-18116Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in HIGH7.317%EPSS 17%ileNVD2026-09-14
CVE-2026-54634Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld HIGH7.317%EPSS 17%ileNVD2026-09-17
CVE-2026-83417Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle CommunicatHIGH7.117%EPSS 17%ileNVD2026-09-15
CVE-2026-54580mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failHIGH8.317%EPSS 17%ileNVD2026-09-17
CVE-2026-91732Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromisHIGH8.117%EPSS 17%ileNVD2026-09-15
CVE-2026-18595The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler RequHIGH7.217%EPSS 17%ileNVD2026-09-16
CVE-2026-53957Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-serHIGH7.717%EPSS 17%ileNVD2026-09-15
CVE-2026-90927filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissionHIGH7.117%EPSS 17%ileNVD2026-09-14
CVE-2026-84623An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOHIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-18110Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint HIGH8.716%EPSS 16%ileNVD2026-09-15
CVE-2026-83127Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). SupporteHIGH7.716%EPSS 16%ileNVD2026-09-15
CVE-2026-90767Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing cusHIGH7.116%EPSS 16%ileNVD2026-09-13
CVE-2026-73446On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker canHIGH7.016%EPSS 16%ileNVD2026-09-16
CVE-2026-81894Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-imHIGH8.516%EPSS 16%ileNVD2026-09-15
CVE-2026-91102HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.416%EPSS 16%ileNVD2026-09-16
CVE-2026-80943In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before indeHIGH7.616%EPSS 16%ileNVD2026-09-11
CVE-2026-85189Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 1HIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-85190Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 HIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-85191Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for JoomHIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-85195Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2HIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-88852Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0,HIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-88853Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla <HIGH7.516%EPSS 16%ileNVD2026-09-14
CVE-2026-15451The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incHIGH8.816%EPSS 16%ileNVD2026-09-12
CVE-2026-65415A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden GatHIGH8.116%EPSS 16%ileNVD2026-09-14
CVE-2026-87250Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.616%EPSS 16%ileNVD2026-09-15
CVE-2026-76676Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allowHIGH8.816%EPSS 16%ileNVD2026-09-15
CVE-2026-19535Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative weHIGH8.616%EPSS 16%ileNVD2026-09-16
CVE-2026-92800Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documentHIGH7.616%EPSS 16%ileNVD2026-09-16
CVE-2026-73462On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by HIGH7.116%EPSS 16%ileNVD2026-09-16
CVE-2026-90768CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to reHIGH8.616%EPSS 16%ileNVD2026-09-13
CVE-2026-86359Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileHIGH8.516%EPSS 16%ileNVD2026-09-16
CVE-2026-73943Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported HIGH7.616%EPSS 16%ileNVD2026-09-15
CVE-2026-83052Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH7.616%EPSS 16%ileNVD2026-09-15
CVE-2026-87213Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.416%EPSS 16%ileNVD2026-09-15
CVE-2026-93015BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP streamHIGH7.016%EPSS 16%ileNVD2026-09-17
CVE-2026-86109The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures becauHIGH7.516%EPSS 16%ileNVD2026-09-16
CVE-2026-91145Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to HIGH7.116%EPSS 16%ileNVD2026-09-14
CVE-2026-91825Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable loHIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-80935In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM addressHIGH8.816%EPSS 16%ileNVD2026-09-11
CVE-2026-83236Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH8.216%EPSS 16%ileNVD2026-09-15
CVE-2026-83242Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.316%EPSS 16%ileNVD2026-09-15
CVE-2026-87145Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.316%EPSS 16%ileNVD2026-09-15
CVE-2026-92055Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbHIGH8.816%EPSS 16%ileNVD2026-09-15
CVE-2026-1758Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GaHIGH8.316%EPSS 16%ileNVD2026-09-15
CVE-2026-15600Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotioHIGH8.616%EPSS 16%ileNVD2026-09-14
CVE-2026-87161Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH8.516%EPSS 16%ileNVD2026-09-15
CVE-2026-87229Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.216%EPSS 16%ileNVD2026-09-15
CVE-2026-83217Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that areHIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-83221Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are HIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-87146Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secuHIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-87149Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenHIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-87160Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). SupportedHIGH7.116%EPSS 16%ileNVD2026-09-15
CVE-2026-44715OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticatHIGH8.715%EPSS 15%ileNVD2026-09-11
CVE-2026-92591Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makesHIGH8.215%EPSS 15%ileNVD2026-09-16
CVE-2026-83185Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management FrameHIGH7.315%EPSS 15%ileNVD2026-09-15
CVE-2026-61596djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH7.115%EPSS 15%ileNVD2026-09-16
CVE-2026-86466Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience cHIGH8.115%EPSS 15%ileNVD2026-09-16
CVE-2026-54240libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmeticHIGH7.415%EPSS 15%ileNVD2026-09-11
CVE-2026-54241libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmeticHIGH7.415%EPSS 15%ileNVD2026-09-11
CVE-2026-92795Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticateHIGH7.115%EPSS 15%ileNVD2026-09-16
CVE-2026-86049Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupHIGH7.115%EPSS 15%ileNVD2026-09-17
CVE-2026-78428For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving anothHIGH8.015%EPSS 15%ileNVD2026-09-17
CVE-2026-87262Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering ComHIGH7.115%EPSS 15%ileNVD2026-09-15
CVE-2026-90650The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eveHIGH7.215%EPSS 15%ileNVD2026-09-15
CVE-2026-92047Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, THIGH8.815%EPSS 15%ileNVD2026-09-15
CVE-2026-92062Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, THIGH8.815%EPSS 15%ileNVD2026-09-15
CVE-2026-92073Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.HIGH8.815%EPSS 15%ileNVD2026-09-15
CVE-2026-83091Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). SupporteHIGH7.615%EPSS 15%ileNVD2026-09-15
CVE-2026-61668DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1HIGH8.115%EPSS 15%ileNVD2026-09-15
CVE-2026-83028Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedHIGH7.515%EPSS 15%ileNVD2026-09-15
CVE-2026-83065Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The suppoHIGH7.515%EPSS 15%ileNVD2026-09-15
CVE-2026-83463Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH7.515%EPSS 15%ileNVD2026-09-15
CVE-2026-87247Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.515%EPSS 15%ileNVD2026-09-15
CVE-2026-90444A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shelHIGH8.715%EPSS 15%ileNVD2026-09-11
CVE-2026-88802The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3HIGH7.514%EPSS 14%ileNVD2026-09-13
CVE-2026-87759The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pHIGH8.814%EPSS 14%ileNVD2026-09-12
CVE-2026-89023ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its RESHIGH8.814%EPSS 14%ileNVD2026-09-14
CVE-2026-88904The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests theHIGH8.814%EPSS 14%ileNVD2026-09-17
CVE-2026-25687A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruptiHIGH8.114%EPSS 14%ileNVD2026-09-14
CVE-2026-76852Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmwHIGH8.714%EPSS 14%ileNVD2026-09-15
CVE-2026-61544libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic coHIGH8.214%EPSS 14%ileNVD2026-09-15
CVE-2026-87218Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.114%EPSS 14%ileNVD2026-09-15
CVE-2026-81898In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enablingHIGH7.514%EPSS 14%ileNVD2026-09-15
CVE-2026-87208Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.114%EPSS 14%ileNVD2026-09-15
CVE-2026-54549Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, thHIGH8.314%EPSS 14%ileNVD2026-09-15
CVE-2026-87260Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering ComHIGH7.314%EPSS 14%ileNVD2026-09-15
CVE-2026-92912AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keyHIGH8.314%EPSS 14%ileNVD2026-09-17
CVE-2026-18115Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoiHIGH7.414%EPSS 14%ileNVD2026-09-15
CVE-2026-73175Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway componeHIGH7.114%EPSS 14%ileNVD2026-09-16
CVE-2026-55318In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code executHIGH8.814%EPSS 14%ileNVD2026-09-15
CVE-2026-81567Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-HIGH8.714%EPSS 14%ileNVD2026-09-15
CVE-2026-81895In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] withouHIGH8.514%EPSS 14%ileNVD2026-09-15
CVE-2026-91748Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromHIGH8.314%EPSS 14%ileNVD2026-09-15
CVE-2026-83465Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal ServerHIGH8.214%EPSS 14%ileNVD2026-09-15
CVE-2026-87264Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). SuHIGH7.714%EPSS 14%ileNVD2026-09-15
CVE-2026-87888The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its priHIGH8.014%EPSS 14%ileNVD2026-09-12
CVE-2026-90948A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer oveHIGH7.814%EPSS 14%ileNVD2026-09-14
CVE-2026-90949A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-baseHIGH7.814%EPSS 14%ileNVD2026-09-14
CVE-2026-68950The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providiHIGH8.713%EPSS 13%ileNVD2026-09-15
CVE-2026-54253TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pacHIGH8.213%EPSS 13%ileNVD2026-09-17
CVE-2026-67103HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to HIGH7.613%EPSS 13%ileNVD2026-09-18
CVE-2026-83231Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versiHIGH7.013%EPSS 13%ileNVD2026-09-15
CVE-2026-90133In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_iHIGH7.813%EPSS 13%ileNVD2026-09-17
CVE-2026-83026Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedHIGH8.313%EPSS 13%ileNVD2026-09-15
CVE-2026-83111Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). SupHIGH7.113%EPSS 13%ileNVD2026-09-15
CVE-2026-83045Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH8.513%EPSS 13%ileNVD2026-09-15
CVE-2026-83050Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported HIGH7.113%EPSS 13%ileNVD2026-09-15
CVE-2026-83230Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). SupportHIGH7.113%EPSS 13%ileNVD2026-09-15
CVE-2026-87286Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affHIGH8.113%EPSS 13%ileNVD2026-09-15
CVE-2026-87287Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affHIGH8.113%EPSS 13%ileNVD2026-09-15
CVE-2026-87288Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affHIGH8.113%EPSS 13%ileNVD2026-09-15
CVE-2026-93138In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinHIGH7.813%EPSS 13%ileNVD2026-09-17
CVE-2026-92128Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirmingHIGH7.513%EPSS 13%ileNVD2026-09-16
CVE-2026-73955Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported veHIGH7.313%EPSS 13%ileNVD2026-09-15
CVE-2026-90933laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allowHIGH7.113%EPSS 13%ileNVD2026-09-14
CVE-2026-11745Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)HIGH13%EPSS 13%ileGitHub2026-09-11
CVE-2026-89534In the Linux kernel, the following vulnerability has been resolved: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacemenHIGH8.813%EPSS 13%ileNVD2026-09-11
CVE-2026-78375Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (FreHIGH8.613%EPSS 13%ileNVD2026-09-14
CVE-2026-86320A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. HIGH7.813%EPSS 13%ileNVD2026-09-17
CVE-2026-76853Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restHIGH7.212%EPSS 12%ileNVD2026-09-15
CVE-2026-87220Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.112%EPSS 12%ileNVD2026-09-15
CVE-2026-83368Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SEHIGH7.012%EPSS 12%ileNVD2026-09-15
CVE-2026-73438On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticatedHIGH7.012%EPSS 12%ileNVD2026-09-16
CVE-2026-90052In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed discarHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-85719The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTHIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-85013A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named HIGH7.312%EPSS 12%ileNVD2026-09-15
CVE-2026-90537WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plHIGH8.812%EPSS 12%ileNVD2026-09-12
CVE-2026-55343In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This couHIGH8.012%EPSS 12%ileNVD2026-09-15
CVE-2026-87164Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). SuppHIGH8.012%EPSS 12%ileNVD2026-09-15
CVE-2026-90071In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: restore skb->dev on the slave HIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90292In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix use-after-free in siw_accept() siw_aHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90341In the Linux kernel, the following vulnerability has been resolved: firmware: coreboot: Validate table bounds The exisHIGH7.712%EPSS 12%ileNVD2026-09-17
CVE-2026-90102In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: key the data server cache on the NFS veHIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-90224In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_exHIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-90141In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/addreHIGH7.312%EPSS 12%ileNVD2026-09-17
CVE-2026-90062In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step afHIGH7.112%EPSS 12%ileNVD2026-09-17
CVE-2026-90203In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a HIGH7.112%EPSS 12%ileNVD2026-09-17
CVE-2026-93178In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage indexHIGH7.112%EPSS 12%ileNVD2026-09-17
CVE-2026-93046In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_argsHIGH7.012%EPSS 12%ileNVD2026-09-17
CVE-2026-90286In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx6: Use PFP on the compute queues too HIGH8.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90329In the Linux kernel, the following vulnerability has been resolved: HID: synchronize input before cleaning up a failed HIGH8.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90120In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Check get_logical_index() return vaHIGH8.412%EPSS 12%ileNVD2026-09-17
CVE-2026-90332In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush cached MSI write before unmappiHIGH8.212%EPSS 12%ileNVD2026-09-17
CVE-2026-90143In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF parsHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90225In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket lHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90388In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Check atomic pool allocation result direHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-93037In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_HIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-93170In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix channel idle state managHIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-93165In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Fix memory overread in HIGH7.712%EPSS 12%ileNVD2026-09-17
CVE-2026-90103In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion enHIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-90293In the Linux kernel, the following vulnerability has been resolved: IB/isert: post the full-feature receive buffers aftHIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-90294In the Linux kernel, the following vulnerability has been resolved: IB/isert: delay the final Login Response until the HIGH7.512%EPSS 12%ileNVD2026-09-17
CVE-2026-93039In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc faHIGH7.412%EPSS 12%ileNVD2026-09-17
CVE-2026-93177In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage indexHIGH7.312%EPSS 12%ileNVD2026-09-17
CVE-2026-92750Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticatHIGH7.112%EPSS 12%ileNVD2026-09-16
CVE-2026-90372In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: avoid nss underflow in mt7915_mHIGH7.112%EPSS 12%ileNVD2026-09-17
CVE-2026-90419In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root blHIGH7.112%EPSS 12%ileNVD2026-09-17
CVE-2026-90403In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix error path in rtl_pci_probeHIGH7.012%EPSS 12%ileNVD2026-09-17
CVE-2026-92504In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe faiHIGH7.012%EPSS 12%ileNVD2026-09-17
CVE-2026-93054In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration HIGH7.012%EPSS 12%ileNVD2026-09-17
CVE-2026-93144In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers HIGH7.812%EPSS 12%ileNVD2026-09-17
CVE-2026-90772Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HIGH8.311%EPSS 11%ileNVD2026-09-13
CVE-2026-54581mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.cHIGH8.311%EPSS 11%ileNVD2026-09-17
CVE-2026-63325Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/rHIGH7.811%EPSS 11%ileNVD2026-09-16
CVE-2023-28148A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.HIGH7.211%EPSS 11%ileNVD2026-09-14
CVE-2026-54239Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertexHIGH8.811%EPSS 11%ileNVD2026-09-17
CVE-2026-58704In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (prHIGH8.811%KEV EPSS 11%ileNVD2026-09-15
CVE-2026-90162In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer publishing granted locks to prevent UAHIGH8.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90553vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores tHIGH8.511%EPSS 11%ileNVD2026-09-12
CVE-2026-20773A role-based access control issue was identified in the administrative expression evaluation functionality. This could aHIGH8.511%EPSS 11%ileNVD2026-09-14
CVE-2026-86894A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to breHIGH7.511%EPSS 11%ileNVD2026-09-14
CVE-2026-90448A deployment mode intended to expose only read access to stored data proxies a set of application programming interface HIGH7.111%EPSS 11%ileNVD2026-09-11
CVE-2026-91846Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whetheHIGH7.111%EPSS 11%ileNVD2026-09-15
CVE-2026-91992Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused acrHIGH8.211%EPSS 11%ileNVD2026-09-15
CVE-2026-90092In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject accept queue add unless BTHIGH8.011%EPSS 11%ileNVD2026-09-17
CVE-2026-90057In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free inHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90207In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize input teardown with evenHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90316In the Linux kernel, the following vulnerability has been resolved: drm/omap: dsi: Do not copy isr table To be able toHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90325In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: skip dying blkg in blkcg_activate_policHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-92507In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_deallHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-92508In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_HIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90353In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix ext PHY use-after-free on rHIGH7.011%EPSS 11%ileNVD2026-09-17
CVE-2026-92033Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.HIGH8.811%EPSS 11%ileNVD2026-09-15
CVE-2026-90255In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context lifeHIGH8.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90357In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unlink TWT flow if the MCU rejeHIGH8.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90176In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte rangHIGH8.111%EPSS 11%ileNVD2026-09-17
CVE-2026-90091In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listeHIGH8.011%EPSS 11%ileNVD2026-09-17
CVE-2026-90309In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold CQ references when processing EQ eHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-93137In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vmHIGH7.811%EPSS 11%ileNVD2026-09-17
CVE-2026-90067In the Linux kernel, the following vulnerability has been resolved: libceph: validate banner payload length When parsiHIGH7.511%EPSS 11%ileNVD2026-09-17
CVE-2026-90228In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_executHIGH7.511%EPSS 11%ileNVD2026-09-17
CVE-2026-93151In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix response resource leak on queue teaHIGH7.511%EPSS 11%ileNVD2026-09-17
CVE-2026-92525In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing HIGH7.111%EPSS 11%ileNVD2026-09-17
CVE-2026-87187Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.811%EPSS 11%ileNVD2026-09-15
CVE-2026-93494A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending HIGH7.511%EPSS 11%ileNVD2026-09-18
CVE-2026-83081Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: CoreHIGH8.011%EPSS 11%ileNVD2026-09-15
CVE-2026-87245Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.011%EPSS 11%ileNVD2026-09-15
CVE-2026-89080The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an HIGH7.510%EPSS 10%ileNVD2026-09-13
CVE-2026-49464NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customHIGH8.110%EPSS 10%ileNVD2026-09-11
CVE-2026-26950Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerabilHIGH8.110%EPSS 10%ileNVD2026-09-17
CVE-2026-83022Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH7.910%EPSS 10%ileNVD2026-09-15
CVE-2026-86862pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbnHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90246In the Linux kernel, the following vulnerability has been resolved: apparmor: fix integer overflow in verify_tags() bouHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-93042In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors withoHIGH8.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90399In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix stride mismatch in mac_phy_caps_pHIGH8.410%EPSS 10%ileNVD2026-09-17
CVE-2026-93107In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet aftHIGH8.210%EPSS 10%ileNVD2026-09-17
CVE-2026-90199In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in mi_enum_attr(HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90227In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90291In the Linux kernel, the following vulnerability has been resolved: module/dups: Fix use-after-free in kmod_dup_req lifHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90308In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold QP references for AE and CM procesHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90358In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix trampoline stack size for 128-bit argHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90387In the Linux kernel, the following vulnerability has been resolved: swiotlb: Preserve allocation virtual address for dyHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90392In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF when reading bpf link info HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-93070In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after iniHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90137In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bouHIGH7.710%EPSS 10%ileNVD2026-09-17
CVE-2026-90229In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Destroy the admin queue on removal TheHIGH7.410%EPSS 10%ileNVD2026-09-17
CVE-2026-93121In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_HIGH7.010%EPSS 10%ileNVD2026-09-17
CVE-2026-90241In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Tear down scalable-mode context on probHIGH8.210%EPSS 10%ileNVD2026-09-17
CVE-2026-83220Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). SuppHIGH8.110%EPSS 10%ileNVD2026-09-15
CVE-2026-90153In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DACHIGH8.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90243In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down cHIGH8.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90326In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90383In the Linux kernel, the following vulnerability has been resolved: misc: sgi-gru: remove interrupt-context page-table HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90407In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_cHIGH7.710%EPSS 10%ileNVD2026-09-17
CVE-2026-55887MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YHIGH8.710%EPSS 10%ileNVD2026-09-15
CVE-2026-84581A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SequoiHIGH8.410%EPSS 10%ileNVD2026-09-14
CVE-2026-83096Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoHIGH7.910%EPSS 10%ileNVD2026-09-15
CVE-2026-90240In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush context cache with correct SID whHIGH8.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90371In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RXDMAD_C buffer recycling race TheHIGH8.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90380In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: fix use-after-free in mt76_rx_pHIGH8.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90191In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notificationHIGH8.410%EPSS 10%ileNVD2026-09-17
CVE-2026-90231In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unconfined user namespace restrictionHIGH8.410%EPSS 10%ileNVD2026-09-17
CVE-2026-83085Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.210%EPSS 10%ileNVD2026-09-15
CVE-2026-90051In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx dHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90069In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - allocate async request context whenHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90146In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install()HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90204In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate DIO orphan slot during inode read HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90205In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate orphan slot during inode read PatcHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90244In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Restore locking around msi_page_list UnHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90312In the Linux kernel, the following vulnerability has been resolved: bpf: Check load-acquire src ptr type before the loaHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90324In the Linux kernel, the following vulnerability has been resolved: ublk: check import_ubuf() return value import_ubufHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90343In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardoHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90429In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR agaHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-92518In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcallHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-93079In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-93122In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uac: validate rate list length before HIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-93154In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Add refcounting to user ring MRs PreveHIGH7.810%EPSS 10%ileNVD2026-09-17
CVE-2026-90059In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA offHIGH7.510%EPSS 10%ileNVD2026-09-17
CVE-2026-90149In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 dHIGH7.510%EPSS 10%ileNVD2026-09-17
CVE-2026-90089In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Validate the FW dump header lHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90145In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skbHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90161In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-diHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-90260In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't clobber the extent buffer when HIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-20336As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security ApplHIGH8.810%EPSS 10%ileNVD2026-09-16
CVE-2026-93189In the Linux kernel, the following vulnerability has been resolved: HID: core: quiesce input in hid_hw_stop() to prevenHIGH8.810%EPSS 10%ileNVD2026-09-17
CVE-2026-66372The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding tokeHIGH7.610%EPSS 10%ileNVD2026-09-15
CVE-2026-93203In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid CRC corruption due to parallHIGH7.110%EPSS 10%ileNVD2026-09-17
CVE-2026-63127RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crHIGH8.210%EPSS 10%ileNVD2026-09-16
CVE-2026-82438Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP comHIGH8.110%EPSS 10%ileNVD2026-09-14
CVE-2026-19655On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with HIGH7.19%EPSS 9%ileNVD2026-09-15
CVE-2026-79298An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attckerHIGH8.49%EPSS 9%ileNVD2026-09-16
CVE-2026-85892Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-HIGH7.89%EPSS 9%ileNVD2026-09-14
CVE-2026-57112PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolHIGH8.39%EPSS 9%ileNVD2026-09-15
CVE-2026-93190In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: Reject out-of-boundHIGH8.49%EPSS 9%ileNVD2026-09-17
CVE-2026-76692A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtainHIGH7.19%EPSS 9%ileNVD2026-09-15
CVE-2026-93063In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: check SAP message length beforeHIGH8.49%EPSS 9%ileNVD2026-09-17
CVE-2026-81897In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not valiHIGH7.79%EPSS 9%ileNVD2026-09-15
CVE-2026-86406The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a memHIGH7.59%EPSS 9%ileNVD2026-09-13
CVE-2026-90256In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use proto_lock for l2cap_data to HIGH8.89%EPSS 9%ileNVD2026-09-17
CVE-2026-87767The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter befHIGH8.69%EPSS 9%ileNVD2026-09-18
CVE-2026-87770The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using HIGH8.69%EPSS 9%ileNVD2026-09-18
CVE-2026-87771The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using themHIGH8.69%EPSS 9%ileNVD2026-09-18
CVE-2026-87774The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to HIGH8.69%EPSS 9%ileNVD2026-09-18
CVE-2026-87775The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to HIGH8.69%EPSS 9%ileNVD2026-09-18
CVE-2026-40857WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. THIGH8.49%EPSS 9%ileNVD2026-09-16
CVE-2026-87210Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.39%EPSS 9%ileNVD2026-09-15
CVE-2026-82786Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerHIGH8.29%EPSS 9%ileNVD2026-09-14
CVE-2026-55225Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IHIGH8.09%EPSS 9%ileNVD2026-09-15
CVE-2026-90093In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/sHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90142In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix resize of the RX ring When a AF_XDHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90237In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: move custom expectation support HIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90317In the Linux kernel, the following vulnerability has been resolved: bpf: Invalidate RCU pointers after final spin unlocHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90320In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate external xattr entries when readingHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-93105In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unrHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90172In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: destroy QP before mem pools on acceHIGH7.59%EPSS 9%ileNVD2026-09-17
CVE-2026-90234In the Linux kernel, the following vulnerability has been resolved: NFS: Return a delegation the client fails to recordHIGH7.59%EPSS 9%ileNVD2026-09-17
CVE-2026-90132In the Linux kernel, the following vulnerability has been resolved: ntfs: reject unprivileged writes to reserved $LX* xHIGH7.19%EPSS 9%ileNVD2026-09-17
CVE-2026-90347In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: Keep 'orig_x0' in-sync with x0 on syHIGH8.49%EPSS 9%ileNVD2026-09-17
CVE-2026-90651Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificHIGH8.19%EPSS 9%ileNVD2026-09-13
CVE-2026-83073Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH8.19%EPSS 9%ileNVD2026-09-15
CVE-2026-90268In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix error handling in sd_probe() after laHIGH8.19%EPSS 9%ileNVD2026-09-17
CVE-2026-90301In the Linux kernel, the following vulnerability has been resolved: ocfs2: o2hb: quiesce negotiate handlers and timeoutHIGH8.19%EPSS 9%ileNVD2026-09-17
CVE-2026-90111In the Linux kernel, the following vulnerability has been resolved: ip6mr: do not clone dst in ip6mr_cache_report() IPHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90118In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompreHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90177In the Linux kernel, the following vulnerability has been resolved: bpf: Check pointer type for all atomic RMW paths AHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90210In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in bpf_trampoline_multi_attach_free onHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90217In the Linux kernel, the following vulnerability has been resolved: bpf: Compare iterator types during state pruning AHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90289In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Resize MST HDCP per-connector arraHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90321In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline xattrs during inode block vaHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-92485In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The tHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-93127In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing staHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-93147In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Replace ly instruction with llgf cpu_nr HIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-93175In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in CRTC resetHIGH7.89%EPSS 9%ileNVD2026-09-17
CVE-2026-90288In the Linux kernel, the following vulnerability has been resolved: phy: renesas: rcar-gen2: Fix double of_node_put on HIGH7.49%EPSS 9%ileNVD2026-09-17
CVE-2026-90131In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize resident iomap reads with mrec_lockHIGH7.19%EPSS 9%ileNVD2026-09-17
CVE-2026-90174In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_uHIGH7.19%EPSS 9%ileNVD2026-09-17
CVE-2026-93176In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in plane reseHIGH7.09%EPSS 9%ileNVD2026-09-17
CVE-2026-20683An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOSHIGH7.19%EPSS 9%ileNVD2026-09-14
CVE-2026-87232Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.18%EPSS 8%ileNVD2026-09-15
CVE-2026-93192In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Clear queue->active_job when v3d_fence_creHIGH7.88%EPSS 8%ileNVD2026-09-17
CVE-2026-85128The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration HIGH7.58%EPSS 8%ileNVD2026-09-17
CVE-2026-64790A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SequoiaHIGH7.88%EPSS 8%ileNVD2026-09-14
CVE-2026-58200Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payloaHIGH7.18%EPSS 8%ileNVD2026-09-15
CVE-2026-93196In the Linux kernel, the following vulnerability has been resolved: nvdimm: virtio_pmem: refcount requests for token liHIGH8.48%EPSS 8%ileNVD2026-09-17
CVE-2026-54167Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8HIGH8.28%EPSS 8%ileNVD2026-09-15
CVE-2026-89994In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference duHIGH7.88%EPSS 8%ileNVD2026-09-16
CVE-2026-86039libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in paHIGH8.28%EPSS 8%ileNVD2026-09-17
CVE-2023-32803The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certaiHIGH7.58%EPSS 8%ileNVD2026-09-14
CVE-2026-62089Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affectHIGH7.18%EPSS 8%ileNVD2026-09-11
CVE-2026-81902Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBloHIGH7.18%EPSS 8%ileNVD2026-09-14
CVE-2026-73460On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can injectHIGH7.08%EPSS 8%ileNVD2026-09-16
CVE-2026-89913In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v3: take an LPI reference in vgic_HIGH8.88%EPSS 8%ileNVD2026-09-16
CVE-2026-85122The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the storHIGH8.88%EPSS 8%ileNVD2026-09-18
CVE-2026-90934EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints tHIGH8.78%EPSS 8%ileNVD2026-09-14
CVE-2026-80967In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting tHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-81017In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported sHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-89588In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: GHES: fix ARM section length accountingHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-89781In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_buHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89856In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to HIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89943In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI propertyHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89992In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name aHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89947In the Linux kernel, the following vulnerability has been resolved: clk: meson: align gxbb_32k_clk_sel number of parentHIGH8.08%EPSS 8%ileNVD2026-09-16
CVE-2026-43691A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS SequoiaHIGH7.88%EPSS 8%ileNVD2026-09-14
CVE-2026-84497A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 aHIGH7.88%EPSS 8%ileNVD2026-09-14
CVE-2026-89720In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length cHIGH7.78%EPSS 8%ileNVD2026-09-11
CVE-2026-68955The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there iHIGH8.48%EPSS 8%ileNVD2026-09-14
CVE-2026-82049In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives conHIGH8.48%EPSS 8%ileNVD2026-09-14
CVE-2026-80953In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabliHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-81004In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Cancel work cleanly on an error IHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-89452In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failuHIGH8.48%EPSS 8%ileNVD2026-09-11
CVE-2026-89877In the Linux kernel, the following vulnerability has been resolved: media: saa7164: fix cleanup on resource allocation HIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89885In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Fix SCP device refcountiHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89904In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix acpi_package_ids[] array overflow WHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89980In the Linux kernel, the following vulnerability has been resolved: ALSA: harmony: initialize locks before requesting IHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89954In the Linux kernel, the following vulnerability has been resolved: mtd: afs: validate v2 image info bounds The AFS v2HIGH8.08%EPSS 8%ileNVD2026-09-16
CVE-2026-92248A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (PhotosHIGH7.88%EPSS 8%ileNVD2026-09-15
CVE-2026-81016In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and valiHIGH7.78%EPSS 8%ileNVD2026-09-11
CVE-2026-90887Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.HIGH7.18%EPSS 8%ileNVD2026-09-17
CVE-2026-90986Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.HIGH7.18%EPSS 8%ileNVD2026-09-17
CVE-2026-61593djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH8.18%EPSS 8%ileNVD2026-09-16
CVE-2026-89782In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MAHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89806In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer overflow in fb_size cHIGH8.48%EPSS 8%ileNVD2026-09-16
CVE-2026-89927In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Clamp stimer deadline to avoid lHIGH7.18%EPSS 8%ileNVD2026-09-16
CVE-2026-90435In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer sHIGH7.88%EPSS 8%ileNVD2026-09-17
CVE-2026-93095In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key rHIGH7.88%EPSS 8%ileNVD2026-09-17
CVE-2026-92522In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds HIGH7.38%EPSS 8%ileNVD2026-09-17
CVE-2026-89510In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device oHIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-89609In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daemHIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-81903Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validaHIGH7.07%EPSS 7%ileNVD2026-09-14
CVE-2026-82427Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the superviHIGH7.87%EPSS 7%ileNVD2026-09-14
CVE-2026-57441MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, HIGH8.47%EPSS 7%ileNVD2026-09-15
CVE-2026-87241Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.17%EPSS 7%ileNVD2026-09-15
CVE-2026-89646In the Linux kernel, the following vulnerability has been resolved: ceph: fix leaked inode reference on writeback abortHIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-19885OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-89912In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Don't dereference a NULL collHIGH7.17%EPSS 7%ileNVD2026-09-16
CVE-2026-88825The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowinHIGH8.87%EPSS 7%ileNVD2026-09-18
CVE-2026-19781Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability HIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-92510In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destrHIGH7.87%EPSS 7%ileNVD2026-09-17
CVE-2026-92511In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destrHIGH7.87%EPSS 7%ileNVD2026-09-17
CVE-2026-89596In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix off-by-one when saving/restoring nonHIGH7.17%EPSS 7%ileNVD2026-09-11
CVE-2026-89602In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when HIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-89668In the Linux kernel, the following vulnerability has been resolved: nfsd: move nfsd_debugfs_init() after nfsd4_init_slaHIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-92230Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thrHIGH7.57%EPSS 7%ileNVD2026-09-17
CVE-2026-8821Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel mHIGH7.17%EPSS 7%ileNVD2026-09-14
CVE-2026-85127The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthenticHIGH8.87%EPSS 7%ileNVD2026-09-18
CVE-2026-19886OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allowHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-92176pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remoHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-92177pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alloHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-92178pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allowsHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-92179pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability alloHIGH7.87%EPSS 7%ileNVD2026-09-15
CVE-2026-90025In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode arraHIGH7.77%EPSS 7%ileNVD2026-09-16
CVE-2026-61591djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to HIGH8.17%EPSS 7%ileNVD2026-09-16
CVE-2026-89624In the Linux kernel, the following vulnerability has been resolved: HID: universal-pidff: stop the device when force-feHIGH7.87%EPSS 7%ileNVD2026-09-11
CVE-2026-12150IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1HIGH7.07%EPSS 7%ileNVD2026-09-15
CVE-2026-90398In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix stride mismatch in mac_phy_caps_pHIGH8.46%EPSS 6%ileNVD2026-09-17
CVE-2026-93045In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_aHIGH7.86%EPSS 6%ileNVD2026-09-17
CVE-2026-90402In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix controller cleanup on EDL sysfsHIGH7.06%EPSS 6%ileNVD2026-09-17
CVE-2026-92488In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destrHIGH7.06%EPSS 6%ileNVD2026-09-17
CVE-2026-89579In the Linux kernel, the following vulnerability has been resolved: bpf: Harden bloom filter sizing and indexing on 32-HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-84505An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mHIGH7.86%EPSS 6%ileNVD2026-09-14
CVE-2026-31278An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0HIGH7.76%EPSS 6%ileNVD2026-09-14
CVE-2026-90616In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whiHIGH7.46%EPSS 6%ileNVD2026-09-12
CVE-2026-20222A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and CiscHIGH7.46%EPSS 6%ileNVD2026-09-16
CVE-2026-90367In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: hold dev->mt76.mutex while disaHIGH8.86%EPSS 6%ileNVD2026-09-17
CVE-2026-90379In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: Add PCIe AER handler support toHIGH8.86%EPSS 6%ileNVD2026-09-17
CVE-2026-90425In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream IDHIGH8.86%EPSS 6%ileNVD2026-09-17
CVE-2026-90423In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path HIGH7.86%EPSS 6%ileNVD2026-09-17
CVE-2026-92751CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing HIGH7.26%EPSS 6%ileNVD2026-09-16
CVE-2026-92806phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form haHIGH7.26%EPSS 6%ileNVD2026-09-16
CVE-2026-93112In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populateHIGH7.16%EPSS 6%ileNVD2026-09-17
CVE-2026-50158yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool HIGH7.76%EPSS 6%ileNVD2026-09-17
CVE-2026-93116In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probeHIGH7.06%EPSS 6%ileNVD2026-09-17
CVE-2026-89959In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_apHIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89733In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_funcHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89870In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_deviHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89880In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: release URBs and stream buffersHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89883In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probeHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89887In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov7740: fix use-after-destroy in removeHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89893In the Linux kernel, the following vulnerability has been resolved: media: cx23885: cancel NetUP CI work before teardowHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89965In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below thHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89979In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race between non-atomic ops and trigHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89988In the Linux kernel, the following vulnerability has been resolved: kprobes: Protect kprobe_blacklist with RCU __withiHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89908In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Preserve memslot arch flags on KVM_HIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89929In the Linux kernel, the following vulnerability has been resolved: KVM: nVM: Ensure INVVPID is emulated on the correctHIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89932In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always flush vpid02 on first use Make sHIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89957In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP aHIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-80992In the Linux kernel, the following vulnerability has been resolved: net: ravb: avoid dereferencing an invalid PTP clockHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-81000In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() usHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89440In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89557In the Linux kernel, the following vulnerability has been resolved: md: do overflow check for sb->bblog_shift in super_HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89559In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Prevent integer overflow in __nd_HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89574In the Linux kernel, the following vulnerability has been resolved: dm array: validate array block headers on read arrHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89585In the Linux kernel, the following vulnerability has been resolved: auxdisplay: charlcd: cancel backlight work on regisHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89594In the Linux kernel, the following vulnerability has been resolved: hsi: omap_ssi_core: fix missing DMA mask setup for HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89597In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: unregister connector callback on inHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89605In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89607In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject oversized encrypted_key_size in paHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89723In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix slab-out-of-bounds in nilfs_direct_propHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89724In the Linux kernel, the following vulnerability has been resolved: media: vicodec: fix out-of-bounds write in FWHT encHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89738In the Linux kernel, the following vulnerability has been resolved: usb: gadget: at91_udc: drain polled-VBUS timer/workHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89741In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-dev: fix error handling in __viHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89793In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char deviHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89823In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() faHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89890In the Linux kernel, the following vulnerability has been resolved: media: go7007: defer the ALSA v4l2 put until card rHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89894In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the VHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89922In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint dataHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89961In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: fix wrong addr_pfn tracking in compoundHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89998In the Linux kernel, the following vulnerability has been resolved: dm: fix race when loading and unloading a table IfHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-90001In the Linux kernel, the following vulnerability has been resolved: HID: bpf: serialize device reference release in strHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-90007In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-XHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-83244Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.16%EPSS 6%ileNVD2026-09-15
CVE-2025-15697The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sevHIGH7.16%EPSS 6%ileNVD2026-09-17
CVE-2026-91014The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of itsHIGH7.16%EPSS 6%ileNVD2026-09-17
CVE-2026-73459On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially cHIGH7.06%EPSS 6%ileNVD2026-09-16
CVE-2026-73435On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafteHIGH7.06%EPSS 6%ileNVD2026-09-16
CVE-2026-89442In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_assoHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89501In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-43684A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, mHIGH7.86%EPSS 6%ileNVD2026-09-14
CVE-2026-89803In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event befHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89819In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size foHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89825In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix firmware control interface bounds HIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89899In the Linux kernel, the following vulnerability has been resolved: media: cec: disable delayed work before freeing an HIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89902In the Linux kernel, the following vulnerability has been resolved: LoongArch: Avoid preempt count underflow without prHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89903In the Linux kernel, the following vulnerability has been resolved: LoongArch: Do not save/restore percpu base registerHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89986In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix sleeping allocation in alloc_pageHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-93074In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_accesHIGH7.86%EPSS 6%ileNVD2026-09-17
CVE-2026-86038libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses tHIGH7.56%EPSS 6%ileNVD2026-09-17
CVE-2026-89445In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUFHIGH8.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89811In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after MES queue eviction/HIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-80929In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] tHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80950In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid befoHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80961In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80962In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk caHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80975In the Linux kernel, the following vulnerability has been resolved: mfd: qnap-mcu: keep the reply buffer alive past a cHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-81015In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks whHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89500In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_daHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89503In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffeHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89520In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-flighHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89620In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: validate reportHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89670In the Linux kernel, the following vulnerability has been resolved: nfsd: hold rcu across localio cmpxchg retry nfsd_fHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-84511An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mHIGH7.86%EPSS 6%ileNVD2026-09-14
CVE-2026-84568A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS SHIGH7.86%EPSS 6%ileNVD2026-09-14
CVE-2026-83247Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.86%EPSS 6%ileNVD2026-09-15
CVE-2026-83294Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.86%EPSS 6%ileNVD2026-09-15
CVE-2026-89799In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The getHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89808In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at sHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89810In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at svm_migrate_copy_to_rHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89814In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings outHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89829In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to pass folio->index to f2fs_sanity_checkHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89832In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to clear dirty flag on folio in error patHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89841In the Linux kernel, the following vulnerability has been resolved: f2fs: only redirty pinned folios in redirty_blocks HIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89906In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Refactor jump offset calculation inHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89920In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory corruption by not reinjectingHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-90008In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Limit NVMe request size to the HIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-24073Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.HIGH7.86%EPSS 6%ileNVD2026-09-17
CVE-2026-24074Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operatHIGH7.86%EPSS 6%ileNVD2026-09-17
CVE-2026-64736An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS HIGH7.16%EPSS 6%ileNVD2026-09-14
CVE-2026-11929IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptographHIGH7.56%EPSS 6%ileNVD2026-09-15
CVE-2026-83155Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.36%EPSS 6%ileNVD2026-09-15
CVE-2026-93485Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPreHIGH7.16%EPSS 6%ileNVD2026-09-18
CVE-2026-92025Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FirefoHIGH8.86%EPSS 6%ileNVD2026-09-15
CVE-2026-92027Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox EHIGH8.86%EPSS 6%ileNVD2026-09-15
CVE-2026-83264Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).HIGH8.46%EPSS 6%ileNVD2026-09-15
CVE-2026-36453Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra HIGH7.46%EPSS 6%ileNVD2026-09-13
CVE-2026-89777In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on HIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89960In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix stale pqap_hook pointer on error HIGH8.86%EPSS 6%ileNVD2026-09-16
CVE-2026-80947In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq oHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80971In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: clear the URB pointers on disconnectHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80982In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_releHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80991In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_iHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-80994In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on fHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-81001In the Linux kernel, the following vulnerability has been resolved: slip: fix use-after-free in sl_sync() slip_devs[] HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-81008In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and oHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89472In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulatorsHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89690In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_statusHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89742In the Linux kernel, the following vulnerability has been resolved: rapidio: mport_cdev: fix use-after-free in dma_req_HIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89746In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free with same-name named trHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89747In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on sHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89750In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state befHIGH7.86%EPSS 6%ileNVD2026-09-11
CVE-2026-89789In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error pHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89801In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on failHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89854In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host teHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89888In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov02a10: fix endpoint parsing use-afterHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89938In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: use iio_trigger_poll_nHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89940In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Tie IIO dma fence lock lifetime to theHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89941In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe THIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89942In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix potential use-after-free in anonymHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89997In the Linux kernel, the following vulnerability has been resolved: dm: fix resume-vs-remove race If the user issues tHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-90003In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeuHIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-90022In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string HIGH7.86%EPSS 6%ileNVD2026-09-16
CVE-2026-89443In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask iocHIGH7.16%EPSS 6%ileNVD2026-09-11
CVE-2026-89608In the Linux kernel, the following vulnerability has been resolved: ecryptfs: pass packet set buffer size to parser ecHIGH7.16%EPSS 6%ileNVD2026-09-11
CVE-2026-89818In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg bufHIGH7.16%EPSS 6%ileNVD2026-09-16
CVE-2026-76856Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_configHIGH7.06%EPSS 6%ileNVD2026-09-15
CVE-2026-83079Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppHIGH7.95%EPSS 5%ileNVD2026-09-15
CVE-2026-43688A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macHIGH7.85%EPSS 5%ileNVD2026-09-14
CVE-2026-89928In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Consume the locked rmap value in the HIGH8.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89795In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot resetHIGH8.45%EPSS 5%ileNVD2026-09-16
CVE-2026-80955In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg operaHIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-89545In the Linux kernel, the following vulnerability has been resolved: sunrpc: defer rq_argp and rq_resp free until after HIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-89622In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer HIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-90002In the Linux kernel, the following vulnerability has been resolved: ftrace: Take trace_array reference before accessingHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90013In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening opHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-42784A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags suHIGH7.45%EPSS 5%ileNVD2026-09-16
CVE-2026-89731In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AHIGH7.15%EPSS 5%ileNVD2026-09-11
CVE-2026-89826In the Linux kernel, the following vulnerability has been resolved: drm/panthor: harden firmware build-info bounds checHIGH7.15%EPSS 5%ileNVD2026-09-16
CVE-2026-92026Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESRHIGH8.85%EPSS 5%ileNVD2026-09-15
CVE-2026-84535An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS HIGH8.25%EPSS 5%ileNVD2026-09-14
CVE-2026-24081Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabHIGH7.45%EPSS 5%ileNVD2026-09-17
CVE-2026-25281Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.HIGH7.45%EPSS 5%ileNVD2026-09-17
CVE-2026-25294Transient DOS while parsing frame during channel usage.HIGH7.45%EPSS 5%ileNVD2026-09-17
CVE-2026-90381In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix handling channel context with diffeHIGH8.85%EPSS 5%ileNVD2026-09-17
CVE-2026-92816ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to arHIGH8.55%EPSS 5%ileNVD2026-09-16
CVE-2026-93111In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace managHIGH7.85%EPSS 5%ileNVD2026-09-17
CVE-2026-93125In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments thHIGH7.85%EPSS 5%ileNVD2026-09-17
CVE-2026-93148In the Linux kernel, the following vulnerability has been resolved: bpf: Reject MEM_ALLOC BTF accesses past object bounHIGH7.85%EPSS 5%ileNVD2026-09-17
CVE-2026-90408In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix overreads in ath12k_wmi_process_cHIGH7.75%EPSS 5%ileNVD2026-09-17
CVE-2026-90427In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed smHIGH7.45%EPSS 5%ileNVD2026-09-17
CVE-2026-90401In the Linux kernel, the following vulnerability has been resolved: md: remove REQ_NOWAIT support from raid1/10/456 REHIGH7.15%EPSS 5%ileNVD2026-09-17
CVE-2026-87183Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.75%EPSS 5%ileNVD2026-09-15
CVE-2026-83277Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppoHIGH7.35%EPSS 5%ileNVD2026-09-15
CVE-2026-81632Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone abHIGH7.25%EPSS 5%ileNVD2026-09-17
CVE-2026-89804In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatched DMA unmap size forHIGH8.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89907In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate MSI data before routing itHIGH8.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89615In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound page_lcns[] index by the log recordHIGH8.45%EPSS 5%ileNVD2026-09-11
CVE-2026-90895Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web applicationHIGH8.45%EPSS 5%ileNVD2026-09-14
CVE-2026-80954In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_dHIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-89584In the Linux kernel, the following vulnerability has been resolved: block: validate user space vectors during extractioHIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-89748In the Linux kernel, the following vulnerability has been resolved: tracing: Fix retry exhaustion in simple ring bufferHIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-89805In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Fix folio allocation fallback and use-HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89815In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after successful restore HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89836In the Linux kernel, the following vulnerability has been resolved: f2fs: fix folio_nr_pages() race after put in large HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89873In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS countsHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89875In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: quiesce overflow recovery before frHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89882In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED iHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89919In the Linux kernel, the following vulnerability has been resolved: KVM: s390: keyop: use mmu_lock to read gmap->asce HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89967In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for cHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-89985In the Linux kernel, the following vulnerability has been resolved: memcg: keep folio's objcg same as its node memcg_rHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90009In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough commaHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90010In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90014In the Linux kernel, the following vulnerability has been resolved: tracing: Have show_event_filters/triggers files takHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-43683An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.15%EPSS 5%ileNVD2026-09-14
CVE-2026-43783A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be abHIGH7.85%EPSS 5%ileNVD2026-09-14
CVE-2026-90032In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exiHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-81474Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. AHIGH7.85%EPSS 5%ileNVD2026-09-17
CVE-2026-93456django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing HIGH8.45%EPSS 5%ileNVD2026-09-18
CVE-2026-89911In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap TLBI Range to the archituHIGH7.95%EPSS 5%ileNVD2026-09-16
CVE-2026-89767In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mismHIGH7.85%EPSS 5%ileNVD2026-09-11
CVE-2026-90026In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: cancel reset_work on stop pHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90027In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic-typec: disable cc_debounce_dwHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-43786This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia HIGH7.85%EPSS 5%ileNVD2026-09-14
CVE-2026-65362This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaHIGH7.85%EPSS 5%ileNVD2026-09-14
CVE-2026-90030In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer HIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-90047In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usabHIGH7.85%EPSS 5%ileNVD2026-09-16
CVE-2026-78081Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0HIGH7.15%EPSS 5%ileNVD2026-09-15
CVE-2026-57586CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the defaultHIGH8.64%EPSS 4%ileNVD2026-09-15
CVE-2026-81235Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high pHIGH8.04%EPSS 4%ileNVD2026-09-15
CVE-2026-17133IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-89791In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival rHIGH7.84%EPSS 4%ileNVD2026-09-16
CVE-2026-84620An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2HIGH7.34%EPSS 4%ileNVD2026-09-14
CVE-2026-89705In the Linux kernel, the following vulnerability has been resolved: nfsd: restore rq_status_counter to even on all nfsdHIGH7.14%EPSS 4%ileNVD2026-09-11
CVE-2026-90648wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforHIGH7.14%EPSS 4%ileNVD2026-09-13
CVE-2026-89792In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config HIGH7.14%EPSS 4%ileNVD2026-09-16
CVE-2026-89838In the Linux kernel, the following vulnerability has been resolved: f2fs: limit recovery filename logging to stored lenHIGH7.14%EPSS 4%ileNVD2026-09-16
CVE-2026-71538@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the WinHIGH8.54%EPSS 4%ileNVD2026-09-17
CVE-2026-93337NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection creaHIGH8.54%EPSS 4%ileNVD2026-09-17
CVE-2026-90894Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_sHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-43689A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 HIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-65359An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS HIGH7.14%EPSS 4%ileNVD2026-09-14
CVE-2026-84580The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TahHIGH8.44%EPSS 4%ileNVD2026-09-14
CVE-2026-90044In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error HIGH7.84%EPSS 4%ileNVD2026-09-16
CVE-2026-90045In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_dataHIGH7.84%EPSS 4%ileNVD2026-09-16
CVE-2026-89521In the Linux kernel, the following vulnerability has been resolved: sched/core: Handle pick_task() releasing the rq locHIGH7.34%EPSS 4%ileNVD2026-09-11
CVE-2026-89456In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length acroHIGH7.04%EPSS 4%ileNVD2026-09-11
CVE-2026-84584This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be HIGH8.44%EPSS 4%ileNVD2026-09-14
CVE-2026-92903Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be intHIGH8.24%EPSS 4%ileNVD2026-09-17
CVE-2026-82992Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions tHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-82996Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized ThirdHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83018Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versionHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83024Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). SupportedHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83071Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine LeaHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83118Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions HIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83147Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). THIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83211Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83288Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).HIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83290Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83291Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83293Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). ThHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83317Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: InstallatioHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83336Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics SHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83337Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: RemoteHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-83420Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering).HIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-87268Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-87271Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-87272Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-93201In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent mHIGH7.84%EPSS 4%ileNVD2026-09-17
CVE-2026-81900Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them intHIGH7.34%EPSS 4%ileNVD2026-09-14
CVE-2026-89910In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix uninitialized stack variable isHIGH7.34%EPSS 4%ileNVD2026-09-16
CVE-2026-78295Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.HIGH8.84%EPSS 4%ileNVD2026-09-17
CVE-2026-81012In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in hHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89465In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: quiesce delayed work before HIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89470In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd: Limit port counts to EC_HIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89471In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd-charger: bound the EC-repHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89504In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix prematHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89599In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: panel-dsi-cm: initialize lock beforeHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89744In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_eaHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-84546An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH8.44%EPSS 4%ileNVD2026-09-14
CVE-2026-89755In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freeinHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-89758In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: skip non-present PMDs when queueing fHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-89764In the Linux kernel, the following vulnerability has been resolved: rust: devres: fix race between concurrent revokers HIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-90043In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-bHIGH7.84%EPSS 4%ileNVD2026-09-16
CVE-2026-90046In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP PHIGH7.84%EPSS 4%ileNVD2026-09-16
CVE-2026-89466In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings HIGH7.74%EPSS 4%ileNVD2026-09-11
CVE-2026-89743In the Linux kernel, the following vulnerability has been resolved: misc: nsm: bound the device-reported response lengtHIGH7.74%EPSS 4%ileNVD2026-09-11
CVE-2026-19816A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (HIGH7.14%EPSS 4%ileNVD2026-09-14
CVE-2026-73174Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserveHIGH8.74%EPSS 4%ileNVD2026-09-16
CVE-2026-73177Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware HIGH8.64%EPSS 4%ileNVD2026-09-16
CVE-2026-89603In the Linux kernel, the following vulnerability has been resolved: entry: Fix seccomp bypass after ptrace with TSYNC HIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89587In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: fix stack buffer overflow in querHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-92180pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation VulHIGH7.84%EPSS 4%ileNVD2026-09-15
CVE-2026-54692SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. PHIGH7.84%EPSS 4%ileNVD2026-09-17
CVE-2026-81810The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several ofHIGH7.24%EPSS 4%ileNVD2026-09-18
CVE-2026-90783MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to iHIGH8.54%EPSS 4%ileNVD2026-09-13
CVE-2026-82430Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-17156IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-17416IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-80356Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an UnHIGH7.34%EPSS 4%ileNVD2026-09-17
CVE-2026-89840In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE destination size F2FS_IOHIGH7.14%EPSS 4%ileNVD2026-09-16
CVE-2026-54510Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, theHIGH7.14%EPSS 4%ileNVD2026-09-17
CVE-2026-54608MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/SysteHIGH7.14%EPSS 4%ileNVD2026-09-17
CVE-2026-80932In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virtHIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-89469In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8727: fix use-after-free in lp8727HIGH8.44%EPSS 4%ileNVD2026-09-11
CVE-2026-87243Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.04%EPSS 4%ileNVD2026-09-15
CVE-2026-89641In the Linux kernel, the following vulnerability has been resolved: cifs: clear tcon after cifsFileInfo_put() in cifs_fHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-83190Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.34%EPSS 4%ileNVD2026-09-15
CVE-2026-83193Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported verHIGH7.34%EPSS 4%ileNVD2026-09-15
CVE-2026-84548An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqHIGH7.14%EPSS 4%ileNVD2026-09-14
CVE-2026-90556Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declHIGH8.54%EPSS 4%ileNVD2026-09-12
CVE-2026-89563In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() iHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-89606In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject too-small tag 70 packets ecryptfsHIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-89617In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay HIGH7.84%EPSS 4%ileNVD2026-09-11
CVE-2026-43702The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPaHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-65344An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-84506A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOSHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-92838A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or HIGH7.84%EPSS 4%ileNVD2026-09-17
CVE-2026-19515The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing MicrHIGH7.04%EPSS 4%ileNVD2026-09-15
CVE-2026-81192OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSHIGH7.04%EPSS 4%ileGitHub2026-09-16
CVE-2026-84578A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSHIGH8.84%EPSS 4%ileNVD2026-09-14
CVE-2026-64701A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS TahoeHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-84515An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-84575An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mHIGH7.84%EPSS 4%ileNVD2026-09-14
CVE-2026-86585The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01HIGH7.74%EPSS 4%ileNVD2026-09-16
CVE-2026-64752A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, maHIGH7.34%EPSS 4%ileNVD2026-09-14
CVE-2026-82964Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-HIGH8.83%EPSS 3%ileNVD2026-09-16
CVE-2026-93375Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attackerHIGH8.13%EPSS 3%ileNVD2026-09-17
CVE-2026-89489In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via orHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89523In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89564In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forwardHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89619In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: bound GET_REPORHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-84566The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOHIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-84565An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.13%EPSS 3%ileNVD2026-09-14
CVE-2026-84577An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS THIGH8.23%EPSS 3%ileNVD2026-09-14
CVE-2026-71180Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low priviHIGH8.23%EPSS 3%ileNVD2026-09-16
CVE-2026-81010In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_wHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89553In the Linux kernel, the following vulnerability has been resolved: nouveau/gem: reserve the bo in the info ioctl arounHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-87216Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.83%EPSS 3%ileNVD2026-09-15
CVE-2026-58485mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through HIGH7.13%EPSS 3%ileNVD2026-09-15
CVE-2026-87219Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.43%EPSS 3%ileNVD2026-09-15
CVE-2026-87259Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering ComHIGH8.43%EPSS 3%ileNVD2026-09-15
CVE-2026-89436In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89522In the Linux kernel, the following vulnerability has been resolved: media: staging/ipu7: fix async notifier UAF on probHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-90978The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the noncHIGH7.13%EPSS 3%ileNVD2026-09-18
CVE-2026-82429Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walkingHIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-90947A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does notHIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-65398An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, HIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-73450On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with aHIGH7.03%EPSS 3%ileNVD2026-09-16
CVE-2026-57122PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signaHIGH8.63%EPSS 3%ileNVD2026-09-14
CVE-2026-19477There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  ThisHIGH8.63%EPSS 3%ileNVD2026-09-17
CVE-2026-55062uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/unigetHIGH8.43%EPSS 3%ileNVD2026-09-17
CVE-2026-65354A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeHIGH8.23%EPSS 3%ileNVD2026-09-14
CVE-2026-19624A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vHIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-87261Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering ComHIGH7.33%EPSS 3%ileNVD2026-09-15
CVE-2026-80928In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80931In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C blHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80933In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmwarHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80944In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupteHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80977In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in sHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80978In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel dHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80979In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89487In the Linux kernel, the following vulnerability has been resolved: openvswitch: only skb_tx_error() a packet we are abHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89497In the Linux kernel, the following vulnerability has been resolved: orangefs: skip leading spaces before parsing clientHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89540In the Linux kernel, the following vulnerability has been resolved: sunrpc: init gssp_lock before publishing proc entryHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89562In the Linux kernel, the following vulnerability has been resolved: ip6_gre: fix hardware header length for NBMA tunnelHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89573In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size isHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89580In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in __bpf_get_stack get_perHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89581In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix per-CPU address resolution into an exHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-92786LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wrHIGH8.53%EPSS 3%ileNVD2026-09-16
CVE-2026-56795Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A loHIGH8.23%EPSS 3%ileNVD2026-09-17
CVE-2026-37008CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vuHIGH8.13%EPSS 3%ileNVD2026-09-13
CVE-2026-75092A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository).HIGH7.33%EPSS 3%ileNVD2026-09-15
CVE-2026-89450In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the HIGH8.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80936In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-80959In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offsetHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-81006In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failurHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89441In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89507In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_write_cm_event(HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-83159Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that HIGH7.83%EPSS 3%ileNVD2026-09-15
CVE-2026-83253Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.83%EPSS 3%ileNVD2026-09-15
CVE-2026-84611An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.HIGH7.33%EPSS 3%ileNVD2026-09-14
CVE-2026-84632The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOHIGH7.33%EPSS 3%ileNVD2026-09-14
CVE-2026-84572An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeHIGH7.13%EPSS 3%ileNVD2026-09-14
CVE-2026-77407RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as HIGH7.03%EPSS 3%ileNVD2026-09-16
CVE-2026-89560In the Linux kernel, the following vulnerability has been resolved: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for wHIGH8.43%EPSS 3%ileNVD2026-09-11
CVE-2026-80952In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregiHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89488In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix CT limit teardown use-after-free HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89508In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_set_ib_path() HIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89548In the Linux kernel, the following vulnerability has been resolved: SUNRPC: always drain cache_cleaner before destroyinHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-89736In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound cHIGH7.83%EPSS 3%ileNVD2026-09-11
CVE-2026-65357The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6HIGH7.83%EPSS 3%ileNVD2026-09-14
CVE-2026-81007In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_wriHIGH7.13%EPSS 3%ileNVD2026-09-11
CVE-2026-89593In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping iHIGH7.13%EPSS 3%ileNVD2026-09-11
CVE-2026-89640In the Linux kernel, the following vulnerability has been resolved: cifs: fix loff_t underflow in cifs_remap_file_rangeHIGH7.13%EPSS 3%ileNVD2026-09-11
CVE-2026-83016Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported versionHIGH7.22%EPSS 2%ileNVD2026-09-15
CVE-2026-81011In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element coHIGH7.12%EPSS 2%ileNVD2026-09-11
CVE-2026-89639In the Linux kernel, the following vulnerability has been resolved: cifs: use cifs_invalidate_cache() in cifs_do_truncaHIGH7.12%EPSS 2%ileNVD2026-09-11
CVE-2026-89691In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to prevenHIGH7.12%EPSS 2%ileNVD2026-09-11
CVE-2026-83219Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.12%EPSS 2%ileNVD2026-09-15
CVE-2026-89486In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destrHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89570In the Linux kernel, the following vulnerability has been resolved: cxl/mce: Make the MCE notifier per-region Flavien HIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89600In the Linux kernel, the following vulnerability has been resolved: fanotify: fix use-after-free of file range info fsHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-64712This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaHIGH7.82%EPSS 2%ileNVD2026-09-14
CVE-2026-80958In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment HIGH7.12%EPSS 2%ileNVD2026-09-11
CVE-2026-89571In the Linux kernel, the following vulnerability has been resolved: cxl/features: bound fwctl command payload to the inHIGH7.12%EPSS 2%ileNVD2026-09-11
CVE-2026-59569An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potHIGH8.12%EPSS 2%ileNVD2026-09-14
CVE-2026-89769In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_HIGH7.42%EPSS 2%ileNVD2026-09-11
CVE-2026-92582AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.jsHIGH7.12%EPSS 2%ileNVD2026-09-16
CVE-2026-89513In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflowHIGH8.82%EPSS 2%ileNVD2026-09-11
CVE-2026-56967In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (proHIGH8.02%EPSS 2%ileNVD2026-09-15
CVE-2026-80995In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in HIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89499In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Stop remote reader update when page swHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89761In the Linux kernel, the following vulnerability has been resolved: apparmor: fix out-of-bounds write when null terminaHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89762In the Linux kernel, the following vulnerability has been resolved: apparmor: fix cred UAF caused by begin_current_labeHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89771In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffeHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-89754In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix stale walk->action escaping walk_pHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-87273Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH8.62%EPSS 2%ileNVD2026-09-15
CVE-2026-83015Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). SupporteHIGH7.02%EPSS 2%ileNVD2026-09-15
CVE-2026-83316Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.02%EPSS 2%ileNVD2026-09-15
CVE-2026-89763In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_tHIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-84607A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 aHIGH7.82%EPSS 2%ileNVD2026-09-14
CVE-2026-83240Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.12%EPSS 2%ileNVD2026-09-15
CVE-2026-84631This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be HIGH7.82%EPSS 2%ileNVD2026-09-14
CVE-2026-87182Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH8.82%EPSS 2%ileNVD2026-09-15
CVE-2026-81301Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider withHIGH8.52%EPSS 2%ileNVD2026-09-14
CVE-2026-89760In the Linux kernel, the following vulnerability has been resolved: mm, swap: don't free a hibernation slot that is in HIGH7.82%EPSS 2%ileNVD2026-09-11
CVE-2026-83214Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-83216Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported vHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-83342Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SysHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-83353Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). SupporteHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-87269Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-87270Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.82%EPSS 2%ileNVD2026-09-15
CVE-2026-87276Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thHIGH7.52%EPSS 2%ileNVD2026-09-15
CVE-2026-45720Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.HIGH7.02%EPSS 2%ileNVD2026-09-17
CVE-2026-86917A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS SequoHIGH7.82%EPSS 2%ileNVD2026-09-14
CVE-2025-59607Memory Corruption when copying large input data exceeds normal allocation limits.HIGH7.82%EPSS 2%ileNVD2026-09-17
CVE-2026-24075Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper syHIGH7.82%EPSS 2%ileNVD2026-09-17
CVE-2026-25280Memory corruption when processing escape handling flow with insufficient user buffer sizes.HIGH7.82%EPSS 2%ileNVD2026-09-17
CVE-2026-83004Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).HIGH7.22%EPSS 2%ileNVD2026-09-15
CVE-2026-83158Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClonHIGH7.12%EPSS 2%ileNVD2026-09-15
CVE-2026-25283Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.HIGH8.81%EPSS 1%ileNVD2026-09-17
CVE-2026-91727Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker HIGH8.11%EPSS 1%ileNVD2026-09-15
CVE-2026-23789An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 13HIGH7.81%EPSS 1%ileNVD2026-09-14
CVE-2026-25290Memory Corruption when validating large data buffers from external sources using addition to check buffer length.HIGH7.81%EPSS 1%ileNVD2026-09-17
CVE-2026-86474The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions pHIGH7.71%EPSS 1%ileNVD2026-09-16
CVE-2026-81546The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when paHIGH7.71%EPSS 1%ileNVD2026-09-17
CVE-2026-89459In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils HIGH7.01%EPSS 1%ileNVD2026-09-11
CVE-2026-92718Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without contentHIGH7.01%EPSS 1%ileNVD2026-09-16
CVE-2026-90493A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is HIGH8.51%EPSS 1%ileNVD2026-09-13
CVE-2026-12518A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileHIGH8.51%EPSS 1%ileNVD2026-09-14
CVE-2026-25284Information Disclosure when a pointer is reused after being deallocated.HIGH7.31%EPSS 1%ileNVD2026-09-17
CVE-2026-86901An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. MHIGH7.11%EPSS 1%ileNVD2026-09-14
CVE-2026-83150Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to exHIGH7.01%EPSS 1%ileNVD2026-09-15
CVE-2026-79994The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workHIGH8.71%EPSS 1%ileNVD2026-09-15
CVE-2026-54174melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to meHIGH8.31%EPSS 1%ileNVD2026-09-11
CVE-2026-33963An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680.HIGH7.51%EPSS 1%ileNVD2026-09-14
CVE-2026-91734Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to executHIGH7.41%EPSS 1%ileNVD2026-09-15
CVE-2026-54447garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.HIGH8.41%EPSS 1%ileNVD2026-09-14
CVE-2026-57012In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to reHIGH8.41%EPSS 1%ileNVD2026-09-15
CVE-2024-58383Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via HIGH8.41%EPSS 1%ileNVD2026-09-14
CVE-2026-84507A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 andHIGH7.81%EPSS 1%ileNVD2026-09-14
CVE-2026-47773ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missinHIGH7.21%EPSS 1%ileNVD2026-09-11
CVE-2026-77404RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACHIGH8.71%EPSS 1%ileNVD2026-09-16
CVE-2026-25282Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.HIGH7.91%EPSS 1%ileNVD2026-09-17
CVE-2026-45726Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a stHIGH7.61%EPSS 1%ileNVD2026-09-17
CVE-2026-76159Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions befHIGH7.01%EPSS 1%ileNVD2026-09-15
CVE-2026-83249Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.81%EPSS 1%ileNVD2026-09-15
CVE-2026-66571Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.HIGH7.11%EPSS 1%ileNVD2026-09-17
CVE-2026-83239Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compHIGH7.01%EPSS 1%ileNVD2026-09-15
CVE-2026-59570On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user HIGH7.51%EPSS 1%ileNVD2026-09-14
CVE-2026-83323Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform SeHIGH7.51%EPSS 1%ileNVD2026-09-15
CVE-2026-50605A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. InsuHIGH7.41%EPSS 1%ileNVD2026-09-17
CVE-2026-50609A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. HIGH7.41%EPSS 1%ileNVD2026-09-17
CVE-2026-50610A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense dHIGH7.41%EPSS 1%ileNVD2026-09-17
CVE-2026-20323A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD SoHIGH8.30%EPSS 0%ileNVD2026-09-16
CVE-2026-81429The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its templateHIGH7.10%EPSS 0%ileNVD2026-09-12
CVE-2026-87240Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporHIGH7.00%EPSS 0%ileNVD2026-09-15
CVE-2026-86836In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFHIGH8.40%EPSS 0%ileNVD2026-09-14
CVE-2026-0189In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to HIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56881In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead toHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-25278Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copyiHIGH7.80%EPSS 0%ileNVD2026-09-17
CVE-2026-40058CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability onHIGH8.80%EPSS 0%ileNVD2026-09-15
CVE-2026-0194In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalaHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56970In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to localHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-58679In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. ThiHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-58691In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to loHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-55359In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local HIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-58678In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalatiHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-56941In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could HIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56982In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of HIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-55301In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead tHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56978In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This couldHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56985In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalatiHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56986In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of HIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-58699In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This HIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-0199In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. ThisHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-55323In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This HIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-55351In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of priviHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-57014In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing HIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-58695In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing boundHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-58766In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. ThHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-40539An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1HIGH7.10%EPSS 0%ileNVD2026-09-18
CVE-2026-85628Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application HIGH7.00%EPSS 0%ileNVD2026-09-16
CVE-2026-88622NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.HIGH8.8NVD2026-09-18
CVE-2025-14754IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges onHIGH8.8NVD2026-09-18
CVE-2026-10575IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a heHIGH8.8NVD2026-09-18
CVE-2026-11375IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to aHIGH8.8NVD2026-09-18
CVE-2026-11378IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to aHIGH8.8NVD2026-09-18
CVE-2026-11381IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to iHIGH8.8NVD2026-09-18
CVE-2026-58197ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to TooHIGH8.8NVD2026-09-18
CVE-2026-33625LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contaHIGH8.8NVD2026-09-18
CVE-2026-81180SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor ProfessHIGH8.8NVD2026-09-18
CVE-2026-93759Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the dHIGH8.8NVD2026-09-18
GHSA-xwmw-prc4-v3crObot: OAuth Dynamic Client Registration Enables API Token Theft via Audience ConfusionHIGH8.8GitHub2026-09-18
USN-8779-2USN-8779-2: Bubblewrap regressionHIGH8.8Ubuntu2026-09-17
DSA 6501-1[SECURITY] [DSA 6501-1] firefox-esr security updateHIGH8.8Debian2026-09-16
DSA 6503-1[SECURITY] [DSA 6503-1] thunderbird security updateHIGH8.8Debian2026-09-16
CVE-2026-93592vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, HIGH8.7NVD2026-09-18
CVE-2026-93599rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_strHIGH8.7NVD2026-09-18
CVE-2026-77929ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote cHIGH8.7NVD2026-09-18
CVE-2026-93657hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and RHIGH8.7NVD2026-09-18
CVE-2026-68914Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not liHIGH8.7NVD2026-09-18
CVE-2026-81942PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contHIGH8.7NVD2026-09-18
CVE-2026-84398CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attHIGH8.7NVD2026-09-18
CVE-2026-86520Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active HIGH8.7NVD2026-09-18
CVE-2026-88259CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthentiHIGH8.7NVD2026-09-18
CVE-2026-93687braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. AttackHIGH8.7NVD2026-09-18
CVE-2026-93688SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstraHIGH8.7NVD2026-09-18
CVE-2026-93690uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely HIGH8.7NVD2026-09-18
CVE-2026-62943btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filHIGH8.7NVD2026-09-18
CVE-2026-93748http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-sHIGH8.7NVD2026-09-18
CVE-2026-93749source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackeHIGH8.7NVD2026-09-18
CVE-2026-93752CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validaHIGH8.7NVD2026-09-18
CVE-2026-93753deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properlHIGH8.7NVD2026-09-18
CVE-2026-93761An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library maHIGH8.7NVD2026-09-18
CVE-2026-93593ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver bHIGH8.6NVD2026-09-18
CVE-2025-61682Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's HIGH8.6NVD2026-09-18
CVE-2026-93758An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a HIGH8.6NVD2026-09-18
CVE-2026-61551Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhausHIGH8.6NVD2026-09-18
DSA 6502-1[SECURITY] [DSA 6502-1] mkvtoolnix security updateHIGH8.5Debian2026-09-16
CVE-2026-56914In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation oHIGH8.40%EPSS 0%ileNVD2026-09-15
CVE-2026-81943PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contHIGH8.4NVD2026-09-18
CVE-2026-63638OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH8.3NVD2026-09-18
CVE-2026-93765Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. InHIGH8.3NVD2026-09-18
CVE-2026-63199Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the HIGH8.3NVD2026-09-18
CVE-2026-93760Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands thatHIGH8.3NVD2026-09-18
CVE-2026-93569HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authorityHIGH8.2NVD2026-09-18
CVE-2026-86689Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active HIGH8.2NVD2026-09-18
CVE-2026-55556Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_autHIGH8.2NVD2026-09-18
CVE-2026-91127File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applicHIGH8.2NVD2026-09-18
CVE-2026-93750http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails tHIGH8.2NVD2026-09-18
DSA 6496-1[SECURITY] [DSA 6496-1] nginx security updateHIGH8.2Debian2026-09-12
CVE-2026-10027IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow wheHIGH8.1NVD2026-09-18
CVE-2026-54148http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvidHIGH8.1NVD2026-09-18
CVE-2026-61548Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSHIGH8.1NVD2026-09-18
CVE-2026-61833zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior HIGH8.1NVD2026-09-18
CVE-2026-77239WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routesHIGH8.1NVD2026-09-18
CVE-2026-62278LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenHIGH8.1NVD2026-09-18
CVE-2026-81179SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password resetHIGH8.1NVD2026-09-18
GHSA-5648-rgj9-v224@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticateHIGH8.1GitHub2026-09-15
DSA 6496-2[SECURITY] [DSA 6496-2] nginx regression updateHIGH8.1Debian2026-09-16
CVE-2026-56945In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privileHIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-58744In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to HIGH7.80%EPSS 0%ileNVD2026-09-15
CVE-2026-63419OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.8NVD2026-09-18
CVE-2026-63422OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.8NVD2026-09-18
CVE-2026-46655virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permitsHIGH7.8NVD2026-09-18
DSA 6498-1[SECURITY] [DSA 6498-1] network-manager-l2tp security updateHIGH7.8Debian2026-09-14
FG-IR-26-144Linux Kernel vulnerability Dirty FragHIGH7.8Fortinet2026-06-03
CVE-2026-81944PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contHIGH7.7NVD2026-09-18
CVE-2026-67549OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aHIGH7.6NVD2026-09-18
GHSA-jgh3-fggc-mcpmObot: Server-Side Request Forgery via remote MCP server URLHIGH7.6GitHub2026-09-18
CVE-2026-93563Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoSHIGH7.5NVD2026-09-18
CVE-2026-93572## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis rHIGH7.5NVD2026-09-18
CVE-2026-93575### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` exHIGH7.5NVD2026-09-18
CVE-2026-93488A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams becauseHIGH7.5NVD2026-09-18
CVE-2026-93491A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeliHIGH7.5NVD2026-09-18
CVE-2026-93560STOMP codec content-length long-to-int truncation causes infinite decode loop DoSHIGH7.5NVD2026-09-18
CVE-2026-93558Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of ServiceHIGH7.5NVD2026-09-18
CVE-2026-93564HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881)HIGH7.5NVD2026-09-18
CVE-2026-93565### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the HIGH7.5NVD2026-09-18
CVE-2026-93567HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authorityHIGH7.5NVD2026-09-18
CVE-2026-93568HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requestsHIGH7.5NVD2026-09-18
CVE-2026-93576Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419)HIGH7.5NVD2026-09-18
CVE-2026-93652Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoHIGH7.5NVD2026-09-18
CVE-2025-14753IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could sendHIGH7.5NVD2026-09-18
CVE-2026-10744IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or poteHIGH7.5NVD2026-09-18
CVE-2026-10751IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicatiHIGH7.5NVD2026-09-18
CVE-2026-10853IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arbHIGH7.5NVD2026-09-18
CVE-2026-81945PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 contaHIGH7.5NVD2026-09-18
CVE-2026-84384libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadataHIGH7.5NVD2026-09-18
CVE-2026-84446libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list HIGH7.5NVD2026-09-18
CVE-2026-84447libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden referencHIGH7.5NVD2026-09-18
CVE-2026-77301adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntHIGH7.5NVD2026-09-18
CVE-2026-91149A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustainHIGH7.5NVD2026-09-18
CVE-2026-32641Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/htHIGH7.5NVD2026-09-18
CVE-2026-69184c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poiHIGH7.5NVD2026-09-18
CVE-2026-85058Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last WHIGH7.5NVD2026-09-18
GHSA-39wr-7q6h-cf68LMDeploy has an SSRF bypassHIGH7.5GitHub2026-09-18
DSA 6505-1[SECURITY] [DSA 6505-1] bind9 security updateHIGH7.5Debian2026-09-17
FG-IR-26-163HTTP/2 Bomb CVE-2026-49975HIGH7.5Fortinet2026-08-12
CVE-2026-84444libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heHIGH7.4NVD2026-09-18
CVE-2026-84975PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTHIGH7.4NVD2026-09-18
CVE-2026-93658uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership HIGH7.3NVD2026-09-18
CVE-2026-93591SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag valuesHIGH7.2NVD2026-09-18
CVE-2026-61552Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attaHIGH7.2NVD2026-09-18
CVE-2026-93594ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ruHIGH7.1NVD2026-09-18
CVE-2026-93595ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AIHIGH7.1NVD2026-09-18
CVE-2026-93598ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot sHIGH7.1NVD2026-09-18
CVE-2026-77927ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract HIGH7.1NVD2026-09-18
CVE-2026-77928ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract HIGH7.1NVD2026-09-18
CVE-2026-93660SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing autheHIGH7.1NVD2026-09-18
CVE-2026-10030IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authorizHIGH7.1NVD2026-09-18
CVE-2026-93737Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticateHIGH7.1NVD2026-09-18
CVE-2026-61672Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pHIGH7.1NVD2026-09-18
CVE-2026-81505Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID}HIGH7.1NVD2026-09-18
CVE-2026-62279LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an autHIGH7.1NVD2026-09-18
CVE-2026-63445Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpointHIGH7.1NVD2026-09-18
CVE-2026-63458Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authentiHIGH7.1NVD2026-09-18
CVE-2026-93763A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields thatHIGH7.1NVD2026-09-18
CVE-2026-93764Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encHIGH7.1NVD2026-09-18
USN-8761-2USN-8761-2: Linux kernel (Azure FIPS) vulnerabilitiesHIGH7.1Ubuntu2026-09-18
USN-8729-2USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilitiesHIGH7.1Ubuntu2026-09-18
CVE-2026-58701In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could lHIGH7.00%EPSS 0%ileNVD2026-09-15
CVE-2026-58724In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation oHIGH7.00%EPSS 0%ileNVD2026-09-15
CVE-2026-58728In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalatiHIGH7.00%EPSS 0%ileNVD2026-09-15
CVE-2026-58734In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This couldHIGH7.00%EPSS 0%ileNVD2026-09-15
CVE-2026-7006Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege HIGH7.0NVD2026-09-18
CVE-2026-81305CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity oHIGH7.0NVD2026-09-18
CVE-2026-63349AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In HIGH7.0NVD2026-09-18
CVE-2026-73863NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/proHIGH7.0NVD2026-09-18
CVE-2026-77874CVE-2026-77874HIGHRed Hat2026-09-17
CVE-2026-92828CVE-2026-92828HIGHRed Hat2026-09-16
GHSA-xjw9-38cr-6372djust: A template binding inherits a context safety grant it never earned (XSS)HIGHGitHub2026-09-17
GHSA-9395-2g46-rj3fdjust: Six template-layer defects emit attacker-controlled markup unescaped (XSS)HIGHGitHub2026-09-17
CVE-2026-76698A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN GateMEDIUM6.590%EPSS 90%ileNVD2026-09-15
CVE-2026-90617A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerabilitMEDIUM5.575%EPSS 75%ileNVD2026-09-14
CVE-2026-90618A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the fMEDIUM5.575%EPSS 75%ileNVD2026-09-14
CVE-2026-90843A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. ThisMEDIUM5.571%EPSS 71%ileNVD2026-09-15
CVE-2026-90619A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknMEDIUM5.570%EPSS 70%ileNVD2026-09-14
CVE-2026-93371A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NeMEDIUM5.570%EPSS 70%ileNVD2026-09-18
CVE-2026-90690A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemenMEDIUM5.570%EPSS 70%ileNVD2026-09-14
CVE-2026-54645CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, MEDIUM4.868%EPSS 68%ileNVD2026-09-17
CVE-2026-76431A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC couMEDIUM4.965%EPSS 65%ileNVD2026-09-16
CVE-2026-54644CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses stripMEDIUM6.163%EPSS 63%ileNVD2026-09-17
CVE-2023-40772A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information MEDIUM4.362%EPSS 62%ileNVD2026-09-14
CVE-2026-76433A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticateMEDIUM5.359%EPSS 59%ileNVD2026-09-16
CVE-2026-76432A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remotMEDIUM4.958%EPSS 58%ileNVD2026-09-16
CVE-2026-51133Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to eMEDIUM6.157%EPSS 57%ileNVD2026-09-15
CVE-2026-86465Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlledMEDIUM6.555%EPSS 55%ileNVD2026-09-16
CVE-2026-53717Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.552%EPSS 52%ileNVD2026-09-14
CVE-2026-54177backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM6.651%EPSS 51%ileNVD2026-09-14
CVE-2026-90524A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995MEDIUM5.551%EPSS 51%ileNVD2026-09-13
CVE-2026-53716Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.551%EPSS 51%ileNVD2026-09-14
CVE-2026-53719Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.551%EPSS 51%ileNVD2026-09-14
CVE-2026-55701The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, thMEDIUM6.950%EPSS 50%ileNVD2026-09-15
CVE-2026-92399A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utiMEDIUM5.550%EPSS 50%ileNVD2026-09-16
CVE-2026-92401A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affMEDIUM6.950%EPSS 50%ileNVD2026-09-16
CVE-2026-57173vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /vMEDIUM6.550%EPSS 50%ileNVD2026-09-16
CVE-2026-16777The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable toMEDIUM4.950%EPSS 50%ileNVD2026-09-18
CVE-2026-76151Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt GrMEDIUM4.649%EPSS 49%ileNVD2026-09-16
CVE-2026-69201Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode MEDIUM5.949%EPSS 49%ileNVD2026-09-15
CVE-2026-90504A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted eMEDIUM5.549%EPSS 49%ileNVD2026-09-13
CVE-2026-77360oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, thMEDIUM6.348%EPSS 48%ileNVD2026-09-16
CVE-2026-11748Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasionMEDIUM48%EPSS 48%ileGitHub2026-09-11
CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craftMEDIUM5.347%EPSS 47%ileNVD2026-09-11
CVE-2026-20282A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operMEDIUM4.945%EPSS 45%ileNVD2026-09-16
CVE-2026-90494A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plMEDIUM6.945%EPSS 45%ileNVD2026-09-13
CVE-2026-76705A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful expMEDIUM5.544%EPSS 44%ileNVD2026-09-15
CVE-2026-92114A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/MEDIUM6.944%EPSS 44%ileNVD2026-09-15
CVE-2026-27553A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_taMEDIUM6.544%EPSS 44%ileNVD2026-09-16
CVE-2026-54582mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming nonMEDIUM6.044%EPSS 44%ileNVD2026-09-17
CVE-2026-86522Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attackMEDIUM6.344%EPSS 44%ileNVD2026-09-17
CVE-2026-92220A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_MEDIUM6.943%EPSS 43%ileNVD2026-09-16
CVE-2026-54585mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c didMEDIUM6.043%EPSS 43%ileNVD2026-09-17
CVE-2026-92363A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cppMEDIUM5.343%EPSS 43%ileNVD2026-09-16
CVE-2026-73169Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site ScripMEDIUM6.343%EPSS 43%ileNVD2026-09-16
CVE-2026-92361A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdkMEDIUM5.342%EPSS 42%ileNVD2026-09-16
CVE-2026-82426Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a servMEDIUM6.542%EPSS 42%ileNVD2026-09-14
CVE-2026-90565A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e0MEDIUM5.542%EPSS 42%ileNVD2026-09-13
CVE-2026-19607A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial aMEDIUM5.342%EPSS 42%ileNVD2026-09-16
CVE-2026-92362A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-clieMEDIUM6.942%EPSS 42%ileNVD2026-09-16
CVE-2026-14277IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normalMEDIUM6.342%EPSS 42%ileNVD2026-09-14
CVE-2026-90522A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938MEDIUM5.542%EPSS 42%ileNVD2026-09-13
CVE-2026-90523A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0MEDIUM5.542%EPSS 42%ileNVD2026-09-13
CVE-2026-50157Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the AuthorizeMEDIUM6.542%EPSS 42%ileNVD2026-09-14
CVE-2026-92091A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using MEDIUM5.942%EPSS 42%ileNVD2026-09-16
CVE-2026-90686A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loadeMEDIUM5.542%EPSS 42%ileNVD2026-09-14
CVE-2026-90698A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_MEDIUM5.542%EPSS 42%ileNVD2026-09-14
CVE-2026-93295MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web userMEDIUM5.142%EPSS 42%ileNVD2026-09-17
CVE-2026-17463IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) couldMEDIUM6.541%EPSS 41%ileNVD2026-09-14
CVE-2026-54637Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the scheduleMEDIUM5.541%EPSS 41%ileNVD2026-09-15
CVE-2026-20121A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall AdaptMEDIUM5.341%EPSS 41%ileNVD2026-09-16
CVE-2023-29377An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By usMEDIUM6.641%EPSS 41%ileNVD2026-09-14
CVE-2026-84993MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 aMEDIUM6.541%EPSS 41%ileNVD2026-09-16
CVE-2026-81176Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the MEDIUM5.341%EPSS 41%ileNVD2026-09-16
CVE-2026-59149@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only MEDIUM6.541%EPSS 41%ileGitHub2026-09-11
CVE-2026-90603A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknMEDIUM6.940%EPSS 40%ileNVD2026-09-13
CVE-2026-92366A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /searchMEDIUM5.540%EPSS 40%ileNVD2026-09-16
CVE-2026-90710A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file coMEDIUM5.540%EPSS 40%ileNVD2026-09-14
CVE-2026-92380A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreMEDIUM5.540%EPSS 40%ileNVD2026-09-16
CVE-2026-57497webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in sessioMEDIUM5.340%EPSS 40%ileNVD2026-09-14
CVE-2026-61793Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenMEDIUM6.939%EPSS 39%ileNVD2026-09-17
CVE-2026-54176backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM6.539%EPSS 39%ileNVD2026-09-14
CVE-2026-59157webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior MEDIUM6.539%EPSS 39%ileNVD2026-09-15
CVE-2026-69147vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions MEDIUM6.539%EPSS 39%ileNVD2026-09-16
CVE-2026-91848A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson ofMEDIUM5.539%EPSS 39%ileNVD2026-09-15
CVE-2026-43791A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.539%EPSS 39%ileNVD2026-09-14
CVE-2026-65412A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7MEDIUM6.539%EPSS 39%ileNVD2026-09-14
CVE-2026-55776OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller withMEDIUM6.539%EPSS 39%ileNVD2026-09-15
CVE-2026-76700Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a MEDIUM5.939%EPSS 39%ileNVD2026-09-15
CVE-2026-76555The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it aMEDIUM6.839%EPSS 39%ileNVD2026-09-16
CVE-2026-59944Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious orMEDIUM6.139%EPSS 39%ileNVD2026-09-16
CVE-2026-76697A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remoteMEDIUM6.539%EPSS 39%ileNVD2026-09-15
CVE-2026-90566A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. AMEDIUM5.539%EPSS 39%ileNVD2026-09-13
CVE-2026-53496ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URLMEDIUM5.338%EPSS 38%ileNVD2026-09-14
CVE-2026-55770OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFCMEDIUM6.838%EPSS 38%ileNVD2026-09-15
CVE-2026-50024GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_taMEDIUM5.338%EPSS 38%ileNVD2026-09-15
CVE-2026-92216A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file MEDIUM5.338%EPSS 38%ileNVD2026-09-16
CVE-2026-81453Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a ResMEDIUM6.538%EPSS 38%ileNVD2026-09-17
CVE-2026-91002A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of tMEDIUM5.538%EPSS 38%ileNVD2026-09-15
CVE-2026-92003Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authMEDIUM6.938%EPSS 38%ileNVD2026-09-15
CVE-2026-57581DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applicMEDIUM5.338%EPSS 38%ileNVD2026-09-14
CVE-2026-86000Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in srcMEDIUM5.338%EPSS 38%ileNVD2026-09-17
CVE-2026-90513A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue MEDIUM6.938%EPSS 38%ileNVD2026-09-13
CVE-2026-86861pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested patMEDIUM6.038%EPSS 38%ileNVD2026-09-17
CVE-2026-59823LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated MEDIUM5.338%EPSS 38%ileNVD2026-09-16
CVE-2026-92879A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/MEDIUM5.337%EPSS 37%ileNVD2026-09-17
CVE-2026-20283A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbiMEDIUM6.537%EPSS 37%ileNVD2026-09-16
CVE-2026-40535An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in SynoloMEDIUM6.537%EPSS 37%ileNVD2026-09-18
CVE-2026-90526A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unkMEDIUM5.537%EPSS 37%ileNVD2026-09-13
CVE-2026-15797The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress MEDIUM6.437%EPSS 37%ileNVD2026-09-18
CVE-2026-90691A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impMEDIUM5.537%EPSS 37%ileNVD2026-09-14
CVE-2026-90786A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the filMEDIUM5.537%EPSS 37%ileNVD2026-09-14
CVE-2026-69215Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unanMEDIUM6.836%EPSS 36%ileNVD2026-09-15
CVE-2026-76553The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data MEDIUM6.536%EPSS 36%ileNVD2026-09-16
CVE-2026-81915Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::sMEDIUM5.136%EPSS 36%ileNVD2026-09-11
CVE-2026-79409An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and thMEDIUM6.536%EPSS 36%ileNVD2026-09-15
CVE-2026-76701A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote MEDIUM5.936%EPSS 36%ileNVD2026-09-15
CVE-2026-76694A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways.MEDIUM6.636%EPSS 36%ileNVD2026-09-15
CVE-2026-76706A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remMEDIUM5.336%EPSS 36%ileNVD2026-09-15
CVE-2026-84439When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields intMEDIUM5.336%EPSS 36%ileNVD2026-09-16
CVE-2026-83097Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoMEDIUM6.536%EPSS 36%ileNVD2026-09-15
CVE-2026-90584A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrMEDIUM5.536%EPSS 36%ileNVD2026-09-13
CVE-2026-90784A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of MEDIUM5.536%EPSS 36%ileNVD2026-09-14
CVE-2026-90785A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compMEDIUM5.536%EPSS 36%ileNVD2026-09-14
CVE-2026-91855A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality oMEDIUM5.536%EPSS 36%ileNVD2026-09-15
CVE-2026-84524An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS MEDIUM4.336%EPSS 36%ileNVD2026-09-14
CVE-2026-84179Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and retuMEDIUM6.536%EPSS 36%ileNVD2026-09-14
CVE-2026-82433Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorMEDIUM6.536%EPSS 36%ileNVD2026-09-14
CVE-2026-47256OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generatingMEDIUM5.336%EPSS 36%ileNVD2026-09-14
CVE-2026-92936vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting.MEDIUM6.935%EPSS 35%ileNVD2026-09-17
CVE-2026-19662An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send mMEDIUM5.935%EPSS 35%ileNVD2026-09-16
CVE-2026-90840A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of MEDIUM5.535%EPSS 35%ileNVD2026-09-15
CVE-2026-54168Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8MEDIUM6.535%EPSS 35%ileNVD2026-09-15
CVE-2026-8030GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM4.335%EPSS 35%ileNVD2026-09-16
CVE-2026-77117Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in theMEDIUM5.935%EPSS 35%ileNVD2026-09-15
CVE-2026-80489Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GMEDIUM5.935%EPSS 35%ileNVD2026-09-15
CVE-2026-90516A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown fMEDIUM5.535%EPSS 35%ileNVD2026-09-13
CVE-2026-90701A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29aMEDIUM5.535%EPSS 35%ileNVD2026-09-14
CVE-2026-92405A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element iMEDIUM5.535%EPSS 35%ileNVD2026-09-16
CVE-2026-92406A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown fMEDIUM5.535%EPSS 35%ileNVD2026-09-16
CVE-2026-85652The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL InjectioMEDIUM6.535%EPSS 35%ileNVD2026-09-18
CVE-2026-90601A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_servMEDIUM6.935%EPSS 35%ileNVD2026-09-13
CVE-2026-90881A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.MEDIUM5.535%EPSS 35%ileNVD2026-09-15
CVE-2026-28966An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM4.335%EPSS 35%ileNVD2026-09-14
CVE-2026-92803LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated accMEDIUM6.935%EPSS 35%ileNVD2026-09-16
CVE-2026-56831Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negMEDIUM6.535%EPSS 35%ileNVD2026-09-15
CVE-2026-20120A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall AdaptMEDIUM5.835%EPSS 35%ileNVD2026-09-16
CVE-2026-82837GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, andMEDIUM5.335%EPSS 35%ileNVD2026-09-15
CVE-2026-90582A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file sMEDIUM5.534%EPSS 34%ileNVD2026-09-13
CVE-2026-93310A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES CollectMEDIUM5.534%EPSS 34%ileNVD2026-09-18
CVE-2026-84501An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a craMEDIUM5.334%EPSS 34%ileNVD2026-09-16
CVE-2026-75029In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOMEDIUM5.334%EPSS 34%ileNVD2026-09-16
CVE-2026-19668A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kMEDIUM5.334%EPSS 34%ileNVD2026-09-16
CVE-2026-84397Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-MEDIUM5.434%EPSS 34%ileNVD2026-09-16
CVE-2026-83458Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affecteMEDIUM5.334%EPSS 34%ileNVD2026-09-15
CVE-2026-83459Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versioMEDIUM5.334%EPSS 34%ileNVD2026-09-15
CVE-2026-84596An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS GoMEDIUM6.534%EPSS 34%ileNVD2026-09-14
CVE-2026-55946Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unautMEDIUM6.134%EPSS 34%ileNVD2026-09-17
CVE-2026-84536An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.534%EPSS 34%ileNVD2026-09-14
CVE-2026-90787A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is MEDIUM5.534%EPSS 34%ileNVD2026-09-14
CVE-2026-92416A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_repoMEDIUM5.334%EPSS 34%ileNVD2026-09-16
CVE-2026-47780free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and HMEDIUM6.934%EPSS 34%ileNVD2026-09-15
CVE-2026-76558The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database MEDIUM6.834%EPSS 34%ileNVD2026-09-16
CVE-2026-84088The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link sMEDIUM6.834%EPSS 34%ileNVD2026-09-16
CVE-2026-86784The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befoMEDIUM6.834%EPSS 34%ileNVD2026-09-16
CVE-2026-92140Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in MEDIUM6.834%EPSS 34%ileNVD2026-09-16
CVE-2026-64684RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTranspMEDIUM6.834%EPSS 34%ileNVD2026-09-16
CVE-2026-43787A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSMEDIUM5.934%EPSS 34%ileNVD2026-09-14
CVE-2026-92081fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a responMEDIUM5.934%EPSS 34%ileNVD2026-09-16
CVE-2026-87793The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.MEDIUM5.134%EPSS 34%ileNVD2026-09-15
CVE-2026-88255Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the TeMEDIUM6.333%EPSS 33%ileNVD2026-09-16
CVE-2026-89186Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and serMEDIUM6.333%EPSS 33%ileNVD2026-09-16
CVE-2026-84554An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqMEDIUM5.933%EPSS 33%ileNVD2026-09-14
CVE-2026-48490ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in MEDIUM6.933%EPSS 33%ileNVD2026-09-11
CVE-2026-90579A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_httpMEDIUM5.533%EPSS 33%ileNVD2026-09-13
CVE-2026-90620A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted elemenMEDIUM5.533%EPSS 33%ileNVD2026-09-14
CVE-2026-84571A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldenMEDIUM4.333%EPSS 33%ileNVD2026-09-14
CVE-2026-54452safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits theMEDIUM6.333%EPSS 33%ileNVD2026-09-14
CVE-2026-62949AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on toMEDIUM6.533%EPSS 33%ileNVD2026-09-16
CVE-2026-92356A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the fMEDIUM5.333%EPSS 33%ileNVD2026-09-16
CVE-2026-92365A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of theMEDIUM5.333%EPSS 33%ileNVD2026-09-16
CVE-2026-81829A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by MEDIUM5.333%EPSS 33%ileNVD2026-09-17
CVE-2026-54355MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpuMEDIUM5.333%EPSS 33%ileNVD2026-09-17
CVE-2026-92002Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exceMEDIUM5.132%EPSS 32%ileNVD2026-09-15
CVE-2026-90819A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSeMEDIUM6.932%EPSS 32%ileNVD2026-09-14
CVE-2026-53941Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiMEDIUM6.932%EPSS 32%ileNVD2026-09-15
CVE-2026-91966AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availabilityMEDIUM6.932%EPSS 32%ileNVD2026-09-15
CVE-2026-68570Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and accessMEDIUM6.532%EPSS 32%ileNVD2026-09-14
CVE-2026-53556SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datMEDIUM6.032%EPSS 32%ileNVD2026-09-17
CVE-2026-90593A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of tMEDIUM6.932%EPSS 32%ileNVD2026-09-13
CVE-2026-92215A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.gMEDIUM6.932%EPSS 32%ileNVD2026-09-16
CVE-2026-43761An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, mMEDIUM6.532%EPSS 32%ileNVD2026-09-14
CVE-2026-76104Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerabiMEDIUM5.532%EPSS 32%ileNVD2026-09-16
CVE-2026-92005Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16MEDIUM5.332%EPSS 32%ileNVD2026-09-15
CVE-2026-92790Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper tMEDIUM6.932%EPSS 32%ileNVD2026-09-16
CVE-2026-85732oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go aMEDIUM4.732%EPSS 32%ileNVD2026-09-16
CVE-2026-54529SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.pMEDIUM5.332%EPSS 32%ileNVD2026-09-14
CVE-2026-84538A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macMEDIUM6.532%EPSS 32%ileNVD2026-09-14
CVE-2026-56719MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unautMEDIUM6.332%EPSS 32%ileNVD2026-09-16
CVE-2026-78474The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks MEDIUM5.332%EPSS 32%ileNVD2026-09-16
CVE-2026-75961The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the MEDIUM4.932%EPSS 32%ileNVD2026-09-18
CVE-2026-92976A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. AMEDIUM5.131%EPSS 31%ileNVD2026-09-18
CVE-2026-75015Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, MEDIUM4.931%EPSS 31%ileNVD2026-09-14
CVE-2026-77883Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate MEDIUM4.931%EPSS 31%ileNVD2026-09-14
CVE-2026-58196ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior MEDIUM4.731%EPSS 31%ileNVD2026-09-15
CVE-2026-76556The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter valuesMEDIUM6.831%EPSS 31%ileNVD2026-09-16
CVE-2026-76557The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configurationMEDIUM6.831%EPSS 31%ileNVD2026-09-16
CVE-2026-76695Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways tMEDIUM6.531%EPSS 31%ileNVD2026-09-15
CVE-2026-52819Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user aMEDIUM6.331%EPSS 31%ileNVD2026-09-15
CVE-2026-54150next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-videMEDIUM6.931%EPSS 31%ileNVD2026-09-14
CVE-2026-12759IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolledMEDIUM6.531%EPSS 31%ileNVD2026-09-14
CVE-2026-11864IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0MEDIUM6.531%EPSS 31%ileNVD2026-09-15
CVE-2026-83175Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported MEDIUM6.531%EPSS 31%ileNVD2026-09-15
CVE-2026-83443Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versiMEDIUM6.531%EPSS 31%ileNVD2026-09-15
CVE-2026-90715A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the MEDIUM5.531%EPSS 31%ileNVD2026-09-14
CVE-2026-91087A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file composMEDIUM5.531%EPSS 31%ileNVD2026-09-15
CVE-2026-86879A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A rMEDIUM6.531%EPSS 31%ileNVD2026-09-14
CVE-2026-20072A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtaMEDIUM4.931%EPSS 31%ileNVD2026-09-16
CVE-2026-40536An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in SynologyMEDIUM4.331%EPSS 31%ileNVD2026-09-18
CVE-2026-55828qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stricMEDIUM6.031%EPSS 31%ileNVD2026-09-15
CVE-2026-76428A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conductMEDIUM4.931%EPSS 31%ileNVD2026-09-16
CVE-2026-44282Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electioMEDIUM4.831%EPSS 31%ileNVD2026-09-15
CVE-2026-77401Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusteMEDIUM6.831%EPSS 31%ileNVD2026-09-16
CVE-2026-89027miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgMEDIUM6.930%EPSS 30%ileNVD2026-09-15
CVE-2023-46035The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.MEDIUM5.930%EPSS 30%ileNVD2026-09-14
CVE-2026-76865Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filtMEDIUM6.930%EPSS 30%ileNVD2026-09-15
CVE-2026-76868Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by aMEDIUM6.930%EPSS 30%ileNVD2026-09-15
CVE-2026-92565Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns schedMEDIUM6.930%EPSS 30%ileNVD2026-09-16
CVE-2026-84487An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2MEDIUM6.530%EPSS 30%ileNVD2026-09-14
CVE-2026-56830Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() MEDIUM6.530%EPSS 30%ileNVD2026-09-15
CVE-2026-53555SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uplMEDIUM5.130%EPSS 30%ileNVD2026-09-17
CVE-2026-87076Tanium addressed an information disclosure vulnerability in Discover.MEDIUM6.530%EPSS 30%ileNVD2026-09-16
CVE-2026-77281Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depeMEDIUM6.530%EPSS 30%ileNVD2026-09-17
CVE-2026-83416Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arMEDIUM4.330%EPSS 30%ileNVD2026-09-15
CVE-2026-54688mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through MEDIUM6.530%EPSS 30%ileNVD2026-09-15
CVE-2026-90806A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCaseMEDIUM5.330%EPSS 30%ileNVD2026-09-14
CVE-2026-53715Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM5.330%EPSS 30%ileNVD2026-09-14
CVE-2026-90982@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4MEDIUM5.330%EPSS 30%ileNVD2026-09-17
CVE-2026-20285A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive IdenMEDIUM4.330%EPSS 30%ileNVD2026-09-16
CVE-2026-20286A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticatMEDIUM4.330%EPSS 30%ileNVD2026-09-16
CVE-2026-78427The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one ofMEDIUM4.330%EPSS 30%ileNVD2026-09-17
CVE-2021-3030Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GMEDIUM6.129%EPSS 29%ileNVD2026-09-17
CVE-2026-17495moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 throMEDIUM5.929%EPSS 29%ileNVD2026-09-15
CVE-2026-52822Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesMEDIUM5.329%EPSS 29%ileNVD2026-09-15
CVE-2026-52828Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportCMEDIUM5.329%EPSS 29%ileNVD2026-09-15
CVE-2026-83347Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are MEDIUM6.529%EPSS 29%ileNVD2026-09-15
CVE-2026-91079Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hMEDIUM6.329%EPSS 29%ileNVD2026-09-14
CVE-2026-65395An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.529%EPSS 29%ileNVD2026-09-14
CVE-2026-92774Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based acceMEDIUM5.329%EPSS 29%ileNVD2026-09-16
CVE-2026-44235rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersMEDIUM6.529%EPSS 29%ileNVD2026-09-17
CVE-2026-81917Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the MEDIUM5.129%EPSS 29%ileNVD2026-09-11
CVE-2026-90816A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c oMEDIUM5.329%EPSS 29%ileNVD2026-09-14
CVE-2026-92402A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affectMEDIUM5.329%EPSS 29%ileNVD2026-09-16
CVE-2026-85999Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soupsMEDIUM5.329%EPSS 29%ileNVD2026-09-17
CVE-2026-84510A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSMEDIUM6.529%EPSS 29%ileNVD2026-09-14
CVE-2026-93013RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadatMEDIUM5.329%EPSS 29%ileNVD2026-09-17
CVE-2026-43687The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOMEDIUM6.528%EPSS 28%ileNVD2026-09-14
CVE-2026-90543WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a misMEDIUM6.928%EPSS 28%ileNVD2026-09-12
CVE-2026-76426A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct MEDIUM4.928%EPSS 28%ileNVD2026-09-16
CVE-2026-90569A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicMEDIUM4.828%EPSS 28%ileNVD2026-09-13
CVE-2026-90570A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdmMEDIUM4.828%EPSS 28%ileNVD2026-09-13
CVE-2026-86882An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.528%EPSS 28%ileNVD2026-09-14
CVE-2026-16702IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) couldMEDIUM6.528%EPSS 28%ileNVD2026-09-14
CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templMEDIUM5.828%EPSS 28%ileNVD2026-09-11
CVE-2026-89064The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versiMEDIUM5.328%EPSS 28%ileNVD2026-09-17
CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A usMEDIUM4.828%EPSS 28%ileNVD2026-09-11
CVE-2026-17607The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the MEDIUM6.528%EPSS 28%ileNVD2026-09-18
CVE-2026-19641On affected platforms running Arista EOS with password authentication configured, a specially crafted password can creatMEDIUM6.928%EPSS 28%ileNVD2026-09-15
CVE-2026-84635A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOMEDIUM6.528%EPSS 28%ileNVD2026-09-14
CVE-2026-82567The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connMEDIUM5.328%EPSS 28%ileNVD2026-09-15
CVE-2026-83200Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal OMEDIUM6.528%EPSS 28%ileNVD2026-09-15
CVE-2026-20248A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software aMEDIUM6.828%EPSS 28%ileNVD2026-09-16
CVE-2026-28934A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SequoiMEDIUM6.527%EPSS 27%ileNVD2026-09-14
CVE-2026-4036An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in MEDIUM6.527%EPSS 27%ileNVD2026-09-18
CVE-2026-54246Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluMEDIUM5.727%EPSS 27%ileNVD2026-09-14
CVE-2026-20350A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticatMEDIUM4.727%EPSS 27%ileNVD2026-09-16
CVE-2026-92881A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory MEDIUM5.327%EPSS 27%ileNVD2026-09-17
CVE-2026-12739The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypasMEDIUM4.327%EPSS 27%ileNVD2026-09-18
CVE-2026-90596A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_MEDIUM6.927%EPSS 27%ileNVD2026-09-13
CVE-2026-91997evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evalMEDIUM6.927%EPSS 27%ileNVD2026-09-15
CVE-2026-89207A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface (MEDIUM6.927%EPSS 27%ileNVD2026-09-16
CVE-2026-44163fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.MEDIUM5.327%EPSS 27%ileNVD2026-09-15
CVE-2026-61709OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return MEDIUM5.327%EPSS 27%ileNVD2026-09-16
CVE-2026-86870A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSMEDIUM6.527%EPSS 27%ileNVD2026-09-14
CVE-2026-90602A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is tMEDIUM5.127%EPSS 27%ileNVD2026-09-13
CVE-2026-90517A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the MEDIUM5.527%EPSS 27%ileNVD2026-09-13
CVE-2026-76427A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read MEDIUM4.927%EPSS 27%ileNVD2026-09-16
CVE-2026-84526An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM4.327%EPSS 27%ileNVD2026-09-14
CVE-2026-90472msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deMEDIUM6.927%EPSS 27%ileNVD2026-09-12
CVE-2026-85717The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTMEDIUM6.827%EPSS 27%ileNVD2026-09-17
CVE-2026-40531An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690MEDIUM4.327%EPSS 27%ileNVD2026-09-18
CVE-2026-91099HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.126%EPSS 26%ileNVD2026-09-16
CVE-2026-76438A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an MEDIUM6.526%EPSS 26%ileNVD2026-09-16
CVE-2026-54594OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/dMEDIUM5.326%EPSS 26%ileNVD2026-09-17
CVE-2026-93296MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event GeneMEDIUM5.126%EPSS 26%ileNVD2026-09-17
CVE-2026-13471The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure DirecMEDIUM4.326%EPSS 26%ileNVD2026-09-18
CVE-2026-82124The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protectMEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-86445The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative templaMEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-86447The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative courseMEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-86449The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied posMEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-91967AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functiMEDIUM5.326%EPSS 26%ileNVD2026-09-15
CVE-2026-90567A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function MEDIUM5.126%EPSS 26%ileNVD2026-09-13
CVE-2026-53718Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.426%EPSS 26%ileNVD2026-09-14
CVE-2026-49865Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerMEDIUM5.326%EPSS 26%ileNVD2026-09-11
CVE-2026-90809A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_commanMEDIUM6.926%EPSS 26%ileNVD2026-09-14
CVE-2026-73445On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may MEDIUM6.926%EPSS 26%ileNVD2026-09-16
CVE-2026-83140Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). SupporteMEDIUM6.526%EPSS 26%ileNVD2026-09-15
CVE-2026-69206Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastMEDIUM5.926%EPSS 26%ileNVD2026-09-15
CVE-2026-76448A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow aMEDIUM4.926%EPSS 26%ileNVD2026-09-16
CVE-2026-76449A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow aMEDIUM4.926%EPSS 26%ileNVD2026-09-16
CVE-2026-16794GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.MEDIUM4.326%EPSS 26%ileNVD2026-09-16
CVE-2026-7514GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM4.326%EPSS 26%ileNVD2026-09-16
CVE-2026-76439A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE MEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-92298EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campMEDIUM6.326%EPSS 26%ileNVD2026-09-16
CVE-2026-92141Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attackMEDIUM4.326%EPSS 26%ileNVD2026-09-16
CVE-2026-54559PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c MEDIUM6.926%EPSS 26%ileNVD2026-09-14
CVE-2026-17585The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive MEDIUM5.326%EPSS 26%ileNVD2026-09-12
CVE-2026-92778CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackersMEDIUM5.326%EPSS 26%ileNVD2026-09-16
CVE-2026-63461Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facMEDIUM5.326%EPSS 26%ileNVD2026-09-17
CVE-2026-53954Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied wMEDIUM4.326%EPSS 26%ileNVD2026-09-15
CVE-2026-54648CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely MEDIUM6.525%EPSS 25%ileNVD2026-09-17
CVE-2026-86338Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may notMEDIUM6.025%EPSS 25%ileNVD2026-09-16
CVE-2026-40532A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-MEDIUM6.525%EPSS 25%ileNVD2026-09-18
CVE-2026-54254Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler MEDIUM5.925%EPSS 25%ileNVD2026-09-15
CVE-2026-81916Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the poMEDIUM5.125%EPSS 25%ileNVD2026-09-11
CVE-2026-68535Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's valiMEDIUM5.125%EPSS 25%ileNVD2026-09-11
CVE-2026-90782S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_itemsMEDIUM6.025%EPSS 25%ileNVD2026-09-13
CVE-2026-92217A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file MEDIUM5.325%EPSS 25%ileNVD2026-09-16
CVE-2026-78223Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the MEDIUM6.925%EPSS 25%ileNVD2026-09-17
CVE-2026-85718The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTMEDIUM5.925%EPSS 25%ileNVD2026-09-17
CVE-2026-12910GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM5.425%EPSS 25%ileNVD2026-09-15
CVE-2026-90443A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate eMEDIUM5.325%EPSS 25%ileNVD2026-09-11
CVE-2026-57120PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime asseMEDIUM6.525%EPSS 25%ileNVD2026-09-14
CVE-2026-54723devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a MEDIUM6.525%EPSS 25%ileNVD2026-09-14
CVE-2026-84597An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, mMEDIUM6.525%EPSS 25%ileNVD2026-09-14
CVE-2026-92927A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing oMEDIUM5.525%EPSS 25%ileNVD2026-09-17
CVE-2026-86341GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3MEDIUM4.425%EPSS 25%ileNVD2026-09-16
CVE-2026-84519An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.525%EPSS 25%ileNVD2026-09-14
CVE-2026-73457Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI)MEDIUM6.025%EPSS 25%ileNVD2026-09-16
CVE-2026-44202Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListeneMEDIUM5.325%EPSS 25%ileNVD2026-09-15
CVE-2026-75017The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid pluMEDIUM4.325%EPSS 25%ileNVD2026-09-18
CVE-2026-49463NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customMEDIUM6.525%EPSS 25%ileNVD2026-09-11
CVE-2026-90852A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtxMEDIUM5.525%EPSS 25%ileNVD2026-09-15
CVE-2026-82775An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M ContMEDIUM5.325%EPSS 25%ileNVD2026-09-14
CVE-2026-90707A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallMEDIUM6.924%EPSS 24%ileNVD2026-09-14
CVE-2026-93331A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file MEDIUM6.924%EPSS 24%ileNVD2026-09-18
CVE-2026-54165Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stMEDIUM6.424%EPSS 24%ileNVD2026-09-11
CVE-2026-88932multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a requestMEDIUM5.324%EPSS 24%ileNVD2026-09-14
CVE-2026-81565Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.MEDIUM6.924%EPSS 24%ileNVD2026-09-14
CVE-2026-83109Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). SuppoMEDIUM5.324%EPSS 24%ileNVD2026-09-15
CVE-2026-59341A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modifMEDIUM4.224%EPSS 24%ileNVD2026-09-15
CVE-2026-91922Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/paMEDIUM5.324%EPSS 24%ileNVD2026-09-15
CVE-2026-80225In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT readinMEDIUM5.324%EPSS 24%ileNVD2026-09-16
CVE-2026-85501Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. TMEDIUM5.324%EPSS 24%ileNVD2026-09-16
CVE-2026-54050Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/pMEDIUM6.524%EPSS 24%ileNVD2026-09-15
CVE-2026-17628IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account dMEDIUM5.424%EPSS 24%ileNVD2026-09-14
CVE-2026-90568A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSorMEDIUM5.124%EPSS 24%ileNVD2026-09-13
CVE-2026-90449When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party adminMEDIUM6.924%EPSS 24%ileNVD2026-09-11
CVE-2026-90940novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpMEDIUM6.924%EPSS 24%ileNVD2026-09-14
CVE-2026-83433Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). SuppMEDIUM6.524%EPSS 24%ileNVD2026-09-15
CVE-2026-84048Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < MEDIUM6.324%EPSS 24%ileNVD2026-09-15
CVE-2026-18065IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information throuMEDIUM5.324%EPSS 24%ileNVD2026-09-14
CVE-2026-90858A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. AfMEDIUM5.524%EPSS 24%ileNVD2026-09-15
CVE-2026-82125The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moMEDIUM5.324%EPSS 24%ileNVD2026-09-16
CVE-2026-92915WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/useMEDIUM6.924%EPSS 24%ileNVD2026-09-17
CVE-2026-15924Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of MEDIUM5.924%EPSS 24%ileNVD2026-09-14
CVE-2026-43677An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27,MEDIUM6.524%EPSS 24%ileNVD2026-09-14
CVE-2026-84509An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.524%EPSS 24%ileNVD2026-09-14
CVE-2026-17586The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_imgMEDIUM6.424%EPSS 24%ileNVD2026-09-18
CVE-2026-16435IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or IntMEDIUM5.924%EPSS 24%ileNVD2026-09-14
CVE-2026-8674Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search liMEDIUM5.324%EPSS 24%ileNVD2026-09-17
CVE-2026-83480Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are afMEDIUM5.324%EPSS 24%ileNVD2026-09-15
CVE-2026-12758IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoiMEDIUM5.423%EPSS 23%ileNVD2026-09-14
CVE-2026-54918NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the aMEDIUM5.323%EPSS 23%ileNVD2026-09-17
CVE-2026-65365An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM6.523%EPSS 23%ileNVD2026-09-14
CVE-2026-76446A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&MEDIUM4.923%EPSS 23%ileNVD2026-09-16
CVE-2026-19619GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM4.723%EPSS 23%ileNVD2026-09-16
CVE-2026-83076Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). SupporMEDIUM6.823%EPSS 23%ileNVD2026-09-15
CVE-2026-48987pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyloadMEDIUM6.523%EPSS 23%ileNVD2026-09-15
CVE-2026-81872OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/loMEDIUM6.323%EPSS 23%ileNVD2026-09-16
CVE-2026-29810CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.MEDIUM4.323%EPSS 23%ileNVD2026-09-13
CVE-2026-886181024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This MEDIUM6.523%EPSS 23%ileNVD2026-09-15
CVE-2026-54604OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes MEDIUM5.323%EPSS 23%ileNVD2026-09-17
CVE-2026-61597djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to MEDIUM5.123%EPSS 23%ileNVD2026-09-16
CVE-2026-84564An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPaMEDIUM4.323%EPSS 23%ileNVD2026-09-14
CVE-2026-50018Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClieMEDIUM6.523%EPSS 23%ileNVD2026-09-11
CVE-2026-61588djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to MEDIUM6.523%EPSS 23%ileNVD2026-09-16
CVE-2026-77490Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) MEDIUM6.123%EPSS 23%ileNVD2026-09-11
CVE-2026-19273IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File GatewaMEDIUM5.423%EPSS 23%ileNVD2026-09-14
CVE-2026-73444On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauMEDIUM5.323%EPSS 23%ileNVD2026-09-15
CVE-2026-43719A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOSMEDIUM6.523%EPSS 23%ileNVD2026-09-14
CVE-2026-92764OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returniMEDIUM5.323%EPSS 23%ileNVD2026-09-16
CVE-2026-54561MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_iMEDIUM6.223%EPSS 23%ileNVD2026-09-15
CVE-2026-92357A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-proceMEDIUM5.323%EPSS 23%ileNVD2026-09-16
CVE-2026-84859ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search eMEDIUM6.522%EPSS 22%ileNVD2026-09-16
CVE-2026-85078Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling doesMEDIUM6.522%EPSS 22%ileNVD2026-09-17
CVE-2026-54181backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM5.422%EPSS 22%ileNVD2026-09-14
CVE-2026-82785Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a speMEDIUM5.322%EPSS 22%ileNVD2026-09-14
CVE-2026-91859Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CaMEDIUM5.322%EPSS 22%ileNVD2026-09-15
CVE-2026-55795Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllMEDIUM6.922%EPSS 22%ileNVD2026-09-14
CVE-2026-93451snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that alloMEDIUM6.922%EPSS 22%ileNVD2026-09-18
CVE-2026-92139Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includinMEDIUM6.522%EPSS 22%ileNVD2026-09-16
CVE-2026-86358Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauMEDIUM6.522%EPSS 22%ileNVD2026-09-16
CVE-2026-52852Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups aMEDIUM6.522%EPSS 22%ileNVD2026-09-17
CVE-2026-64753A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 2MEDIUM6.522%EPSS 22%ileNVD2026-09-14
CVE-2026-16588The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versiMEDIUM6.522%EPSS 22%ileNVD2026-09-16
CVE-2026-73469When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain MEDIUM6.922%EPSS 22%ileNVD2026-09-16
CVE-2026-40533An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (MEDIUM5.322%EPSS 22%ileNVD2026-09-18
CVE-2025-68624N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user MEDIUM4.322%EPSS 22%ileNVD2026-09-14
CVE-2026-83441Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported MEDIUM6.822%EPSS 22%ileNVD2026-09-15
CVE-2026-92568MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allowsMEDIUM5.322%EPSS 22%ileNVD2026-09-16
CVE-2026-50022Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSoMEDIUM5.822%EPSS 22%ileNVD2026-09-17
CVE-2026-90509A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspecMEDIUM5.522%EPSS 22%ileNVD2026-09-13
CVE-2026-90510A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceIMEDIUM5.522%EPSS 22%ileNVD2026-09-13
CVE-2026-77702The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to MEDIUM5.322%EPSS 22%ileNVD2026-09-16
CVE-2026-73191URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configMEDIUM6.122%EPSS 22%ileNVD2026-09-14
CVE-2026-84532An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.422%EPSS 22%ileNVD2026-09-14
CVE-2026-55863motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program wMEDIUM5.322%EPSS 22%ileNVD2026-09-15
CVE-2026-92813Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unaMEDIUM6.922%EPSS 22%ileNVD2026-09-16
CVE-2026-90856A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts aMEDIUM5.522%EPSS 22%ileNVD2026-09-15
CVE-2026-92991The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variouMEDIUM5.422%EPSS 22%ileNVD2026-09-18
CVE-2026-85198The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SMEDIUM6.522%EPSS 22%ileNVD2026-09-12
CVE-2026-90808A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._MEDIUM5.322%EPSS 22%ileNVD2026-09-14
CVE-2026-75523Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicatiMEDIUM5.921%EPSS 21%ileNVD2026-09-17
CVE-2026-76703A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN GatewaMEDIUM5.521%EPSS 21%ileNVD2026-09-15
CVE-2026-89020MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in MEDIUM5.321%EPSS 21%ileNVD2026-09-14
CVE-2026-11984The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions upMEDIUM5.321%EPSS 21%ileNVD2026-09-16
CVE-2026-76559The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during tMEDIUM4.121%EPSS 21%ileNVD2026-09-16
CVE-2026-76444A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker toMEDIUM5.321%EPSS 21%ileNVD2026-09-16
CVE-2026-91101HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.121%EPSS 21%ileNVD2026-09-16
CVE-2026-91103HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM5.121%EPSS 21%ileNVD2026-09-16
CVE-2026-20235A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to viewMEDIUM4.921%EPSS 21%ileNVD2026-09-16
CVE-2026-56666 ZITADEL: Auto-linking by email: IdP-side email verification is not checkedMEDIUM4.821%EPSS 21%ileGitHub2026-09-11
CVE-2026-49446Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as MEDIUM6.121%EPSS 21%ileNVD2026-09-15
CVE-2026-82720NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPsMEDIUM5.921%EPSS 21%ileNVD2026-09-16
CVE-2026-92461yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoinMEDIUM5.321%EPSS 21%ileNVD2026-09-16
CVE-2026-77147Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequaMEDIUM6.521%EPSS 21%ileNVD2026-09-14
CVE-2026-89307The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject aMEDIUM5.121%EPSS 21%ileNVD2026-09-15
CVE-2026-13277IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By MEDIUM4.721%EPSS 21%ileNVD2026-09-14
CVE-2026-85349The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boardMEDIUM4.321%EPSS 21%ileNVD2026-09-16
CVE-2026-85572The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lessMEDIUM4.321%EPSS 21%ileNVD2026-09-16
CVE-2026-83460Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affectedMEDIUM6.521%EPSS 21%ileNVD2026-09-15
CVE-2024-11222GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1MEDIUM6.421%EPSS 21%ileNVD2026-09-16
CVE-2026-62132Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.MEDIUM5.321%EPSS 21%ileNVD2026-09-11
CVE-2026-90583A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected MEDIUM5.321%EPSS 21%ileNVD2026-09-13
CVE-2026-75792IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative useMEDIUM4.321%EPSS 21%ileNVD2026-09-14
CVE-2026-88994The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a MEDIUM6.621%EPSS 21%ileNVD2026-09-18
CVE-2026-92358A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a diffMEDIUM6.421%EPSS 21%ileNVD2026-09-16
CVE-2026-77190On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to MEDIUM6.021%EPSS 21%ileNVD2026-09-16
CVE-2026-49462NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customMEDIUM5.321%EPSS 21%ileNVD2026-09-11
CVE-2026-92893A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unMEDIUM4.321%EPSS 21%ileNVD2026-09-17
CVE-2026-12985Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client ReMEDIUM6.821%EPSS 21%ileNVD2026-09-14
CVE-2020-15875An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the infMEDIUM5.021%EPSS 21%ileNVD2026-09-13
CVE-2026-76858Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi causedMEDIUM4.821%EPSS 21%ileNVD2026-09-15
CVE-2026-90498A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the fiMEDIUM5.520%EPSS 20%ileNVD2026-09-13
CVE-2026-92184A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of thMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-83250Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compMEDIUM6.520%EPSS 20%ileNVD2026-09-15
CVE-2026-55636Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templatesMEDIUM5.720%EPSS 20%ileNVD2026-09-15
CVE-2026-76447A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow anMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-91720Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outsideMEDIUM4.720%EPSS 20%ileNVD2026-09-15
CVE-2026-18515IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with NavigaMEDIUM4.320%EPSS 20%ileNVD2026-09-14
CVE-2026-19542Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end MEDIUM5.620%EPSS 20%ileNVD2026-09-14
CVE-2026-91982Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settinMEDIUM5.320%EPSS 20%ileNVD2026-09-15
CVE-2026-15892The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete(MEDIUM5.320%EPSS 20%ileNVD2026-09-13
CVE-2026-16188IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the serverMEDIUM5.320%EPSS 20%ileNVD2026-09-14
CVE-2026-17576The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to,MEDIUM6.520%EPSS 20%ileNVD2026-09-18
CVE-2026-90841A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is aMEDIUM5.520%EPSS 20%ileNVD2026-09-15
CVE-2026-90981The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site ScriptingMEDIUM6.120%EPSS 20%ileNVD2026-09-18
CVE-2026-55591Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in srMEDIUM5.820%EPSS 20%ileNVD2026-09-15
CVE-2026-15758The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to SensitMEDIUM5.320%EPSS 20%ileNVD2026-09-15
CVE-2026-73443On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker withinMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-55617Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logicMEDIUM6.920%EPSS 20%ileNVD2026-09-15
CVE-2026-81303A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes theMEDIUM6.320%EPSS 20%ileNVD2026-09-15
CVE-2026-11918IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mechMEDIUM5.420%EPSS 20%ileNVD2026-09-15
CVE-2026-90527A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admiMEDIUM5.320%EPSS 20%ileNVD2026-09-13
CVE-2026-90571A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functioMEDIUM5.320%EPSS 20%ileNVD2026-09-13
CVE-2026-92455yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, aMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-87028Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint belMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-90977The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is eMEDIUM5.320%EPSS 20%ileNVD2026-09-18
CVE-2026-54546CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.MEDIUM5.020%EPSS 20%ileNVD2026-09-17
CVE-2026-89141The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct ObjeMEDIUM6.520%EPSS 20%ileNVD2026-09-15
CVE-2026-90535Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/aMEDIUM6.320%EPSS 20%ileNVD2026-09-12
CVE-2026-14275IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute MEDIUM6.320%EPSS 20%ileNVD2026-09-14
CVE-2026-14276IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute MEDIUM6.320%EPSS 20%ileNVD2026-09-14
CVE-2026-92569Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-92933vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to theMEDIUM6.920%EPSS 20%ileNVD2026-09-17
CVE-2026-91980vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enuMEDIUM5.320%EPSS 20%ileNVD2026-09-15
CVE-2026-87854The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protectingMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-87896The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint thatMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-87907The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints thaMEDIUM5.320%EPSS 20%ileNVD2026-09-16
CVE-2026-92237Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2MEDIUM6.520%EPSS 20%ileNVD2026-09-15
CVE-2026-91983Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails tMEDIUM5.320%EPSS 20%ileNVD2026-09-15
CVE-2026-12751IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML codMEDIUM5.419%EPSS 19%ileNVD2026-09-15
CVE-2026-52820Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets MEDIUM5.319%EPSS 19%ileNVD2026-09-15
CVE-2026-52825Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/MEDIUM5.319%EPSS 19%ileNVD2026-09-15
CVE-2026-91726Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memoMEDIUM4.719%EPSS 19%ileNVD2026-09-15
CVE-2026-79700Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP PaMEDIUM6.919%EPSS 19%ileNVD2026-09-14
CVE-2026-79701Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form BuiMEDIUM6.919%EPSS 19%ileNVD2026-09-14
CVE-2026-91143goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticatedMEDIUM6.919%EPSS 19%ileNVD2026-09-14
CVE-2026-77161The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter MEDIUM6.519%EPSS 19%ileNVD2026-09-12
CVE-2026-76696A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conducMEDIUM6.519%EPSS 19%ileNVD2026-09-15
CVE-2026-90876A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is MEDIUM5.519%EPSS 19%ileNVD2026-09-15
CVE-2026-92926A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writeparMEDIUM5.519%EPSS 19%ileNVD2026-09-17
CVE-2026-82782Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and senMEDIUM5.319%EPSS 19%ileNVD2026-09-14
CVE-2026-92255Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by impMEDIUM5.319%EPSS 19%ileNVD2026-09-15
CVE-2026-89029Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. MEDIUM5.319%EPSS 19%ileNVD2026-09-16
CVE-2026-89030Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to lMEDIUM5.319%EPSS 19%ileNVD2026-09-16
CVE-2026-82437Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For MEDIUM4.319%EPSS 19%ileNVD2026-09-14
CVE-2026-78227NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUICMEDIUM6.519%EPSS 19%ileNVD2026-09-16
CVE-2023-50462An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to veriMEDIUM5.319%EPSS 19%ileNVD2026-09-14
CVE-2026-92458yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler thatMEDIUM5.319%EPSS 19%ileNVD2026-09-16
CVE-2026-90849A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by thMEDIUM5.519%EPSS 19%ileNVD2026-09-15
CVE-2026-13635An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-MEDIUM5.319%EPSS 19%ileNVD2026-09-18
CVE-2026-89321Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limiteMEDIUM4.319%EPSS 19%ileNVD2026-09-14
CVE-2026-56665ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP ProviderMEDIUM4.219%EPSS 19%ileGitHub2026-09-11
CVE-2026-92249The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter iMEDIUM6.119%EPSS 19%ileNVD2026-09-18
CVE-2026-92554The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to ReflecteMEDIUM6.119%EPSS 19%ileNVD2026-09-18
CVE-2026-76434A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISEMEDIUM4.919%EPSS 19%ileNVD2026-09-16
CVE-2026-82191Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2,MEDIUM5.319%EPSS 19%ileNVD2026-09-15
CVE-2026-91707The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.MEDIUM5.319%EPSS 19%ileNVD2026-09-18
CVE-2026-92894A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LooMEDIUM4.319%EPSS 19%ileNVD2026-09-17
CVE-2026-90514A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown functionMEDIUM5.518%EPSS 18%ileNVD2026-09-13
CVE-2026-90515A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknMEDIUM5.518%EPSS 18%ileNVD2026-09-13
CVE-2026-90789A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functMEDIUM5.518%EPSS 18%ileNVD2026-09-14
CVE-2026-90805A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. ThMEDIUM5.518%EPSS 18%ileNVD2026-09-14
CVE-2026-90844A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of MEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90846A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the fiMEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90877A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown MEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90879A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzzMEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-91004A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknownMEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90848A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StMEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-83251Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (compMEDIUM6.518%EPSS 18%ileNVD2026-09-15
CVE-2026-88743Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags.MEDIUM6.118%EPSS 18%ileNVD2026-09-15
CVE-2026-82778An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on tMEDIUM5.318%EPSS 18%ileNVD2026-09-14
CVE-2026-86900An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. MMEDIUM6.518%EPSS 18%ileNVD2026-09-14
CVE-2026-14472The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block CoMEDIUM6.418%EPSS 18%ileNVD2026-09-18
CVE-2026-53658Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP MEDIUM6.318%EPSS 18%ileNVD2026-09-15
CVE-2026-91851Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DaMEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-32599Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's databaseMEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-54724Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidMEDIUM6.118%EPSS 18%ileNVD2026-09-15
CVE-2026-90495A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance-MEDIUM5.518%EPSS 18%ileNVD2026-09-13
CVE-2026-90854A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted elementMEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90855A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown fMEDIUM5.518%EPSS 18%ileNVD2026-09-15
CVE-2026-69214Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a MEDIUM6.818%EPSS 18%ileNVD2026-09-15
CVE-2026-1759Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege EscalaMEDIUM6.518%EPSS 18%ileNVD2026-09-15
CVE-2026-90771joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation functionMEDIUM6.318%EPSS 18%ileNVD2026-09-13
CVE-2026-82561Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a clMEDIUM5.918%EPSS 18%ileNVD2026-09-16
CVE-2026-92781Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten heMEDIUM5.318%EPSS 18%ileNVD2026-09-16
CVE-2026-85196Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere exMEDIUM5.318%EPSS 18%ileNVD2026-09-14
CVE-2026-92214A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/cMEDIUM5.118%EPSS 18%ileNVD2026-09-16
CVE-2026-84518This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOMEDIUM4.318%EPSS 18%ileNVD2026-09-14
CVE-2026-57115PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the iniMEDIUM6.518%EPSS 18%ileNVD2026-09-14
CVE-2026-52821Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{pMEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-52826Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/MEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-90439NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL vMEDIUM6.918%EPSS 18%ileNVD2026-09-15
CVE-2026-65355An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPaMEDIUM4.318%EPSS 18%ileNVD2026-09-14
CVE-2026-87267Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM5.318%EPSS 18%ileNVD2026-09-15
CVE-2026-89278The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vMEDIUM5.318%EPSS 18%ileNVD2026-09-18
CVE-2026-86475The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission agaMEDIUM5.317%EPSS 17%ileNVD2026-09-16
CVE-2026-56592HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate aMEDIUM6.517%EPSS 17%ileNVD2026-09-18
CVE-2026-90708A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file MEDIUM5.517%EPSS 17%ileNVD2026-09-14
CVE-2026-86823The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a publicMEDIUM5.317%EPSS 17%ileNVD2026-09-16
CVE-2026-40537A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-MEDIUM4.317%EPSS 17%ileNVD2026-09-18
CVE-2026-85720The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTMEDIUM5.917%EPSS 17%ileNVD2026-09-17
CVE-2026-87169Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componenMEDIUM6.117%EPSS 17%ileNVD2026-09-15
CVE-2026-88976Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.MEDIUM6.117%EPSS 17%ileNVD2026-09-16
CVE-2026-15396IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requMEDIUM6.517%EPSS 17%ileNVD2026-09-14
CVE-2026-15634IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requMEDIUM6.517%EPSS 17%ileNVD2026-09-14
CVE-2026-12749IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authentMEDIUM6.417%EPSS 17%ileNVD2026-09-15
CVE-2026-12750IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authentMEDIUM6.417%EPSS 17%ileNVD2026-09-15
CVE-2026-83419Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle CommunicatMEDIUM5.417%EPSS 17%ileNVD2026-09-15
CVE-2026-83488Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported MEDIUM5.417%EPSS 17%ileNVD2026-09-15
CVE-2025-5802The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of useMEDIUM5.317%EPSS 17%ileNVD2026-09-15
CVE-2026-86796The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befoMEDIUM5.317%EPSS 17%ileNVD2026-09-18
CVE-2026-86800The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before MEDIUM5.317%EPSS 17%ileNVD2026-09-18
CVE-2026-16187IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitivMEDIUM6.517%EPSS 17%ileNVD2026-09-14
CVE-2026-10148The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mMEDIUM6.417%EPSS 17%ileNVD2026-09-12
CVE-2026-15402The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to SMEDIUM6.417%EPSS 17%ileNVD2026-09-15
CVE-2026-91993Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoinMEDIUM5.317%EPSS 17%ileNVD2026-09-15
CVE-2026-55375canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryMEDIUM5.317%EPSS 17%ileNVD2026-09-15
CVE-2026-92754PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where thMEDIUM5.317%EPSS 17%ileNVD2026-09-16
CVE-2026-92904A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_MEDIUM4.317%EPSS 17%ileNVD2026-09-17
CVE-2026-87113Tanium addressed an improper access controls vulnerability in Threat Response.MEDIUM6.317%EPSS 17%ileNVD2026-09-16
CVE-2026-76704A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticateMEDIUM5.517%EPSS 17%ileNVD2026-09-15
CVE-2026-2380On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sensMEDIUM5.117%EPSS 17%ileNVD2026-09-16
CVE-2026-91081Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymousMEDIUM6.916%EPSS 16%ileNVD2026-09-14
CVE-2026-12106The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, MEDIUM6.416%EPSS 16%ileNVD2026-09-18
CVE-2026-10556Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entrMEDIUM5.316%EPSS 16%ileNVD2026-09-14
CVE-2026-76450A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow aMEDIUM4.916%EPSS 16%ileNVD2026-09-16
CVE-2026-76451A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow aMEDIUM4.916%EPSS 16%ileNVD2026-09-16
CVE-2026-91740Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin MEDIUM4.316%EPSS 16%ileNVD2026-09-15
CVE-2026-70755Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File downMEDIUM6.516%EPSS 16%ileNVD2026-09-15
CVE-2026-87116Tanium addressed a server-side request forgery vulnerability in Threat Response.MEDIUM6.516%EPSS 16%ileNVD2026-09-16
CVE-2026-78318Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. MEDIUM6.116%EPSS 16%ileNVD2026-09-14
CVE-2026-92880A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/cMEDIUM5.316%EPSS 16%ileNVD2026-09-17
CVE-2026-91944crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forMEDIUM5.116%EPSS 16%ileNVD2026-09-15
CVE-2026-65352An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadMEDIUM4.316%EPSS 16%ileNVD2026-09-14
CVE-2026-91100HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM6.816%EPSS 16%ileNVD2026-09-16
CVE-2026-57570backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaMEDIUM6.516%EPSS 16%ileNVD2026-09-14
CVE-2026-86869An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM6.516%EPSS 16%ileNVD2026-09-14
CVE-2026-90614A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_modeMEDIUM5.316%EPSS 16%ileNVD2026-09-14
CVE-2026-92949vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowinMEDIUM6.316%EPSS 16%ileNVD2026-09-17
CVE-2026-79705A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archMEDIUM4.516%EPSS 16%ileNVD2026-09-15
CVE-2026-55847Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js MEDIUM6.116%EPSS 16%ileNVD2026-09-14
CVE-2026-11355The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a mMEDIUM5.316%EPSS 16%ileNVD2026-09-12
CVE-2024-38639An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the MEDIUM4.816%EPSS 16%ileNVD2026-09-18
CVE-2026-91198GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unaMEDIUM6.916%EPSS 16%ileNVD2026-09-14
CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated MEDIUM5.916%EPSS 16%ileNVD2026-09-11
CVE-2026-16750The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of daMEDIUM5.316%EPSS 16%ileNVD2026-09-17
CVE-2026-90547WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark pMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-89021MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractioMEDIUM6.916%EPSS 16%ileNVD2026-09-14
CVE-2026-54676Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieveMEDIUM6.516%EPSS 16%ileNVD2026-09-17
CVE-2026-18120Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invokinMEDIUM6.316%EPSS 16%ileNVD2026-09-16
CVE-2026-91962FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values frMEDIUM5.316%EPSS 16%ileNVD2026-09-15
CVE-2026-92622The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' ShortcodeMEDIUM6.416%EPSS 16%ileNVD2026-09-18
CVE-2026-52724Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2MEDIUM5.816%EPSS 16%ileNVD2026-09-15
CVE-2026-15004The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site ScMEDIUM5.416%EPSS 16%ileNVD2026-09-18
CVE-2026-18441The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to IMEDIUM4.316%EPSS 16%ileNVD2026-09-18
CVE-2026-90536WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoinMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-90539WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in tMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-90541WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-90550WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkinsMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-77169A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowedMEDIUM6.516%EPSS 16%ileNVD2026-09-18
CVE-2024-58384Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage returnMEDIUM6.316%EPSS 16%ileNVD2026-09-15
CVE-2026-87828The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-updaMEDIUM5.716%EPSS 16%ileNVD2026-09-16
CVE-2026-69216Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-sizMEDIUM5.416%EPSS 16%ileNVD2026-09-15
CVE-2026-91981Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. AttackersMEDIUM5.316%EPSS 16%ileNVD2026-09-15
CVE-2026-90473msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAMEDIUM6.916%EPSS 16%ileNVD2026-09-12
CVE-2026-92132Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected iMEDIUM5.416%EPSS 16%ileNVD2026-09-16
CVE-2026-78152The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the strMEDIUM5.316%EPSS 16%ileNVD2026-09-12
CVE-2026-76796The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parameMEDIUM5.116%EPSS 16%ileNVD2026-09-15
CVE-2026-83354Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version thaMEDIUM6.315%EPSS 15%ileNVD2026-09-15
CVE-2026-84588A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. MoMEDIUM6.515%EPSS 15%ileNVD2026-09-14
CVE-2026-88910The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthMEDIUM5.315%EPSS 15%ileNVD2026-09-16
CVE-2026-92714The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and incluMEDIUM6.515%EPSS 15%ileNVD2026-09-18
CVE-2026-13276IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 MEDIUM6.115%EPSS 15%ileNVD2026-09-14
CVE-2023-50459An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for MEDIUM5.415%EPSS 15%ileNVD2026-09-14
CVE-2023-50460An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticateMEDIUM5.415%EPSS 15%ileNVD2026-09-14
CVE-2026-93395A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when procMEDIUM6.915%EPSS 15%ileNVD2026-09-17
CVE-2026-91714Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engiMEDIUM5.315%EPSS 15%ileNVD2026-09-15
CVE-2026-91725Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive informMEDIUM5.315%EPSS 15%ileNVD2026-09-15
CVE-2026-92583AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rateMEDIUM6.915%EPSS 15%ileNVD2026-09-16
CVE-2026-90551WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_frMEDIUM6.915%EPSS 15%ileNVD2026-09-12
CVE-2026-82847The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputtingMEDIUM6.815%EPSS 15%ileNVD2026-09-12
CVE-2026-83532The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes bMEDIUM6.815%EPSS 15%ileNVD2026-09-12
CVE-2026-86790The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a MEDIUM6.815%EPSS 15%ileNVD2026-09-12
CVE-2026-86788The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the sMEDIUM6.815%EPSS 15%ileNVD2026-09-17
CVE-2026-91011The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites MEDIUM6.815%EPSS 15%ileNVD2026-09-17
CVE-2026-53708ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MMEDIUM6.615%EPSS 15%ileNVD2026-09-14
CVE-2026-55832Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2MEDIUM6.115%EPSS 15%ileNVD2026-09-14
CVE-2026-54521FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMPMEDIUM6.115%EPSS 15%ileNVD2026-09-17
CVE-2026-92213A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/weMEDIUM5.115%EPSS 15%ileNVD2026-09-16
CVE-2026-69212Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware striMEDIUM5.915%EPSS 15%ileNVD2026-09-15
CVE-2026-54613Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5MEDIUM5.415%EPSS 15%ileNVD2026-09-17
CVE-2026-45056matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix cliMEDIUM6.915%EPSS 15%ileNVD2026-09-11
CVE-2026-15814Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount oMEDIUM6.515%EPSS 15%ileNVD2026-09-14
CVE-2026-5132Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpaMEDIUM6.515%EPSS 15%ileNVD2026-09-14
CVE-2026-84909The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site ScriMEDIUM6.415%EPSS 15%ileNVD2026-09-18
CVE-2026-55235langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a rMEDIUM5.915%EPSS 15%ileNVD2026-09-14
CVE-2026-90548WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGalleMEDIUM6.915%EPSS 15%ileNVD2026-09-12
CVE-2026-73436On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 pMEDIUM6.015%EPSS 15%ileNVD2026-09-16
CVE-2026-77753The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an ApMEDIUM5.515%EPSS 15%ileNVD2026-09-12
CVE-2026-90486A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by thMEDIUM5.315%EPSS 15%ileNVD2026-09-12
CVE-2026-90941novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allMEDIUM5.315%EPSS 15%ileNVD2026-09-14
CVE-2026-90957Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains MEDIUM5.115%EPSS 15%ileNVD2026-09-14
CVE-2026-54503plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME typeMEDIUM4.315%EPSS 15%ileNVD2026-09-15
CVE-2026-73497MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0MEDIUM6.514%EPSS 14%ileNVD2026-09-14
CVE-2026-90820A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizatMEDIUM5.314%EPSS 14%ileNVD2026-09-14
CVE-2026-91744Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who haMEDIUM5.314%EPSS 14%ileNVD2026-09-15
CVE-2026-89031Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records oMEDIUM5.314%EPSS 14%ileNVD2026-09-16
CVE-2026-73245Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-authMEDIUM6.514%EPSS 14%ileGitHub2026-09-17
CVE-2026-16593The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them MEDIUM6.814%EPSS 14%ileNVD2026-09-15
CVE-2026-54248Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services andMEDIUM6.514%EPSS 14%ileNVD2026-09-11
CVE-2026-83077Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). SuppMEDIUM6.414%EPSS 14%ileNVD2026-09-15
CVE-2026-81443Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerabMEDIUM6.414%EPSS 14%ileNVD2026-09-17
CVE-2026-92561The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter inMEDIUM6.114%EPSS 14%ileNVD2026-09-18
CVE-2026-12742IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted MEDIUM5.414%EPSS 14%ileNVD2026-09-15
CVE-2026-16582The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatioMEDIUM5.314%EPSS 14%ileNVD2026-09-17
CVE-2026-92932In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error inMEDIUM5.114%EPSS 14%ileNVD2026-09-17
CVE-2026-90467aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMMEDIUM6.314%EPSS 14%ileNVD2026-09-12
CVE-2026-90936Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. AuthentMEDIUM5.314%EPSS 14%ileNVD2026-09-14
CVE-2026-81566Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0MEDIUM5.114%EPSS 14%ileNVD2026-09-14
CVE-2026-93379Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatioMEDIUM4.314%EPSS 14%ileNVD2026-09-17
CVE-2023-34854HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.MEDIUM6.614%EPSS 14%ileNVD2026-09-14
CVE-2026-81479Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A MEDIUM5.814%EPSS 14%ileNVD2026-09-17
CVE-2026-55374canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrMEDIUM4.814%EPSS 14%ileNVD2026-09-15
CVE-2026-5920The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' paraMEDIUM6.414%EPSS 14%ileNVD2026-09-16
CVE-2026-62114Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.MEDIUM5.314%EPSS 14%ileNVD2026-09-11
CVE-2026-62140Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.MEDIUM5.314%EPSS 14%ileNVD2026-09-11
CVE-2026-66676Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.MEDIUM5.314%EPSS 14%ileNVD2026-09-17
CVE-2026-74017Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.MEDIUM5.314%EPSS 14%ileNVD2026-09-17
CVE-2026-54247Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetesMEDIUM4.314%EPSS 14%ileNVD2026-09-14
CVE-2026-91746Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-originMEDIUM4.314%EPSS 14%ileNVD2026-09-15
CVE-2026-54495The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant whMEDIUM4.314%EPSS 14%ileNVD2026-09-17
CVE-2026-83278Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported verMEDIUM6.814%EPSS 14%ileNVD2026-09-15
CVE-2026-83491Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). SupportedMEDIUM6.814%EPSS 14%ileNVD2026-09-15
CVE-2026-91181Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objeMEDIUM6.514%EPSS 14%ileNVD2026-09-14
CVE-2026-7208Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows autMEDIUM6.014%EPSS 14%ileNVD2026-09-14
CVE-2026-89138The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.MEDIUM4.314%EPSS 14%ileNVD2026-09-18
CVE-2026-73965Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions MEDIUM6.814%EPSS 14%ileNVD2026-09-15
CVE-2026-87253Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version thMEDIUM6.114%EPSS 14%ileNVD2026-09-15
CVE-2026-18555The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to ReflMEDIUM6.114%EPSS 14%ileNVD2026-09-16
CVE-2026-76081ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissionMEDIUM5.514%EPSS 14%ileNVD2026-09-14
CVE-2026-7884IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit theirMEDIUM5.414%EPSS 14%ileNVD2026-09-14
CVE-2026-83431Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versionsMEDIUM5.414%EPSS 14%ileNVD2026-09-15
CVE-2026-92973ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fMEDIUM5.314%EPSS 14%ileNVD2026-09-17
CVE-2026-90453A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's RefeMEDIUM5.114%EPSS 14%ileNVD2026-09-11
CVE-2026-93386UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging sociMEDIUM5.413%EPSS 13%ileNVD2026-09-17
CVE-2026-93383Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin dMEDIUM4.313%EPSS 13%ileNVD2026-09-17
CVE-2026-93387Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origMEDIUM4.313%EPSS 13%ileNVD2026-09-17
CVE-2026-13265IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1MEDIUM6.813%EPSS 13%ileNVD2026-09-14
CVE-2026-67071HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted properMEDIUM6.513%EPSS 13%ileNVD2026-09-17
CVE-2026-54642CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-MEDIUM5.313%EPSS 13%ileNVD2026-09-17
CVE-2026-91942crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns uMEDIUM5.113%EPSS 13%ileNVD2026-09-15
CVE-2026-88261Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.MEDIUM5.113%EPSS 13%ileNVD2026-09-15
CVE-2026-91019The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored paymeMEDIUM4.913%EPSS 13%ileNVD2026-09-17
CVE-2026-77689The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actuaMEDIUM5.313%EPSS 13%ileNVD2026-09-12
CVE-2026-43696An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An aMEDIUM5.313%EPSS 13%ileNVD2026-09-14
CVE-2026-15412IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attackMEDIUM6.513%EPSS 13%ileNVD2026-09-14
CVE-2026-92133Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API toMEDIUM5.413%EPSS 13%ileNVD2026-09-16
CVE-2026-90884The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all vMEDIUM5.413%EPSS 13%ileNVD2026-09-18
CVE-2026-76863Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plMEDIUM5.313%EPSS 13%ileNVD2026-09-15
CVE-2026-90976The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an accoMEDIUM5.313%EPSS 13%ileNVD2026-09-18
CVE-2026-92627A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a MEDIUM4.613%EPSS 13%ileNVD2026-09-16
CVE-2026-92131Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to MEDIUM4.213%EPSS 13%ileNVD2026-09-16
CVE-2026-90455A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later revertMEDIUM6.313%EPSS 13%ileNVD2026-09-11
CVE-2026-90450The application's role-authorization lookup defaults to granting access when a request handler's name is not present in MEDIUM5.313%EPSS 13%ileNVD2026-09-11
CVE-2026-85188Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, ConditionMEDIUM6.913%EPSS 13%ileNVD2026-09-14
CVE-2026-91991Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitraryMEDIUM6.313%EPSS 13%ileNVD2026-09-15
CVE-2026-54643CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.phMEDIUM5.413%EPSS 13%ileNVD2026-09-17
CVE-2026-91742Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging MEDIUM4.813%EPSS 13%ileNVD2026-09-15
CVE-2026-13407The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted throuMEDIUM5.412%EPSS 12%ileNVD2026-09-16
CVE-2026-12765IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticMEDIUM6.512%EPSS 12%ileNVD2026-09-14
CVE-2026-12767IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticMEDIUM6.512%EPSS 12%ileNVD2026-09-14
CVE-2026-93385Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informatMEDIUM6.512%EPSS 12%ileNVD2026-09-17
CVE-2026-69211Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-infMEDIUM4.812%EPSS 12%ileNVD2026-09-15
CVE-2026-86348Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authentiMEDIUM4.312%EPSS 12%ileNVD2026-09-14
CVE-2026-86349Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting MEDIUM4.312%EPSS 12%ileNVD2026-09-14
CVE-2026-90534Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/noMEDIUM6.112%EPSS 12%ileNVD2026-09-12
CVE-2026-84600An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS MEDIUM5.412%EPSS 12%ileNVD2026-09-14
CVE-2026-16189IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the serverMEDIUM4.812%EPSS 12%ileNVD2026-09-14
CVE-2026-43674An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An atMEDIUM4.612%EPSS 12%ileNVD2026-09-14
CVE-2026-29812CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.MEDIUM4.312%EPSS 12%ileNVD2026-09-13
CVE-2026-90546WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the liMEDIUM5.312%EPSS 12%ileNVD2026-09-12
CVE-2026-90538WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plMEDIUM6.912%EPSS 12%ileNVD2026-09-12
CVE-2026-27378Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.MEDIUM5.312%EPSS 12%ileNVD2026-09-11
CVE-2026-90790A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notMEDIUM5.312%EPSS 12%ileNVD2026-09-14
CVE-2026-66575Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.MEDIUM5.312%EPSS 12%ileNVD2026-09-17
CVE-2026-74000Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.MEDIUM5.312%EPSS 12%ileNVD2026-09-17
CVE-2026-74002Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.MEDIUM5.312%EPSS 12%ileNVD2026-09-17
CVE-2026-78528Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.MEDIUM5.312%EPSS 12%ileNVD2026-09-17
CVE-2026-54677Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of MEDIUM6.512%EPSS 12%ileNVD2026-09-17
CVE-2026-79713The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-MEDIUM6.512%EPSS 12%ileNVD2026-09-18
CVE-2026-90935Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in MEDIUM5.312%EPSS 12%ileNVD2026-09-14
CVE-2026-92802kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing MEDIUM5.312%EPSS 12%ileNVD2026-09-16
CVE-2026-92839Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the applicatMEDIUM4.312%EPSS 12%ileNVD2026-09-17
CVE-2026-18317The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to aMEDIUM4.312%EPSS 12%ileNVD2026-09-18
CVE-2026-62597Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event ManaMEDIUM6.512%EPSS 12%ileNVD2026-09-15
CVE-2026-20287As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISEMEDIUM6.512%EPSS 12%ileNVD2026-09-16
CVE-2026-52823Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}MEDIUM5.312%EPSS 12%ileNVD2026-09-15
CVE-2026-11993Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce tMEDIUM4.312%EPSS 12%ileNVD2026-09-14
CVE-2026-12882Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autMEDIUM4.312%EPSS 12%ileNVD2026-09-14
CVE-2026-13417Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type MEDIUM4.312%EPSS 12%ileNVD2026-09-14
CVE-2026-55837dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_MEDIUM6.812%EPSS 12%ileNVD2026-09-14
CVE-2026-15650The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site SMEDIUM6.412%EPSS 12%ileNVD2026-09-18
CVE-2026-81907Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function MEDIUM6.112%EPSS 12%ileNVD2026-09-11
CVE-2026-89330The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for MEDIUM6.112%EPSS 12%ileNVD2026-09-18
CVE-2026-90552WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the PlaylistMEDIUM5.312%EPSS 12%ileNVD2026-09-12
CVE-2026-9812Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a prMEDIUM6.512%EPSS 12%ileNVD2026-09-14
CVE-2026-21822HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handlMEDIUM6.312%EPSS 12%ileNVD2026-09-18
CVE-2026-62280Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoinMEDIUM6.112%EPSS 12%ileNVD2026-09-15
CVE-2026-92611In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops atMEDIUM4.812%EPSS 12%ileNVD2026-09-17
CVE-2026-54551WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.MEDIUM4.312%EPSS 12%ileNVD2026-09-17
CVE-2026-73999Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.MEDIUM5.411%EPSS 11%ileNVD2026-09-17
CVE-2026-82980Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DMEDIUM6.311%EPSS 11%ileNVD2026-09-18
CVE-2026-91984Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task'MEDIUM5.311%EPSS 11%ileNVD2026-09-15
CVE-2026-90461OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is confMEDIUM6.311%EPSS 11%ileNVD2026-09-11
CVE-2026-82190Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0MEDIUM6.311%EPSS 11%ileNVD2026-09-15
CVE-2026-90446An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path oMEDIUM5.311%EPSS 11%ileNVD2026-09-11
CVE-2026-90454A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list oMEDIUM5.311%EPSS 11%ileNVD2026-09-11
CVE-2025-63842A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote MEDIUM5.411%EPSS 11%ileNVD2026-09-14
CVE-2026-87916The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stMEDIUM5.311%EPSS 11%ileNVD2026-09-12
CVE-2026-77773The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, MEDIUM5.311%EPSS 11%ileNVD2026-09-13
CVE-2026-88995The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returnedMEDIUM5.311%EPSS 11%ileNVD2026-09-13
CVE-2026-18232The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returningMEDIUM5.311%EPSS 11%ileNVD2026-09-15
CVE-2026-90549WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndrMEDIUM6.911%EPSS 11%ileNVD2026-09-12
CVE-2026-92963vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL glMEDIUM6.911%EPSS 11%ileNVD2026-09-17
CVE-2026-11996The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' FieMEDIUM6.411%EPSS 11%ileNVD2026-09-16
CVE-2026-16185IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin consoleMEDIUM6.411%EPSS 11%ileNVD2026-09-14
CVE-2026-80355Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabiMEDIUM5.411%EPSS 11%ileNVD2026-09-17
CVE-2026-40534An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in SyMEDIUM5.411%EPSS 11%ileNVD2026-09-18
CVE-2026-91986gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackeMEDIUM5.311%EPSS 11%ileNVD2026-09-15
CVE-2026-19033For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer MEDIUM6.511%EPSS 11%ileNVD2026-09-16
CVE-2026-87892The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment methoMEDIUM5.311%EPSS 11%ileNVD2026-09-12
CVE-2026-92584AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticatMEDIUM5.311%EPSS 11%ileNVD2026-09-16
CVE-2026-90563A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the filMEDIUM5.111%EPSS 11%ileNVD2026-09-13
CVE-2026-87891The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when sMEDIUM6.510%EPSS 10%ileNVD2026-09-12
CVE-2026-82985The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolderMEDIUM6.510%EPSS 10%ileNVD2026-09-18
CVE-2026-36989A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.MEDIUM5.810%EPSS 10%ileNVD2026-09-13
CVE-2026-82784Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*MEDIUM6.910%EPSS 10%ileNVD2026-09-14
CVE-2026-54258ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, andMEDIUM6.510%EPSS 10%ileNVD2026-09-11
CVE-2026-14855The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all MEDIUM6.410%EPSS 10%ileNVD2026-09-18
CVE-2026-75016The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientMEDIUM6.410%EPSS 10%ileNVD2026-09-18
CVE-2026-15893net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachMEDIUM6.510%EPSS 10%ileNVD2026-09-14
CVE-2026-91958FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unboMEDIUM6.910%EPSS 10%ileNVD2026-09-15
CVE-2026-81237Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unautheMEDIUM6.510%EPSS 10%ileNVD2026-09-15
CVE-2026-91199Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetchMEDIUM5.310%EPSS 10%ileNVD2026-09-14
CVE-2026-91773Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users MEDIUM5.310%EPSS 10%ileNVD2026-09-15
CVE-2026-91774Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in usMEDIUM5.310%EPSS 10%ileNVD2026-09-15
CVE-2026-92810PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, alloMEDIUM5.310%EPSS 10%ileNVD2026-09-16
CVE-2026-55093Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1MEDIUM6.110%EPSS 10%ileNVD2026-09-14
CVE-2026-73463On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configuredMEDIUM6.010%EPSS 10%ileNVD2026-09-16
CVE-2026-90528A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality oMEDIUM5.110%EPSS 10%ileNVD2026-09-13
CVE-2026-90529A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip ofMEDIUM5.110%EPSS 10%ileNVD2026-09-13
CVE-2026-90564A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMMEDIUM5.110%EPSS 10%ileNVD2026-09-13
CVE-2026-18063The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter iMEDIUM6.410%EPSS 10%ileNVD2026-09-15
CVE-2026-62088Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive MEDIUM5.310%EPSS 10%ileNVD2026-09-11
CVE-2026-81871OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggMEDIUM6.310%EPSS 10%ileNVD2026-09-16
CVE-2026-21848HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticatMEDIUM5.010%EPSS 10%ileNVD2026-09-18
CVE-2026-62113Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.MEDIUM4.310%EPSS 10%ileNVD2026-09-11
CVE-2026-73437On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthentiMEDIUM6.510%EPSS 10%ileNVD2026-09-15
CVE-2026-86311The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site ScripMEDIUM6.410%EPSS 10%ileNVD2026-09-17
CVE-2026-92595Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccMEDIUM6.010%EPSS 10%ileNVD2026-09-16
CVE-2026-92809PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticaMEDIUM5.310%EPSS 10%ileNVD2026-09-16
CVE-2025-13533The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, anMEDIUM4.410%EPSS 10%ileNVD2026-09-18
CVE-2026-90533Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authMEDIUM6.010%EPSS 10%ileNVD2026-09-12
CVE-2026-76864NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_MEDIUM4.810%EPSS 10%ileNVD2026-09-15
CVE-2026-91146Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, aMEDIUM5.39%EPSS 9%ileNVD2026-09-14
CVE-2026-53495containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the MEDIUM6.89%EPSS 9%ileNVD2026-09-14
CVE-2026-20309A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticMEDIUM6.19%EPSS 9%ileNVD2026-09-16
CVE-2025-11395A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create MEDIUM5.59%EPSS 9%ileNVD2026-09-15
CVE-2026-89267starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empMEDIUM5.39%EPSS 9%ileNVD2026-09-12
CVE-2026-87894The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint thatMEDIUM5.39%EPSS 9%ileNVD2026-09-12
CVE-2026-87918The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that MEDIUM5.39%EPSS 9%ileNVD2026-09-12
CVE-2026-91016The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published MEDIUM5.39%EPSS 9%ileNVD2026-09-17
CVE-2026-87919The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its prMEDIUM4.99%EPSS 9%ileNVD2026-09-12
CVE-2026-13623An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in SyMEDIUM4.89%EPSS 9%ileNVD2026-09-18
CVE-2026-85125The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebVieMEDIUM5.19%EPSS 9%ileNVD2026-09-14
CVE-2026-76873Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display aMEDIUM5.19%EPSS 9%ileNVD2026-09-15
CVE-2026-91739Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who hadMEDIUM4.29%EPSS 9%ileNVD2026-09-15
CVE-2026-92082By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute forMEDIUM6.39%EPSS 9%ileNVD2026-09-15
CVE-2026-91713Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised tMEDIUM4.29%EPSS 9%ileNVD2026-09-15
CVE-2026-55244ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BasMEDIUM5.09%EPSS 9%ileNVD2026-09-14
CVE-2026-15609The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via MEDIUM6.49%EPSS 9%ileNVD2026-09-15
CVE-2026-93394A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake andMEDIUM6.39%EPSS 9%ileNVD2026-09-17
CVE-2026-55073WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restriMEDIUM6.29%EPSS 9%ileNVD2026-09-14
CVE-2026-20290A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (MEDIUM5.89%EPSS 9%ileNVD2026-09-16
CVE-2026-86898A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macOMEDIUM5.49%EPSS 9%ileNVD2026-09-14
CVE-2026-92234QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel ResMEDIUM5.19%EPSS 9%ileNVD2026-09-15
CVE-2026-79035A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0MEDIUM6.19%EPSS 9%ileNVD2026-09-11
CVE-2023-51769Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.MEDIUM6.19%EPSS 9%ileNVD2026-09-14
CVE-2026-19941An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow anMEDIUM5.99%EPSS 9%ileNVD2026-09-16
CVE-2026-77119A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegMEDIUM5.99%EPSS 9%ileNVD2026-09-16
CVE-2026-82773Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vMEDIUM5.19%EPSS 9%ileNVD2026-09-14
CVE-2026-82776Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary scriMEDIUM5.19%EPSS 9%ileNVD2026-09-14
CVE-2026-86889A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden GMEDIUM4.89%EPSS 9%ileNVD2026-09-14
CVE-2026-19857The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress sMEDIUM4.89%EPSS 9%ileNVD2026-09-16
CVE-2026-84522A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may bMEDIUM5.99%EPSS 9%ileNVD2026-09-14
CVE-2026-92588n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpMEDIUM5.99%EPSS 9%ileNVD2026-09-16
CVE-2026-62137Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.MEDIUM5.39%EPSS 9%ileNVD2026-09-11
CVE-2026-82982The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing MEDIUM4.38%EPSS 8%ileNVD2026-09-18
CVE-2026-50166Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2MEDIUM5.58%EPSS 8%ileNVD2026-09-15
CVE-2026-90893MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setMEDIUM5.18%EPSS 8%ileNVD2026-09-14
CVE-2026-28836A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with phyMEDIUM6.18%EPSS 8%ileNVD2026-09-14
CVE-2026-92920admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain aMEDIUM5.38%EPSS 8%ileNVD2026-09-17
CVE-2026-78415IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing andMEDIUM5.48%EPSS 8%ileNVD2026-09-14
CVE-2026-55226Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IMEDIUM5.48%EPSS 8%ileNVD2026-09-15
CVE-2026-68526Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concretMEDIUM5.38%EPSS 8%ileNVD2026-09-11
CVE-2026-91772Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate tMEDIUM5.38%EPSS 8%ileNVD2026-09-15
CVE-2026-92587n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relativMEDIUM5.38%EPSS 8%ileNVD2026-09-16
CVE-2026-92921admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivatioMEDIUM6.98%EPSS 8%ileNVD2026-09-17
CVE-2026-16147The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on noMEDIUM6.88%EPSS 8%ileNVD2026-09-14
CVE-2026-14986The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGEMEDIUM6.88%EPSS 8%ileNVD2026-09-14
CVE-2026-87252Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported veMEDIUM6.88%EPSS 8%ileNVD2026-09-15
CVE-2026-15887IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requMEDIUM5.48%EPSS 8%ileNVD2026-09-14
CVE-2026-50025Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, MousMEDIUM6.98%EPSS 8%ileNVD2026-09-11
CVE-2026-85131The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk aMEDIUM6.58%EPSS 8%ileNVD2026-09-16
CVE-2026-39038BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (truMEDIUM6.18%EPSS 8%ileNVD2026-09-15
CVE-2026-11757Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics TecMEDIUM6.18%EPSS 8%ileNVD2026-09-18
CVE-2026-78301A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inMEDIUM5.88%EPSS 8%ileNVD2026-09-16
CVE-2026-16186IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability.MEDIUM5.48%EPSS 8%ileNVD2026-09-14
CVE-2026-12766IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticatMEDIUM5.48%EPSS 8%ileNVD2026-09-14
CVE-2026-87959The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AIMEDIUM5.48%EPSS 8%ileNVD2026-09-16
CVE-2026-90922The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported bMEDIUM5.38%EPSS 8%ileNVD2026-09-17
CVE-2026-91015The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX actioMEDIUM5.38%EPSS 8%ileNVD2026-09-17
CVE-2026-76867Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT confMEDIUM5.18%EPSS 8%ileNVD2026-09-15
CVE-2026-76872Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL manMEDIUM5.18%EPSS 8%ileNVD2026-09-15
CVE-2026-92257Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages tMEDIUM5.18%EPSS 8%ileNVD2026-09-15
CVE-2026-48737pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/pMEDIUM4.98%EPSS 8%ileNVD2026-09-15
CVE-2026-4103Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered wMEDIUM6.48%EPSS 8%ileNVD2026-09-14
CVE-2026-64756A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden MEDIUM5.58%EPSS 8%ileNVD2026-09-14
CVE-2026-90781alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes oMEDIUM4.88%EPSS 8%ileNVD2026-09-13
CVE-2026-73451On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched ViMEDIUM6.38%EPSS 8%ileNVD2026-09-15
CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboardMEDIUM5.78%EPSS 8%ileNVD2026-09-11
CVE-2026-90545WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the coMEDIUM5.38%EPSS 8%ileNVD2026-09-12
CVE-2026-92360A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput ofMEDIUM5.38%EPSS 8%ileNVD2026-09-16
CVE-2026-62135Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.MEDIUM5.37%EPSS 7%ileNVD2026-09-11
CVE-2026-62136Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versMEDIUM5.37%EPSS 7%ileNVD2026-09-11
CVE-2026-65382A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in mMEDIUM5.57%EPSS 7%ileNVD2026-09-14
CVE-2026-14311The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and MEDIUM5.47%EPSS 7%ileNVD2026-09-17
CVE-2026-54907Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, CaddyMEDIUM5.37%EPSS 7%ileNVD2026-09-17
CVE-2026-92581In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowinMEDIUM5.37%EPSS 7%ileNVD2026-09-16
CVE-2026-89332Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before versionMEDIUM6.77%EPSS 7%ileNVD2026-09-11
CVE-2026-86885An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An MEDIUM6.57%EPSS 7%ileNVD2026-09-14
CVE-2026-19543IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validMEDIUM6.27%EPSS 7%ileNVD2026-09-14
CVE-2026-65407A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, iMEDIUM5.57%EPSS 7%ileNVD2026-09-14
CVE-2026-83198Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). SupporteMEDIUM5.47%EPSS 7%ileNVD2026-09-15
CVE-2026-83346Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). SuppoMEDIUM5.47%EPSS 7%ileNVD2026-09-15
CVE-2026-91857Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affecMEDIUM5.37%EPSS 7%ileNVD2026-09-15
CVE-2026-63225Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the splMEDIUM4.47%EPSS 7%ileNVD2026-09-16
CVE-2026-81441Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical FunctioMEDIUM4.07%EPSS 7%ileNVD2026-09-17
CVE-2026-56590HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation cMEDIUM6.47%EPSS 7%ileNVD2026-09-18
CVE-2024-23176An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xssMEDIUM5.47%EPSS 7%ileNVD2026-09-14
CVE-2026-89268QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping MEDIUM5.17%EPSS 7%ileNVD2026-09-12
CVE-2026-93454Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting pluMEDIUM5.17%EPSS 7%ileNVD2026-09-18
CVE-2026-80072The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login rediMEDIUM4.77%EPSS 7%ileNVD2026-09-13
CVE-2026-84489A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOMEDIUM5.57%EPSS 7%ileNVD2026-09-14
CVE-2026-90931LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticatedMEDIUM5.17%EPSS 7%ileNVD2026-09-14
CVE-2026-82769Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary sMEDIUM4.86%EPSS 6%ileNVD2026-09-14
CVE-2026-82771Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary scriMEDIUM4.86%EPSS 6%ileNVD2026-09-14
CVE-2026-66608Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= MEDIUM6.46%EPSS 6%ileNVD2026-09-17
CVE-2026-65380An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixMEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-92259Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the byMEDIUM5.56%EPSS 6%ileNVD2026-09-15
CVE-2026-15923The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O lMEDIUM4.66%EPSS 6%ileNVD2026-09-14
CVE-2026-16148The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&privMEDIUM4.66%EPSS 6%ileNVD2026-09-14
CVE-2026-57442MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, MEDIUM6.96%EPSS 6%ileNVD2026-09-15
CVE-2026-86890A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27.MEDIUM4.66%EPSS 6%ileNVD2026-09-14
CVE-2026-76707A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view sMEDIUM4.36%EPSS 6%ileNVD2026-09-15
CVE-2026-90923The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unautMEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-85575The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgMEDIUM6.46%EPSS 6%ileNVD2026-09-15
CVE-2026-65413An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqMEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-84902The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check whenMEDIUM6.86%EPSS 6%ileNVD2026-09-18
CVE-2026-26947Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper PrivilegMEDIUM6.76%EPSS 6%ileNVD2026-09-16
CVE-2026-43664This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadMEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-65405A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26MEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-71568In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requirMEDIUM5.36%EPSS 6%ileNVD2026-09-17
CVE-2026-90679Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity intMEDIUM4.36%EPSS 6%ileNVD2026-09-13
CVE-2026-62110Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-11
CVE-2026-62111Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-11
CVE-2026-66572Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66573Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66574Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66576Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66577Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66578Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66579Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-66617Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-78294Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.MEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-76699A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeMEDIUM6.46%EPSS 6%ileNVD2026-09-15
CVE-2026-82767Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be exeMEDIUM4.86%EPSS 6%ileNVD2026-09-14
CVE-2026-86472fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3MEDIUM4.86%EPSS 6%ileNVD2026-09-15
CVE-2026-86818fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parseMEDIUM4.86%EPSS 6%ileNVD2026-09-15
CVE-2026-57128PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonMEDIUM4.36%EPSS 6%ileNVD2026-09-14
CVE-2026-55236langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creMEDIUM5.96%EPSS 6%ileNVD2026-09-14
CVE-2026-64714A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.MEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-76781A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL poMEDIUM5.56%EPSS 6%ileNVD2026-09-17
CVE-2026-81868Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicatiMEDIUM6.56%EPSS 6%ileNVD2026-09-17
CVE-2026-84517An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS SeqMEDIUM5.56%EPSS 6%ileNVD2026-09-14
CVE-2026-90485A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegMEDIUM5.46%EPSS 6%ileNVD2026-09-12
CVE-2026-91819Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-secMEDIUM6.95%EPSS 5%ileNVD2026-09-15
CVE-2026-84537The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, MEDIUM6.65%EPSS 5%ileNVD2026-09-14
CVE-2024-53922An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. LMEDIUM5.75%EPSS 5%ileNVD2026-09-14
CVE-2026-28899A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-65377A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, MEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-84523An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-90540WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAMEDIUM5.35%EPSS 5%ileNVD2026-09-12
CVE-2026-90544WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the viMEDIUM5.35%EPSS 5%ileNVD2026-09-12
CVE-2026-92585AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the MEDIUM5.35%EPSS 5%ileNVD2026-09-16
CVE-2026-92586AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the seMEDIUM5.35%EPSS 5%ileNVD2026-09-16
CVE-2026-92589Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder MEDIUM5.35%EPSS 5%ileNVD2026-09-16
CVE-2026-49439OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoinMEDIUM4.35%EPSS 5%ileNVD2026-09-11
CVE-2026-49992Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forMEDIUM6.35%EPSS 5%ileNVD2026-09-11
CVE-2026-65408An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2MEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-84552The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-86910A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS SequMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-92579In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without MEDIUM5.35%EPSS 5%ileNVD2026-09-16
CVE-2026-2585The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ paraMEDIUM6.45%EPSS 5%ileNVD2026-09-18
CVE-2026-84541An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-61589djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to MEDIUM6.35%EPSS 5%ileNVD2026-09-16
CVE-2026-45057matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matriMEDIUM4.95%EPSS 5%ileNVD2026-09-11
CVE-2026-84570A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOSMEDIUM4.45%EPSS 5%ileNVD2026-09-14
CVE-2026-43737An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 aMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-82788Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may beMEDIUM5.15%EPSS 5%ileNVD2026-09-14
CVE-2025-24890gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats rMEDIUM6.85%EPSS 5%ileNVD2026-09-14
CVE-2026-65402A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-88993The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting itMEDIUM6.85%EPSS 5%ileNVD2026-09-18
CVE-2026-82920Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on theMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-84513A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and MEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-78547Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app fMEDIUM4.45%EPSS 5%ileNVD2026-09-11
CVE-2026-62134Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.MEDIUM4.35%EPSS 5%ileNVD2026-09-11
CVE-2026-87797The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a MEDIUM4.35%EPSS 5%ileNVD2026-09-12
CVE-2026-14259Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creaMEDIUM4.35%EPSS 5%ileNVD2026-09-14
CVE-2026-14344Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-MEDIUM4.35%EPSS 5%ileNVD2026-09-14
CVE-2026-91010The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check theMEDIUM4.35%EPSS 5%ileNVD2026-09-17
CVE-2026-87829The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate tMEDIUM4.35%EPSS 5%ileNVD2026-09-17
CVE-2026-87831The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate tMEDIUM4.35%EPSS 5%ileNVD2026-09-17
CVE-2026-77170The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without vaMEDIUM4.35%EPSS 5%ileNVD2026-09-18
CVE-2026-28968An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-83279Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppoMEDIUM5.55%EPSS 5%ileNVD2026-09-15
CVE-2026-93493A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by provMEDIUM5.95%EPSS 5%ileNVD2026-09-18
CVE-2026-89172Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052MEDIUM5.65%EPSS 5%ileNVD2026-09-12
CVE-2026-43762The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-84534A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 anMEDIUM5.55%EPSS 5%ileNVD2026-09-14
CVE-2026-82792Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vuMEDIUM4.85%EPSS 5%ileNVD2026-09-14
CVE-2026-87248Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supporMEDIUM6.74%EPSS 4%ileNVD2026-09-15
CVE-2026-55846Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP serMEDIUM6.24%EPSS 4%ileNVD2026-09-14
CVE-2026-65376An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-82764Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page whMEDIUM5.14%EPSS 4%ileNVD2026-09-14
CVE-2026-78546Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: befMEDIUM4.84%EPSS 4%ileNVD2026-09-11
CVE-2026-47215SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.MEDIUM4.84%EPSS 4%ileNVD2026-09-15
CVE-2026-89038Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows coMEDIUM6.94%EPSS 4%ileNVD2026-09-17
CVE-2026-28933A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOSMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-12763IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context MEDIUM4.24%EPSS 4%ileNVD2026-09-14
CVE-2026-85009The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on MEDIUM6.54%EPSS 4%ileNVD2026-09-18
CVE-2026-75944A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclMEDIUM5.64%EPSS 4%ileNVD2026-09-14
CVE-2026-43808A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, mMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-84540An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-84593A use after free issue was addressed with improved memory management. This issue is fixed in iOS 27 and iPadOS 27. An apMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-85123The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the storMEDIUM5.34%EPSS 4%ileNVD2026-09-18
CVE-2026-85350The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought MEDIUM5.34%EPSS 4%ileNVD2026-09-18
CVE-2026-87966The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthMEDIUM5.34%EPSS 4%ileNVD2026-09-18
CVE-2026-87965The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoiMEDIUM4.84%EPSS 4%ileNVD2026-09-18
CVE-2026-75025Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict servMEDIUM4.74%EPSS 4%ileNVD2026-09-16
CVE-2026-73449On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured wiMEDIUM5.94%EPSS 4%ileNVD2026-09-14
CVE-2026-43741A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-88798The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before usingMEDIUM5.34%EPSS 4%ileNVD2026-09-18
CVE-2026-65404An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-86878A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-84906The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is appliMEDIUM5.34%EPSS 4%ileNVD2026-09-16
CVE-2026-87860The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cMEDIUM4.34%EPSS 4%ileNVD2026-09-16
CVE-2026-65411A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 anMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-90542WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access liMEDIUM5.34%EPSS 4%ileNVD2026-09-12
CVE-2026-43788An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. ProcessinMEDIUM6.64%EPSS 4%ileNVD2026-09-14
CVE-2026-87282Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM6.04%EPSS 4%ileNVD2026-09-15
CVE-2026-87285Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM6.04%EPSS 4%ileNVD2026-09-15
CVE-2026-43785A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-84560An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS MEDIUM6.14%EPSS 4%ileNVD2026-09-14
CVE-2026-91021Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renMEDIUM5.44%EPSS 4%ileNVD2026-09-14
CVE-2026-50604A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The MEDIUM4.94%EPSS 4%ileNVD2026-09-17
CVE-2026-18251IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation ofMEDIUM4.34%EPSS 4%ileNVD2026-09-14
CVE-2026-18151IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race cMEDIUM4.24%EPSS 4%ileNVD2026-09-14
CVE-2026-87278Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM6.14%EPSS 4%ileNVD2026-09-15
CVE-2026-65403This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, maMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-84491A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-86911This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app maMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-91201DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint MEDIUM5.34%EPSS 4%ileNVD2026-09-14
CVE-2026-82781Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary scrMEDIUM5.14%EPSS 4%ileNVD2026-09-14
CVE-2026-82795SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnMEDIUM5.14%EPSS 4%ileNVD2026-09-14
CVE-2026-82796SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited,MEDIUM5.14%EPSS 4%ileNVD2026-09-14
CVE-2026-84551A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27,MEDIUM4.44%EPSS 4%ileNVD2026-09-14
CVE-2026-48496OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languagesMEDIUM6.24%EPSS 4%ileNVD2026-09-11
CVE-2026-84624A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27MEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-85657The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vuMEDIUM5.44%EPSS 4%ileNVD2026-09-15
CVE-2026-85104In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulationMEDIUM5.34%EPSS 4%ileNVD2026-09-16
CVE-2026-92590Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated FieldsMEDIUM5.14%EPSS 4%ileNVD2026-09-16
CVE-2026-82763Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerabiliMEDIUM4.84%EPSS 4%ileNVD2026-09-14
CVE-2026-82790Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RYMEDIUM4.84%EPSS 4%ileNVD2026-09-14
CVE-2026-84569An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macMEDIUM5.54%EPSS 4%ileNVD2026-09-14
CVE-2026-88764The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payMEDIUM5.44%EPSS 4%ileNVD2026-09-13
CVE-2026-90984The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetchMEDIUM5.83%EPSS 3%ileNVD2026-09-18
CVE-2026-81320A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log levMEDIUM5.53%EPSS 3%ileNVD2026-09-15
CVE-2026-50291OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.53%EPSS 3%ileNVD2026-09-17
CVE-2026-54689mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through MEDIUM6.33%EPSS 3%ileNVD2026-09-15
CVE-2026-84622A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26MEDIUM6.23%EPSS 3%ileNVD2026-09-14
CVE-2026-18069IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a MEDIUM6.03%EPSS 3%ileNVD2026-09-14
CVE-2026-54586mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mpMEDIUM6.03%EPSS 3%ileNVD2026-09-17
CVE-2026-65406A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOSMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84514This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84583A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84621An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-87280Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM4.23%EPSS 3%ileNVD2026-09-15
CVE-2026-54633PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed colMEDIUM6.93%EPSS 3%ileNVD2026-09-17
CVE-2026-93376Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social enMEDIUM6.33%EPSS 3%ileNVD2026-09-17
CVE-2026-44940The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecuMEDIUM5.73%EPSS 3%ileNVD2026-09-17
CVE-2026-65369A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-86897This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7,MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-85641The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user lasMEDIUM4.33%EPSS 3%ileNVD2026-09-16
CVE-2023-45023The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the MEDIUM4.23%EPSS 3%ileNVD2026-09-14
CVE-2026-23792An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480,MEDIUM4.03%EPSS 3%ileNVD2026-09-14
CVE-2022-42917In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configMEDIUM6.73%EPSS 3%ileNVD2026-09-14
CVE-2026-91786A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to valiMEDIUM6.13%EPSS 3%ileNVD2026-09-15
CVE-2026-84576This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-86886A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-55650Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2MEDIUM4.43%EPSS 3%ileNVD2026-09-15
CVE-2026-62138Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.MEDIUM6.53%EPSS 3%ileNVD2026-09-11
CVE-2026-62133Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.MEDIUM5.43%EPSS 3%ileNVD2026-09-11
CVE-2024-27123A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit tMEDIUM5.23%EPSS 3%ileNVD2026-09-18
CVE-2026-54565rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox eMEDIUM4.73%EPSS 3%ileNVD2026-09-17
CVE-2026-79699A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. vMEDIUM4.43%EPSS 3%ileNVD2026-09-15
CVE-2026-87279Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM6.13%EPSS 3%ileNVD2026-09-15
CVE-2026-84527A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden GaMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-10542Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel aMEDIUM5.03%EPSS 3%ileNVD2026-09-14
CVE-2026-84586An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 2MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-86902A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in mMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84533A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS GMEDIUM5.33%EPSS 3%ileNVD2026-09-14
CVE-2026-65383This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may bypass GatekeeperMEDIUM4.43%EPSS 3%ileNVD2026-09-14
CVE-2026-77955In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) MEDIUM4.43%EPSS 3%ileNVD2026-09-16
CVE-2026-82783Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker MEDIUM4.13%EPSS 3%ileNVD2026-09-14
CVE-2026-92615A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repositoMEDIUM6.63%EPSS 3%ileNVD2026-09-16
CVE-2026-77164Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instaMEDIUM6.23%EPSS 3%ileNVD2026-09-18
CVE-2026-65345A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-65393A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An apMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84521A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-84555An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-81869OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attrMEDIUM5.13%EPSS 3%ileNVD2026-09-16
CVE-2026-84589A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may MEDIUM5.53%EPSS 3%ileNVD2026-09-14
CVE-2026-90557Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processinMEDIUM6.92%EPSS 2%ileNVD2026-09-12
CVE-2026-81447Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerabilMEDIUM6.82%EPSS 2%ileNVD2026-09-17
CVE-2026-88819In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.MEDIUM6.32%EPSS 2%ileNVD2026-09-14
CVE-2026-65348A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-81326QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affMEDIUM6.82%EPSS 2%ileNVD2026-09-16
CVE-2026-84525A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84567The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84585A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app maMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-65409A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84559A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84612An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-19280IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authMEDIUM5.22%EPSS 2%ileNVD2026-09-14
CVE-2026-84531An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, mMEDIUM6.22%EPSS 2%ileNVD2026-09-14
CVE-2026-84573This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84587A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS SequoMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84558A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app mMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84602A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-86883A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27.MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84619An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, mMEDIUM6.12%EPSS 2%ileNVD2026-09-14
CVE-2026-86892This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 andMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-83274Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppoMEDIUM5.52%EPSS 2%ileNVD2026-09-15
CVE-2026-17047IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper reqMEDIUM5.42%EPSS 2%ileNVD2026-09-14
CVE-2026-48785Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefixMEDIUM4.82%EPSS 2%ileNVD2026-09-15
CVE-2026-88912The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changinMEDIUM4.22%EPSS 2%ileNVD2026-09-13
CVE-2026-90994A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser,MEDIUM4.02%EPSS 2%ileNVD2026-09-14
CVE-2026-89329A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this MEDIUM6.22%EPSS 2%ileNVD2026-09-11
CVE-2026-54575mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used raMEDIUM5.82%EPSS 2%ileNVD2026-09-17
CVE-2026-84628An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-65399A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 aMEDIUM4.42%EPSS 2%ileNVD2026-09-14
CVE-2026-19504Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to discloseMEDIUM4.02%EPSS 2%ileNVD2026-09-15
CVE-2026-25261Memory corruption while processing rear sensor IOCTL calls.MEDIUM6.72%EPSS 2%ileNVD2026-09-17
CVE-2026-43695An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84556An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS SeMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84603A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84618A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-86903An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS GMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84574A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS SeqMEDIUM4.42%EPSS 2%ileNVD2026-09-14
CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in srcMEDIUM5.82%EPSS 2%ileNVD2026-09-14
CVE-2026-28937This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be aMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-65361This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-86876An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.MEDIUM5.22%EPSS 2%ileNVD2026-09-14
CVE-2026-90554vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from videoMEDIUM6.92%EPSS 2%ileNVD2026-09-12
CVE-2026-84023The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomyMEDIUM6.52%EPSS 2%ileNVD2026-09-12
CVE-2026-76702A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated localMEDIUM5.82%EPSS 2%ileNVD2026-09-15
CVE-2026-86924A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7,MEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-87275Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM4.62%EPSS 2%ileNVD2026-09-15
CVE-2026-87283Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM6.02%EPSS 2%ileNVD2026-09-15
CVE-2026-65353An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, maMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84616A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOSMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-84617An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOMEDIUM5.52%EPSS 2%ileNVD2026-09-14
CVE-2026-78296Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. MEDIUM5.32%EPSS 2%ileNVD2026-09-17
CVE-2026-90955Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user acMEDIUM4.62%EPSS 2%ileNVD2026-09-14
CVE-2026-91826Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading toMEDIUM4.42%EPSS 2%ileNVD2026-09-15
CVE-2025-36591Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken oMEDIUM4.42%EPSS 2%ileNVD2026-09-16
CVE-2026-90996A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to thMEDIUM4.02%EPSS 2%ileNVD2026-09-14
CVE-2026-84615An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOMEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-84636An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 2MEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-86884A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeMEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-84492A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 andMEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-87274Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thMEDIUM4.41%EPSS 1%ileNVD2026-09-15
CVE-2026-90995A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (PlugMEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-43690A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, mMEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-86909A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be aMEDIUM4.41%EPSS 1%ileNVD2026-09-14
CVE-2026-16726Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.MEDIUM6.81%EPSS 1%ileNVD2026-09-14
CVE-2025-70819Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as MEDIUM6.31%EPSS 1%ileNVD2026-09-13
CVE-2026-92758If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitiveMEDIUM5.71%EPSS 1%ileNVD2026-09-17
CVE-2026-84601A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app maMEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-74005Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.MEDIUM5.41%EPSS 1%ileNVD2026-09-17
CVE-2026-65358A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden GMEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-84630A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 andMEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-92138The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callbMEDIUM4.21%EPSS 1%ileNVD2026-09-16
CVE-2026-90463A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specMEDIUM4.01%EPSS 1%ileNVD2026-09-14
CVE-2026-56975In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (prMEDIUM6.51%EPSS 1%ileNVD2026-09-15
CVE-2026-89050The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the confiMEDIUM4.31%EPSS 1%ileNVD2026-09-13
CVE-2026-58767In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. ThMEDIUM6.71%EPSS 1%ileNVD2026-09-15
CVE-2026-54576mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c usedMEDIUM5.81%EPSS 1%ileNVD2026-09-17
CVE-2026-54587mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE MEDIUM5.81%EPSS 1%ileNVD2026-09-17
CVE-2026-48722Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth loMEDIUM5.51%EPSS 1%ileNVD2026-09-15
CVE-2026-86824The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy aMEDIUM4.81%EPSS 1%ileNVD2026-09-17
CVE-2026-91009The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation anMEDIUM4.31%EPSS 1%ileNVD2026-09-17
CVE-2026-23788An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRMEDIUM4.21%EPSS 1%ileNVD2026-09-14
CVE-2026-86443Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an MEDIUM6.91%EPSS 1%ileNVD2026-09-16
CVE-2026-86905This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden GateMEDIUM5.51%EPSS 1%ileNVD2026-09-14
CVE-2026-62139Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.MEDIUM4.31%EPSS 1%ileNVD2026-09-11
CVE-2026-84024The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowinMEDIUM4.31%EPSS 1%ileNVD2026-09-12
CVE-2026-33964An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occMEDIUM6.41%EPSS 1%ileNVD2026-09-14
CVE-2026-84550A race condition was addressed with additional validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15MEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-90890ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability.MEDIUM6.81%EPSS 1%ileNVD2026-09-14
CVE-2026-64717A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS MEDIUM6.31%EPSS 1%ileNVD2026-09-14
CVE-2026-73465On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear texMEDIUM6.01%EPSS 1%ileNVD2026-09-15
CVE-2026-73466On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to loMEDIUM6.01%EPSS 1%ileNVD2026-09-15
CVE-2026-73467On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal AMEDIUM6.01%EPSS 1%ileNVD2026-09-15
CVE-2026-91717Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtaiMEDIUM5.11%EPSS 1%ileNVD2026-09-15
CVE-2026-33957An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory froMEDIUM4.21%EPSS 1%ileNVD2026-09-14
CVE-2026-90457The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one auMEDIUM6.91%EPSS 1%ileNVD2026-09-11
CVE-2026-65360A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 andMEDIUM4.71%EPSS 1%ileNVD2026-09-14
CVE-2026-23787An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26MEDIUM4.21%EPSS 1%ileNVD2026-09-14
CVE-2026-23790An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26MEDIUM4.21%EPSS 1%ileNVD2026-09-14
CVE-2026-23791An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26MEDIUM4.21%EPSS 1%ileNVD2026-09-14
CVE-2026-90452Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchMEDIUM6.00%EPSS 0%ileNVD2026-09-11
CVE-2026-65401A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26MEDIUM5.50%EPSS 0%ileNVD2026-09-14
CVE-2026-90891ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. AutheMEDIUM6.80%EPSS 0%ileNVD2026-09-14
CVE-2026-88922The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-55302In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local MEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56979In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local MEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-0186In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This couldMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-0187In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the cMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-55304In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. ThisMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56889In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escalaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56973In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to MEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58726In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to lMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58751In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could MEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58755In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the codMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56888In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could leadMEDIUM6.20%EPSS 0%ileNVD2026-09-15
CVE-2026-84562A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able tMEDIUM4.70%EPSS 0%ileNVD2026-09-14
CVE-2026-0179In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalatMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-0192In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local eMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-55317In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to locaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-55332In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to locaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-55365In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56879In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to lMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56907In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalatioMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56922In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilegeMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56932In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could leaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56972In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to locaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56989In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local eMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56992In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation oMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-57035In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local eMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-57042In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This coMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58698In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This couldMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58718In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validationMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58739In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. ThMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58747In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could MEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58765In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of pMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-56892In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could MEDIUM6.20%EPSS 0%ileNVD2026-09-15
CVE-2026-58731In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This MEDIUM6.20%EPSS 0%ileNVD2026-09-15
CVE-2026-50603A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The MEDIUM4.90%EPSS 0%ileNVD2026-09-17
CVE-2026-0177In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This couMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-0183In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information discloMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-0197In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local informatiMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56950In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This coMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-57006In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information diMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-58721In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to loMEDIUM4.40%EPSS 0%ileNVD2026-09-15
CVE-2026-93604vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowMEDIUM6.9NVD2026-09-18
CVE-2026-77960Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active MEDIUM6.9NVD2026-09-18
CVE-2026-93338Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unaMEDIUM6.9NVD2026-09-18
CVE-2026-93559A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affMEDIUM6.9NVD2026-09-18
CVE-2026-77396PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parserMEDIUM6.9NVD2026-09-18
CVE-2026-93751uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlonMEDIUM6.9NVD2026-09-18
CVE-2026-92756Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provMEDIUM6.80%EPSS 0%ileNVD2026-09-17
CVE-2026-92757Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inMEDIUM6.80%EPSS 0%ileNVD2026-09-17
CVE-2026-75883The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up tMEDIUM6.8NVD2026-09-18
CVE-2026-93689WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device controMEDIUM6.8NVD2026-09-18
CVE-2026-61794Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validaMEDIUM6.8NVD2026-09-18
CVE-2026-61795Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUMEDIUM6.8NVD2026-09-18
CVE-2026-64847AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. PriMEDIUM6.8NVD2026-09-18
CVE-2026-58716In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to locaMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-58773In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This coMEDIUM6.70%EPSS 0%ileNVD2026-09-15
CVE-2026-81627A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remMEDIUM6.7NVD2026-09-18
CVE-2026-81946PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MEDIUM6.7NVD2026-09-18
CVE-2026-93561Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smugglingMEDIUM6.5NVD2026-09-18
CVE-2026-62282OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack intMEDIUM6.5NVD2026-09-18
CVE-2026-93566### Summary Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size lMEDIUM6.5NVD2026-09-18
CVE-2026-93573Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smugglingMEDIUM6.5NVD2026-09-18
CVE-2025-33141IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information frMEDIUM6.5NVD2026-09-18
CVE-2026-54147http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvidMEDIUM6.5NVD2026-09-18
CVE-2026-59156OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM6.5NVD2026-09-18
CVE-2026-84451libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unMEDIUM6.5NVD2026-09-18
CVE-2026-93579A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, sMEDIUM6.5NVD2026-09-18
CVE-2026-71537Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/SeMEDIUM6.5NVD2026-09-18
CVE-2026-77386Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker couMEDIUM6.5NVD2026-09-18
CVE-2026-56915In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead toMEDIUM6.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56923In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could leadMEDIUM6.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56964In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation oMEDIUM6.40%EPSS 0%ileNVD2026-09-15
CVE-2026-56988In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead tMEDIUM6.40%EPSS 0%ileNVD2026-09-15
CVE-2026-93589ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for tMEDIUM6.3NVD2026-09-18
CVE-2026-93590ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checMEDIUM6.3NVD2026-09-18
CVE-2026-79294Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbiMEDIUM6.1NVD2026-09-18
CVE-2025-36147IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross-MEDIUM6.1NVD2026-09-18
CVE-2026-1025IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-1031IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-1037IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM6.1NVD2026-09-18
CVE-2026-59181OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM6.1NVD2026-09-18
CVE-2026-59956OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM6.1NVD2026-09-18
CVE-2026-77606Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77607Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77608Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77609Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77610Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-77616Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's MEDIUM6.1NVD2026-09-18
CVE-2026-84992md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()MEDIUM6.1NVD2026-09-18
CVE-2026-93432A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it failsMEDIUM6.1NVD2026-09-18
CVE-2026-93578A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPMEDIUM5.9NVD2026-09-18
CVE-2026-93602rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onlMEDIUM5.9NVD2026-09-18
CVE-2024-56344IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain seMEDIUM5.9NVD2026-09-18
CVE-2026-10832A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhausMEDIUM5.9NVD2026-09-18
CVE-2025-33147IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networMEDIUM5.9NVD2026-09-18
CVE-2025-36421IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow anMEDIUM5.9NVD2026-09-18
CVE-2026-63405AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-MEDIUM5.9NVD2026-09-18
CVE-2026-63406AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetMEDIUM5.9NVD2026-09-18
CVE-2026-91147A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of ServMEDIUM5.9NVD2026-09-18
CVE-2026-56958In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. ThisMEDIUM5.50%EPSS 0%ileNVD2026-09-15
CVE-2026-93653A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching tMEDIUM5.5NVD2026-09-18
CVE-2026-63420OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-63635OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-65969OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.5NVD2026-09-18
CVE-2026-92768A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VMMEDIUM5.5NVD2026-09-18
CVE-2026-93685A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentiMEDIUM5.4NVD2026-09-18
CVE-2025-36178IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpuMEDIUM5.4NVD2026-09-18
CVE-2026-1029IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to croMEDIUM5.4NVD2026-09-18
CVE-2026-93492A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wiMEDIUM5.3NVD2026-09-18
CVE-2026-93504A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+seMEDIUM5.3NVD2026-09-18
CVE-2026-93596ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabMEDIUM5.3NVD2026-09-18
CVE-2026-93597ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE andMEDIUM5.3NVD2026-09-18
CVE-2025-13882IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM MEDIUM5.3NVD2026-09-18
CVE-2025-1350IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitivMEDIUM5.3NVD2026-09-18
CVE-2026-93506A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/MEDIUM5.3NVD2026-09-18
CVE-2026-65970OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / aMEDIUM5.3NVD2026-09-18
CVE-2026-93736Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated attMEDIUM5.3NVD2026-09-18
CVE-2026-93533A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectiviMEDIUM5.3NVD2026-09-18
CVE-2026-93534A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file apMEDIUM5.3NVD2026-09-18
CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSMEDIUM5.3NVD2026-09-18
GHSA-pr6h-vr44-xq8jObot: MCP Registry API readable without authenticationMEDIUM5.3GitHub2026-09-18
CVE-2026-93505A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-MEDIUM5.1NVD2026-09-18
CVE-2026-77339Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listenMEDIUM5.1NVD2026-09-18
CVE-2026-92745A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metMEDIUM5.0NVD2026-09-18
CVE-2026-92747A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running pMEDIUM5.0NVD2026-09-18
CVE-2026-28199An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlyMEDIUM4.8NVD2026-09-18
CVE-2026-93587ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUMEDIUM4.8NVD2026-09-18
CVE-2026-16515net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rulMEDIUM4.7NVD2026-09-18
CVE-2026-25684A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatioMEDIUM4.4NVD2026-09-18
CVE-2026-16514gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS MEDIUM4.3NVD2026-09-18
CVE-2025-36045IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service dMEDIUM4.3NVD2026-09-18
CVE-2025-36076IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source codMEDIUM4.3NVD2026-09-18
CVE-2026-11537IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fiMEDIUM4.3NVD2026-09-18
CVE-2026-1030IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error mMEDIUM4.3NVD2026-09-18
CVE-2026-84450libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a MEDIUM4.3NVD2026-09-18
CVE-2026-77385Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the coreMEDIUM4.3NVD2026-09-18
CVE-2026-85511A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauMEDIUM4.2NVD2026-09-18
CVE-2026-10841IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling.MEDIUM4.2NVD2026-09-18
CVE-2026-77568Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, aMEDIUM4.2NVD2026-09-18
CVE-2026-81182SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a MEDIUM4.2NVD2026-09-18
CVE-2026-84448libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inliMEDIUM4.0NVD2026-09-18
CVE-2026-92382CVE-2026-92382MEDIUMRed Hat2026-09-17
CVE-2026-90788A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown LOW2.074%EPSS 74%ileNVD2026-09-14
CVE-2026-90704A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/forLOW2.074%EPSS 74%ileNVD2026-09-14
CVE-2026-90705A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsLOW2.074%EPSS 74%ileNVD2026-09-14
CVE-2026-90706A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc.LOW2.074%EPSS 74%ileNVD2026-09-14
CVE-2026-90492A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function cLOW2.173%EPSS 73%ileNVD2026-09-13
CVE-2026-92993A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript ofLOW2.172%EPSS 72%ileNVD2026-09-17
CVE-2026-91853A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpLOW2.171%EPSS 71%ileNVD2026-09-15
CVE-2026-90621A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the LOW2.164%EPSS 64%ileNVD2026-09-14
CVE-2026-90880A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cLOW2.163%EPSS 63%ileNVD2026-09-15
CVE-2023-24035An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing cLOW3.554%EPSS 54%ileNVD2026-09-14
CVE-2026-35867A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LILOW3.143%EPSS 43%ileNVD2026-09-13
CVE-2026-90818A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the fLOW2.142%EPSS 42%ileNVD2026-09-14
CVE-2026-81637Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim'LOW2.340%EPSS 40%ileNVD2026-09-17
CVE-2026-54649punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. PrLOW2.140%EPSS 40%ileNVD2026-09-17
CVE-2026-90575A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/loginLOW2.939%EPSS 39%ileNVD2026-09-13
CVE-2026-44778Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiLOW2.939%EPSS 39%ileNVD2026-09-15
CVE-2026-55774OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/lLOW2.138%EPSS 38%ileNVD2026-09-15
CVE-2026-90795A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function oLOW2.138%EPSS 38%ileNVD2026-09-14
CVE-2026-92413A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability isLOW2.137%EPSS 37%ileNVD2026-09-16
CVE-2026-81866Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enLOW0.534%EPSS 34%ileNVD2026-09-16
CVE-2026-90572A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClientLOW2.034%EPSS 34%ileNVD2026-09-13
CVE-2026-90521A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. ThLOW2.133%EPSS 33%ileNVD2026-09-13
CVE-2026-90490A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the componeLOW2.133%EPSS 33%ileNVD2026-09-13
CVE-2026-90792A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegrLOW2.133%EPSS 33%ileNVD2026-09-14
CVE-2026-91091A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child ofLOW2.133%EPSS 33%ileNVD2026-09-15
CVE-2026-45723Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreatLOW2.732%EPSS 32%ileNVD2026-09-17
CVE-2023-24034An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a maLOW3.132%EPSS 32%ileNVD2026-09-14
CVE-2026-18422Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in thLOW2.131%EPSS 31%ileNVD2026-09-15
CVE-2026-81925Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messagesLOW2.131%EPSS 31%ileNVD2026-09-15
CVE-2026-91842A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert oLOW1.230%EPSS 30%ileNVD2026-09-15
CVE-2026-90520A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa6LOW2.130%EPSS 30%ileNVD2026-09-13
CVE-2026-68534Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stoLOW2.330%EPSS 30%ileNVD2026-09-15
CVE-2026-55775OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities oLOW2.330%EPSS 30%ileNVD2026-09-15
CVE-2026-90507A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is thLOW2.129%EPSS 29%ileNVD2026-09-13
CVE-2026-44162fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads LOW2.729%EPSS 29%ileNVD2026-09-14
CVE-2026-92385A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown funLOW1.929%EPSS 29%ileNVD2026-09-16
CVE-2026-92527A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controllLOW2.129%EPSS 29%ileNVD2026-09-16
CVE-2026-93312A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JLOW2.127%EPSS 27%ileNVD2026-09-18
CVE-2026-90525A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the fLOW2.127%EPSS 27%ileNVD2026-09-13
CVE-2025-26790Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memoLOW3.727%EPSS 27%ileNVD2026-09-14
CVE-2026-69200node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fielLOW3.726%EPSS 26%ileNVD2026-09-16
CVE-2026-90793A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/LOW2.126%EPSS 26%ileNVD2026-09-14
CVE-2026-91957FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread cLOW2.326%EPSS 26%ileNVD2026-09-15
CVE-2026-92418A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affLOW2.026%EPSS 26%ileNVD2026-09-16
CVE-2026-91086A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_procLOW2.126%EPSS 26%ileNVD2026-09-15
CVE-2026-87031n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of coLOW2.125%EPSS 25%ileNVD2026-09-16
CVE-2026-90574A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of LOW2.125%EPSS 25%ileNVD2026-09-13
CVE-2026-90712A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file LOW2.125%EPSS 25%ileNVD2026-09-14
CVE-2026-92364A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknownLOW2.125%EPSS 25%ileNVD2026-09-16
CVE-2026-93311A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunLOW2.125%EPSS 25%ileNVD2026-09-18
CVE-2026-85716The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTLOW3.725%EPSS 25%ileNVD2026-09-17
CVE-2026-3855GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, andLOW3.125%EPSS 25%ileNVD2026-09-16
CVE-2026-54450ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior LOW2.925%EPSS 25%ileNVD2026-09-15
CVE-2026-90813A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand LOW2.124%EPSS 24%ileNVD2026-09-14
CVE-2026-92381A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/LOW2.024%EPSS 24%ileNVD2026-09-16
CVE-2026-91836A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/staLOW0.924%EPSS 24%ileNVD2026-09-15
CVE-2026-81926Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupliLOW2.024%EPSS 24%ileNVD2026-09-15
CVE-2026-81927Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processinLOW1.824%EPSS 24%ileNVD2026-09-15
CVE-2026-90878A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/compLOW2.123%EPSS 23%ileNVD2026-09-15
CVE-2026-93307A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES CollLOW2.123%EPSS 23%ileNVD2026-09-17
CVE-2026-93309A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of tLOW2.123%EPSS 23%ileNVD2026-09-18
CVE-2026-86071Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/gitLOW3.723%EPSS 23%ileNVD2026-09-16
CVE-2026-86448The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before servLOW3.723%EPSS 23%ileNVD2026-09-16
CVE-2026-93308A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of LOW2.122%EPSS 22%ileNVD2026-09-18
CVE-2026-92247A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename oLOW2.022%EPSS 22%ileNVD2026-09-16
CVE-2026-90687A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal LOW2.122%EPSS 22%ileNVD2026-09-14
CVE-2026-90791A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the fLOW2.122%EPSS 22%ileNVD2026-09-14
CVE-2026-90794A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file sceLOW2.122%EPSS 22%ileNVD2026-09-14
CVE-2026-91089A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegrapLOW2.122%EPSS 22%ileNVD2026-09-15
CVE-2026-86089Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST APILOW2.322%EPSS 22%ileNVD2026-09-16
CVE-2026-90807A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of theLOW2.122%EPSS 22%ileNVD2026-09-14
CVE-2026-18424Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a hLOW2.122%EPSS 22%ileNVD2026-09-15
CVE-2026-82126The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit theLOW2.721%EPSS 21%ileNVD2026-09-16
CVE-2026-18423Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search pLOW2.121%EPSS 21%ileNVD2026-09-15
CVE-2026-49254Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/roLOW2.920%EPSS 20%ileNVD2026-09-15
CVE-2026-90499A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of LOW2.120%EPSS 20%ileNVD2026-09-13
CVE-2026-92992A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functioLOW2.120%EPSS 20%ileNVD2026-09-17
CVE-2026-54541Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior toLOW3.720%EPSS 20%ileNVD2026-09-14
CVE-2026-54542Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior toLOW3.720%EPSS 20%ileNVD2026-09-14
CVE-2026-90615A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknLOW2.120%EPSS 20%ileNVD2026-09-14
CVE-2026-91854A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the filLOW2.120%EPSS 20%ileNVD2026-09-15
CVE-2026-77860In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a douLOW3.720%EPSS 20%ileNVD2026-09-16
CVE-2026-91849A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /inLOW2.120%EPSS 20%ileNVD2026-09-15
CVE-2026-84905The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speakerLOW2.719%EPSS 19%ileNVD2026-09-16
CVE-2026-92221A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. AffecteLOW2.019%EPSS 19%ileNVD2026-09-16
CVE-2026-90714A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the fLOW2.119%EPSS 19%ileNVD2026-09-14
CVE-2026-90623A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the filLOW2.919%EPSS 19%ileNVD2026-09-14
CVE-2026-90716A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of tLOW2.019%EPSS 19%ileNVD2026-09-14
CVE-2026-68533Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluatinLOW2.318%EPSS 18%ileNVD2026-09-15
CVE-2026-73440On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remoLOW2.318%EPSS 18%ileNVD2026-09-16
CVE-2026-68530Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards areaLOW2.117%EPSS 17%ileNVD2026-09-15
CVE-2026-50607A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. LOW2.717%EPSS 17%ileNVD2026-09-17
CVE-2026-68531Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file mLOW2.117%EPSS 17%ileNVD2026-09-15
CVE-2026-13683An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler LOW2.717%EPSS 17%ileNVD2026-09-18
CVE-2026-90796A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the fileLOW2.117%EPSS 17%ileNVD2026-09-14
CVE-2026-40538An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation ManagerLOW3.717%EPSS 17%ileNVD2026-09-18
CVE-2026-93313A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTablLOW2.116%EPSS 16%ileNVD2026-09-18
CVE-2026-93314A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of tLOW2.116%EPSS 16%ileNVD2026-09-18
CVE-2026-91747Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendereLOW3.116%EPSS 16%ileNVD2026-09-15
CVE-2026-90491A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the filLOW2.116%EPSS 16%ileNVD2026-09-13
CVE-2026-90581A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdLOW2.116%EPSS 16%ileNVD2026-09-13
CVE-2026-90815A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setLOW2.116%EPSS 16%ileNVD2026-09-14
CVE-2026-90505A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the fuLOW1.316%EPSS 16%ileNVD2026-09-13
CVE-2026-90506A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts aLOW1.316%EPSS 16%ileNVD2026-09-13
CVE-2026-18421Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboarLOW2.115%EPSS 15%ileNVD2026-09-15
CVE-2026-68529Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard actLOW2.115%EPSS 15%ileNVD2026-09-15
CVE-2026-90709A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the fiLOW2.015%EPSS 15%ileNVD2026-09-14
CVE-2026-84907The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) paymLOW3.715%EPSS 15%ileNVD2026-09-16
CVE-2026-90697A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the fiLOW2.115%EPSS 15%ileNVD2026-09-14
CVE-2025-64059Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is LOW1.814%EPSS 14%ileNVD2026-09-13
CVE-2026-91926A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE messaLOW3.714%EPSS 14%ileNVD2026-09-15
CVE-2026-83369Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versiLOW3.114%EPSS 14%ileNVD2026-09-15
CVE-2026-81922Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the LOW2.114%EPSS 14%ileNVD2026-09-15
CVE-2026-81923In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before savingLOW2.114%EPSS 14%ileNVD2026-09-15
CVE-2026-92359A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_aLOW2.314%EPSS 14%ileNVD2026-09-16
CVE-2026-18426Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's controlLOW2.014%EPSS 14%ileNVD2026-09-15
CVE-2026-91730Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromisedLOW3.114%EPSS 14%ileNVD2026-09-15
CVE-2026-90488A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass ofLOW2.114%EPSS 14%ileNVD2026-09-13
CVE-2026-90580A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fiLOW2.114%EPSS 14%ileNVD2026-09-13
CVE-2026-90598A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2LOW2.114%EPSS 14%ileNVD2026-09-13
CVE-2023-22631PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.LOW2.713%EPSS 13%ileNVD2026-09-14
CVE-2023-22632PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.LOW2.713%EPSS 13%ileNVD2026-09-14
CVE-2026-82019TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows uLOW2.313%EPSS 13%ileNVD2026-09-14
CVE-2023-32778An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.LOW3.313%EPSS 13%ileNVD2026-09-14
CVE-2026-90812A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checLOW2.113%EPSS 13%ileNVD2026-09-14
CVE-2026-92814changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markuLOW2.313%EPSS 13%ileNVD2026-09-16
CVE-2026-55866SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34LOW3.713%EPSS 13%ileNVD2026-09-14
CVE-2026-25832In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadverLOW3.713%EPSS 13%ileNVD2026-09-14
CVE-2025-13166The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered usLOW3.712%EPSS 12%ileNVD2026-09-15
CVE-2026-46696October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 havLOW3.312%EPSS 12%ileNVD2026-09-14
CVE-2026-82519Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allowLOW2.312%EPSS 12%ileNVD2026-09-14
CVE-2026-92945vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefixLOW2.312%EPSS 12%ileNVD2026-09-17
CVE-2026-79300SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforcedLOW3.512%EPSS 12%ileNVD2026-09-12
CVE-2026-92130Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentialsLOW3.112%EPSS 12%ileNVD2026-09-16
CVE-2026-93384Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker lLOW3.712%EPSS 12%ileNVD2026-09-17
CVE-2026-85387Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the staLOW2.012%EPSS 12%ileNVD2026-09-16
CVE-2026-90518A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function ofLOW2.112%EPSS 12%ileNVD2026-09-13
CVE-2026-90519A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the fLOW2.112%EPSS 12%ileNVD2026-09-13
CVE-2026-90594A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PerLOW2.112%EPSS 12%ileNVD2026-09-13
CVE-2026-90595A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineLOW2.112%EPSS 12%ileNVD2026-09-13
CVE-2026-90810A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the functionLOW2.112%EPSS 12%ileNVD2026-09-14
CVE-2026-90814A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function gitLOW2.112%EPSS 12%ileNVD2026-09-14
CVE-2026-90851A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includLOW2.112%EPSS 12%ileNVD2026-09-15
CVE-2026-90857A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown functLOW2.112%EPSS 12%ileNVD2026-09-15
CVE-2026-91005A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploadedLOW2.112%EPSS 12%ileNVD2026-09-15
CVE-2026-73442On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged iLOW2.112%EPSS 12%ileNVD2026-09-16
CVE-2026-90850A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionLOW1.912%EPSS 12%ileNVD2026-09-15
CVE-2026-89327The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user thLOW3.811%EPSS 11%ileNVD2026-09-16
CVE-2026-89328The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges befLOW3.811%EPSS 11%ileNVD2026-09-16
CVE-2026-81921Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, wLOW2.311%EPSS 11%ileNVD2026-09-15
CVE-2026-90487A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the fiLOW2.111%EPSS 11%ileNVD2026-09-12
CVE-2026-93378Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised tLOW3.111%EPSS 11%ileNVD2026-09-17
CVE-2026-90600A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the fLOW2.111%EPSS 11%ileNVD2026-09-13
CVE-2026-90842A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown fLOW2.910%EPSS 10%ileNVD2026-09-15
CVE-2026-90500A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload ofLOW2.110%EPSS 10%ileNVD2026-09-13
CVE-2026-90501A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.uLOW2.110%EPSS 10%ileNVD2026-09-13
CVE-2026-90496A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_ordeLOW2.010%EPSS 10%ileNVD2026-09-13
CVE-2026-90597A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unLOW2.110%EPSS 10%ileNVD2026-09-13
CVE-2026-90700A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown functiLOW2.110%EPSS 10%ileNVD2026-09-14
CVE-2026-92526A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/LOW2.110%EPSS 10%ileNVD2026-09-16
CVE-2026-90604A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the componentLOW2.010%EPSS 10%ileNVD2026-09-14
CVE-2026-90694A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of theLOW2.010%EPSS 10%ileNVD2026-09-14
CVE-2026-90695A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknowLOW2.010%EPSS 10%ileNVD2026-09-14
CVE-2026-90696A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknownLOW2.010%EPSS 10%ileNVD2026-09-14
CVE-2026-90835A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the LOW2.010%EPSS 10%ileNVD2026-09-14
CVE-2026-90845A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the LOW2.010%EPSS 10%ileNVD2026-09-15
CVE-2026-23793An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vuLOW3.510%EPSS 10%ileNVD2026-09-14
CVE-2026-33970An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 21LOW3.510%EPSS 10%ileNVD2026-09-14
CVE-2023-37252An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames thLOW3.110%EPSS 10%ileNVD2026-09-14
CVE-2023-37253An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppreLOW3.110%EPSS 10%ileNVD2026-09-14
CVE-2026-92383A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControlLOW2.110%EPSS 10%ileNVD2026-09-16
CVE-2026-61700MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3LOW3.79%EPSS 9%ileNVD2026-09-17
CVE-2026-13666An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation ManLOW3.59%EPSS 9%ileNVD2026-09-18
CVE-2026-19640On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management InterfaLOW2.39%EPSS 9%ileNVD2026-09-16
CVE-2026-90511A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerabilLOW2.19%EPSS 9%ileNVD2026-09-13
CVE-2026-81920Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reseLOW2.39%EPSS 9%ileNVD2026-09-15
CVE-2026-90489A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobiLOW2.09%EPSS 9%ileNVD2026-09-13
CVE-2026-90497A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functioLOW2.09%EPSS 9%ileNVD2026-09-13
CVE-2026-90502A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/LOW2.09%EPSS 9%ileNVD2026-09-13
CVE-2026-93380Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the rLOW3.19%EPSS 9%ileNVD2026-09-17
CVE-2026-68532Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cLOW2.39%EPSS 9%ileNVD2026-09-15
CVE-2026-16592The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shoLOW2.79%EPSS 9%ileNVD2026-09-15
CVE-2026-87836The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderatLOW2.79%EPSS 9%ileNVD2026-09-17
CVE-2026-81870OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emLOW2.09%EPSS 9%ileNVD2026-09-16
CVE-2026-87026Tanium addressed an improper access controls vulnerability in Threat Response.LOW3.88%EPSS 8%ileNVD2026-09-16
CVE-2026-81439Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A lLOW3.78%EPSS 8%ileNVD2026-09-17
CVE-2025-70820Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.LOW3.58%EPSS 8%ileNVD2026-09-13
CVE-2026-49400October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, thLOW3.38%EPSS 8%ileNVD2026-09-14
CVE-2026-82851The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a usLOW2.78%EPSS 8%ileNVD2026-09-12
CVE-2026-86407The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its memberLOW3.78%EPSS 8%ileNVD2026-09-13
CVE-2026-86446The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is cLOW3.78%EPSS 8%ileNVD2026-09-17
CVE-2026-81438Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic AlgoriLOW3.78%EPSS 8%ileNVD2026-09-17
CVE-2026-81924Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation featuLOW2.18%EPSS 8%ileNVD2026-09-15
CVE-2026-54471Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or PrivilegLOW3.57%EPSS 7%ileNVD2026-09-17
CVE-2026-90824A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraLOW1.97%EPSS 7%ileNVD2026-09-14
CVE-2026-90577A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field ofLOW1.97%EPSS 7%ileNVD2026-09-13
CVE-2026-91723Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements LOW3.17%EPSS 7%ileNVD2026-09-15
CVE-2026-92962vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareLOW2.16%EPSS 6%ileNVD2026-09-17
CVE-2026-91008The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization LOW3.76%EPSS 6%ileNVD2026-09-17
CVE-2026-75588Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is inteLOW2.66%EPSS 6%ileNVD2026-09-17
CVE-2026-90829A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the fLOW1.96%EPSS 6%ileNVD2026-09-14
CVE-2026-81919Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() acLOW2.36%EPSS 6%ileNVD2026-09-15
CVE-2026-86891An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS LOW3.56%EPSS 6%ileNVD2026-09-14
CVE-2026-90599A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affecLOW2.16%EPSS 6%ileNVD2026-09-13
CVE-2026-91708Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendLOW3.16%EPSS 6%ileNVD2026-09-15
CVE-2026-90576A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of thLOW1.96%EPSS 6%ileNVD2026-09-13
CVE-2026-90578A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/lisLOW1.96%EPSS 6%ileNVD2026-09-13
CVE-2026-90622A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.specLOW1.96%EPSS 6%ileNVD2026-09-14
CVE-2026-90825A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the fileLOW1.96%EPSS 6%ileNVD2026-09-14
CVE-2026-90827A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/bLOW1.96%EPSS 6%ileNVD2026-09-14
CVE-2026-90831A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the fiLOW1.96%EPSS 6%ileNVD2026-09-14
CVE-2026-92472A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the fileLOW1.96%EPSS 6%ileNVD2026-09-16
CVE-2026-92473A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file srcLOW1.96%EPSS 6%ileNVD2026-09-16
CVE-2026-56597HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unautheLOW3.16%EPSS 6%ileNVD2026-09-18
CVE-2026-18425Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\SitemLOW2.16%EPSS 6%ileNVD2026-09-15
CVE-2026-52296FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libLOW2.95%EPSS 5%ileNVD2026-09-13
CVE-2026-90830A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of tLOW1.95%EPSS 5%ileNVD2026-09-14
CVE-2026-16190IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.LOW3.15%EPSS 5%ileNVD2026-09-14
CVE-2026-90826A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrapLOW0.95%EPSS 5%ileNVD2026-09-14
CVE-2025-45480Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.LOW3.05%EPSS 5%ileNVD2026-09-13
CVE-2026-84025The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data bLOW2.25%EPSS 5%ileNVD2026-09-12
CVE-2026-54577mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted loLOW2.05%EPSS 5%ileNVD2026-09-17
CVE-2026-90713A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokeLOW1.95%EPSS 5%ileNVD2026-09-14
CVE-2026-90828A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible LOW1.95%EPSS 5%ileNVD2026-09-14
CVE-2026-84903The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or passwordLOW2.74%EPSS 4%ileNVD2026-09-18
CVE-2026-92474A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file srcLOW1.94%EPSS 4%ileNVD2026-09-16
CVE-2026-65371This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26LOW3.34%EPSS 4%ileNVD2026-09-14
CVE-2026-84530An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOLOW3.34%EPSS 4%ileNVD2026-09-14
CVE-2026-56595HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin heLOW3.14%EPSS 4%ileNVD2026-09-18
CVE-2026-20071A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticatedLOW3.84%EPSS 4%ileNVD2026-09-16
CVE-2026-87281Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thLOW3.24%EPSS 4%ileNVD2026-09-15
CVE-2026-82723Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of usLOW1.84%EPSS 4%ileNVD2026-09-17
CVE-2026-81340The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capabilityLOW3.84%EPSS 4%ileNVD2026-09-18
CVE-2026-84904The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a groLOW3.84%EPSS 4%ileNVD2026-09-18
CVE-2026-86888A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS GoldeLOW3.34%EPSS 4%ileNVD2026-09-14
CVE-2026-50608A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. LOW1.24%EPSS 4%ileNVD2026-09-17
CVE-2026-92475A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utLOW1.94%EPSS 4%ileNVD2026-09-16
CVE-2026-87284Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version thLOW3.24%EPSS 4%ileNVD2026-09-15
CVE-2026-68493After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships LOW3.14%EPSS 4%ileNVD2026-09-18
CVE-2026-89008The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on oLOW2.74%EPSS 4%ileNVD2026-09-18
CVE-2026-77191An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricteLOW2.14%EPSS 4%ileNVD2026-09-14
CVE-2026-54579mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without validaLOW2.34%EPSS 4%ileNVD2026-09-17
CVE-2026-88844The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the cLOW2.73%EPSS 3%ileNVD2026-09-18
CVE-2026-89007The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one oLOW2.73%EPSS 3%ileNVD2026-09-18
CVE-2026-90801A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.cLOW1.93%EPSS 3%ileNVD2026-09-14
CVE-2026-12284Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a mLOW3.73%EPSS 3%ileNVD2026-09-17
CVE-2026-57583OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelinLOW3.33%EPSS 3%ileNVD2026-09-14
CVE-2026-91782A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynreLOW1.93%EPSS 3%ileNVD2026-09-15
CVE-2026-91781A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_indeLOW1.93%EPSS 3%ileNVD2026-09-15
CVE-2026-75943A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the cleLOW2.13%EPSS 3%ileNVD2026-09-14
CVE-2026-75945A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.LOW2.13%EPSS 3%ileNVD2026-09-14
CVE-2026-90682A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo LOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90803A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_LOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-83413Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that arLOW1.92%EPSS 2%ileNVD2026-09-15
CVE-2026-71181Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('LinLOW3.02%EPSS 2%ileNVD2026-09-16
CVE-2026-71182Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('LinLOW3.02%EPSS 2%ileNVD2026-09-16
CVE-2025-64031libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename fieldLOW2.52%EPSS 2%ileNVD2026-09-14
CVE-2026-91090A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the fLOW0.92%EPSS 2%ileNVD2026-09-15
CVE-2026-19086IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authLOW3.32%EPSS 2%ileNVD2026-09-14
CVE-2026-86887A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPLOW3.32%EPSS 2%ileNVD2026-09-14
CVE-2023-24284Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() funLOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2023-24285Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when aLOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2023-24287Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.LOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2023-24291Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parLOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2026-38924In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier obserLOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2026-83414Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version thaLOW2.52%EPSS 2%ileNVD2026-09-15
CVE-2026-90573A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file LOW1.92%EPSS 2%ileNVD2026-09-13
CVE-2026-90611A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-84626An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOSLOW3.32%EPSS 2%ileNVD2026-09-14
CVE-2026-25827An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any resLOW2.32%EPSS 2%ileNVD2026-09-15
CVE-2026-90609A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegrapLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90610A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegrapLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90612A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scenLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90613A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSamplLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90683A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/LOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-91779A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of LOW1.92%EPSS 2%ileNVD2026-09-15
CVE-2026-91780A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bLOW1.92%EPSS 2%ileNVD2026-09-15
CVE-2026-90804A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_framLOW0.92%EPSS 2%ileNVD2026-09-14
CVE-2026-78426The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holdingLOW3.72%EPSS 2%ileNVD2026-09-17
CVE-2026-38332TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectAreLOW2.92%EPSS 2%ileNVD2026-09-13
CVE-2026-52297FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in LOW2.92%EPSS 2%ileNVD2026-09-13
CVE-2026-91088A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the fileLOW2.42%EPSS 2%ileNVD2026-09-15
CVE-2026-55061uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/unigetLOW1.02%EPSS 2%ileNVD2026-09-17
CVE-2023-24283Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers toLOW2.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90681A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c oLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90802A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of theLOW1.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90508A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability iLOW1.82%EPSS 2%ileNVD2026-09-13
CVE-2026-91835A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the LOW0.92%EPSS 2%ileNVD2026-09-15
CVE-2026-90503A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008LOW1.82%EPSS 2%ileNVD2026-09-13
CVE-2026-90684A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of LOW0.92%EPSS 2%ileNVD2026-09-14
CVE-2026-90685A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of tLOW0.92%EPSS 2%ileNVD2026-09-14
CVE-2023-24288An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via cLOW2.91%EPSS 1%ileNVD2026-09-14
CVE-2026-86893A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, viLOW3.31%EPSS 1%ileNVD2026-09-14
CVE-2026-54578mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue aftLOW2.01%EPSS 1%ileNVD2026-09-17
CVE-2026-90773procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command LOW2.41%EPSS 1%ileNVD2026-09-13
CVE-2026-90811A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManageLOW1.91%EPSS 1%ileNVD2026-09-14
CVE-2023-24286Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description LOW2.91%EPSS 1%ileNVD2026-09-14
CVE-2026-82759Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audiLOW1.81%EPSS 1%ileNVD2026-09-17
CVE-2026-91017The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incomingLOW3.71%EPSS 1%ileNVD2026-09-17
CVE-2026-86701Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its componentLOW1.81%EPSS 1%ileNVD2026-09-15
CVE-2026-33962An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. ALOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-33966An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680.LOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-33956An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a mLOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-33960An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W9LOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-33967An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680.LOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-33968An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680.LOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2023-37366An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, ExLOW2.81%EPSS 1%ileNVD2026-09-14
CVE-2026-23786An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26LOW2.80%EPSS 0%ileNVD2026-09-14
CVE-2026-50606A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. LOW1.20%EPSS 0%ileNVD2026-09-17
CVE-2026-84449libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() LOW3.7NVD2026-09-18
CVE-2026-44639NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c LOW3.7NVD2026-09-18
CVE-2026-81181SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for proLOW3.7NVD2026-09-18
CVE-2026-91142A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offseLOW3.6NVD2026-09-18
CVE-2026-81178SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public noLOW3.5NVD2026-09-18
CVE-2026-93676xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictioLOW3.2NVD2026-09-18
CVE-2026-21806HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allowsLOW3.1NVD2026-09-18
CVE-2026-16512gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switchedLOW3.1NVD2026-09-18
CVE-2026-85478A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physicalLOW2.4NVD2026-09-18
CVE-2026-93588ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reLOW2.3NVD2026-09-18
CVE-2026-84400CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote dLOW2.3NVD2026-09-18
CVE-2026-93586ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cauLOW2.1NVD2026-09-18
CVE-2026-93600rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignoreLOW2.1NVD2026-09-18
CVE-2026-93601rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrLOW2.1NVD2026-09-18
CVE-2026-93531A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vuLOW2.1NVD2026-09-18
CVE-2026-93532A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf7LOW2.1NVD2026-09-18
CVE-2026-61633NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/suppLOW2.0NVD2026-09-18
GHSA-rf68-8gjr-36q7Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is emptyLOWGitHub2026-09-15
CVE-2024-53920Emacs arbitrary code execution: incomplete fix for CVE-2024-53920UNKNOWN49%EPSS 49%ileOSS-Security2026-09-14
CVE-2026-38999A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0UNKNOWN43%EPSS 43%ileNVD2026-09-16
CVE-2026-55630Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted NONE0.025%EPSS 25%ileNVD2026-09-15
CVE-2026-60163CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL executionUNKNOWN19%EPSS 19%ileOSS-Security2026-09-15
CVE-2026-79551Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.UNKNOWN18%EPSS 18%ileNVD2026-09-15
CVE-2026-49292Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBVNONE0.018%EPSS 18%ileNVD2026-09-17
CVE-2026-90169In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardownUNKNOWN16%EPSS 16%ileNVD2026-09-17
CVE-2026-90360In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init cUNKNOWN15%EPSS 15%ileNVD2026-09-17
CVE-2026-89575In the Linux kernel, the following vulnerability has been resolved: dm raid1: reserve space for NUL-terminator in buildUNKNOWN14%EPSS 14%ileNVD2026-09-11
CVE-2026-89732In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent deadlock during ep0 readUNKNOWN14%EPSS 14%ileNVD2026-09-11
CVE-2026-90393In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF in bpf_netns_link_update_proUNKNOWN14%EPSS 14%ileNVD2026-09-17
CVE-2026-90198In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix use-after-free in snd_card_do_free(UNKNOWN13%EPSS 13%ileNVD2026-09-17
CVE-2026-90219In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure cUNKNOWN13%EPSS 13%ileNVD2026-09-17
CVE-2026-90283In the Linux kernel, the following vulnerability has been resolved: hugetlbfs: release subpool on fill_super failure hUNKNOWN13%EPSS 13%ileNVD2026-09-17
CVE-2026-90314In the Linux kernel, the following vulnerability has been resolved: remoteproc: fix OOB read via signed offset in rsc_tUNKNOWN13%EPSS 13%ileNVD2026-09-17
CVE-2026-89621In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_eUNKNOWN13%EPSS 13%ileNVD2026-09-11
CVE-2026-93141In the Linux kernel, the following vulnerability has been resolved: usb: gadget: r8a66597: avoid double free of ep0_reqUNKNOWN13%EPSS 13%ileNVD2026-09-17
CVE-2026-79303kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without tUNKNOWN12%EPSS 12%ileNVD2026-09-15
CVE-2026-92240A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagUNKNOWN12%EPSS 12%ileNVD2026-09-15
CVE-2026-93131In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-privacy: Fix race condition AccUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93136In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Fix device refcount leak in the errorUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93142In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/rcar: Fix error checking in probe()UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90006In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: handle damon_stop() failure dUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89749In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop(UNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89855In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in reseUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89936In the Linux kernel, the following vulnerability has been resolved: iio: dac: m62332: Fix regulator reference count imbUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-90055In the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initializatiUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90056In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90058In the Linux kernel, the following vulnerability has been resolved: net/sched: bound qdisc_pkt_len to prevent qdisc sofUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90070In the Linux kernel, the following vulnerability has been resolved: tpm: st33zp24: Return zero on status read failure UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90073In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() tUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90075In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_codel: clamp default quantum and mtu UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90081In the Linux kernel, the following vulnerability has been resolved: net/rds: use wq_has_sleeper() in rds_cong_map_updatUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90088In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn(UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90107In the Linux kernel, the following vulnerability has been resolved: net/smc: free pending qentry in smc_llc_flow_stop()UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90126In the Linux kernel, the following vulnerability has been resolved: rtc: pcf8563: fix clock provider leak on unbind pcUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90214In the Linux kernel, the following vulnerability has been resolved: ASoC: xilinx: formatter_pcm: fix stream_data leak oUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90245In the Linux kernel, the following vulnerability has been resolved: fbdev: kyro: Validate overlay viewport coordinates UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90249In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90295In the Linux kernel, the following vulnerability has been resolved: cpufreq: imx6q: fix out-of-bounds write when probedUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90297In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization errUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90302In the Linux kernel, the following vulnerability has been resolved: ocfs2: synchronize heartbeat callbacks with o2net tUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90327In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsockoUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90348In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: snoc: use memcpy_fromio() for MSA ramUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90386In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assignsUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90394In the Linux kernel, the following vulnerability has been resolved: power: supply: sc2731_charger: cancel work on removUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93048In the Linux kernel, the following vulnerability has been resolved: mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_parUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93098In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: fix deadlock in endpoint destroy duriUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93108In the Linux kernel, the following vulnerability has been resolved: RDMA/ipoib: Drain RCU callbacks during module teardUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93140In the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking itUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93167In the Linux kernel, the following vulnerability has been resolved: csky: Fix a4/a5 restoration in syscall trace path UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93183In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocatioUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-80941In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_pUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-80966In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at probUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-80968In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe AlUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-80969In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe mUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-80973In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: bound the MIDI event length from the dUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89491In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_liveUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89512In the Linux kernel, the following vulnerability has been resolved: remoteproc: scp: Fix device reference leak on faileUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89576In the Linux kernel, the following vulnerability has been resolved: dm-era: fix shadowed superblock leak on take-snap fUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89595In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix stale object mask after concurrent maUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89730In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trailUNKNOWN12%EPSS 12%ileNVD2026-09-11
CVE-2026-89780In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: restore skb->dev on deaggregaUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89851In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debuUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89876In the Linux kernel, the following vulnerability has been resolved: media: tda18250: fix possible integer overflow IntUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89895In the Linux kernel, the following vulnerability has been resolved: media: cobalt: Avoid freeing ALSA private data twicUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89925In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory leak in guest debug handling UNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89949In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: avoid unaligned fault in IP extracUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-89964In the Linux kernel, the following vulnerability has been resolved: parisc: eisa: Fix infinite loop when parsing invaliUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-90054In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segmentUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90061In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: skip double clone set expressUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90068In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix off-by-one check on the second enumUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90072In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum to avoid signed overfUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90074In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: clamp default quantum to avoid sUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90114In the Linux kernel, the following vulnerability has been resolved: net: bridge: Reject descending VLAN tunnel ranges UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90128In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_chUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90157In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt hoUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90160In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit progrUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90202In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL bUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90218In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix WARNING in res_to_rt syzbot reportedUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90222In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb durUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90226In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optlUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90251In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against thUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90261In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90281In the Linux kernel, the following vulnerability has been resolved: phy: qcom: snps-femto-v2: Fix possible NULL-deref oUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90284In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallbUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90285In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in sUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90290In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: Restore DAIF state on error SashUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90296In the Linux kernel, the following vulnerability has been resolved: cpufreq: imx6q: fix devres accumulation across drivUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90298In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: tcon: Drop TCON TOP device reference ofUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90303In the Linux kernel, the following vulnerability has been resolved: ARM: 9485/1: mm: acquire mmap write lock around shoUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90307In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: fix heap information leak on a truncated UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90318In the Linux kernel, the following vulnerability has been resolved: fat: release buffer head after rebuilding parent fUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90319In the Linux kernel, the following vulnerability has been resolved: rapidio: clear mport->net when rio_add_net() fails UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90334In the Linux kernel, the following vulnerability has been resolved: tty: clear cdev pointer after cdev_add() failure tUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90361In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix leak in ath11k_service_ready_ext_UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90362In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_opUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90382In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx descUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90391In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm: fail dmirror_fault() when the mirroreUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90411In the Linux kernel, the following vulnerability has been resolved: nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failureUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90416In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_paramUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90420In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments()UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90431In the Linux kernel, the following vulnerability has been resolved: remoteproc: Prevent crash handling to race with rprUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-90434In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head ziUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-92496In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_tUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-92524In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93049In the Linux kernel, the following vulnerability has been resolved: mtd: mtdswap: Avoid freeing registered blktrans devUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93051In the Linux kernel, the following vulnerability has been resolved: misc: ad525x_dpot: use driver core groups for sysfsUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93061In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Avoid stack over-read in debug output UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93120In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qwUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93145In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gdsc: tear down per-domain genpds in gdsUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93159In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix heap info leak on I2C tUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-93180In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NPD issue on partial unmap of an eUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-89828In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_inUNKNOWN12%EPSS 12%ileNVD2026-09-16
CVE-2026-90200In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix integer overflow in MFT cluster validUNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-92495In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page UNKNOWN12%EPSS 12%ileNVD2026-09-17
CVE-2026-89623In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop QuUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-90339In the Linux kernel, the following vulnerability has been resolved: powerpc/syscall: Fix syscall skip handling for seccUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-89592In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix NULL dereference and integer overUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-89983In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix debugfs UAF on adapter removal i2c_UNKNOWN11%EPSS 11%ileNVD2026-09-16
CVE-2026-90053In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_htb: limit htb_classify inner-class UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90063In the Linux kernel, the following vulnerability has been resolved: virtio-net: Ensure that TCP packets don't overflow UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90078In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: fix length calculations and UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90090In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: Fix out-of-bounds DMA read inUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90122In the Linux kernel, the following vulnerability has been resolved: clk: visconti: Make sure clk_init_data is fully iniUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90124In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-rzg2l: Fix loss of interrupt rzg2lUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90180In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device remUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90209In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister UnregisUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90253In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90287In the Linux kernel, the following vulnerability has been resolved: phy: sunplus: fix error handling in sp_uphy_init() UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-92476In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93109In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Drain RCU callbacks during module teardoUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93115In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION(UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93161In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qaUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93185In the Linux kernel, the following vulnerability has been resolved: ASoC: rt700-sdw: always drain jack work on remove UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-80951In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requesteUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-89444In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump attriUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-89463In the Linux kernel, the following vulnerability has been resolved: power: supply: ucs1002: fix use-after-free on removUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-89475In the Linux kernel, the following vulnerability has been resolved: power: supply: bq24257: fix use-after-free on removUNKNOWN11%EPSS 11%ileNVD2026-09-11
CVE-2026-89776In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: enforce exact length of GROUP/GROUNKNOWN11%EPSS 11%ileNVD2026-09-16
CVE-2026-89824In the Linux kernel, the following vulnerability has been resolved: drm/panel-edp: fix i2c adapter leak on probe failurUNKNOWN11%EPSS 11%ileNVD2026-09-16
CVE-2026-89926In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix length check __import_wp_info() strUNKNOWN11%EPSS 11%ileNVD2026-09-16
CVE-2026-90108In the Linux kernel, the following vulnerability has been resolved: net/smc: free stashed qentry before overwrite in REUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90140In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exitUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90184In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute updates withUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90185In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute stores with UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90186In the Linux kernel, the following vulnerability has been resolved: null_blk: reject per-device queue resize for sharedUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90188In the Linux kernel, the following vulnerability has been resolved: null_blk: free global tag_set on init error path IUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90190In the Linux kernel, the following vulnerability has been resolved: null_blk: use DEFINE_MUTEX for the file-scope mutexUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90194In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: fix bus ID cleanup on device_add() failUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90196In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: validate topology volume range before alUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90221In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_IUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90248In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted protUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90254In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90257In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90352In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: release hif2 reference on probeUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-92481In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-92494In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_infoUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-92514In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on removUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93050In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix UAF, null-ptr-deref, and use-afUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93052In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93117In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID rUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93130In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix resource leak on mUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93149In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: avoid NULL skb in stop queue UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93152In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Use acquire/release for queue enabled sUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-93182In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix overflow in update_tg_cfs_runnable(UNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90181In the Linux kernel, the following vulnerability has been resolved: ublk: avoid teardown retry loop on xarray allocatioUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-90299In the Linux kernel, the following vulnerability has been resolved: bpf: Fix sleepable check for tracing/lsm prog WhenUNKNOWN11%EPSS 11%ileNVD2026-09-17
CVE-2026-92126Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStratUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89527In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on creatUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-90236In the Linux kernel, the following vulnerability has been resolved: NFSD: Release the export reference when reaping opeUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90384In the Linux kernel, the following vulnerability has been resolved: iomap: release the folio batch on iomap callback faUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-80974In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during removUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-80984In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer onUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89438In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and cloUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89439In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[]UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89451In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Set handle->dev before the SVA handle isUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89453In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faultsUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89454In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89455In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89484In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocationUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89502In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbufUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89566In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89673In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getdUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89794In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound reUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89807In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: guard against NULL restore_mqd in CRIU UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89830In the Linux kernel, the following vulnerability has been resolved: f2fs: fix valid block count leak on data block alloUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89834In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to migrate all curseg types during free_sUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89835In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid NULL checkpoint thread access in sysfs UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89886In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix async notifier cleanup leak UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89909In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Free init resources if kvm_init() fUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89931In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES isUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89944In the Linux kernel, the following vulnerability has been resolved: ASoC: hdac_hda: Fix hlink refcount leak on componenUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89950In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: linearize skbuff for packet geneUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89958In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix dereference matrix_mdev->kvm withUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89963In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Fix null-ptr-def in extra size UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-90021In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_alloUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-90060In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED lUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90065In the Linux kernel, the following vulnerability has been resolved: net/smc: release the internal TCP sock on IPPROTO_SUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90066In the Linux kernel, the following vulnerability has been resolved: samples/ftrace: Fix kthread_stop() on ERR_PTR in ftUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90076In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: add overflow bounds to quantum and iUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90085In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix NULL deref in NIX TM tree debugfsUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90101In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix call to hardware monitoring event handUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90109In the Linux kernel, the following vulnerability has been resolved: net: sched: fix 32-bit backlog wrap in gred, bfifo UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90112In the Linux kernel, the following vulnerability has been resolved: net: qlcnic: validate unified ROM sections before lUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90115In the Linux kernel, the following vulnerability has been resolved: xsk: fix NULL pointer dereference in __xsk_rcv() IUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90119In the Linux kernel, the following vulnerability has been resolved: ALSA: ice1712: Fix the card leak at probe error witUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90125In the Linux kernel, the following vulnerability has been resolved: smb: client: fix request buffer leak in smb2_new_reUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90130In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: fix cleanup after worker creation failureUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90135In the Linux kernel, the following vulnerability has been resolved: net: add missing ref_tracker_dir_exit() to alloc_neUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90138In the Linux kernel, the following vulnerability has been resolved: vsock: don't check the listener's sk_err in vsock_aUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90139In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90147In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_eUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90148In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_deleteUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90150In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failureUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90152In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_regisUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90158In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() inUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90159In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX gUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90165In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmbUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90166In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_coUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90170In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ipc response length before derefereUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90187In the Linux kernel, the following vulnerability has been resolved: null_blk: free zones array on device power-off nulUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90192In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: handle NULL data in send_data UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90193In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock iUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90195In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix missing sign-ext for signed 1-byte UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90201In the Linux kernel, the following vulnerability has been resolved: net: page_pool: fix UAF in __page_pool_release_netmUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90213In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix memory leak in error path of buUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90220In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer inUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90262In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle fUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90279In the Linux kernel, the following vulnerability has been resolved: md/raid5: round bitmap stripes with sector divisionUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90282In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb-legacy: Fix possible NULL-deref UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90306In the Linux kernel, the following vulnerability has been resolved: ARM: 9481/2: breakpoint: CFI breakpoints only on deUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90322In the Linux kernel, the following vulnerability has been resolved: ocfs2/cluster: keep heartbeat local node stable o2UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90364In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Unregister cpufreq notifier on iniUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90368In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unwind state on add_interface fUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90370In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_geUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90373In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: clear wcid mask under mutex aftUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90374In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate RX band_idx before derUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90385In the Linux kernel, the following vulnerability has been resolved: md/raid1: create serial pool adding rdev to array wUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90389In the Linux kernel, the following vulnerability has been resolved: md: scope memalloc_noio to allocation critical sectUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90390In the Linux kernel, the following vulnerability has been resolved: md/bitmap: resume array on backlog_store() error paUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90404In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_debugfs: Unregister panic UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90426In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before teaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92506In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal raUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92515In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested struUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93062In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: guard against division by zero in iwUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93072In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip leUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93097In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Break poison list loop on an empty payloaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93119In the Linux kernel, the following vulnerability has been resolved: usb: ljca: bound bank_num in ljca_enumerate_gpio() UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93123In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: do not advance stale DMA completUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93126In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93128In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93132In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop hanUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93133In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Check acpi_get_handle() status in risUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93134In the Linux kernel, the following vulnerability has been resolved: printk: Fix possible console use-after-free When eUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93155In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Fix AEAD unregister count in erroUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93156In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - fail ahash requests on HASH idle tUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93162In the Linux kernel, the following vulnerability has been resolved: crypto: qat - cancel work on re-enable SR-IOV timeoUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93163In the Linux kernel, the following vulnerability has been resolved: hwrng: core - fix rng list on registration error hUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93172In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: handle alloc_percpu failure in free_areUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93184In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_audmix: rework runtime PM handling in proUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-80990In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was hanUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-90050In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum inUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90175In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of ksmbd_ipc_login_request_exUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90250In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after replaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90280In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: Fix possible NULL-deref on earlUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90313In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix invalid storage access after __cgrUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90344In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: disconnect on CSA to channel 0 TheUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90397In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix NULL dereference in IRQ haUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92484In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_waysUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92519In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When bUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93082In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox setUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93085In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Reject out of range DT protocolUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93086In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Avoid IDR updates while cleaninUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93150In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: Make nr_deadline_tasks an atomic_t UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-80956In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segmentsUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-80960In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the caUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-80970In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init reUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89446In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failureUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89509In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Embed counter driver data in rdma_countUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89517In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix rq->core_pick corruption under core UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89543In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix use-after-free in __rpc_clnt_handle_eveUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89556In the Linux kernel, the following vulnerability has been resolved: module: validate string table section types In elfUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89577In the Linux kernel, the following vulnerability has been resolved: dm-io: report non-retryable errors separatedly TheUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89578In the Linux kernel, the following vulnerability has been resolved: dm-io: clone the source bio instead of copying its UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89591In the Linux kernel, the following vulnerability has been resolved: accel/rocket: initialize job domain before cleanup UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89629In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Check size of status and firmwarUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89698In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to sockaUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89714In the Linux kernel, the following vulnerability has been resolved: NFS: fix delegation_hash_table leak when nfs4_serveUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89715In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89716In the Linux kernel, the following vulnerability has been resolved: zram: validate deflate params We must validate useUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89721In the Linux kernel, the following vulnerability has been resolved: phy: rockchip-samsung-dcphy: fix out-of-range max_rUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89722In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_legaUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89739In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix use-after-free in dwc3_gadgeUNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-89790In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid divide by zero in rt6_multipath_rebalanUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89798In the Linux kernel, the following vulnerability has been resolved: rpcrdma: arm rn_done before publishing the notificaUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89820In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix dc_lock leak on GPU reset erroUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89869In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: use disable_irq() during power-oUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89889In the Linux kernel, the following vulnerability has been resolved: media: i2c: imx415: Release runtime PM reference onUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89917In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle VNCR TLB invalidation race with UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89921In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Zero initialize data structures for injeUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89935In the Linux kernel, the following vulnerability has been resolved: iio: light: apds9306: fix PM reference leak in apdsUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89978In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: return early from a zero-length flusUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89991In the Linux kernel, the following vulnerability has been resolved: bpf: Fix infinite loop in pcpu_freelist push with oUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-89996In the Linux kernel, the following vulnerability has been resolved: dma-buf: dma-heap: don't publish fd before copy_to_UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-90005In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure PUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-90077In the Linux kernel, the following vulnerability has been resolved: net: fix a resource leak in copy_net_ns() error hanUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90080In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90083In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Only operate on Ethernet framesUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90084In the Linux kernel, the following vulnerability has been resolved: octeontx2-vf: fix workqueue and netdev race in probUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90086In the Linux kernel, the following vulnerability has been resolved: xsk: honor XDP_TX_METADATA in zero-copy path The zUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90094In the Linux kernel, the following vulnerability has been resolved: arm64: process: Fix context switching MTE store-onlUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90097In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Skip VMBus module cleanup for nUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90100In the Linux kernel, the following vulnerability has been resolved: ptp: netc: fix period truncation and potential diviUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90113In the Linux kernel, the following vulnerability has been resolved: netdevsim: update queue NAPI association on queue rUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90116In the Linux kernel, the following vulnerability has been resolved: ALSA: mtpav: shut down output timer before card teaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90127In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: time out alarm requests RTC class opeUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90129In the Linux kernel, the following vulnerability has been resolved: virtio_balloon: quiesce balloon work before device UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90136In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap wrUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90179In the Linux kernel, the following vulnerability has been resolved: apparmor: fix deadlock in complain-mode change_hat UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90197In the Linux kernel, the following vulnerability has been resolved: HID: haptic: don't write an uninitialized value to UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90211In the Linux kernel, the following vulnerability has been resolved: bpf, s390: Clear fetch destination on faulting arenUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90232In the Linux kernel, the following vulnerability has been resolved: amt: Don't support cross-netns setup. When a lowerUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90233In the Linux kernel, the following vulnerability has been resolved: nvme-pci: release descriptor pools on probe failureUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90247In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_mapUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90252In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is caUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90258In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers WUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90259In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qgUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90264In the Linux kernel, the following vulnerability has been resolved: btrfs: always wait for ordered extents to avoid OE UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90265In the Linux kernel, the following vulnerability has been resolved: btrfs: defrag: fix deadlock between defrag and delaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90269In the Linux kernel, the following vulnerability has been resolved: bpf: Reject load-acquire from pointers requiring faUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90272In the Linux kernel, the following vulnerability has been resolved: perf: arm_pmuv3: Zero initialize hw_id branch stackUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90276In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: stop daemon timer rearm on destroy UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90277In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: prevent create failure bitmap UAF UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90278In the Linux kernel, the following vulnerability has been resolved: md: wait for behind writes before destroying bitmapUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90328In the Linux kernel, the following vulnerability has been resolved: HID: steam: Reject short reads Steam Controller FEUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90338In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: keep console clock enabled for UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90349In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix out-of-bounds link array acUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90350In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: reject out-of-range link ids in mt76_viUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90351In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: do not attach hif2 WED when theUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90356In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: free vif links after clearing wUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90363In the Linux kernel, the following vulnerability has been resolved: drm/msm: don't tear down KMS twice when KMS init faUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90376In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90396In the Linux kernel, the following vulnerability has been resolved: block: fix dio leak on metadata mapping error A faUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90406In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: handle runtime PM resume failureUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90422In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in regiUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90430In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92486In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF suUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92492In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynamiUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92499In the Linux kernel, the following vulnerability has been resolved: ext4: validate readdir offset before accessing direUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92505In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix undefined behavior in devid_write deUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92513In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial tabUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92516In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock SUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-92517In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acqUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93058In the Linux kernel, the following vulnerability has been resolved: drm/msm: Only fini scheduler after successful init UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93059In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix task_struct reference leak in recover_UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93068In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix DM I2C teardown race DM I2C aUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93077In the Linux kernel, the following vulnerability has been resolved: cxl/features: Clamp Get Feature output size to the UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93078In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Set Features output buffer smaUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93080In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix transport device teardown lUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93106In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correcUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93146In the Linux kernel, the following vulnerability has been resolved: time/namespace: Validate nanosecond field in proc_tUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93157In the Linux kernel, the following vulnerability has been resolved: hwrng: xilinx-trng - propagate timeout before any dUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-93169In the Linux kernel, the following vulnerability has been resolved: dmaengine: zynqmp_dma: fix race between runtime PM UNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-90034In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() UNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-93191In the Linux kernel, the following vulnerability has been resolved: smack: fix incorrect task context in smack_msg_queuUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-89765In the Linux kernel, the following vulnerability has been resolved: timers/itimer: Zero-init old itimerval before copy UNKNOWN10%EPSS 10%ileNVD2026-09-11
CVE-2026-90040In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Forcefully invalidate SNP VMSA if its bacUNKNOWN10%EPSS 10%ileNVD2026-09-16
CVE-2026-93188In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index kUNKNOWN10%EPSS 10%ileNVD2026-09-17
CVE-2026-88742Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.UNKNOWN10%EPSS 10%ileNVD2026-09-15
CVE-2026-93204In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: atomically update mac addresses WUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-89827In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid force-completing uninitialized UVUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89867In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Defer job_finish() only UNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89905In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Move arena register slot below TCC UNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89966In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb_cma: fix null nodemask dereference in huUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-90004In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: handle region split failure in applyUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-90064In the Linux kernel, the following vulnerability has been resolved: drm/xe: Reject page faults from non-fault-mode scraUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90095In the Linux kernel, the following vulnerability has been resolved: fuse: Fix the condition to enable over-io-uring ThUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90098In the Linux kernel, the following vulnerability has been resolved: net: sparx5: fix sleep in atomic context in MAC tabUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90105In the Linux kernel, the following vulnerability has been resolved: vxlan: fix reading neigh ha Currently arp/neigh_reUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90121In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Clear per-CPU IRS data on teardown UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90134In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local_page() usage in compress SeveUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90154In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connectUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90156In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90164In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup faUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90167In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break owUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90182In the Linux kernel, the following vulnerability has been resolved: blk-iocost: clear delay state when freeing policy dUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90305In the Linux kernel, the following vulnerability has been resolved: ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORKUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90310Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90311In the Linux kernel, the following vulnerability has been resolved: thermal: hwmon: Remove hwmon class device along witUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90330In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix FF device cleanup on init UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90346In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: clean up color-change beacon data onUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90355In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: clear stale link state on full UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90359In the Linux kernel, the following vulnerability has been resolved: bpf: Reject >8 byte return values on return-readingUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90417In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix dereg_skb leak and double free in wUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90432In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handlUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-92503In the Linux kernel, the following vulnerability has been resolved: ext4: fix ABBA deadlock in ext4_xattr_inode_cache_fUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93047In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Associate BOs with every job that accessesUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93069In the Linux kernel, the following vulnerability has been resolved: OPP: Fix cleanup ordering Commit 173e02d67494 ("OPUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93094In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dp_link_peer dangling references UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93129In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix handling of ultra UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93153In the Linux kernel, the following vulnerability has been resolved: RDMA/bng_re: return a timeout when firmware responsUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93164In the Linux kernel, the following vulnerability has been resolved: uprobes/x86: Move optimized uprobe from nop5 to nopUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-89518In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix this_rq() assumptions in dispatch kfUNKNOWN9%EPSS 9%ileNVD2026-09-11
CVE-2026-89519In the Linux kernel, the following vulnerability has been resolved: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch UNKNOWN9%EPSS 9%ileNVD2026-09-11
CVE-2026-89529In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode tUNKNOWN9%EPSS 9%ileNVD2026-09-11
CVE-2026-89568In the Linux kernel, the following vulnerability has been resolved: kho: fix size calculation in kho_preserved_memory_rUNKNOWN9%EPSS 9%ileNVD2026-09-11
CVE-2026-89661In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent post-shutdown use-after-free in unlocUNKNOWN9%EPSS 9%ileNVD2026-09-11
CVE-2026-88620SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryUNKNOWN9%EPSS 9%ileNVD2026-09-15
CVE-2026-88621OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.pUNKNOWN9%EPSS 9%ileNVD2026-09-15
CVE-2026-89831In the Linux kernel, the following vulnerability has been resolved: f2fs: protect critical_task_priority updates with sUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89866In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Resume device before setUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89976In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix job completion fence cleanup ethUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89977In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: check MMIO mapping errors in probe dUNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-89981In the Linux kernel, the following vulnerability has been resolved: arm64: Don't read GMID_EL1 when MTE is disabled __UNKNOWN9%EPSS 9%ileNVD2026-09-16
CVE-2026-90079In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix cn20k mailbox lifetime on repeateUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90082In the Linux kernel, the following vulnerability has been resolved: net: mana: Cap MSI-X vectors to the device MSI-X taUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90087In the Linux kernel, the following vulnerability has been resolved: Bluetooth: do not leak an hci_conn when a second LEUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90096In the Linux kernel, the following vulnerability has been resolved: fuse: invalidate the correct range after O_APPEND dUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90099In the Linux kernel, the following vulnerability has been resolved: net/sched: account classifier filter allocations toUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90106In the Linux kernel, the following vulnerability has been resolved: net: bridge: arp/nd proxy: fix reading neigh ha CuUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90117In the Linux kernel, the following vulnerability has been resolved: ntfs: validate usa_ofs before preserving the updateUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90123In the Linux kernel, the following vulnerability has been resolved: irqchip/ast2700-intc: Avoid allocating in the irq_dUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90144In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during teUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90155In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90163In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module iniUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90168Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90171In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: release pending child sockets outsiUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90183In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: clear delay state when freeing policUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90206In the Linux kernel, the following vulnerability has been resolved: nvmet: fix max_qid race between configfs and controUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90208In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/samsung_pwm: Switch to raw_spinUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90238In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: fix self-deadlock in isp4sd_pwronUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90239In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: release partial allocations in isUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90242In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix iopf_refcount leak on RID domain reUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90263In the Linux kernel, the following vulnerability has been resolved: btrfs: check if root is readonly when setting posixUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90266In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't force read-only on transient -EUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90271In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix a NULL pointer dereference on unbindiUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90300In the Linux kernel, the following vulnerability has been resolved: bpf: Clear buf on error in __bpf_get_task_stack BoUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90304In the Linux kernel, the following vulnerability has been resolved: ARM: 9484/1: enable interrupts when unhandled user UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90315In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Add lockdown checks to legacy I/O and meUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90323In the Linux kernel, the following vulnerability has been resolved: ublk: validate auto buf reg before taking uring_cmdUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90331In the Linux kernel, the following vulnerability has been resolved: HID: asus: refactor the two workqueues and init seqUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90336In the Linux kernel, the following vulnerability has been resolved: serial: core: clear freed pointers on uart_registerUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90337In the Linux kernel, the following vulnerability has been resolved: serial: core: do fallible allocations before the coUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90340In the Linux kernel, the following vulnerability has been resolved: pinctrl: generic: free maps on pinctrl_generic_to_mUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90405In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: fix some error handling bugs inUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90409In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Add vm_bind region with kbo range overUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90412In the Linux kernel, the following vulnerability has been resolved: nvmet: fix return status of RMI log page on allocatUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-90421In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID rUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-92478In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts ThUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-92482In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() forUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-92487In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writaUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93038In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad5686: missing NULL check on match data UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93060In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix use after free on error path inUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93081In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93096In the Linux kernel, the following vulnerability has been resolved: cxl/features: Serialize multi-part Get/Set Feature UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93099In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix UAF from worker threads when domainUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93135In the Linux kernel, the following vulnerability has been resolved: bpf: Reject programs with inlined helpers if JIT isUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93139In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93166In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: debug: fix off by on in rtw89_ppdu_strUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93171In the Linux kernel, the following vulnerability has been resolved: leds: lp5860: Fix a potential double-unlock In lp5UNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-93181In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix uncore_box ref/unref ordUNKNOWN9%EPSS 9%ileNVD2026-09-17
CVE-2026-89759In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup when scanning task sUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-39039In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and seUNKNOWN8%EPSS 8%ileNVD2026-09-15
CVE-2025-56565DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials inUNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-93186In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the paUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-89525In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count UUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89766In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctlUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89868In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_sUNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-90029In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on disUNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-90039In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_UNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-93179In the Linux kernel, the following vulnerability has been resolved: drm/amd/powerplay: fix VoltageObjectInfo zero-stridUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93193In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: Fix OF node reference leUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93194In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Release core resources Core rUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93195In the Linux kernel, the following vulnerability has been resolved: drm/bridge: synopsys: dw-dp: Support unregistering UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93198In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate the persisted dirty_tail chain UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93199In the Linux kernel, the following vulnerability has been resolved: i3c: master: Do not treat master device as a duplicUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-81013In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on emptUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-92238A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violUNKNOWN8%EPSS 8%ileNVD2026-09-15
CVE-2026-92239A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in ThunderbirUNKNOWN8%EPSS 8%ileNVD2026-09-15
CVE-2026-93073In the Linux kernel, the following vulnerability has been resolved: dax: read holder_ops once in dax_holder_notify_failUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2025-56566MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile UNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-80930In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout UNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-80963In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu dataUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-80965In the Linux kernel, the following vulnerability has been resolved: ALSA: serial-u16550: Check card index validity at pUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-80988In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP linUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89457In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks againstUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89458In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as sucUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89490In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit keUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89496In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write completUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89498In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdirUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89515In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fill in DMA padding bytes in scsi_allocUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-89752In the Linux kernel, the following vulnerability has been resolved: mm: memcg: stop reclaim when a limit update is supeUNKNOWN8%EPSS 8%ileNVD2026-09-11
CVE-2026-90028In the Linux kernel, the following vulnerability has been resolved: usb: typec: hd3ss3220: track VBUS enable state per UNKNOWN8%EPSS 8%ileNVD2026-09-16
CVE-2026-90216In the Linux kernel, the following vulnerability has been resolved: ubi: Fix rollback for explicit UBI device numbers UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-90395In the Linux kernel, the following vulnerability has been resolved: power: supply: isp1704_charger: cancel work on remoUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-90415In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: free STAG index when TPT entry write faUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-92498In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event hUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-92501In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write falUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-92521In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that freeUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93040In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize channel state checks UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93041In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize abort state updates UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93053In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible outUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93055In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_symlUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93056In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: remove broken string coUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93067In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: clamp the reported AUX read sUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93103In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Preserve unit 0 on allocation failure hUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93110In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93158In the Linux kernel, the following vulnerability has been resolved: crypto: sa2ul - stop probe if context pool creationUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-93160In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-73638Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_UNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-73639Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRUNKNOWN8%EPSS 8%ileNVD2026-09-17
CVE-2026-89447In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89772In the Linux kernel, the following vulnerability has been resolved: btrfs: write-protect folios during data writeback UNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89773In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip Update HDCP Config In TransitUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-92500In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state aUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93187In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Return error for invalid UNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93197In the Linux kernel, the following vulnerability has been resolved: memcg: move LRU size accounting on reparenting instUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-89618In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in inUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89683In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehandUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89514In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spiUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89589In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER worUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-93143In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix pm_runtime refcount leak UNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-80938In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work undeUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-80964In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe UNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-80972In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Check card index validity at probe alUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89464In the Linux kernel, the following vulnerability has been resolved: power: supply: twl4030_charger: cancel workers via UNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89474In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freeiUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89710In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: fix layout segment leak on the pnfs_layoutUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-89751In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handlUNKNOWN7%EPSS 7%ileNVD2026-09-11
CVE-2026-90189In the Linux kernel, the following vulnerability has been resolved: null_blk: register configfs subsystem after creatinUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-90274In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: fix underflow for usage of (nrseqUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-90354In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix double hif2 init on the nonUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-90378In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: Fix memory leak in SDIO TX pathUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-92477In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string termUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-92483In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO keeUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-92509In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_UNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-92512In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() WheUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-92523In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute lengUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93064In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93102In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Free RX data on late probe failure hfi1UNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93114In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companionUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-93118In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: check endpoint DMA allocatUNKNOWN7%EPSS 7%ileNVD2026-09-17
CVE-2026-75157Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EUNKNOWN7%EPSS 7%ileNVD2026-09-18
CVE-2026-80940In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80942In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-81014In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_sUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89460In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead cUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89468In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8788-charger: fix use-after-free oUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89552In the Linux kernel, the following vulnerability has been resolved: params: fix charp corruption on allocation failure UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89666In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range nseconds in NFSv3 SETATTRUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89735In the Linux kernel, the following vulnerability has been resolved: usb: gadget: midi2: remove default configfs groups UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-92019Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.UNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-90178In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix core_data leak on CPUs withouUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90215In the Linux kernel, the following vulnerability has been resolved: mtd: ubi: Release device reference on busy detach UNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90275In the Linux kernel, the following vulnerability has been resolved: md/raid1: don't set array_frozen in raid1_takeover(UNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90366In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: reserve space for the CSA-abortUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90375In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix non-AQL packet accounting for MLO sUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90400In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync remUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90410In the Linux kernel, the following vulnerability has been resolved: spi: davinci: switch to managed controller allocatiUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90418In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirtUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90428In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR beforUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90433In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocatiUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92490In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver regUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92491In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol tablUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92497In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_oUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92502In the Linux kernel, the following vulnerability has been resolved: ext4: clear stale xarray tags on folios skipped durUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93065In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix counter type in iwl_fwrt_dump_erUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93071In the Linux kernel, the following vulnerability has been resolved: media: bcm2835-unicam: Fix asc leaked in error/remoUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93083In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setuUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93084In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Drop handle on protocol bind faUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93089In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR fUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93090In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Clean up channels on setup failUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93091In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before teUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93092In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unregister device notifier befoUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93093In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Publish channel state before caUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93101In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: Unregister sub-device if asc_lisUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93113In the Linux kernel, the following vulnerability has been resolved: clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93173In the Linux kernel, the following vulnerability has been resolved: bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hookUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93174In the Linux kernel, the following vulnerability has been resolved: bpf: Copy per-CPU map value padding in copy_map_valUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-88593kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes UNKNOWN6%EPSS 6%ileNVD2026-09-16
CVE-2026-79362Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80927In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_tUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80934In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for AddUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80939In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rfUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80946In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for iUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80957In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain duUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-80993In the Linux kernel, the following vulnerability has been resolved: net: phylink: correctly validate returned PCS in phUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-81009In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_structUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89437In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak inUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89449In the Linux kernel, the following vulnerability has been resolved: iommu: Fix dev_iommu memory leak when device_add faUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89467In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: fix use-after-free qcUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89506In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_RUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89590In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_jobUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89644In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O writUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89693In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfsUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89700In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listenUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89701In the Linux kernel, the following vulnerability has been resolved: nfsd: validate nseconds in TIME_DELEG decode paths UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89717In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destroUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89719In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state(UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89734In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Fix null pointer dereference in uUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89737In the Linux kernel, the following vulnerability has been resolved: usb: typec: thunderbolt: Disable work before freeinUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-90333In the Linux kernel, the following vulnerability has been resolved: dm-integrity: replace forgeable discard filler withUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90377In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RX data queuing of RRO 3.0 For RROUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-90424In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-fUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92493In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate UNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-92520In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure UNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93066In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Take cpa_lock around large-page collapsUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-93100In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Prevent use-after-free in rdtgroup_kn_pUNKNOWN6%EPSS 6%ileNVD2026-09-17
CVE-2026-89572In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix OPP table cleanup apple_soUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-92030Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, FirefUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-89505In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Guard legacy bundles without method_elUNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-89516In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't BUG_ON a destroyed DSQ in process_UNKNOWN6%EPSS 6%ileNVD2026-09-11
CVE-2026-92018Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FirefUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92022Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FirefUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92023Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16UNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92024Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16UNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92028Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, FirefUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92029Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16UNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92038Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.UNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92039Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, TUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92041Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92074Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThundeUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-92075Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbiUNKNOWN6%EPSS 6%ileNVD2026-09-15
CVE-2026-89728In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Fix out-of-bounds access for newdevs UNKNOWN5%EPSS 5%ileNVD2026-09-11
CVE-2026-92016Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16,UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92031Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92032Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-89718In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store()UNKNOWN5%EPSS 5%ileNVD2026-09-11
CVE-2026-89727In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_UNKNOWN5%EPSS 5%ileNVD2026-09-11
CVE-2026-89745In the Linux kernel, the following vulnerability has been resolved: debugfs: Fix lockdown check for mmap_prepare CommiUNKNOWN5%EPSS 5%ileNVD2026-09-11
CVE-2026-90212In the Linux kernel, the following vulnerability has been resolved: arm64/efi: Avoid voluntary preemption with efi_mm iUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90267In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix special_vec mempool leak when scsi_alUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90270In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Disable driver unbind to avoid UAF When UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90273In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: missing cscfg_csdev_disable_activUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90335In the Linux kernel, the following vulnerability has been resolved: tty: skip cdev_del() when no cdev is registered TTUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90342In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock deadlock on arena lock failure UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90345In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix P2P action frame handling withoUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90365In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: cancel reset and rc work on device unreUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-90369In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix out-of-bounds access in mmio copy hUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-92479In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reportinUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-92480In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The sUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93043In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for gotox insn UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93044In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for arena-relateUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93057In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Avoid possible memory reclaim deadUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93075In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear pgmap ops and owner on unbind fsdUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93076In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear vmemmap_shift when binding static UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93104In the Linux kernel, the following vulnerability has been resolved: RDMA/rvt: Return NULL after port allocation failureUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93124In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93168In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93200In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix use-after-free of master->this syUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-93202In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix recursive locking during device reUNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2025-55787In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.UNKNOWN5%EPSS 5%ileNVD2026-09-17
CVE-2026-11927IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party serviceUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-39040BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (truUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92035Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92042Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92044Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92045Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92046Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92048Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in FireUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92076Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92077Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156,UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92021Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and ThunderbiUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92034Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92036Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and ThunderUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92037Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and ThunderbiUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92040Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92057Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, UNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2026-92079Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThundeUNKNOWN5%EPSS 5%ileNVD2026-09-15
CVE-2025-69904Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on tUNKNOWN4%EPSS 4%ileNVD2026-09-11
CVE-2026-52483The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(UNKNOWN4%EPSS 4%ileNVD2026-09-17
CVE-2026-13272IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as theUNKNOWN4%EPSS 4%ileNVD2026-09-14
CVE-2026-25825An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs theUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-25826An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be sUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-89770In the Linux kernel, the following vulnerability has been resolved: iomap: don't free integrity payload that doesn't exUNKNOWN4%EPSS 4%ileNVD2026-09-11
CVE-2026-92049Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbiUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92056Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92058Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92059Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92060Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92064Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in FireUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92065Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in FireUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92067Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbirdUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92068Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThundUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92069Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92070Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92071Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in FireUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92072Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 1UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92078Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, ThunderbirdUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92050Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and ThunderUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92051Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and ThunderUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92061Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92063Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-92066Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.UNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-12101IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to iUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-90969Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authentUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-90971Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allUNKNOWN4%EPSS 4%ileNVD2026-09-15
CVE-2026-81018In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Free system certificate siUNKNOWN3%EPSS 3%ileNVD2026-09-11
CVE-2026-13327Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allUNKNOWN2%EPSS 2%ileNVD2026-09-15
CVE-2026-84850Improper certificate validation in the shared HTTP client used by synchronization and integration features in DevolutionUNKNOWN1%EPSS 1%ileNVD2026-09-15
CVE-2026-49030Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. UNKNOWNNVD2026-09-13
CVE-2026-87087Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All rUNKNOWNNVD2026-09-14
CVE-2013-1446Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issuUNKNOWNNVD2026-09-14
CVE-2026-87730Rejected reason: this is rejectedUNKNOWNNVD2026-09-15
CVE-2026-66789Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerabilUNKNOWNNVD2026-09-15
CVE-2026-66790Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerabilUNKNOWNNVD2026-09-15
CVE-2026-10145Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-15
CVE-2026-10149Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-15
CVE-2026-10150Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-15
CVE-2026-61396Rejected reason: Did not need CVE IDUNKNOWNNVD2026-09-16
CVE-2026-92571Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574.UNKNOWNNVD2026-09-16
CVE-2026-85789Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-16
CVE-2026-11874Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.UNKNOWNNVD2026-09-17
CVE-2026-53679Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.UNKNOWNNVD2026-09-17
CVE-2026-53681Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.UNKNOWNNVD2026-09-17
CVE-2026-9314Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-57846Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2025-62167Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33626. Reason: This candidate is a UNKNOWNNVD2026-09-17
CVE-2026-10594Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-11314Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-49137Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-57847Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-11432Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-78668Rejected reason: reserved but not neededUNKNOWNNVD2026-09-17
CVE-2026-65323Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-17
CVE-2026-88623NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the usUNKNOWNNVD2026-09-18
CVE-2026-93018Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pasUNKNOWNNVD2026-09-18
CVE-2026-60115Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.UNKNOWNNVD2026-09-18
CVE-2026-91863CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of servicUNKNOWNOSS-Security2026-09-18
CVE-2026-91864CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustionUNKNOWNOSS-Security2026-09-18
CVE-2026-91865CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to deUNKNOWNOSS-Security2026-09-18
CVE-2026-91866CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of serviceUNKNOWNOSS-Security2026-09-18
CVE-2026-91867CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request inUNKNOWNOSS-Security2026-09-18
USN-8782-1USN-8782-1: Rclone vulnerabilityUNKNOWNUbuntu2026-09-18
USN-8730-3USN-8730-3: Linux kernel (Azure) vulnerabilityUNKNOWNUbuntu2026-09-18
USN-8715-2USN-8715-2: Linux kernel (AWS FIPS) vulnerabilitiesUNKNOWNUbuntu2026-09-18
DSA 6494-1[SECURITY] [DSA 6494-1] kamailio security updateUNKNOWNDebian2026-09-11
DSA 6495-1[SECURITY] [DSA 6495-1] spip security updateUNKNOWNDebian2026-09-11
DSA 6497-1[SECURITY] [DSA 6497-1] xorg-server security updateUNKNOWNDebian2026-09-12
DSA 6499-1[SECURITY] [DSA 6499-1] cjose security updateUNKNOWNDebian2026-09-15
DSA 6500-1[SECURITY] [DSA 6500-1] tor security updateUNKNOWNDebian2026-09-16
DSA 6504-1[SECURITY] [DSA 6504-1] libapache2-mod-auth-openidc security updateUNKNOWNDebian2026-09-17
DSA 6506-1[SECURITY] [DSA 6506-1] chromium security updateUNKNOWNDebian2026-09-17
OSS-20260918-3A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpillUNKNOWNOSS-Security2026-09-18
OSS-20260918-4Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpillUNKNOWNOSS-Security2026-09-18
OSS-20260918-5Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpillUNKNOWNOSS-Security2026-09-18
OSS-20260918-6Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpillUNKNOWNOSS-Security2026-09-18
OSS-20260918-15Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpillUNKNOWNOSS-Security2026-09-18
OSS-20260917-4The GNU C Library security advisories update for 2026-09-17UNKNOWNOSS-Security2026-09-17
OSS-20260916-3Unbound: 1.26.1 addresses multiple CVE itemsUNKNOWNOSS-Security2026-09-16
OSS-20260916-5Multiple vulnerabilities in Jenkins pluginsUNKNOWNOSS-Security2026-09-16
OSS-20260914-26graphql-go/graphql &lt;= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRuleUNKNOWNOSS-Security2026-09-14
OSS-20260914-31The GNU C Library security advisories update for 2026-09-14UNKNOWNOSS-Security2026-09-14
OSS-20260913-1Fwd: UnrealIRCd 6.2.7 released &amp; hot-patch to fix security issues for existing installationsUNKNOWNOSS-Security2026-09-13
OSS-20260913-2Re: UnrealIRCd 6.2.7 released &amp; hot-patch to fix security issues for existing installationsUNKNOWNOSS-Security2026-09-13
OSS-20260913-5GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efiUNKNOWNOSS-Security2026-09-13
OSS-20260912-1Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKeyUNKNOWNOSS-Security2026-09-12
OSS-20260912-2[vim-security] Ex Command Injection in sign_jump() in Vim &lt; v9.2.1090UNKNOWNOSS-Security2026-09-12
GHSA-7jxh-36q5-gcqvGHSA-7jxh-36q5-gcqvUNKNOWNOSV2026-09-17
GO-2026-6444GO-2026-6444UNKNOWNOSV2026-09-17
GO-2026-6454GO-2026-6454UNKNOWNOSV2026-09-17
GO-2026-6455GO-2026-6455UNKNOWNOSV2026-09-17
GO-2026-6465GO-2026-6465UNKNOWNOSV2026-09-17
GO-2026-6466GO-2026-6466UNKNOWNOSV2026-09-17
GO-2026-6467GO-2026-6467UNKNOWNOSV2026-09-17
GO-2026-6468GO-2026-6468UNKNOWNOSV2026-09-17
RUSTSEC-2026-0285RUSTSEC-2026-0285UNKNOWNOSV2026-09-14
FG-IR-26-165Arbitrary process termination from exposed minifilter communication portUNKNOWNFortinet2026-09-08
FG-IR-26-164Broken Access control on Websocket streamsUNKNOWNFortinet2026-09-08
FG-IR-26-167Cron Job Injection in Remote BackupUNKNOWNFortinet2026-09-08
FG-IR-26-168Improper Authentication of FortiPAM ServerUNKNOWNFortinet2026-09-08
FG-IR-26-170JWT used for authentication in web GUI signed with static keyUNKNOWNFortinet2026-09-08
FG-IR-26-173Null Pointer Dereference in Log ReportUNKNOWNFortinet2026-09-08
FG-IR-26-169Open Redirect on FortiSIEMUNKNOWNFortinet2026-09-08
FG-IR-26-166Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive InformationUNKNOWNFortinet2026-09-08
FG-IR-26-172Uncontrolled Resource Consumption in SNMPUNKNOWNFortinet2026-09-08
FG-IR-26-171Workflow session email approval process bypassUNKNOWNFortinet2026-09-08
FG-IR-26-174ZTNA Portal Improper Certificate ValidationUNKNOWNFortinet2026-09-08
FG-IR-26-158Broken access control in the RADIUS type admin groupUNKNOWNFortinet2026-08-12
FG-IR-26-157Content-Encoding WAF EvasionUNKNOWNFortinet2026-08-12
FG-IR-26-160FGFM Authentication Weakening via CLI ConfigurationUNKNOWNFortinet2026-08-12
FG-IR-26-156Heap overflow in kernel driver due to missing size validationUNKNOWNFortinet2026-08-12
FG-IR-26-159Server-Side Request Forgery (SSRF)UNKNOWNFortinet2026-08-12
FG-IR-26-161Stack buffer overflow in WADUNKNOWNFortinet2026-08-12
FG-IR-26-162UI DoS attackUNKNOWNFortinet2026-08-12
FG-IR-26-154Buffer overread in authd and wad daemonUNKNOWNFortinet2026-07-14
FG-IR-26-149Cross-Site Scripting in Domain parameterUNKNOWNFortinet2026-07-14
FG-IR-26-152Header injection in Web Filter warning pageUNKNOWNFortinet2026-07-14
FG-IR-26-153Header injection in captive portal authentication formUNKNOWNFortinet2026-07-14
FG-IR-26-147Missed certificate verification in AD Connector communication with FortiClient EMSUNKNOWNFortinet2026-07-14
FG-IR-26-146Out of bounds read in GUIUNKNOWNFortinet2026-07-14
FG-IR-26-151Path traversal in CLI command allows deletion of root file systemUNKNOWNFortinet2026-07-14
FG-IR-26-150SSL-VPN Reflected XSSUNKNOWNFortinet2026-07-14
FG-IR-26-148Stack Buffer Overflow in Log ReportUNKNOWNFortinet2026-07-14
FG-IR-26-155Supers override fails to properly override supervisor addressUNKNOWNFortinet2026-07-14
FG-IR-26-145Unauthenticated VNC access exposed on all interfacesUNKNOWNFortinet2026-07-14
FG-IR-25-1052LDAP authentication bypass in Agentless VPN and FSSOUNKNOWNFortinet2026-02-10
FG-IR-26-140Improper access control in API endpointsUNKNOWNFortinet2026-06-09
FG-IR-26-143Restricted CLI escape using LuaUNKNOWNFortinet2026-06-09
FG-IR-26-141Second-Order OS Command Injection via JSON Input on start vnc featureUNKNOWNFortinet2026-06-09
FG-IR-24-452Insertion of Sensitive 2FA Information in logs and debug commandUNKNOWNFortinet2025-10-14
FG-IR-25-545Trusted hosts bypass via SSHUNKNOWNFortinet2025-11-18
FG-IR-26-139Linux Kernel Vulnerability copy.fail - CVE-2026-31431UNKNOWNFortinet2026-05-13
FG-IR-26-138Arbitrary log file read in administrative interfaceUNKNOWNFortinet2026-05-12
FG-IR-26-131Command injection in CLIUNKNOWNFortinet2026-05-12
FG-IR-26-137DoS due to unsafe function in signal handlerUNKNOWNFortinet2026-05-12
FG-IR-26-129Hardcoded Encryption Key Used for VPN Saved PasswordsUNKNOWNFortinet2026-05-12
FG-IR-26-128Improper access control on API endpointsUNKNOWNFortinet2026-05-12
FG-IR-26-136Incorrect global authorizationUNKNOWNFortinet2026-05-12
FG-IR-26-133OS command injection in CLIUNKNOWNFortinet2026-05-12
FG-IR-26-130OTP Disclosure via Exported TokenContentProviderUNKNOWNFortinet2026-05-12
FG-IR-26-123Out-of-bounds access in CAPWAP daemonUNKNOWNFortinet2026-05-12

Updated 2026-09-18. Sources: NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB and more. JSON API available for automation.