Vulnerabilities published in the last 7 days (2026-09-11 → 2026-09-18). Updated every 4 hours.
| CVE / ID | Title | Severity | CVSS | EPSS | Why urgent | Source | Date |
|---|---|---|---|---|---|---|---|
| CVE-2026-85706 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1 | CRITICAL | 10.0 | 96% | KEV PoC EPSS 96%ile | NVD | 2026-09-12 |
| CVE-2026-89308 | An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to exec | CRITICAL | 9.3 | 87% | EPSS 87%ile | NVD | 2026-09-15 |
| CVE-2026-58146 | WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the | CRITICAL | 9.4 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-52824 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pub | CRITICAL | 9.1 | 80% | EPSS 80%ile | NVD | 2026-09-15 |
| CVE-2026-76461 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthentic | CRITICAL | 9.8 | 80% | KEV EPSS 80%ile | NVD | 2026-09-14 |
| CVE-2026-73172 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | CRITICAL | 9.3 | 77% | EPSS 77%ile | NVD | 2026-09-16 |
| CVE-2026-90822 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command i | CRITICAL | 9.8 | 71% | EPSS 71%ile | NVD | 2026-09-17 |
| CVE-2026-20305 | A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perfor | CRITICAL | 9.1 | 71% | EPSS 71%ile | NVD | 2026-09-16 |
| CVE-2026-20306 | A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform comman | CRITICAL | 9.1 | 71% | EPSS 71%ile | NVD | 2026-09-16 |
| CVE-2026-76675 | A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploi | CRITICAL | 9.1 | 70% | EPSS 70%ile | NVD | 2026-09-15 |
| CVE-2026-54501 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through | CRITICAL | 9.4 | 67% | EPSS 67%ile | NVD | 2026-09-17 |
| CVE-2026-58147 | WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password cha | CRITICAL | 9.3 | 67% | EPSS 67%ile | NVD | 2026-09-16 |
| CVE-2026-40855 | WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality | CRITICAL | 9.3 | 65% | EPSS 65%ile | NVD | 2026-09-16 |
| CVE-2026-76674 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways t | CRITICAL | 9.8 | 63% | EPSS 63%ile | NVD | 2026-09-15 |
| CVE-2026-90919 | LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_reg | CRITICAL | 9.3 | 62% | EPSS 62%ile | NVD | 2026-09-14 |
| CVE-2026-51990 | An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary | CRITICAL | 9.8 | 61% | EPSS 61%ile | NVD | 2026-09-16 |
| CVE-2026-65414 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | CRITICAL | 9.8 | 61% | EPSS 61%ile | NVD | 2026-09-14 |
| CVE-2026-45140 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a | CRITICAL | 9.8 | 61% | EPSS 61%ile | NVD | 2026-09-17 |
| CVE-2026-57131 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router. | CRITICAL | 9.8 | 60% | EPSS 60%ile | NVD | 2026-09-14 |
| CVE-2026-20307 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to exec | CRITICAL | 9.9 | 60% | EPSS 60%ile | NVD | 2026-09-16 |
| CVE-2026-27546 | An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an adm | CRITICAL | 9.8 | 60% | EPSS 60%ile | NVD | 2026-09-16 |
| CVE-2026-27565 | An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root pr | CRITICAL | 9.8 | 59% | EPSS 59%ile | NVD | 2026-09-16 |
| CVE-2026-89040 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request i | CRITICAL | 9.3 | 59% | EPSS 59%ile | NVD | 2026-09-15 |
| CVE-2026-70416 | Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthentica | CRITICAL | 10.0 | 58% | EPSS 58%ile | NVD | 2026-09-16 |
| CVE-2026-57127 | PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddlewar | CRITICAL | 9.8 | 58% | EPSS 58%ile | NVD | 2026-09-14 |
| CVE-2026-12351 | IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 L | CRITICAL | 9.8 | 57% | EPSS 57%ile | NVD | 2026-09-15 |
| CVE-2026-76834 | b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array obje | CRITICAL | 9.2 | 56% | EPSS 56%ile | NVD | 2026-09-17 |
| CVE-2026-53710 | MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sa | CRITICAL | 10.0 | 56% | EPSS 56%ile | NVD | 2026-09-15 |
| CVE-2026-90011 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Reserve a terminator byte for | CRITICAL | 9.1 | 56% | EPSS 56%ile | NVD | 2026-09-16 |
| CVE-2026-91932 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attac | CRITICAL | 9.0 | 56% | EPSS 56%ile | NVD | 2026-09-15 |
| CVE-2026-92937 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for G | CRITICAL | 10.0 | 55% | EPSS 55%ile | NVD | 2026-09-17 |
| CVE-2026-76460 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to byp | CRITICAL | 10.0 | 54% | KEV EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-61534 | Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use a | CRITICAL | 9.1 | 54% | EPSS 54%ile | NVD | 2026-09-14 |
| CVE-2026-89970 | In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: Synchronize timeout work during SQ tear | CRITICAL | 9.8 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-20176 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyi | CRITICAL | 9.1 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-78006 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including | CRITICAL | 9.8 | 54% | EPSS 54%ile | NVD | 2026-09-12 |
| CVE-2026-57147 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public | CRITICAL | 9.8 | 54% | EPSS 54%ile | NVD | 2026-09-15 |
| CVE-2026-50006 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL fro | CRITICAL | 9.1 | 54% | EPSS 54%ile | NVD | 2026-09-14 |
| CVE-2026-78159 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including | CRITICAL | 9.8 | 54% | EPSS 54%ile | NVD | 2026-09-12 |
| CVE-2026-73447 | A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full | CRITICAL | 9.4 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-73453 | An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary c | CRITICAL | 9.5 | 53% | EPSS 53%ile | NVD | 2026-09-16 |
| CVE-2026-73456 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) | CRITICAL | 9.2 | 53% | EPSS 53%ile | NVD | 2026-09-16 |
| CVE-2026-92934 | vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host | CRITICAL | 9.5 | 53% | EPSS 53%ile | NVD | 2026-09-17 |
| CVE-2026-46495 | OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/ | CRITICAL | 9.2 | 53% | EPSS 53%ile | NVD | 2026-09-15 |
| CVE-2026-91104 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | CRITICAL | 9.3 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-80976 | In the Linux kernel, the following vulnerability has been resolved: seg6: reset IP6CB after IPv6 decapsulation decap_a | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89482 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: do not accept C2HData based on blk_rq_pay | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89485 | In the Linux kernel, the following vulnerability has been resolved: lockd: pin next file across nlm_inspect_file lock-d | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89494 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89495 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89538 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject krb5 v2 wrap tokens with oversized e | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89643 | In the Linux kernel, the following vulnerability has been resolved: audit: avoid dropping live tree ref on fsnotify rul | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89655 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in __kick_flushing_caps() on cf entry | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89712 | In the Linux kernel, the following vulnerability has been resolved: NFSD: restart ssc_expire_umount walk after dropping | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-61560 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (` | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-15 |
| CVE-2026-89783 | In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr( | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-89634 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix ALIGN() overflow in symlink_data() | CRITICAL | 9.1 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-54053 | Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl | CRITICAL | 9.6 | 52% | EPSS 52%ile | NVD | 2026-09-17 |
| CVE-2026-89969 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix out-of-bounds write when receiving a | CRITICAL | 9.8 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-89846 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sens | CRITICAL | 9.1 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-89778 | In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-89697 | In the Linux kernel, the following vulnerability has been resolved: nfsd: add fh_want_write() for early-verified SETATT | CRITICAL | 9.1 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-43790 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, | CRITICAL | 9.1 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-89779 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's nam | CRITICAL | 9.1 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-89786 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_di | CRITICAL | 9.1 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-89555 | In the Linux kernel, the following vulnerability has been resolved: mpls: reload header after pskb_may_pull() mpls_sel | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-89662 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent lock owner use-after-free during clie | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-89669 | In the Linux kernel, the following vulnerability has been resolved: nfsd: initialize copy-notify stateid before publish | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-67399 | Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.8 and 8.0.0 before 8.13.7 allows remote attackers to execute | CRITICAL | 9.3 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-90823 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based b | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-17 |
| CVE-2026-54617 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-17 |
| CVE-2026-89847 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOC | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2025-59953 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior | CRITICAL | 9.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-89686 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on r | CRITICAL | 9.8 | 50% | EPSS 50%ile | NVD | 2026-09-11 |
| CVE-2026-91106 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | CRITICAL | 9.3 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-89649 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound xattr value length in __build_xattrs() | CRITICAL | 9.1 | 50% | EPSS 50%ile | NVD | 2026-09-11 |
| CVE-2026-89636 | In the Linux kernel, the following vulnerability has been resolved: smb: client: clear ce->tgthint in free_tgts() When | CRITICAL | 9.8 | 50% | EPSS 50%ile | NVD | 2026-09-11 |
| CVE-2026-61667 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1 | CRITICAL | 9.9 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-84561 | A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | CRITICAL | 9.8 | 50% | EPSS 50%ile | NVD | 2026-09-14 |
| CVE-2026-62379 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice P | CRITICAL | 9.8 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-73807 | The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthentica | CRITICAL | 9.3 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-19773 | libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerabili | CRITICAL | 9.8 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-86533 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a r | CRITICAL | 9.1 | 50% | EPSS 50%ile | NVD | 2026-09-17 |
| CVE-2026-57124 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-14 |
| CVE-2023-54398 | Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageS | CRITICAL | 9.3 | 49% | EPSS 49%ile | NVD | 2026-09-15 |
| CVE-2026-20242 | A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-91931 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated att | CRITICAL | 9.0 | 49% | EPSS 49%ile | NVD | 2026-09-15 |
| CVE-2026-89526 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Validate Read chunk positions before recon | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-89536 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: wait for in-flight client TLS handshake cal | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-89558 | In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix still_degraded being inverted in rai | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-89651 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound MDSCapAuth path and fs_name decode in h | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-90012 | In the Linux kernel, the following vulnerability has been resolved: spi: Fix DMA mapping ownership on partial map failu | CRITICAL | 9.8 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-69843 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a netwo | CRITICAL | 10.0 | 48% | EPSS 48%ile | NVD | 2026-09-18 |
| CVE-2026-89857 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-92955 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ g | CRITICAL | 10.0 | 48% | EPSS 48%ile | NVD | 2026-09-17 |
| CVE-2026-87719 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 | CRITICAL | 9.9 | 48% | EPSS 48%ile | NVD | 2026-09-12 |
| CVE-2026-16338 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to perform an arbi | CRITICAL | 9.9 | 48% | EPSS 48%ile | NVD | 2026-09-14 |
| CVE-2026-84609 | A permissions issue was addressed with improved path validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Gold | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-14 |
| CVE-2026-87796 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-17 |
| CVE-2026-89658 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during NFSv4.0 | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89688 | In the Linux kernel, the following vulnerability has been resolved: nfsd: drop the stateid, not the stateowner, on seqi | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89703 | In the Linux kernel, the following vulnerability has been resolved: nfsd: set SC_STATUS_FREED in nfsd4_drop_revoked_sti | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-82435 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline a | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-14 |
| CVE-2026-89990 | In the Linux kernel, the following vulnerability has been resolved: ceph: lock mutex in ceph_mds_check_access() MDS se | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-91995 | pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verif | CRITICAL | 9.3 | 48% | EPSS 48%ile | NVD | 2026-09-15 |
| CVE-2026-80980 | In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-80986 | In the Linux kernel, the following vulnerability has been resolved: net/smc: bound the peer rkey counts in SMC-Rv2 LLC | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89492 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate directory-index entry counts when r | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89689 | In the Linux kernel, the following vulnerability has been resolved: nfsd: don't free session slots that are still in us | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-82311 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-76187 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confiden | CRITICAL | 9.8 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-89713 | In the Linux kernel, the following vulnerability has been resolved: NFSD: check truncate permission under inode lock n | CRITICAL | 9.1 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-78330 | Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT auth | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-14 |
| CVE-2026-89972 | In the Linux kernel, the following vulnerability has been resolved: nvme: add missing SRCU grace period in error path | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-16 |
| CVE-2026-54460 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1 | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-17 |
| CVE-2026-91939 | Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing | CRITICAL | 9.3 | 47% | EPSS 47%ile | NVD | 2026-09-15 |
| CVE-2026-62104 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | CRITICAL | 10.0 | 47% | EPSS 47%ile | NVD | 2026-09-17 |
| CVE-2026-80981 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free of the LLC qentry in sm | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-11 |
| CVE-2026-89637 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF and buffer leak in cifs_check_ | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-11 |
| CVE-2026-89660 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during admin st | CRITICAL | 9.8 | 47% | EPSS 47%ile | NVD | 2026-09-11 |
| CVE-2026-92946 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit re | CRITICAL | 10.0 | 47% | EPSS 47%ile | NVD | 2026-09-17 |
| CVE-2026-70200 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize | CRITICAL | 10.0 | 47% | EPSS 47%ile | NVD | 2026-09-17 |
| CVE-2026-92944 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally( | CRITICAL | 9.3 | 46% | EPSS 46%ile | NVD | 2026-09-17 |
| CVE-2026-75030 | Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be abl | CRITICAL | 9.8 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-46619 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authen | CRITICAL | 9.3 | 46% | EPSS 46%ile | NVD | 2026-09-15 |
| CVE-2026-82232 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. | CRITICAL | 9.8 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-77051 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. | CRITICAL | 9.8 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-86460 | Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue | CRITICAL | 9.8 | 45% | EPSS 45%ile | NVD | 2026-09-14 |
| CVE-2026-54237 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal | CRITICAL | 9.3 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-20211 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlyi | CRITICAL | 9.1 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-89610 | In the Linux kernel, the following vulnerability has been resolved: ntfs: verify run length exceeding volume boundary | CRITICAL | 9.8 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-89612 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid MFT LCNs from boot sector The | CRITICAL | 9.8 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-89613 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject invalid empty mapping pairs Reject an | CRITICAL | 9.8 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-89635 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: only rebind the reopened file's own oplock o | CRITICAL | 9.8 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-54670 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont | CRITICAL | 9.1 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-85878 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a netwo | CRITICAL | 9.9 | 45% | EPSS 45%ile | NVD | 2026-09-18 |
| CVE-2026-62263 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize ap | CRITICAL | 9.2 | 45% | EPSS 45%ile | NVD | 2026-09-15 |
| CVE-2026-76423 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain a | CRITICAL | 10.0 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-85500 | Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to | CRITICAL | 9.1 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-55211 | Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fiel | CRITICAL | 9.8 | 44% | EPSS 44%ile | NVD | 2026-09-15 |
| CVE-2026-63695 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticate | CRITICAL | 9.8 | 44% | EPSS 44%ile | NVD | 2026-09-15 |
| CVE-2026-92939 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. | CRITICAL | 9.4 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-54626 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I | CRITICAL | 9.8 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-85885 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized | CRITICAL | 9.9 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-90945 | Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configura | CRITICAL | 9.3 | 44% | EPSS 44%ile | NVD | 2026-09-14 |
| CVE-2026-57141 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-m | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-89672 | In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs2 setacl by argp->mask The NFSACL v2 | CRITICAL | 9.1 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-81002 | In the Linux kernel, the following vulnerability has been resolved: xdp: fix zero-copy frame layout xdp_convert_zc_to_ | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89478 | In the Linux kernel, the following vulnerability has been resolved: sctp: drop a chunk if its transport was removed sc | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89541 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_unwrap_resp_priv length checks | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89542 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: harden gss_krb5_unwrap_v2 against short tok | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89551 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: xdr_buf_trim: clamp buf->len to avoid under | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89656 | In the Linux kernel, the following vulnerability has been resolved: libceph: reject buckets with mismatched CRUSH ids | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89674 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR length calculation in nfsd4_ff_encode | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89026 | The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS | CRITICAL | 9.3 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-92749 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, all | CRITICAL | 9.2 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-81642 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial | CRITICAL | 9.1 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-93467 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execu | CRITICAL | 9.3 | 43% | EPSS 43%ile | NVD | 2026-09-18 |
| CVE-2026-89546 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: close backchannel before destroying callbac | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-82439 | Description The DRPC server kept a map from function name to request queue and created an entry the first time a functi | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-14 |
| CVE-2026-89788 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_t | CRITICAL | 9.8 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-89537 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Reject short RFC 4121 MIC tokens in gss_krb | CRITICAL | 9.1 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-87785 | Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT | CRITICAL | 9.1 | 43% | EPSS 43%ile | NVD | 2026-09-14 |
| CVE-2026-90680 | A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of | CRITICAL | 9.4 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-89533 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix offset arithmetic in read_chunk_range | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-89653 | In the Linux kernel, the following vulnerability has been resolved: ceph: reject export_targets ranks >= CEPH_MAX_MDS i | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-90048 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-89532 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix pcl_for_each_segment for empty chunks | CRITICAL | 9.1 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-89650 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound num_export_targets array for mds info v | CRITICAL | 9.1 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-92913 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number genera | CRITICAL | 9.1 | 42% | EPSS 42%ile | NVD | 2026-09-17 |
| CVE-2026-90558 | sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header val | CRITICAL | 9.3 | 42% | EPSS 42%ile | NVD | 2026-09-12 |
| CVE-2026-45051 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serial | CRITICAL | 9.2 | 42% | EPSS 42%ile | NVD | 2026-09-15 |
| CVE-2026-76186 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Air | CRITICAL | 9.1 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-89479 | In the Linux kernel, the following vulnerability has been resolved: sctp: stop processing a packet once its association | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-13639 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2- | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-18 |
| CVE-2026-89082 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | CRITICAL | 9.3 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-89083 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | CRITICAL | 9.3 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-91843 | A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root | CRITICAL | 9.8 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-92935 | vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor compute | CRITICAL | 9.5 | 42% | EPSS 42%ile | NVD | 2026-09-17 |
| CVE-2026-69399 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-85889 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges o | CRITICAL | 10.0 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-76441 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-92957 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) | CRITICAL | 9.4 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-90042 | In the Linux kernel, the following vulnerability has been resolved: ceph: properly decrypt filenames in vmalloc() buffe | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-76949 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a re | CRITICAL | 9.1 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-89671 | In the Linux kernel, the following vulnerability has been resolved: nfsd: gate nfs3 setacl by argp->mask nfsd3_proc_se | CRITICAL | 9.1 | 41% | EPSS 41%ile | NVD | 2026-09-11 |
| CVE-2026-39919 | Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjp | CRITICAL | 9.3 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-85192 | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension fo | CRITICAL | 9.4 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-81855 | A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wär | CRITICAL | 9.3 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 10.0 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-73956 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-73961 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces). Supported versions t | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-82994 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-82995 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83000 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83035 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83036 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83037 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83042 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83060 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83061 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83062 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83066 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83094 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83095 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83100 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83327 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83339 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83452 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-83462 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-87184 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-89633 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOB read/write from unvalidated Da | CRITICAL | 9.8 | 41% | EPSS 41%ile | NVD | 2026-09-11 |
| CVE-2026-86462 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate t | CRITICAL | 9.1 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-82434 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payl | CRITICAL | 10.0 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-88795 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, | CRITICAL | 9.0 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-73470 | Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-73579 | Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elast | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-73668 | Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Rea | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-77181 | Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unab | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-73370 | Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconc | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-82431 | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-37152 | TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access. | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-57123 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_se | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-68536 | Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affect | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-90692 | A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the compon | CRITICAL | 9.4 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-90693 | A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. | CRITICAL | 9.4 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-80945 | In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on | CRITICAL | 9.1 | 40% | EPSS 40%ile | NVD | 2026-09-11 |
| CVE-2026-70009 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac | CRITICAL | 9.3 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-92720 | Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated a | CRITICAL | 9.3 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-52630 | SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEdito | CRITICAL | 9.8 | 40% | EPSS 40%ile | NVD | 2026-09-11 |
| CVE-2026-92860 | A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fm | CRITICAL | 9.4 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-89530 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject inline replies that overflow the pu | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-11 |
| CVE-2026-89702 | In the Linux kernel, the following vulnerability has been resolved: nfsd: size fh_verify server sockaddr slot by xpt_lo | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-11 |
| CVE-2026-89550 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: svcauth_gss: enforce krb5 token minimum len | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-11 |
| CVE-2026-89652 | In the Linux kernel, the following vulnerability has been resolved: ceph: bound copied dentry name length in NFS export | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-11 |
| CVE-2026-90036 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during blocked- | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-90961 | The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuth | CRITICAL | 9.3 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-79752 | CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::ca | CRITICAL | 9.2 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-83001 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83064 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | CRITICAL | 9.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83260 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX). The supported version | CRITICAL | 9.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-87189 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-77866 | Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reac | CRITICAL | 9.0 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-90037 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during close_lr | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-13684 | An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-6905 | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-18 |
| CVE-2026-76440 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-69865 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev | CRITICAL | 10.0 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-83944 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-76673 | Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unaut | CRITICAL | 9.8 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83020 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | CRITICAL | 10.0 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-83021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported v | CRITICAL | 10.0 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-70756 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-73940 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-73950 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-83108 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-83283 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-76669 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful expl | CRITICAL | 9.9 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-76670 | Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful expl | CRITICAL | 9.9 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-89675 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix UAF in async copy cancel and shutdown An | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-11 |
| CVE-2026-89676 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix stale s2s_cp_stateids IDR entry for async | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-11 |
| CVE-2026-81402 | The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type v | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-12 |
| CVE-2026-92948 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on N | CRITICAL | 9.4 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-89631 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject a tree connect response whose b | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-11 |
| CVE-2026-91949 | FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated at | CRITICAL | 9.2 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-47252 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access | CRITICAL | 9.0 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-20329 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | CRITICAL | 9.9 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-21391 | An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID | CRITICAL | 9.5 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-55158 | Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-20194 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-20341 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenti | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-54627 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I | CRITICAL | 9.8 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-20324 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Sof | CRITICAL | 9.9 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-57578 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, Author | CRITICAL | 9.2 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-83103 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-83107 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-45579 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1 | CRITICAL | 9.9 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-54337 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video up | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-87701 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB al | CRITICAL | 9.6 | 37% | EPSS 37%ile | NVD | 2026-09-17 |
| CVE-2026-80926 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notificat | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-89659 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during delegati | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-89708 | In the Linux kernel, the following vulnerability has been resolved: nfsd: RCU-protect cl_cb_session to fix use-after-fr | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-88952 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another us | CRITICAL | 9.1 | 37% | EPSS 37%ile | NVD | 2026-09-17 |
| CVE-2026-54333 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-54334 | UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Pri | CRITICAL | 9.8 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-92947 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer | CRITICAL | 10.0 | 37% | EPSS 37%ile | NVD | 2026-09-17 |
| CVE-2026-20192 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 10.0 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-83006 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | CRITICAL | 9.1 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-61594 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | CRITICAL | 9.1 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-92960 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandb | CRITICAL | 10.0 | 36% | EPSS 36%ile | NVD | 2026-09-17 |
| CVE-2026-14349 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-90562 | LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the | CRITICAL | 9.2 | 36% | EPSS 36%ile | NVD | 2026-09-13 |
| CVE-2026-54767 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php | CRITICAL | 9.1 | 36% | EPSS 36%ile | NVD | 2026-09-17 |
| CVE-2026-92938 | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin | CRITICAL | 9.4 | 36% | EPSS 36%ile | NVD | 2026-09-17 |
| CVE-2026-55209 | resdata is software for reading and writing result files from the Eclipse reservoir simulator. Prior to 6.2.9, resdata i | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-82441 | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, whi | CRITICAL | 9.1 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-88617 | SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-90038 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent client use-after-free during export s | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-53459 | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and p | CRITICAL | 9.3 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-82997 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-82998 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-82999 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83031 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83039 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83056 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83057 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-57139 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/serve | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-91998 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with | CRITICAL | 9.4 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-75800 | The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication resp | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-12 |
| CVE-2026-59178 | ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the d | CRITICAL | 9.8 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-53713 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | CRITICAL | 9.1 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-57125 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST | CRITICAL | 9.8 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-78225 | A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS | CRITICAL | 9.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-79395 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia I | CRITICAL | 9.8 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-77411 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil | CRITICAL | 9.5 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77408 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte le | CRITICAL | 9.1 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-63472 | Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUse | CRITICAL | 9.1 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-89614 | In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the free-cluster bitmap scan to the vol | CRITICAL | 9.8 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-89654 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix UAF in check_new_map() on session freed d | CRITICAL | 9.8 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-89677 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix possible fh_compose of wrong dentry in nf | CRITICAL | 9.8 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-91728 | Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code insid | CRITICAL | 9.6 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-83104 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83202 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87128 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87170 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87173 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87176 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-62101 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | CRITICAL | 9.8 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-62108 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | CRITICAL | 9.8 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-91039 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one i | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-92956 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on | CRITICAL | 10.0 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-92576 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the | CRITICAL | 9.2 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-54618 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza | CRITICAL | 9.4 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-12258 | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticate | CRITICAL | 9.2 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-82761 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker hol | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-87230 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 10.0 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-20353 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | CRITICAL | 9.8 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2025-56563 | A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts | CRITICAL | 9.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-89630 | In the Linux kernel, the following vulnerability has been resolved: smb: client: restore the data_offset bound in is_va | CRITICAL | 9.1 | 34% | EPSS 34%ile | NVD | 2026-09-11 |
| CVE-2026-20130 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 10.0 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-76672 | A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. | CRITICAL | 9.9 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-79396 | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores sta | CRITICAL | 9.8 | 34% | EPSS 34%ile | NVD | 2026-09-11 |
| CVE-2026-83040 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.6 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83043 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | CRITICAL | 9.6 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-57138 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mo | CRITICAL | 9.9 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-15639 | An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScrip | CRITICAL | 9.3 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-20284 | A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection | CRITICAL | 9.1 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-59971 | MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2 | CRITICAL | 10.0 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-73948 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | CRITICAL | 9.9 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-76443 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | CRITICAL | 9.8 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-12793 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versi | CRITICAL | 9.8 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-20326 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | CRITICAL | 9.8 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-73458 | On affected platforms running Arista EOS with authenticated Bidirectional Forwarding Detection (BFD) sessions configured | CRITICAL | 9.2 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2024-58385 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpo | CRITICAL | 9.3 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-77903 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne | CRITICAL | 9.0 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-89611 | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate non-resident attribute offsets ntfs | CRITICAL | 9.8 | 32% | EPSS 32%ile | NVD | 2026-09-11 |
| CVE-2026-89681 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix layout fence worker double-reference race | CRITICAL | 9.8 | 32% | EPSS 32%ile | NVD | 2026-09-11 |
| CVE-2026-87217 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-92787 | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypas | CRITICAL | 9.3 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-84171 | The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before | CRITICAL | 9.8 | 31% | EPSS 31%ile | NVD | 2026-09-12 |
| CVE-2026-83197 | Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts). Sup | CRITICAL | 9.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-20234 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 9.9 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-92951 | vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses no | CRITICAL | 9.4 | 31% | EPSS 31%ile | NVD | 2026-09-17 |
| CVE-2026-57140 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the | CRITICAL | 9.4 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-57148 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the p | CRITICAL | 9.8 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2023-54397 | Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers | CRITICAL | 9.0 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-76420 | A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Sof | CRITICAL | 9.0 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 10.0 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-54734 | Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl | CRITICAL | 10.0 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-92717 | Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated call | CRITICAL | 9.3 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-55366 | In IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead | CRITICAL | 9.8 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-57145 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-cont | CRITICAL | 9.1 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-86863 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse prox | CRITICAL | 9.3 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-92785 | Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist val | CRITICAL | 9.2 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-73953 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-73963 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83054 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83098 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83151 | Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83261 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core). The supporte | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83269 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83355 | Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Me | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-87188 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83105 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | CRITICAL | 9.0 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-82845 | The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deser | CRITICAL | 9.9 | 29% | EPSS 29%ile | NVD | 2026-09-12 |
| CVE-2026-67100 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. w | CRITICAL | 9.8 | 29% | EPSS 29%ile | NVD | 2026-09-18 |
| CVE-2026-75513 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marte | CRITICAL | 9.1 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-54752 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali | CRITICAL | 9.6 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-84625 | A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 27 and iPadOS 27, mac | CRITICAL | 9.1 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2024-14029 | Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body a | CRITICAL | 9.0 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83029 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). | CRITICAL | 9.6 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-78299 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extr | CRITICAL | 9.1 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-92805 | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Conf | CRITICAL | 9.3 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-90898 | Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that pro | CRITICAL | 9.8 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-92953 | vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. | CRITICAL | 9.3 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-92954 | vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises retu | CRITICAL | 9.2 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-20325 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineer | CRITICAL | 9.9 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-83196 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83229 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Support | CRITICAL | 9.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83268 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | CRITICAL | 9.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-65381 | A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the pro | CRITICAL | 10.0 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-91729 | Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social | CRITICAL | 9.6 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91738 | Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially exec | CRITICAL | 9.6 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-92940 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is e | CRITICAL | 10.0 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-86709 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication | CRITICAL | 9.8 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-20330 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | CRITICAL | 9.9 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-91749 | Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbit | CRITICAL | 9.6 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-45052 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receive | CRITICAL | 9.3 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-92578 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a | CRITICAL | 9.2 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-45143 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private | CRITICAL | 9.0 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-91718 | Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outsi | CRITICAL | 9.6 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-71133 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 10.0 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-70748 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-70757 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-70913 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-73947 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83232 | Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explore | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-69204 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages c | CRITICAL | 9.2 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-20237 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | CRITICAL | 9.1 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-68491 | An insufficient check allowed for the overwrite of arbitrary files via a symlink. | CRITICAL | 9.4 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-48717 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler req | CRITICAL | 9.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-53952 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic f | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-11 |
| CVE-2026-84520 | A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Golden Gate 27. A local atta | CRITICAL | 9.8 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-87223 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-63696 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerab | CRITICAL | 9.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-61568 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTT | CRITICAL | 9.6 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-59151 | Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover | CRITICAL | 9.6 | 26% | EPSS 26%ile | GitHub | 2026-09-11 |
| CVE-2026-92808 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An un | CRITICAL | 10.0 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-73946 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87214 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-77972 | Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS respo | CRITICAL | 9.0 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-62874 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges ov | CRITICAL | 10.0 | 25% | EPSS 25%ile | NVD | 2026-09-18 |
| CVE-2026-62103 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | CRITICAL | 9.8 | 24% | EPSS 24%ile | NVD | 2026-09-11 |
| CVE-2026-62105 | Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. | CRITICAL | 9.8 | 24% | EPSS 24%ile | NVD | 2026-09-11 |
| CVE-2026-91710 | Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary | CRITICAL | 9.6 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-91716 | Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outsi | CRITICAL | 9.6 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-86881 | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in iOS 26.7 and i | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-73944 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-73952 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83154 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83201 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87129 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87175 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83055 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.9 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83058 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | CRITICAL | 9.9 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87172 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.9 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-92395 | @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and i | CRITICAL | 9.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-20332 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | CRITICAL | 9.9 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-93372 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbi | CRITICAL | 9.6 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-56960 | In multiple locations, there is a possible use-after-free due to a logic error in the code. This could lead to remote es | CRITICAL | 9.8 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-73461 | On affected EOS platforms with AAA-based gRPC authorization enabled for OpenConfig, gRPC requests of an authenticated us | CRITICAL | 9.4 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-77005 | The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a | CRITICAL | 9.6 | 23% | EPSS 23%ile | NVD | 2026-09-12 |
| CVE-2026-11928 | IBM Verify Identity Access is vulnerable to a buffer overflow attack. | CRITICAL | 9.8 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-89022 | BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows | CRITICAL | 9.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-73945 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.9 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83038 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration). Suppo | CRITICAL | 9.9 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83282 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | CRITICAL | 9.9 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-93393 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf | CRITICAL | 9.2 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-15640 | Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user. | CRITICAL | 9.5 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-81648 | The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX | CRITICAL | 10.0 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-85681 | The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it ma | CRITICAL | 9.8 | 20% | EPSS 20%ile | NVD | 2026-09-12 |
| CVE-2026-86707 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is on | CRITICAL | 9.8 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-86710 | The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, m | CRITICAL | 9.8 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-73957 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | CRITICAL | 9.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-20322 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineer | CRITICAL | 9.9 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-92943 | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for | CRITICAL | 9.2 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-54072 | Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/autho | CRITICAL | 9.3 | 20% | EPSS 20%ile | NVD | 2026-09-11 |
| CVE-2026-61559 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1 | CRITICAL | 9.6 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-93374 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially ex | CRITICAL | 9.6 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-92941 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls | CRITICAL | 10.0 | 19% | EPSS 19%ile | NVD | 2026-09-17 |
| CVE-2026-67101 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functional | CRITICAL | 9.3 | 19% | EPSS 19%ile | NVD | 2026-09-18 |
| CVE-2026-46488 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w | CRITICAL | 9.1 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-73962 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.6 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-71163 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | CRITICAL | 9.9 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-90937 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cus | CRITICAL | 9.4 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-87802 | Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2. | CRITICAL | 9.1 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-83149 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita | CRITICAL | 9.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90456 | An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-know | CRITICAL | 9.2 | 17% | EPSS 17%ile | NVD | 2026-09-11 |
| CVE-2026-90413 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data tha | CRITICAL | 9.1 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-83027 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | CRITICAL | 9.3 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-91988 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowin | CRITICAL | 9.2 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-12944 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) | CRITICAL | 9.6 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-90561 | Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the cont | CRITICAL | 9.3 | 15% | EPSS 15%ile | NVD | 2026-09-13 |
| CVE-2026-90943 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering | CRITICAL | 9.3 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-93373 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code | CRITICAL | 9.6 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-11921 | IBM Verify Identity Access containers may not apply management password change operations correctly. | CRITICAL | 9.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-77405 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values wit | CRITICAL | 9.4 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-20331 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | CRITICAL | 9.6 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-11746 | Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover | CRITICAL | — | 14% | EPSS 14%ile | GitHub | 2026-09-11 |
| CVE-2026-84738 | The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import f | CRITICAL | 9.1 | 13% | EPSS 13%ile | NVD | 2026-09-18 |
| CVE-2026-90151 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocati | CRITICAL | 9.8 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-92950 | vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary cod | CRITICAL | 9.3 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-90999 | Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled tele | CRITICAL | 9.8 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-90110 | In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using S | CRITICAL | 9.4 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90942 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /a | CRITICAL | 9.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-15638 | An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using on | CRITICAL | 9.1 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90235 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks | CRITICAL | 9.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-66887 | The affected products are missing authorization on state-changing CGIs and session checks are not performed. | CRITICAL | 9.4 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-66890 | The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FT | CRITICAL | 9.4 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-87186 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | CRITICAL | 9.6 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-90104 | In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding | CRITICAL | 9.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90173 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free | CRITICAL | 9.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90711 | proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs E | CRITICAL | 9.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-77006 | The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capa | CRITICAL | 9.6 | 8% | EPSS 8%ile | NVD | 2026-09-12 |
| CVE-2026-89930 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nest | CRITICAL | 9.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-88592 | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFi | CRITICAL | 9.1 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89914 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI inv | CRITICAL | 9.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89915 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter Th | CRITICAL | 9.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89916 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in M | CRITICAL | 9.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89918 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI i | CRITICAL | 9.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90414 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was | CRITICAL | 9.1 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-89775 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR | CRITICAL | 9.3 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-90049 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in | CRITICAL | 9.3 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-92489 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output | CRITICAL | 9.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90230 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_ne | CRITICAL | 9.1 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-61549 | Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_op | CRITICAL | 9.0 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-77179 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file | CRITICAL | 9.4 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-89448 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Force requesting ACS when tboot is enab | CRITICAL | 9.3 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-90647 | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation | CRITICAL | 9.1 | 4% | EPSS 4%ile | NVD | 2026-09-12 |
| CVE-2026-15688 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control S | CRITICAL | 9.2 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-93603 | vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge | CRITICAL | 10.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-93605 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi | CRITICAL | 10.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-93606 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API | CRITICAL | 10.0 | — | — | NVD | 2026-09-18 |
| CVE-2025-15399 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | CRITICAL | 10.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-10747 | IBM MQ Appliance could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to | CRITICAL | 10.0 | — | — | NVD | 2026-09-18 |
| CVE-2025-53837 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int | CRITICAL | 9.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-10858 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote | CRITICAL | 9.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-61682 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t | CRITICAL | 9.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-77240 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security | CRITICAL | 9.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-75031 | In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick qu | CRITICAL | 9.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-84383 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item | CRITICAL | 9.8 | — | — | NVD | 2026-09-18 |
| CVE-2025-66455 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior | CRITICAL | 9.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-61550 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC mes | CRITICAL | 9.8 | — | — | NVD | 2026-09-18 |
| USN-8725-2 | USN-8725-2: Linux kernel (AWS) vulnerabilities | CRITICAL | 9.8 | — | — | Ubuntu | 2026-09-18 |
| USN-8714-3 | USN-8714-3: Linux kernel vulnerabilities | CRITICAL | 9.8 | — | — | Ubuntu | 2026-09-18 |
| CVE-2026-28197 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr | CRITICAL | 9.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-28198 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp | CRITICAL | 9.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-93659 | Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a | CRITICAL | 9.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-81321 | CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker w | CRITICAL | 9.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-85497 | CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insu | CRITICAL | 9.3 | — | — | NVD | 2026-09-18 |
| USN-8781-1 | USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities | CRITICAL | 9.3 | — | — | Ubuntu | 2026-09-18 |
| USN-8726-2 | USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities | CRITICAL | 9.3 | — | — | Ubuntu | 2026-09-18 |
| CVE-2023-5778 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Control | CRITICAL | 9.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-93762 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes | CRITICAL | 9.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-93019 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa | CRITICAL | 9.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-59163 | Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_ | CRITICAL | 9.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-92701 | trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX | CRITICAL | 9.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-92702 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions | CRITICAL | 9.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-63374 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing | CRITICAL | — | — | — | GitHub | 2026-09-18 |
| CVE-2026-90702 | A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. Thi | HIGH | 8.5 | 86% | EPSS 86%ile | NVD | 2026-09-14 |
| CVE-2026-90703 | A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafr | HIGH | 8.5 | 86% | EPSS 86%ile | NVD | 2026-09-14 |
| CVE-2026-92398 | A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality o | HIGH | 8.5 | 84% | EPSS 84%ile | NVD | 2026-09-16 |
| CVE-2026-92397 | A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc | HIGH | 8.5 | 82% | EPSS 82%ile | NVD | 2026-09-16 |
| CVE-2026-27560 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by send | HIGH | 7.2 | 82% | EPSS 82%ile | NVD | 2026-09-16 |
| CVE-2026-27561 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send | HIGH | 7.2 | 82% | EPSS 82%ile | NVD | 2026-09-16 |
| CVE-2026-27562 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by send | HIGH | 7.2 | 82% | EPSS 82%ile | NVD | 2026-09-16 |
| CVE-2026-90847 | A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_se | HIGH | 8.5 | 82% | EPSS 82%ile | NVD | 2026-09-15 |
| CVE-2026-27547 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27548 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27549 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27550 | A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27551 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage en | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27554 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_paramete | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27558 | A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/aj | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27559 | A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendi | HIGH | 8.8 | 81% | EPSS 81%ile | NVD | 2026-09-16 |
| CVE-2026-27563 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by | HIGH | 7.2 | 80% | EPSS 80%ile | NVD | 2026-09-16 |
| CVE-2026-27564 | A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by | HIGH | 7.2 | 80% | EPSS 80%ile | NVD | 2026-09-16 |
| CVE-2026-85200 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 v | HIGH | 7.5 | 79% | EPSS 79%ile | NVD | 2026-09-12 |
| CVE-2026-51134 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' paramete | HIGH | 7.5 | 79% | EPSS 79%ile | NVD | 2026-09-15 |
| CVE-2026-10144 | Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands b | HIGH | 7.1 | 75% | EPSS 75%ile | NVD | 2026-09-15 |
| CVE-2026-90699 | A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/ | HIGH | 8.6 | 75% | EPSS 75%ile | NVD | 2026-09-14 |
| CVE-2026-18912 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allo | HIGH | 7.7 | 73% | EPSS 73%ile | NVD | 2026-09-18 |
| CVE-2026-54646 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator | HIGH | 7.2 | 72% | EPSS 72%ile | NVD | 2026-09-17 |
| CVE-2026-54647 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t | HIGH | 7.2 | 72% | EPSS 72%ile | NVD | 2026-09-17 |
| CVE-2026-91989 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote | HIGH | 8.7 | 68% | EPSS 68%ile | NVD | 2026-09-15 |
| CVE-2026-81476 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Element | HIGH | 8.1 | 68% | EPSS 68%ile | NVD | 2026-09-17 |
| CVE-2026-82762 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 | HIGH | 8.7 | 66% | EPSS 66%ile | NVD | 2026-09-14 |
| CVE-2026-82766 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If t | HIGH | 8.7 | 66% | EPSS 66%ile | NVD | 2026-09-14 |
| CVE-2026-82774 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M | HIGH | 8.7 | 66% | EPSS 66%ile | NVD | 2026-09-14 |
| CVE-2026-82777 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC | HIGH | 8.7 | 66% | EPSS 66%ile | NVD | 2026-09-14 |
| CVE-2026-92580 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClie | HIGH | 8.7 | 64% | EPSS 64%ile | NVD | 2026-09-16 |
| CVE-2026-84408 | QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in | HIGH | 8.7 | 63% | EPSS 63%ile | NVD | 2026-09-16 |
| CVE-2026-18911 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolle | HIGH | 7.5 | 63% | EPSS 63%ile | NVD | 2026-09-18 |
| CVE-2026-77853 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 a | HIGH | 8.7 | 62% | EPSS 62%ile | NVD | 2026-09-15 |
| CVE-2026-82779 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM | HIGH | 8.7 | 62% | EPSS 62%ile | NVD | 2026-09-14 |
| CVE-2026-82791 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2. | HIGH | 8.7 | 62% | EPSS 62%ile | NVD | 2026-09-14 |
| CVE-2026-82794 | SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is explo | HIGH | 8.7 | 62% | EPSS 62%ile | NVD | 2026-09-14 |
| CVE-2026-76690 | A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary com | HIGH | 7.2 | 61% | EPSS 61%ile | NVD | 2026-09-15 |
| CVE-2026-54629 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtu | HIGH | 7.5 | 60% | EPSS 60%ile | NVD | 2026-09-14 |
| CVE-2026-73165 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60% | EPSS 60%ile | NVD | 2026-09-16 |
| CVE-2026-73167 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60% | EPSS 60%ile | NVD | 2026-09-16 |
| CVE-2026-73176 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 60% | EPSS 60%ile | NVD | 2026-09-16 |
| CVE-2026-19780 | Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi | HIGH | 8.8 | 60% | EPSS 60%ile | NVD | 2026-09-15 |
| CVE-2026-14323 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in | HIGH | 7.5 | 59% | EPSS 59%ile | NVD | 2026-09-18 |
| CVE-2026-73163 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 59% | EPSS 59%ile | NVD | 2026-09-16 |
| CVE-2026-73164 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command | HIGH | 8.6 | 59% | EPSS 59%ile | NVD | 2026-09-16 |
| CVE-2026-42018 | JFrog Artifactory Improper Authentication Vulnerability | HIGH | — | 59% | KEV EPSS 59%ile | CISA-KEV | 2026-09-11 |
| CVE-2026-16466 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 58% | EPSS 58%ile | NVD | 2026-09-14 |
| CVE-2026-74909 | Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security p | HIGH | 8.1 | 58% | EPSS 58%ile | NVD | 2026-09-16 |
| CVE-2026-17086 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I | HIGH | 8.8 | 58% | EPSS 58%ile | NVD | 2026-09-18 |
| CVE-2026-42016 | JFrog Artifactory Incorrect Authorization Vulnerability | HIGH | — | 58% | KEV EPSS 58%ile | CISA-KEV | 2026-09-11 |
| CVE-2026-15815 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug | HIGH | 8.8 | 57% | EPSS 57%ile | NVD | 2026-09-17 |
| CVE-2026-27556 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_param | HIGH | 8.8 | 57% | EPSS 57%ile | NVD | 2026-09-16 |
| CVE-2026-76689 | A vulnerability exists in the configuration processing logic of the affected component where malformed input is improper | HIGH | 7.2 | 57% | EPSS 57%ile | NVD | 2026-09-15 |
| CVE-2026-92466 | zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth. | HIGH | 8.7 | 56% | EPSS 56%ile | NVD | 2026-09-16 |
| CVE-2026-86108 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may al | HIGH | 7.5 | 56% | EPSS 56%ile | NVD | 2026-09-16 |
| CVE-2026-27555 | A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_i | HIGH | 8.8 | 56% | EPSS 56%ile | NVD | 2026-09-16 |
| CVE-2026-90608 | A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file | HIGH | 8.6 | 55% | EPSS 55%ile | NVD | 2026-09-14 |
| CVE-2026-89968 | In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: reject unsolicited H2CData PDUs nvmet_t | HIGH | 7.5 | 55% | EPSS 55%ile | NVD | 2026-09-16 |
| CVE-2026-92137 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framewor | HIGH | 8.8 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-76550 | The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expo | HIGH | 7.2 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-76551 | The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported | HIGH | 7.2 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-89696 | In the Linux kernel, the following vulnerability has been resolved: nfsd: block non-SAVEFH ops after FOREIGN PUTFH to p | HIGH | 7.5 | 54% | EPSS 54%ile | NVD | 2026-09-11 |
| CVE-2026-50276 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGG | HIGH | 7.5 | 54% | EPSS 54%ile | NVD | 2026-09-14 |
| CVE-2026-76691 | Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful expl | HIGH | 7.2 | 54% | EPSS 54%ile | NVD | 2026-09-15 |
| CVE-2026-86792 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connectio | HIGH | 8.8 | 54% | EPSS 54%ile | NVD | 2026-09-16 |
| CVE-2026-91771 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function | HIGH | 8.7 | 53% | EPSS 53%ile | NVD | 2026-09-15 |
| CVE-2026-90770 | Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supp | HIGH | 8.7 | 52% | EPSS 52%ile | NVD | 2026-09-13 |
| CVE-2026-88765 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 bef | HIGH | 8.5 | 52% | EPSS 52%ile | NVD | 2026-09-15 |
| CVE-2026-76678 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow a low-privilege authentica | HIGH | 8.8 | 52% | EPSS 52%ile | NVD | 2026-09-15 |
| CVE-2026-89511 | In the Linux kernel, the following vulnerability has been resolved: qede: Fix NULL pointer dereference in TPA fragment | HIGH | 7.5 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-89549 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: route to a populated pool in svc_pool_for_c | HIGH | 7.5 | 52% | EPSS 52%ile | NVD | 2026-09-11 |
| CVE-2026-90944 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenti | HIGH | 8.8 | 52% | EPSS 52%ile | NVD | 2026-09-14 |
| CVE-2026-81475 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio | HIGH | 8.1 | 52% | EPSS 52%ile | NVD | 2026-09-17 |
| CVE-2026-27557 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file | HIGH | 7.5 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-82310 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation | HIGH | 7.2 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-89036 | Appwrite before 2.0.0 contains an argument injection vulnerability that allows authenticated users with functions.write | HIGH | 8.7 | 52% | EPSS 52%ile | NVD | 2026-09-17 |
| CVE-2026-20340 | A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands | HIGH | 8.8 | 52% | EPSS 52%ile | NVD | 2026-09-16 |
| CVE-2026-82428 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from t | HIGH | 8.8 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-14917 | A SAML authentication bypass vulnerability affects the Kong SAML plugin when the validate_assertion_signature option is | HIGH | 7.7 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-84869 | ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability | HIGH | — | 51% | KEV EPSS 51%ile | CISA-KEV | 2026-09-11 |
| CVE-2026-91934 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite datab | HIGH | 8.7 | 51% | EPSS 51%ile | NVD | 2026-09-15 |
| CVE-2026-89476 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix stream->outcnt underflow on duplicate REC | HIGH | 7.5 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-89679 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix null dereference in nfsd4_setattr for del | HIGH | 7.5 | 51% | EPSS 51%ile | NVD | 2026-09-11 |
| CVE-2026-65364 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.5 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-84445 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() | HIGH | 8.7 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-92355 | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pat | HIGH | 8.7 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-63126 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire pro | HIGH | 7.5 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-85893 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | HIGH | 8.8 | 51% | EPSS 51%ile | NVD | 2026-09-15 |
| CVE-2026-76552 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it re | HIGH | 8.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-73173 | Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver m | HIGH | 8.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-84858 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Byp | HIGH | 8.8 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-73166 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the | HIGH | 8.6 | 51% | EPSS 51%ile | NVD | 2026-09-16 |
| CVE-2026-54504 | MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13 | HIGH | 8.8 | 50% | EPSS 50%ile | NVD | 2026-09-17 |
| CVE-2026-91098 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.6 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-91105 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.6 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-89863 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: edif: Fix NULL pointer deref in RX S | HIGH | 7.5 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-91097 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 7.0 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-85731 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked w | HIGH | 8.8 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-76685 | A vulnerability exists in the proxy packet processing logic of the affected component where it improperly processes malf | HIGH | 8.1 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-14916 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit | HIGH | 7.7 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-69486 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net | HIGH | 8.8 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-93450 | go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serializatio | HIGH | 8.7 | 50% | EPSS 50%ile | NVD | 2026-09-18 |
| CVE-2026-92748 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authent | HIGH | 8.7 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2023-45858 | A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files. | HIGH | 8.6 | 50% | EPSS 50%ile | NVD | 2026-09-14 |
| CVE-2026-15579 | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern | HIGH | 8.8 | 50% | EPSS 50%ile | NVD | 2026-09-18 |
| CVE-2026-91948 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handli | HIGH | 7.7 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-50285 | Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-17 |
| CVE-2026-89680 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd_file leak on inter-server COPY setup | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-92417 | A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the lib | HIGH | 7.1 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-91963 | FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirecti | HIGH | 7.1 | 49% | EPSS 49%ile | NVD | 2026-09-15 |
| CVE-2026-12728 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.8 | 49% | EPSS 49%ile | NVD | 2026-09-15 |
| CVE-2025-14871 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-1168 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-89493 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate rl_used against rl_count in refcoun | HIGH | 8.8 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-88064 | Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backst | HIGH | 8.8 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-90778 | SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers wi | HIGH | 8.7 | 49% | EPSS 49%ile | NVD | 2026-09-13 |
| CVE-2026-90780 | SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when proc | HIGH | 8.7 | 49% | EPSS 49%ile | NVD | 2026-09-13 |
| CVE-2026-89647 | In the Linux kernel, the following vulnerability has been resolved: ceph: do not repeat ceph_trim_dentries() if no prog | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-81875 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-81876 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-89528 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject Read lists that exceed the page bud | HIGH | 7.5 | 49% | EPSS 49%ile | NVD | 2026-09-11 |
| CVE-2026-88975 | Http4s is a Scala interface for HTTP services. Prior to 0.23.37 and 1.0.0-M48, Ember’s HTTP/2 read loop parses a frame’s | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-15 |
| CVE-2026-79651 | A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service respo | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-88616 | An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java compo | HIGH | 8.8 | 48% | EPSS 48%ile | NVD | 2026-09-15 |
| CVE-2026-89665 | In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range useconds in NFSv2 SETATTR | HIGH | 8.2 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-81477 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A | HIGH | 7.2 | 48% | EPSS 48%ile | NVD | 2026-09-17 |
| CVE-2026-81480 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. | HIGH | 7.2 | 48% | EPSS 48%ile | NVD | 2026-09-17 |
| CVE-2026-76424 | A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary f | HIGH | 7.2 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-92122 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy crea | HIGH | 8.8 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-91973 | Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiti | HIGH | 8.7 | 48% | EPSS 48%ile | NVD | 2026-09-15 |
| CVE-2026-89648 | In the Linux kernel, the following vulnerability has been resolved: ceph: cap delegated inode count in ceph_parse_deleg | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-82399 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-55416 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticat | HIGH | 8.8 | 48% | EPSS 48%ile | NVD | 2026-09-14 |
| CVE-2026-89554 | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_J | HIGH | 8.2 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89586 | In the Linux kernel, the following vulnerability has been resolved: ata: libata-scsi: fix DSM TRIM for sector sizes lar | HIGH | 8.2 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89973 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: check the data direction of a C2HData PDU | HIGH | 8.2 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-80997 | In the Linux kernel, the following vulnerability has been resolved: net: ipa: fix stalled modem TX queue after runtime | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89657 | In the Linux kernel, the following vulnerability has been resolved: libceph: validate OSD extent maps before cursor adv | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-89707 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release path refs on follow_down() error nfs | HIGH | 7.5 | 48% | EPSS 48%ile | NVD | 2026-09-11 |
| CVE-2026-8462 | SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allo | HIGH | 8.9 | 47% | EPSS 47%ile | NVD | 2026-09-16 |
| CVE-2026-90689 | A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuth | HIGH | 8.7 | 47% | EPSS 47%ile | NVD | 2026-09-14 |
| CVE-2026-78088 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unaut | HIGH | 8.8 | 47% | EPSS 47%ile | NVD | 2026-09-16 |
| CVE-2026-91080 | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticate | HIGH | 8.7 | 47% | EPSS 47%ile | NVD | 2026-09-14 |
| CVE-2026-76683 | Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways that could allow | HIGH | 8.1 | 47% | EPSS 47%ile | NVD | 2026-09-15 |
| CVE-2026-78175 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all v | HIGH | 8.8 | 47% | EPSS 47%ile | NVD | 2026-09-12 |
| CVE-2026-11728 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 47% | EPSS 47%ile | NVD | 2026-09-15 |
| CVE-2026-55864 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tool | HIGH | 7.8 | 47% | EPSS 47%ile | NVD | 2026-09-15 |
| CVE-2026-92123 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null recei | HIGH | 8.8 | 47% | EPSS 47%ile | NVD | 2026-09-16 |
| CVE-2026-92124 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elem | HIGH | 8.8 | 47% | EPSS 47%ile | NVD | 2026-09-16 |
| CVE-2026-54567 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask | HIGH | 7.5 | 47% | EPSS 47%ile | NVD | 2026-09-14 |
| CVE-2026-89971 | In the Linux kernel, the following vulnerability has been resolved: nvme: skip the zoned limits update if the zone info | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-89084 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | HIGH | 8.8 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-82410 | Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middlew | HIGH | 8.7 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-76686 | A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful expl | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-15 |
| CVE-2026-85756 | SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-76825 | RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted en | HIGH | 8.4 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-89861 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport reference in qla24xx_repo | HIGH | 8.1 | 46% | EPSS 46%ile | NVD | 2026-09-16 |
| CVE-2026-90946 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSo | HIGH | 8.7 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-89547 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Check svc pool percpu counter allocation _ | HIGH | 8.1 | 46% | EPSS 46%ile | NVD | 2026-09-11 |
| CVE-2026-89544 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-11 |
| CVE-2026-84549 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-91945 | FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to v | HIGH | 7.1 | 46% | EPSS 46%ile | NVD | 2026-09-15 |
| CVE-2026-13293 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.8 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-90779 | SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authenticati | HIGH | 8.7 | 46% | EPSS 46%ile | NVD | 2026-09-13 |
| CVE-2026-50270 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAG | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-14 |
| CVE-2026-50277 | dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggag | HIGH | 7.5 | 46% | EPSS 46%ile | NVD | 2026-09-17 |
| CVE-2026-88263 | XikeStor Layer3 switches miss authentication for downloading configuration data. Unauthenticated attacker may retrieve t | HIGH | 8.7 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-27552 | A low-privileged remote attacker can exploit improper authorization in the /index.php/attached_devices_tab/do_upload end | HIGH | 8.1 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-89028 | MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows re | HIGH | 8.2 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-89483 | In the Linux kernel, the following vulnerability has been resolved: nvme: zero the discard fallback page nvme_setup_di | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-89059 | A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-18 |
| CVE-2026-68791 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network | HIGH | 8.6 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-20342 | A vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attack | HIGH | 7.7 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-54135 | AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-11 |
| CVE-2026-85917 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-91964 | FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Ser | HIGH | 8.7 | 45% | EPSS 45%ile | NVD | 2026-09-15 |
| CVE-2026-20250 | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Softw | HIGH | 8.6 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-20295 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD So | HIGH | 8.6 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-54156 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNon | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-14 |
| CVE-2026-61554 | emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 4.2.5, the `http_poll` C2 transport acc | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-15 |
| CVE-2026-84997 | react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, Re | HIGH | 7.5 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-28326 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. | HIGH | 8.8 | 45% | EPSS 45%ile | NVD | 2026-09-17 |
| CVE-2026-16428 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 44% | EPSS 44%ile | NVD | 2026-09-14 |
| CVE-2026-34151 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinActio | HIGH | 8.2 | 44% | EPSS 44%ile | NVD | 2026-09-14 |
| CVE-2026-92729 | SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the H | HIGH | 8.8 | 44% | EPSS 44%ile | NVD | 2026-09-16 |
| CVE-2026-93436 | vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode di | HIGH | 8.7 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-54632 | SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the S | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-14 |
| CVE-2026-63128 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP s | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-16 |
| CVE-2026-79393 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon i | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-11 |
| CVE-2026-76687 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow a low-privilege authen | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-15 |
| CVE-2026-87935 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1 | HIGH | 8.1 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-92980 | HortusFox-Web prior to version 6.1 contains a remote code execution vulnerability that allows authenticated administrato | HIGH | 8.6 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-84553 | A resource exhaustion issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-14 |
| CVE-2026-75516 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. | HIGH | 8.7 | 44% | EPSS 44%ile | NVD | 2026-09-16 |
| CVE-2026-82760 | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to | HIGH | 8.2 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-81481 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res | HIGH | 7.5 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-92604 | Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows d | HIGH | 7.2 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-18212 | A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management | HIGH | 7.5 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-19407 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an att | HIGH | 7.7 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-61701 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until | HIGH | 8.8 | 43% | EPSS 43%ile | NVD | 2026-09-14 |
| CVE-2026-92970 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authentic | HIGH | 8.7 | 43% | EPSS 43%ile | NVD | 2026-09-17 |
| CVE-2026-90678 | An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 | HIGH | 7.5 | 43% | EPSS 43%ile | NVD | 2026-09-13 |
| CVE-2026-92625 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/r | HIGH | 7.5 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-92985 | SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock | HIGH | 8.6 | 43% | EPSS 43%ile | NVD | 2026-09-17 |
| CVE-2026-80985 | In the Linux kernel, the following vulnerability has been resolved: net/smc: carry oversized SMC-Rv2 LLC messages in th | HIGH | 8.2 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-76682 | A vulnerability in the network security monitoring component of intrusion detection systems could allow an unauthenticat | HIGH | 8.2 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-45794 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS c | HIGH | 7.7 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-54583 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-d | HIGH | 8.3 | 43% | EPSS 43%ile | NVD | 2026-09-17 |
| CVE-2026-43692 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 8.8 | 43% | EPSS 43%ile | NVD | 2026-09-14 |
| CVE-2026-73170 | Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the | HIGH | 8.6 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-92125 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annot | HIGH | 8.8 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-91003 | A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of th | HIGH | 8.5 | 43% | EPSS 43%ile | NVD | 2026-09-15 |
| CVE-2026-89535 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reorder rpcrdma_rn_unregister before rdma_ | HIGH | 8.1 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89667 | In the Linux kernel, the following vulnerability has been resolved: nfsd: close shrinker/GC/fsnotify vs per-net shutdow | HIGH | 8.1 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89704 | In the Linux kernel, the following vulnerability has been resolved: nfsd: sample writeback error cursor before async CO | HIGH | 7.5 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-89706 | In the Linux kernel, the following vulnerability has been resolved: nfsd: Reset write verifier when async COPY writebac | HIGH | 7.5 | 43% | EPSS 43%ile | NVD | 2026-09-11 |
| CVE-2026-76861 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an u | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-15 |
| CVE-2026-89848 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Quiesce response IRQ before freeing | HIGH | 8.1 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-90777 | ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitr | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-13 |
| CVE-2026-80987 | In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers nt | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-89477 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix NULL deref on untransmitted RECONF comple | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-89684 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix cpntf publish race in nfs4_init_cp_state | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-89699 | In the Linux kernel, the following vulnerability has been resolved: nfsd: validate symlink target length in NFSv4 CREAT | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-11 |
| CVE-2026-76646 | A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentia | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-92791 | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated att | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-92592 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun c | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-71179 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used | HIGH | 7.3 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-70658 | Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid | HIGH | 7.4 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-92469 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DE | HIGH | 7.2 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-91972 | Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, re | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-15 |
| CVE-2026-69217 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/1.1 parser accepts differing | HIGH | 8.7 | 42% | EPSS 42%ile | NVD | 2026-09-15 |
| CVE-2026-79993 | The `deleteContainer` opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authent | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-76409 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | HIGH | 8.8 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-73171 | Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore work | HIGH | 8.6 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-18442 | The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injecti | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-18 |
| CVE-2026-86043 | Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWi | HIGH | 7.5 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-12756 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta | HIGH | 7.1 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-12752 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta | HIGH | 7.1 | 42% | EPSS 42%ile | NVD | 2026-09-15 |
| CVE-2026-90606 | A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIp | HIGH | 8.6 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-65375 | The issue was addressed with improved authentication. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, m | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-93452 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that wr | HIGH | 8.7 | 41% | EPSS 41%ile | NVD | 2026-09-18 |
| CVE-2026-46623 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module upda | HIGH | 7.4 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-92971 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop tha | HIGH | 8.7 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-92566 | DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that a | HIGH | 8.8 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-63506 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized a | HIGH | 8.8 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-89664 | In the Linux kernel, the following vulnerability has been resolved: nfsd: release OPEN-decoded posix ACLs via op_releas | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-11 |
| CVE-2026-89695 | In the Linux kernel, the following vulnerability has been resolved: nfsd: cap decoded POSIX ACL count to bound sort cos | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-11 |
| CVE-2026-78501 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business | HIGH | 7.4 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-54612 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until | HIGH | 8.8 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-19667 | If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-81736 | If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-80274 | If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a val | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-18405 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul | HIGH | 7.2 | 41% | EPSS 41%ile | NVD | 2026-09-18 |
| CVE-2026-84860 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints b | HIGH | 8.8 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-91001 | A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of | HIGH | 8.6 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2025-43936 | Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthent | HIGH | 8.1 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-50275 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddt | HIGH | 7.5 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-73464 | On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requ | HIGH | 8.7 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-85469 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docke | HIGH | 8.0 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-54343 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version | HIGH | 8.7 | 41% | EPSS 41%ile | NVD | 2026-09-17 |
| CVE-2026-77692 | An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG( | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-81563 | A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fa | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-19666 | On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a speci | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-76163 | If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-90776 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser componen | HIGH | 8.7 | 40% | EPSS 40%ile | NVD | 2026-09-13 |
| CVE-2026-91925 | Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side | HIGH | 8.7 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-85887 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose informat | HIGH | 7.7 | 40% | EPSS 40%ile | NVD | 2026-09-18 |
| CVE-2026-59960 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-contro | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-73455 | On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafte | HIGH | 8.9 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-44236 | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders | HIGH | 7.1 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-82685 | Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated | HIGH | 7.6 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-87915 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress | HIGH | 7.2 | 40% | EPSS 40%ile | NVD | 2026-09-18 |
| CVE-2026-89266 | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation s | HIGH | 8.8 | 40% | EPSS 40%ile | NVD | 2026-09-12 |
| CVE-2026-56825 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/Collecti | HIGH | 8.1 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-56827 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/At | HIGH | 8.1 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-56829 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantSto | HIGH | 8.1 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-59974 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language | HIGH | 7.8 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-54446 | NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensi | HIGH | 8.1 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-90607 | A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file | HIGH | 8.6 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-92127 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item | HIGH | 8.0 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-80998 | In the Linux kernel, the following vulnerability has been resolved: net: bnxt: ring the doorbell when SW USO exits earl | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-11 |
| CVE-2026-89687 | In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure nfsd_file_do_acquire() does not use a | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-11 |
| CVE-2026-57579 | Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, an | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-90605 | A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter | HIGH | 8.6 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-44203 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect auth | HIGH | 8.3 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-69210 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, WebSocket FrameTranscoder.bodyLength reje | HIGH | 7.5 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-76821 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260706.0 | HIGH | 7.1 | 40% | EPSS 40%ile | NVD | 2026-09-15 |
| CVE-2026-46352 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-76854 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cg | HIGH | 7.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-84829 | The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an | HIGH | 8.8 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-76684 | Vulnerabilities have been identified in the API of HPE Networking EdgeConnect SD-WAN Orchestrator that could potentially | HIGH | 8.1 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-58483 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83082 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83112 | Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operati | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83188 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83195 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83298 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). The supported | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83344 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Applicat | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-81445 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-93468 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-18 |
| CVE-2026-86831 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-69203 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, An Ember server with HTTP/2 enabled throu | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-69218 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, When Ember receives an HTTP/2 HEADERS or | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83183 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83228 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83280 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2). Supported versio | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83281 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions tha | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83330 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are af | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83333 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83349 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-83350 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-87138 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-87277 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-87289 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Support | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-84512 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi | HIGH | 8.8 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-82770 | Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-82772 | Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-52484 | An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code | HIGH | 8.8 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-12954 | The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including | HIGH | 8.8 | 39% | EPSS 39%ile | NVD | 2026-09-18 |
| CVE-2026-20135 | A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unau | HIGH | 8.6 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-89663 | In the Linux kernel, the following vulnerability has been resolved: nfsd: revoke copy-notify stateids before dropping t | HIGH | 8.8 | 39% | EPSS 39%ile | NVD | 2026-09-11 |
| CVE-2026-90932 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. C | HIGH | 8.6 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-92792 | OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-92596 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows re | HIGH | 8.7 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-80218 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for o | HIGH | 7.6 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-91955 | FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, al | HIGH | 8.2 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-12354 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-17526 | Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the | HIGH | 7.2 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-20343 | A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downl | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-91950 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsig | HIGH | 7.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-89711 | In the Linux kernel, the following vulnerability has been resolved: NFSD: remove flawed WARN_ON_ONCE from nfsd_mode_che | HIGH | 8.2 | 38% | EPSS 38%ile | NVD | 2026-09-11 |
| CVE-2026-71198 | In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to | HIGH | 7.0 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-44793 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non | HIGH | 7.0 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-93435 | redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious | HIGH | 8.7 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-92129 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-90896 | Missing Authentication for Critical Function (CWE-306) in the checkout session lookup handler (src/app/api/stripe/checko | HIGH | 8.2 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-92761 | WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform pri | HIGH | 8.7 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-54182 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-57129 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts f | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-91731 | Type confusion in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary cod | HIGH | 8.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-91741 | Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary co | HIGH | 8.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-65831 | ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with lang | HIGH | 7.7 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-91960 | FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allow | HIGH | 7.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-90018 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read / stack overflow i | HIGH | 8.8 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-53659 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZ | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-53752 | docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-69202 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HTTP/2 flow-control window is rep | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-73960 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server). Supported | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-87222 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-43815 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma | HIGH | 8.8 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-85234 | A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a n | HIGH | 7.5 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-92784 | @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source co | HIGH | 7.7 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-57133 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/t | HIGH | 8.8 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-59739 | Information disclosure via SetWatches reconnect replay in Apache ZooKeeper due to missing ACL check. An attacker can dis | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-86003 | CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-83308 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.1 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83314 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). Supported versions t | HIGH | 8.1 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83457 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.1 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-76866 | Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNS | HIGH | 8.6 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-76869 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper ssc | HIGH | 8.6 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-89685 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix clock domain mismatch in clients_still_re | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-89692 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear CALLBACK_RUNNING on failed delegation r | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-89561 | In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix NULL dereference of idev in ipv6_rpl | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-84544 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-87743 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-18 |
| CVE-2026-83117 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83176 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Frame | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83273 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83322 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83325 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83328 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83440 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-83442 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-87207 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-87239 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-87244 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-87246 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-85569 | The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to it | HIGH | 7.2 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-57577 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a rout | HIGH | 8.2 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-52827 | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verif | HIGH | 7.1 | 37% | EPSS 37%ile | NVD | 2026-09-15 |
| CVE-2026-79394 | An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camer | HIGH | 7.5 | 37% | EPSS 37%ile | NVD | 2026-09-11 |
| CVE-2026-82028 | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API serv | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-78472 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it | HIGH | 8.6 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-83248 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.2 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-13260 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of | HIGH | 7.5 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-91946 | FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU | HIGH | 7.1 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-92467 | zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/pass | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-83266 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supp | HIGH | 8.2 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-85385 | Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output en | HIGH | 7.7 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-16673 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-68904 | node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using th | HIGH | 7.0 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-89025 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to mi | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-63443 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10 | HIGH | 8.3 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-91940 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-92719 | Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing at | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-91953 | FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fail | HIGH | 7.1 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76677 | A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could all | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-92952 | vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. | HIGH | 8.9 | 36% | EPSS 36%ile | NVD | 2026-09-17 |
| CVE-2026-91200 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attack | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-83285 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). | HIGH | 8.3 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83307 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.3 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-16335 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or | HIGH | 8.1 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-84516 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 8.1 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-73959 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versi | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83008 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83032 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83033 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83086 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83148 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83160 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3 | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83163 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83180 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83194 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83208 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83271 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21 | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83306 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services). Supp | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83315 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83348 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21 | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83454 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83456 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-87150 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supporte | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-87155 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-87163 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-87179 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-87180 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-91752 | GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function th | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76860 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokeniz | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76862 | Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launc | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirec | HIGH | 8.7 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-83270 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform | HIGH | 7.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83326 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi | HIGH | 7.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-83341 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClon | HIGH | 7.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-44300 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpo | HIGH | 8.8 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-54916 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The abse | HIGH | 8.8 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-90930 | File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reappl | HIGH | 7.6 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-89480 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: reject a read that transferred too few by | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-89616 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix info-leak on partial LZNT decompress | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-55451 | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2 | HIGH | 8.3 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-87779 | Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-73178 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequ | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-78336 | Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query f | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-54671 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra | HIGH | 8.8 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-91990 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart da | HIGH | 8.7 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-92986 | SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attack | HIGH | 8.6 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-56668 | ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange | HIGH | 8.1 | 35% | EPSS 35%ile | GitHub | 2026-09-14 |
| CVE-2026-89481 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix host memory disclosure on R2T for a r | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-11 |
| CVE-2026-77403 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-ad | HIGH | 8.9 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77410 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the messa | HIGH | 8.9 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77412 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-ar | HIGH | 8.9 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77406 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount | HIGH | 8.2 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77409 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in conf | HIGH | 8.2 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-75983 | The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privile | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-63460 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthentica | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-85715 | ExifReader is a JavaScript Exif information parser. Prior to 4.41.1, ExifReader parses attacker-controlled HEIC or AVIF | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-91965 | WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/cale | HIGH | 8.7 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-50125 | MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-61598 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.1 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-19248 | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input | HIGH | 7.1 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-59160 | Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts it | HIGH | 8.8 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-87178 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.7 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-52836 | OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior | HIGH | 8.7 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-54354 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran | HIGH | 8.2 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-54547 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, Au | HIGH | 7.4 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-86688 | Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier | HIGH | 7.4 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-91709 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary c | HIGH | 8.8 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-69208 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes | HIGH | 7.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-92815 | changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attac | HIGH | 8.7 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-54076 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check o | HIGH | 8.1 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-77614 | Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to vers | HIGH | 8.8 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-20154 | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security | HIGH | 8.6 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-20352 | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att | HIGH | 8.6 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-82717 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memor | HIGH | 8.4 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-87105 | Tanium addressed a SQL injection vulnerability in Threat Response. | HIGH | 8.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-54520 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior | HIGH | 8.1 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-87791 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Des | HIGH | 8.7 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-20249 | A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Se | HIGH | 8.6 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-55149 | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87193 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87205 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87211 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87221 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-90688 | A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBin | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-92760 | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restr | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-83302 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). The supported | HIGH | 8.5 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-89682 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix fcache_disposal UAF by inlining dispose s | HIGH | 8.1 | 34% | EPSS 34%ile | NVD | 2026-09-11 |
| CVE-2026-28960 | A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-90997 | A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b | HIGH | 7.4 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-83173 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83237 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83259 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83300 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions tha | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83345 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions tha | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83352 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions tha | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87126 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security). Supported | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-87191 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-69205 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s HeaderP.parse uses a case-sensiti | HIGH | 8.7 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-15955 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writ | HIGH | 7.5 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-62997 | Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.P | HIGH | 7.7 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-47426 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentica | HIGH | 7.6 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-65390 | An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and i | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-65391 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6 | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-83023 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | HIGH | 8.6 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83093 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | HIGH | 8.6 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83034 | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83051 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83075 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83110 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-77615 | Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Op | HIGH | 8.7 | 33% | EPSS 33%ile | NVD | 2026-09-17 |
| CVE-2026-76154 | A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role | HIGH | 7.3 | 33% | EPSS 33%ile | NVD | 2026-09-17 |
| CVE-2026-78252 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 8.2 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-83174 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framewor | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83177 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83297 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83412 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83432 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). S | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83439 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper). S | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83446 | Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83447 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83455 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87152 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Suppor | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87153 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87154 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87157 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87166 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-84629 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, visio | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-89063 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Obje | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-93014 | RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing | HIGH | 7.1 | 33% | EPSS 33%ile | NVD | 2026-09-17 |
| CVE-2026-65374 | A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-83946 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori | HIGH | 8.2 | 33% | EPSS 33%ile | NVD | 2026-09-18 |
| CVE-2026-16141 | OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force th | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-57136 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/s | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-71047 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-73942 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-73949 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83005 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83009 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83013 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83017 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution). S | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83090 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83119 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations). Suppor | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83120 | Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versio | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83121 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83122 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Support | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83124 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83168 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Inter | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83189 | Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supp | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83205 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83301 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Adm | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83329 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83331 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83335 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics S | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83338 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Inter | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83340 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versi | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87204 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87224 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-87227 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-83019 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported version | HIGH | 8.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-55253 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint- | HIGH | 7.7 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-92000 | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncom | HIGH | 8.7 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-65410 | The issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, mac | HIGH | 7.5 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-91721 | Use after free in Internals in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arb | HIGH | 8.8 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-12358 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of | HIGH | 7.5 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-87976 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using g | HIGH | 7.2 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-13285 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-13287 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-83143 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing). Supported versio | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-83422 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-63671 | MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nu | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-90774 | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowi | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-13 |
| CVE-2026-81478 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnera | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-54175 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 7.6 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-92919 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to | HIGH | 7.2 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-86106 | An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions with | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-86830 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution befor | HIGH | 8.6 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-91985 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allo | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-86864 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the p | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-83425 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte | HIGH | 8.5 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-12355 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-87225 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-87236 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-83357 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-92134 | Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confi | HIGH | 8.0 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-92135 | Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configurat | HIGH | 8.0 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-92136 | Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the | HIGH | 8.0 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-85386 | Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload quest | HIGH | 7.3 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-91941 | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that all | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-83305 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.6 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-57126 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_block | HIGH | 8.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-19290 | IBM Sterling File Gateway 6.2.0.0 through 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 could allow a remote attacker | HIGH | 7.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-28935 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoi | HIGH | 7.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-61599 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 8.8 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-81442 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerabilit | HIGH | 8.1 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-61595 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.7 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-83128 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supporte | HIGH | 7.5 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-92772 | Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks perm | HIGH | 7.1 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-69197 | Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Acce | HIGH | 8.7 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-59973 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 a | HIGH | 8.5 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-19499 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied ou | HIGH | 7.7 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-84598 | A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | HIGH | 7.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-92961 | vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allo | HIGH | 8.7 | 31% | EPSS 31%ile | NVD | 2026-09-17 |
| CVE-2026-47253 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functi | HIGH | 7.3 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-76855 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints hand | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-15275 | The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_searc | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-18 |
| CVE-2026-73494 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0. | HIGH | 7.4 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-68953 | The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclos | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-73951 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | HIGH | 8.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83169 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). | HIGH | 8.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83191 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83256 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-91930 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowi | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-54077 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/quer | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-20344 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote | HIGH | 8.8 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-93426 | SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, | HIGH | 8.4 | 31% | EPSS 31%ile | NVD | 2026-09-17 |
| CVE-2026-86040 | libp2p is a JavaScript implementation of the libp2p networking stack. Prior to 11.0.26, @libp2p/floodsub accepts unauthe | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-17 |
| CVE-2026-66269 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Selec | HIGH | 7.3 | 31% | EPSS 31%ile | NVD | 2026-09-17 |
| CVE-2026-55072 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec | HIGH | 8.5 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-83116 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83287 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentatio | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83313 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83319 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API). The supported versi | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83485 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83486 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83487 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported version | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-87124 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-87151 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supporte | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-91144 | ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoi | HIGH | 8.7 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-47094 | SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to | HIGH | 8.7 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2025-66974 | An issue in Prolink 13A Smart Plug Model Version: DS-3202M-UKv3 Wi-Fi and Application Version mEzee 2.6.7 allows attacke | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-88065 | `tts-be` is a backend for a timetable selector that aims to help students better choose their class schedules. Versions | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-92619 | The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11 | HIGH | 7.2 | 31% | EPSS 31%ile | NVD | 2026-09-18 |
| CVE-2026-43686 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, i | HIGH | 8.8 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-91987 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-92783 | Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with r | HIGH | 7.2 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-73247 | Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata | HIGH | 8.6 | 31% | EPSS 31%ile | GitHub | 2026-09-17 |
| CVE-2026-83088 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3 | HIGH | 7.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-55178 | GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1. | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-70469 | Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests th | HIGH | 7.5 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-91968 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deepl | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-91970 | Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce a | HIGH | 7.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-68489 | Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authentic | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-89418 | google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-92983 | InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions bec | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-81446 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab | HIGH | 7.4 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-92468 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-91996 | lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attacker | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83152 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83428 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83429 | Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations) | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83430 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-92626 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardint | HIGH | 7.5 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-92087 | @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-13107 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to X | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-41573 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-12667 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83044 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions tha | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83046 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83224 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83284 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.6 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-69213 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames t | HIGH | 7.5 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-57137 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop | HIGH | 8.8 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-82787 | Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-81236 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-81239 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-81240 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type v | HIGH | 8.6 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-87266 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported ve | HIGH | 8.2 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-89999 | In the Linux kernel, the following vulnerability has been resolved: HID: wacom: validate report length in wacom_intuos_ | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-57119 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing | HIGH | 7.5 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-92456 | yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerContr | HIGH | 7.1 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-87792 | The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_g | HIGH | 8.7 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83203 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | HIGH | 8.6 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-55692 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 7.5 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-53554 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat | HIGH | 7.3 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-54178 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-85530 | The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value | HIGH | 8.1 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-83450 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench). Supporte | HIGH | 8.0 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-83483 | Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis) | HIGH | 8.0 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-55091 | flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested. | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-81634 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap b | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-76693 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a | HIGH | 7.0 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-89678 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix partial-write detection in nfsd_direct_wr | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-11 |
| CVE-2026-47424 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an a | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-89849 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Reject non-SCSI SRB on status IOCB f | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-54519 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-92916 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.d | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-92918 | admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-83215 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.2 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83265 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent). S | HIGH | 8.2 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83343 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sys | HIGH | 8.2 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-13210 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1 | HIGH | 7.7 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83304 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W | HIGH | 8.9 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-72524 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-83144 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83145 | Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management). | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83310 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-92987 | roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-53534 | JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef' | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-90017 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_action_fram | HIGH | 7.1 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-83014 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supporte | HIGH | 8.1 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-82768 | Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be | HIGH | 8.6 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-82793 | Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Convert | HIGH | 8.6 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-86107 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betwee | HIGH | 8.2 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-76442 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-89729 | In the Linux kernel, the following vulnerability has been resolved: HID: sensor-hub: Fix out-of-bounds write in sensor_ | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-11 |
| CVE-2026-92006 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-90559 | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) | HIGH | 8.7 | 29% | EPSS 29%ile | NVD | 2026-09-12 |
| CVE-2026-83030 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). | HIGH | 8.3 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-69209 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbo | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-85721 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | HIGH | 7.5 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-92779 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set hel | HIGH | 7.2 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-89626 | In the Linux kernel, the following vulnerability has been resolved: HID: sensor: custom: Fix field sysfs group cleanup | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-11 |
| CVE-2026-90000 | In the Linux kernel, the following vulnerability has been resolved: HID: rmi: fix OOB access with undersized RMI report | HIGH | 8.8 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-83072 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl. Ad | HIGH | 8.1 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83089 | Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations). Supported versio | HIGH | 8.1 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83132 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th | HIGH | 8.1 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-89601 | In the Linux kernel, the following vulnerability has been resolved: ext2: Fix lost inode updates for IS_SYNC inodes ex | HIGH | 8.8 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-91936 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_di | HIGH | 8.3 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91938 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer | HIGH | 7.6 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-78425 | Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticke | HIGH | 7.6 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-83123 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Support | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83011 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83286 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83299 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-87231 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-40530 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manage | HIGH | 8.0 | 28% | EPSS 28%ile | NVD | 2026-09-18 |
| CVE-2026-90445 | An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without valid | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-57130 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/ema | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-92299 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMe | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-90938 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/p | HIGH | 8.8 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-91751 | Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91951 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91952 | FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91954 | FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91956 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91959 | FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91961 | FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-89951 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix stale receive device on merged frag | HIGH | 8.8 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-79410 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated atta | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-90775 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befo | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-13 |
| CVE-2026-93453 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u | HIGH | 8.7 | 28% | EPSS 28%ile | NVD | 2026-09-18 |
| CVE-2026-82432 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalanc | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-76857 | Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_li | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-76859 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi c | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-92463 | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @Pre | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-92942 | vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the | HIGH | 8.7 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-54628 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtu | HIGH | 8.6 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-16432 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacke | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-71646 | An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacke | HIGH | 7.5 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-16482 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection v | HIGH | 7.5 | 28% | EPSS 28%ile | NVD | 2026-09-12 |
| CVE-2026-49846 | libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP re | HIGH | 7.5 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-92603 | ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-87171 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-87143 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.4 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-92570 | reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any | HIGH | 7.1 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-79708 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 | HIGH | 8.5 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-83041 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Support | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83048 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83084 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83134 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83166 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-87257 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: SDK). The supported version that is a | HIGH | 7.7 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-89569 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: serialize security confirmation | HIGH | 8.8 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-54596 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi | HIGH | 8.1 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-73966 | Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions th | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83063 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Suppor | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83453 | Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Interna | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83481 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83482 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 7.2 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-91736 | Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91737 | Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91745 | Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-89180 | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote atta | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression de | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-76679 | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduc | HIGH | 8.6 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-87196 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-87197 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-88619 | 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The A | HIGH | 8.1 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-87133 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.6 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-83222 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-83225 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-83276 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2). Supported versio | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-87148 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-81515 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-81516 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-68523 | `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-68537 | `fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In ve | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-83186 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Cal | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-80989 | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bri | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-11 |
| CVE-2026-89844 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold vport_slock for host map update | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-89860 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Initialize NVMe abort_work once at s | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-83461 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 8.2 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91969 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endp | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91971 | Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing auth | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-91979 | Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial o | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-92759 | SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-90460 | An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 c | HIGH | 7.6 | 27% | EPSS 27%ile | NVD | 2026-09-11 |
| CVE-2026-85705 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-90560 | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress construct | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-12 |
| CVE-2026-82780 | Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uplo | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-92794 | OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verif | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-91724 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the render | HIGH | 8.3 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-73195 | Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet | HIGH | 7.3 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-92460 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-92567 | TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-86801 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress an | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-92762 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-83047 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 8.2 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-83078 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.2 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-54339 | Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe | HIGH | 7.7 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-15891 | The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2026-73236 | Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-92925 | A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packet | HIGH | 7.1 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-92917 | Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-83178 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported | HIGH | 8.0 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-84543 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-84563 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-53660 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes | HIGH | 7.4 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-92972 | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefi | HIGH | 8.8 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-90668 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which al | HIGH | 8.7 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2026-73439 | On affected platforms running Arista EOS, if OpenConfig is configured and running a gNMI server on the system, and if gN | HIGH | 7.7 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-87742 | A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (D | HIGH | 7.5 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-61590 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.4 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-89058 | A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Ori | HIGH | 7.4 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-81568 | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0- | HIGH | 8.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-92770 | Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credenti | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-52727 | lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publica | HIGH | 7.2 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-92765 | ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticate | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-88262 | Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick | HIGH | 8.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-89709 | In the Linux kernel, the following vulnerability has been resolved: lockd, nfsd: RCU-protect nlmsvc_ops dispatch nlmsv | HIGH | 8.1 | 26% | EPSS 26%ile | NVD | 2026-09-11 |
| CVE-2026-54180 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 7.6 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-53966 | XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Da | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-92914 | AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares | HIGH | 8.6 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-90451 | An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication co | HIGH | 8.2 | 26% | EPSS 26%ile | NVD | 2026-09-11 |
| CVE-2026-91929 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resour | HIGH | 7.6 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-91933 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authen | HIGH | 7.6 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-81901 | In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce pa | HIGH | 7.2 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-19774 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent a | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-54155 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentic | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-73496 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-87147 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-79425 | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows | HIGH | 8.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83012 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83068 | Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83070 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Port | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83129 | Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations). Supported versio | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83141 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supporte | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83142 | Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-87256 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported ve | HIGH | 7.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2023-50461 | An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backen | HIGH | 8.8 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-91715 | Type confusion in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary c | HIGH | 8.8 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-80491 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL qu | HIGH | 8.6 | 26% | EPSS 26%ile | NVD | 2026-09-12 |
| CVE-2026-87963 | The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before u | HIGH | 8.6 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-87199 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-87215 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-54716 | Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earli | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-21586 | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9 | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-21587 | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data | HIGH | 7.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83025 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | HIGH | 8.7 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-92616 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege att | HIGH | 7.6 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-83102 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | HIGH | 7.4 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83184 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported | HIGH | 7.4 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2025-39964 | Linux Kernel Race Condition Vulnerability | HIGH | — | 26% | KEV EPSS 26%ile | CISA-KEV | 2026-09-18 |
| CVE-2026-79954 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv | HIGH | 8.7 | 26% | EPSS 26%ile | NVD | 2026-09-18 |
| CVE-2026-83002 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | HIGH | 8.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83272 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19. | HIGH | 8.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83182 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools). Supported ve | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83204 | Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Internal Operations). Supported ver | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83262 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83289 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics W | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83295 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentatio | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83318 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions th | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-83489 | Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-87140 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-87190 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-20247 | A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affe | HIGH | 7.5 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-89898 | In the Linux kernel, the following vulnerability has been resolved: media: cec: extron-da-hd-4k-plus: add sanity check | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-89995 | In the Linux kernel, the following vulnerability has been resolved: dma-direct: return struct page from dma_direct_allo | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-76412 | A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote att | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-76413 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Softw | HIGH | 8.2 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-92601 | Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission def | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-54507 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | HIGH | 8.4 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-83181 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces). Supported versions th | HIGH | 8.2 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-54544 | Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.16, two API endpoints that trigger outbou | HIGH | 7.2 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-77884 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-83010 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-40856 | WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cg | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-92771 | Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-87125 | Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operatio | HIGH | 8.3 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-89632 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix use-before-check of ReparseDataLen | HIGH | 8.2 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-83408 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo | HIGH | 8.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87195 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87206 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87235 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-80937 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: bound the device EEPROM address | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-89774 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: SCO: hold sk properly in sco_conn_ready | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-83303 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87265 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue). Supported versions | HIGH | 8.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-6205 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1- | HIGH | 8.1 | 25% | EPSS 25%ile | NVD | 2026-09-18 |
| CVE-2026-64761 | A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 27 and iPadOS 27. A | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-83484 | Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operation | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-46498 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied | HIGH | 7.6 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-77705 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a | HIGH | 7.2 | 25% | EPSS 25%ile | NVD | 2026-09-12 |
| CVE-2026-77752 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary | HIGH | 7.2 | 25% | EPSS 25%ile | NVD | 2026-09-12 |
| CVE-2026-11934 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i | HIGH | 7.2 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-92600 | Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysU | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-62102 | Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-62106 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-87238 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-80494 | The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file | HIGH | 8.6 | 25% | EPSS 25%ile | NVD | 2026-09-12 |
| CVE-2026-82765 | Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is | HIGH | 8.6 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-83172 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other). Supported versions | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83267 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security). Supported vers | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83309 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83311 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83321 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics A | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83490 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87177 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83115 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClon | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83167 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83213 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports). Supported versions that are | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83235 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-83424 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper). Supported ve | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87136 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-82035 | PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_o | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-83332 | Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Sup | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87135 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87156 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-87158 | Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center). | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-74926 | The MultiVendorX WordPress plugin before 5.0.16 does not verify that a user owns the store they are acting on in one of | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-20333 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-20360 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | HIGH | 8.8 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-83135 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th | HIGH | 8.7 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-91733 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised | HIGH | 8.3 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-92457 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-92459 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoin | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-92462 | yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing | HIGH | 7.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-54597 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi | HIGH | 8.3 | 24% | EPSS 24%ile | NVD | 2026-09-17 |
| CVE-2026-81003 | In the Linux kernel, the following vulnerability has been resolved: net/iucv: filter frames in afiucv_hs_rcv() by ingre | HIGH | 8.1 | 24% | EPSS 24%ile | NVD | 2026-09-11 |
| CVE-2026-86865 | Tanium addressed a SQL injection vulnerability in Asset. | HIGH | 7.2 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-76870 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation ro | HIGH | 7.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83418 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communicat | HIGH | 8.2 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-85410 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template | HIGH | 8.1 | 24% | EPSS 24%ile | NVD | 2026-09-18 |
| CVE-2026-11926 | IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of | HIGH | 7.5 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83241 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.5 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-81564 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP P | HIGH | 7.0 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2023-46273 | Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer ove | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-91943 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_ | HIGH | 8.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-79411 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated ba | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-92716 | Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint tha | HIGH | 8.6 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-92605 | IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, a | HIGH | 7.1 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-91711 | Out of bounds write in ServiceWorker in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitr | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-91722 | Use after free in Input in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitra | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-91735 | Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t | HIGH | 8.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-81440 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability | HIGH | 7.3 | 24% | EPSS 24%ile | NVD | 2026-09-17 |
| CVE-2026-14805 | The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87233 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.6 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-12384 | Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-18 |
| CVE-2026-92773 | Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it | HIGH | 7.1 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-18119 | Concrete CMS below 9.5.3 did not sanitize custom style values in the Block Design dialog before writing them into page C | HIGH | 7.0 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-43789 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS S | HIGH | 7.5 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-65342 | A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | HIGH | 7.5 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-65378 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS | HIGH | 7.5 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-57135 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai- | HIGH | 7.6 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87024 | Tanium addressed a SQL injection vulnerability in Asset. | HIGH | 7.2 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-83053 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83069 | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Suppo | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83153 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83164 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83199 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83209 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow). Supported versions that | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83210 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83212 | Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training). Supported | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83410 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83444 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83445 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Inte | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83479 | Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported ve | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87162 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87165 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87181 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-87185 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83334 | Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). | HIGH | 7.4 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-83171 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported | HIGH | 7.1 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-13673 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) | HIGH | 8.8 | 24% | EPSS 24%ile | NVD | 2026-09-18 |
| CVE-2026-57134 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mc | HIGH | 8.2 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-43697 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-82789 | An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI | HIGH | 8.7 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-93292 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints tha | HIGH | 8.4 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-56839 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass | HIGH | 7.3 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-18111 | Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image | HIGH | 8.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-76820 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260701.0 | HIGH | 7.7 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-92465 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Me | HIGH | 7.6 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-91994 | Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddlewa | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-90016 | In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in rtw_restruct_wm | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-92775 | Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-92789 | Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-84606 | A privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-87194 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83113 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83449 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-76688 | Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83238 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83436 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported v | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87192 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-54571 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3 | HIGH | 8.7 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-54451 | Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attack | HIGH | 8.2 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-83106 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83114 | Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported vers | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83292 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83296 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83415 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87203 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87237 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87254 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The su | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-90928 | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads e | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-92602 | TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigContro | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-91947 | FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a c | HIGH | 7.7 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-90474 | MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server wher | HIGH | 7.6 | 23% | EPSS 23%ile | NVD | 2026-09-12 |
| CVE-2026-90929 | File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (res | HIGH | 7.2 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-73941 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | HIGH | 8.6 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83074 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.6 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-83133 | Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-25275 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-83448 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87159 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87167 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions | HIGH | 8.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-87168 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions | HIGH | 8.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-89897 | In the Linux kernel, the following vulnerability has been resolved: media: cec: Serialize exclusive follower delivery | HIGH | 7.5 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-40854 | WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session | HIGH | 8.7 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-92801 | cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactiv | HIGH | 8.7 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-54087 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie | HIGH | 7.6 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-58502 | githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow r | HIGH | 7.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-90041 | In the Linux kernel, the following vulnerability has been resolved: HID: sony: clean up device list on probe failure s | HIGH | 8.8 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-14850 | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the use | HIGH | 8.8 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-93377 | Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to | HIGH | 8.8 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-49250 | Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From | HIGH | 8.7 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-73454 | On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially | HIGH | 8.6 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-87234 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-48977 | OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() pro | HIGH | 7.7 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-76425 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks | HIGH | 7.6 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-55690 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 7.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-55691 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em | HIGH | 8.6 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-90555 | vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authentic | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-12 |
| CVE-2026-76681 | A vulnerability in the API of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker with low priv | HIGH | 8.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-87200 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83561 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm | HIGH | 7.2 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2026-83252 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.0 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-54251 | netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0 | HIGH | 8.7 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-63459 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/ | HIGH | 8.7 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-83435 | Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.2 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83438 | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.2 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-73958 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83101 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83192 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83245 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83246 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83254 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83255 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83258 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83351 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3 | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83464 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.4 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-20300 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affect | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-89413 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1. | HIGH | 8.1 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2026-83207 | Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting). Supporte | HIGH | 7.6 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-89974 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: fix double free of fabrics options when nv | HIGH | 7.5 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-83003 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83049 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Suppo | HIGH | 8.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83083 | Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that | HIGH | 8.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-59965 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plu | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-57132 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token acc | HIGH | 8.2 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-92812 | decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix | HIGH | 7.6 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-87842 | The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the s | HIGH | 7.5 | 22% | EPSS 22%ile | NVD | 2026-09-12 |
| CVE-2026-21588 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9 | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83092 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supporte | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-83179 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Cal | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-87209 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-87249 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-62107 | Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. | HIGH | 8.8 | 22% | EPSS 22%ile | NVD | 2026-09-11 |
| CVE-2026-11729 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-89034 | TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low En | HIGH | 7.1 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-70915 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83125 | Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations). Support | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83136 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83137 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83165 | Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface). | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83411 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83423 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported v | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87201 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87202 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87226 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-76680 | Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privi | HIGH | 8.5 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-28938 | A privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be a | HIGH | 7.5 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-0171 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remo | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-56882 | In Cellular Modem, there is a possible information disclosure due to a logic error in the code. This could lead to remot | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-56920 | In s_decode_vui_param of fw_hevc_dec_header.c, there is a possible out-of-bounds write due to a logic error in the code. | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-80217 | Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and acce | HIGH | 8.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-92763 | Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project arch | HIGH | 8.6 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-83126 | Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83320 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions th | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87131 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87132 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87137 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87144 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-92780 | KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated | HIGH | 8.7 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-92788 | Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's | HIGH | 8.7 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-92796 | Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL re | HIGH | 8.7 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-53714 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | HIGH | 7.4 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-20361 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-83146 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83243 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83312 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: E-Business Suite - XDO). Supported ver | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83356 | Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security). The | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-83437 | Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management). Supported ve | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87127 | Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing). Supported versions | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87134 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87141 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-20335 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | HIGH | 8.1 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-83477 | Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported vers | HIGH | 8.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-87886 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin | HIGH | 7.8 | 21% | KEV EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-83087 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.2 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-47701 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocato | HIGH | 7.7 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-86895 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 2 | HIGH | 7.5 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-0200 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote esca | HIGH | 8.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-62109 | Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-11 |
| CVE-2026-62112 | Editor SQL Injection in Amelia <= 2.4.9 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-11 |
| CVE-2026-66618 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66619 | Administrator SQL Injection in Newsletters <= 4.18 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66624 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66625 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66626 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66628 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66630 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-66631 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | HIGH | 7.6 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-76871 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json | HIGH | 7.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-92256 | NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_s | HIGH | 7.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-82993 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Su | HIGH | 8.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83007 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 8.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92958 | vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard toge | HIGH | 8.4 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-17467 | IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due t | HIGH | 8.2 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-83067 | Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components). Supporte | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83434 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83161 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). S | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83187 | Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Cal | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-54524 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-92015 | Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Fi | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-91937 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-89524 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: clamp assoc request/response lengths | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-11 |
| CVE-2026-92804 | Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-52851 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an ob | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-81742 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-12 |
| CVE-2026-88793 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-85130 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for t | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-87786 | The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputt | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-88792 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding o | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-58201 | Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2 | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92007 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92008 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92009 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92010 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92011 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92012 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92013 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-92020 | Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was f | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-91935 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83218 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.4 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-87130 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.4 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-73926 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-74933 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJA | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-81899 | Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > G | HIGH | 7.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-88817 | An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exi | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-67102 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a lo | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-18 |
| CVE-2026-50013 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `Add | HIGH | 7.5 | 20% | EPSS 20%ile | NVD | 2026-09-11 |
| CVE-2026-16140 | OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an e | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-68070 | The affected products are missing authentication for a critical function, which could allow an attacker to run as root a | HIGH | 8.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-85077 | Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 respo | HIGH | 8.2 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-73954 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Su | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-65388 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the atta | HIGH | 7.5 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-0159 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-0170 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This c | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-55331 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-56942 | In ReadTileInfo of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-56974 | In Start of AudioRtpPayloadEncoderNode.cpp, there is a possible out-of-bounds write due to improper input validation. Th | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-56997 | In Av1DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This c | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-58683 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to improper input validation. This could lead to | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-58710 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. Th | HIGH | 8.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-89583 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix OOB read in eir_get_service_dat | HIGH | 8.1 | 20% | EPSS 20%ile | NVD | 2026-09-11 |
| CVE-2026-83080 | Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supp | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83206 | Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applicatio | HIGH | 7.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-83234 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.2 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-87174 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-18117 | Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because th | HIGH | 7.3 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-81090 | The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the | HIGH | 7.2 | 19% | EPSS 19%ile | NVD | 2026-09-12 |
| CVE-2026-92753 | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that | HIGH | 7.1 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-91923 | KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoin | HIGH | 8.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-90447 | A routing rule selects between two different authentication mechanisms for the same downstream service based on the valu | HIGH | 7.1 | 19% | EPSS 19%ile | NVD | 2026-09-11 |
| CVE-2026-91712 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had comprom | HIGH | 8.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-84099 | The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that | HIGH | 8.1 | 19% | EPSS 19%ile | NVD | 2026-09-12 |
| CVE-2026-55306 | In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote den | HIGH | 7.5 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-93381 | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging soc | HIGH | 8.8 | 19% | EPSS 19%ile | NVD | 2026-09-17 |
| CVE-2026-65838 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody f | HIGH | 8.2 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-91197 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFa | HIGH | 7.1 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-89725 | In the Linux kernel, the following vulnerability has been resolved: media: cec: stm32: prevent out-of-bounds write on R | HIGH | 8.8 | 19% | EPSS 19%ile | NVD | 2026-09-11 |
| CVE-2026-53557 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use | HIGH | 7.7 | 19% | EPSS 19%ile | NVD | 2026-09-17 |
| CVE-2026-86444 | The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute | HIGH | 7.1 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-91750 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url en | HIGH | 7.1 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-20334 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | HIGH | 8.4 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain | HIGH | 8.3 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-12666 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 8.1 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-85129 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featu | HIGH | 8.8 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-59148 | @Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft | HIGH | 8.8 | 18% | EPSS 18%ile | GitHub | 2026-09-11 |
| CVE-2026-84047 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it | HIGH | 8.6 | 18% | EPSS 18%ile | NVD | 2026-09-12 |
| CVE-2026-7848 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProdu | HIGH | 8.6 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-92053 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 15 | HIGH | 8.8 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-85921 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | HIGH | 8.2 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-90939 | novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks prop | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-87258 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The su | HIGH | 7.6 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83162 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported | HIGH | 7.4 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-92054 | Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbir | HIGH | 8.8 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-92594 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fi | HIGH | 8.7 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-66580 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | HIGH | 8.5 | 18% | EPSS 18%ile | NVD | 2026-09-17 |
| CVE-2026-83138 | Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.0 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83157 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClon | HIGH | 8.0 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-92811 | browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-83324 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83131 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File down | HIGH | 7.7 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83233 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.7 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83130 | Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations). Supported ver | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90769 | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated us | HIGH | 8.3 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-87228 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-57008 | In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa | HIGH | 7.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-91770 | IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated e | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-93455 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff acc | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-18 |
| CVE-2026-83170 | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported | HIGH | 8.0 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-87198 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-87212 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-87242 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-80071 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership | HIGH | 7.2 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-91778 | In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a w | HIGH | 7.2 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-92577 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title | HIGH | 8.7 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-92959 | vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.the | HIGH | 7.1 | 18% | EPSS 18%ile | NVD | 2026-09-17 |
| CVE-2026-92752 | metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in | HIGH | 8.7 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a commen | HIGH | 8.3 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-91719 | Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via | HIGH | 8.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-92014 | Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Fir | HIGH | 8.8 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-92017 | Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115 | HIGH | 8.8 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-92043 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in | HIGH | 8.8 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-92052 | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in | HIGH | 8.8 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-92984 | HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone | HIGH | 8.5 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-29811 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a pr | HIGH | 7.7 | 17% | EPSS 17%ile | NVD | 2026-09-13 |
| CVE-2026-59969 | Apache ZooKeeper quorum TLS fails to enforce peer hostname verification in FIPS-mode deployments. When sslQuorum=true, z | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-86904 | A privacy issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-54166 | Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` p | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-11 |
| CVE-2026-93382 | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code ins | HIGH | 8.8 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-82189 | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0 | HIGH | 8.7 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-91924 | pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, a | HIGH | 8.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-54506 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | HIGH | 7.6 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-81238 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulne | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-87142 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-73468 | A specially crafted packet can cause the premature expiry of multicast forwarding state on affected interfaces, potentia | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-90223 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: bound SNL TLV parsing to the skb and add | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-83451 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supp | HIGH | 8.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-91743 | Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendere | HIGH | 8.3 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83156 | Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affecte | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83223 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote). Supported versions | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83226 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83227 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83257 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83263 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-87139 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-13275 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-92776 | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to a | HIGH | 8.6 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-92782 | Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated a | HIGH | 8.6 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-92793 | GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated use | HIGH | 8.6 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-45048 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session | HIGH | 8.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-81896 | Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering | HIGH | 8.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-18113 | In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing | HIGH | 7.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-18116 | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in | HIGH | 7.3 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-54634 | Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld | HIGH | 7.3 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-83417 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communicat | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-54580 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or fail | HIGH | 8.3 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-91732 | Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromis | HIGH | 8.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-18595 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Requ | HIGH | 7.2 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-53957 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-ser | HIGH | 7.7 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-90927 | filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permission | HIGH | 7.1 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-84623 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-18110 | Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint | HIGH | 8.7 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83127 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations). Supporte | HIGH | 7.7 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-90767 | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing cus | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-73446 | On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can | HIGH | 7.0 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-81894 | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-im | HIGH | 8.5 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-91102 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | HIGH | 8.4 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-80943 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: check QoS TID before inde | HIGH | 7.6 | 16% | EPSS 16%ile | NVD | 2026-09-11 |
| CVE-2026-85189 | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 1 | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-85190 | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-85191 | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joom | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-85195 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2 | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-88852 | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-88853 | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-15451 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and inc | HIGH | 8.8 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-65415 | A race condition was addressed with additional validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gat | HIGH | 8.1 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-87250 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.6 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-76676 | Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow | HIGH | 8.8 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-19535 | Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative we | HIGH | 8.6 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-92800 | Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent document | HIGH | 7.6 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-73462 | On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-90768 | CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to re | HIGH | 8.6 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-86359 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privile | HIGH | 8.5 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-73943 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported | HIGH | 7.6 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83052 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 7.6 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87213 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.4 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-93015 | BlueKitchen BTstack through 1.8.2 fails to validate the peer-reported endpoint count against table bounds in A2DP stream | HIGH | 7.0 | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-86109 | The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures becau | HIGH | 7.5 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-91145 | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-91825 | Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable lo | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-80935 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound the device EEPROM address | HIGH | 8.8 | 16% | EPSS 16%ile | NVD | 2026-09-11 |
| CVE-2026-83236 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 8.2 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83242 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87145 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-92055 | Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderb | HIGH | 8.8 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-1758 | Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects Ga | HIGH | 8.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-15600 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotio | HIGH | 8.6 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-87161 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 8.5 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87229 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.2 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83217 | Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). Supported versions that are | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83221 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87146 | Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87149 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87160 | Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported | HIGH | 7.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-44715 | OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticat | HIGH | 8.7 | 15% | EPSS 15%ile | NVD | 2026-09-11 |
| CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes | HIGH | 8.2 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-83185 | Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Frame | HIGH | 7.3 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-61596 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 7.1 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-86466 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience c | HIGH | 8.1 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-54240 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic | HIGH | 7.4 | 15% | EPSS 15%ile | NVD | 2026-09-11 |
| CVE-2026-54241 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic | HIGH | 7.4 | 15% | EPSS 15%ile | NVD | 2026-09-11 |
| CVE-2026-92795 | Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticate | HIGH | 7.1 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-86049 | Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jup | HIGH | 7.1 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-78428 | For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving anoth | HIGH | 8.0 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-87262 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com | HIGH | 7.1 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-90650 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eve | HIGH | 7.2 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-92047 | Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T | HIGH | 8.8 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-92062 | Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T | HIGH | 8.8 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-92073 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153. | HIGH | 8.8 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-83091 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supporte | HIGH | 7.6 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-61668 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1 | HIGH | 8.1 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-83028 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | HIGH | 7.5 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-83065 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). The suppo | HIGH | 7.5 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-83463 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 7.5 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-87247 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.5 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-90444 | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shel | HIGH | 8.7 | 15% | EPSS 15%ile | NVD | 2026-09-11 |
| CVE-2026-88802 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 | HIGH | 7.5 | 14% | EPSS 14%ile | NVD | 2026-09-13 |
| CVE-2026-87759 | The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a p | HIGH | 8.8 | 14% | EPSS 14%ile | NVD | 2026-09-12 |
| CVE-2026-89023 | ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its RES | HIGH | 8.8 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-88904 | The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the | HIGH | 8.8 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-25687 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corrupti | HIGH | 8.1 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-76852 | Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmw | HIGH | 8.7 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-61544 | libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic co | HIGH | 8.2 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87218 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81898 | In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling | HIGH | 7.5 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87208 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-54549 | Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th | HIGH | 8.3 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87260 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com | HIGH | 7.3 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-92912 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish key | HIGH | 8.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-18115 | Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoi | HIGH | 7.4 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-73175 | Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway compone | HIGH | 7.1 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-55318 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execut | HIGH | 8.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81567 | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0- | HIGH | 8.7 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81895 | In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] withou | HIGH | 8.5 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-91748 | Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had comprom | HIGH | 8.3 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-83465 | Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server | HIGH | 8.2 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87264 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker). Su | HIGH | 7.7 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87888 | The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pri | HIGH | 8.0 | 14% | EPSS 14%ile | NVD | 2026-09-12 |
| CVE-2026-90948 | A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer ove | HIGH | 7.8 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-90949 | A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-base | HIGH | 7.8 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-68950 | The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providi | HIGH | 8.7 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-54253 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pac | HIGH | 8.2 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-67103 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to | HIGH | 7.6 | 13% | EPSS 13%ile | NVD | 2026-09-18 |
| CVE-2026-83231 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versi | HIGH | 7.0 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-90133 | In the Linux kernel, the following vulnerability has been resolved: ntfs: Fix index_root heap OOB write in ntfs_ir_to_i | HIGH | 7.8 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-83026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | HIGH | 8.3 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-83111 | Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations). Sup | HIGH | 7.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-83045 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 8.5 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-83050 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported | HIGH | 7.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-83230 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console). Support | HIGH | 7.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-87286 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is aff | HIGH | 8.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-87287 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is aff | HIGH | 8.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-87288 | Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is aff | HIGH | 8.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-93138 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlin | HIGH | 7.8 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-92128 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming | HIGH | 7.5 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-73955 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting). Supported ve | HIGH | 7.3 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-90933 | laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allow | HIGH | 7.1 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-11745 | Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror) | HIGH | — | 13% | EPSS 13%ile | GitHub | 2026-09-11 |
| CVE-2026-89534 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Clear sc_cm_id when ADDR_CHANGE replacemen | HIGH | 8.8 | 13% | EPSS 13%ile | NVD | 2026-09-11 |
| CVE-2026-78375 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Fre | HIGH | 8.6 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-86320 | A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. | HIGH | 7.8 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-76853 | Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi rest | HIGH | 7.2 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-87220 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-83368 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-73438 | On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90052 | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: fix buffer overflow with keyed discar | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-85719 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-85013 | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named | HIGH | 7.3 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-90537 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in pl | HIGH | 8.8 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-55343 | In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This cou | HIGH | 8.0 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-87164 | Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports). Supp | HIGH | 8.0 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-90071 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_teql: restore skb->dev on the slave | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90292 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix use-after-free in siw_accept() siw_a | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90341 | In the Linux kernel, the following vulnerability has been resolved: firmware: coreboot: Validate table bounds The exis | HIGH | 7.7 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90102 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/pnfs: key the data server cache on the NFS ve | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90224 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_ex | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90141 | In the Linux kernel, the following vulnerability has been resolved: ipvs: fix integer overflow in ftp helper port/addre | HIGH | 7.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90062 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: move hardware offload step af | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90203 | In the Linux kernel, the following vulnerability has been resolved: Squashfs: check block offset is not negative If a | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93178 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage index | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93046 | In the Linux kernel, the following vulnerability has been resolved: software node: Fix software_node_get_reference_args | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90286 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx6: Use PFP on the compute queues too | HIGH | 8.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90329 | In the Linux kernel, the following vulnerability has been resolved: HID: synchronize input before cleaning up a failed | HIGH | 8.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90120 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Check get_logical_index() return va | HIGH | 8.4 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90332 | In the Linux kernel, the following vulnerability has been resolved: PCI: dwc: ep: Flush cached MSI write before unmappi | HIGH | 8.2 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90143 | In the Linux kernel, the following vulnerability has been resolved: net: kcm: Hold RCU read lock while running BPF pars | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90225 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket l | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90388 | In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Check atomic pool allocation result dire | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93037 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Propagate sdma_txinit_ahg() errors set_ | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93170 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix channel idle state manag | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93165 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Fix memory overread in | HIGH | 7.7 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90103 | In the Linux kernel, the following vulnerability has been resolved: NFSv4.2: fix LAYOUTSTATS send buffer exhaustion en | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90293 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: post the full-feature receive buffers aft | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90294 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: delay the final Login Response until the | HIGH | 7.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93039 | In the Linux kernel, the following vulnerability has been resolved: ASoC: meson: Keep link pointers valid on realloc fa | HIGH | 7.4 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93177 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/pm/powerplay: bounds-check voltage index | HIGH | 7.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-92750 | Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticat | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90372 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: avoid nss underflow in mt7915_m | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90419 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: prevent out-of-bounds read in super root bl | HIGH | 7.1 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90403 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: pci: fix error path in rtl_pci_probe | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-92504 | In the Linux kernel, the following vulnerability has been resolved: thermal: intel: int3400: clean up ODVP on probe fai | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93054 | In the Linux kernel, the following vulnerability has been resolved: uio: Fix stale info pointer in failed registration | HIGH | 7.0 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93144 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject writes through untrusted BTF pointers | HIGH | 7.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90772 | Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without | HIGH | 8.3 | 11% | EPSS 11%ile | NVD | 2026-09-13 |
| CVE-2026-54581 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_bootstrap_index() function in libmport/fetch.c | HIGH | 8.3 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-63325 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/r | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2023-28148 | A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520. | HIGH | 7.2 | 11% | EPSS 11%ile | NVD | 2026-09-14 |
| CVE-2026-54239 | Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertex | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-58704 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (pr | HIGH | 8.8 | 11% | KEV EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90162 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: defer publishing granted locks to prevent UA | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90553 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores t | HIGH | 8.5 | 11% | EPSS 11%ile | NVD | 2026-09-12 |
| CVE-2026-20773 | A role-based access control issue was identified in the administrative expression evaluation functionality. This could a | HIGH | 8.5 | 11% | EPSS 11%ile | NVD | 2026-09-14 |
| CVE-2026-86894 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may be able to bre | HIGH | 7.5 | 11% | EPSS 11%ile | NVD | 2026-09-14 |
| CVE-2026-90448 | A deployment mode intended to expose only read access to stored data proxies a set of application programming interface | HIGH | 7.1 | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-91846 | Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whethe | HIGH | 7.1 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-91992 | Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused acr | HIGH | 8.2 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90092 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject accept queue add unless BT | HIGH | 8.0 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90057 | In the Linux kernel, the following vulnerability has been resolved: slip: remove slip_hangup() to fix use-after-free in | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90207 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: midi: Serialize input teardown with even | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90316 | In the Linux kernel, the following vulnerability has been resolved: drm/omap: dsi: Do not copy isr table To be able to | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90325 | In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: skip dying blkg in blkcg_activate_polic | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92507 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_deall | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92508 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_free_ | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90353 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix ext PHY use-after-free on r | HIGH | 7.0 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92033 | Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156. | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90255 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: fix the SCO setup context life | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90357 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unlink TWT flow if the MCU reje | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90176 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: Do not skip lock checks for single-byte rang | HIGH | 8.1 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90091 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix race l2cap_sock_cleanup_liste | HIGH | 8.0 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90309 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold CQ references when processing EQ e | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93137 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free on mm_struct in bpf_find_vm | HIGH | 7.8 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90067 | In the Linux kernel, the following vulnerability has been resolved: libceph: validate banner payload length When parsi | HIGH | 7.5 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90228 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix NULL pointer dereference in nvmet_execut | HIGH | 7.5 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93151 | In the Linux kernel, the following vulnerability has been resolved: nvmet-rdma: fix response resource leak on queue tea | HIGH | 7.5 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92525 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate num_sge/cur_sge before indexing | HIGH | 7.1 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-87187 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-93494 | A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending | HIGH | 7.5 | 11% | EPSS 11%ile | NVD | 2026-09-18 |
| CVE-2026-83081 | Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core | HIGH | 8.0 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-87245 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.0 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-89080 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an | HIGH | 7.5 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-49464 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-26950 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerabil | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-83022 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 7.9 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-86862 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbn | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90246 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix integer overflow in verify_tags() bou | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93042 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Terminate all descriptors witho | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90399 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix stride mismatch in mac_phy_caps_p | HIGH | 8.4 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93107 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Avoid reprocessing the current packet aft | HIGH | 8.2 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90199 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject out-of-range evcn in mi_enum_attr( | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90227 | In the Linux kernel, the following vulnerability has been resolved: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90291 | In the Linux kernel, the following vulnerability has been resolved: module/dups: Fix use-after-free in kmod_dup_req lif | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90308 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Hold QP references for AE and CM proces | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90358 | In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix trampoline stack size for 128-bit arg | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90387 | In the Linux kernel, the following vulnerability has been resolved: swiotlb: Preserve allocation virtual address for dy | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90392 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF when reading bpf link info | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93070 | In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after ini | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90137 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix password encoding bou | HIGH | 7.7 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90229 | In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Destroy the admin queue on removal The | HIGH | 7.4 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93121 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_ | HIGH | 7.0 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90241 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Tear down scalable-mode context on prob | HIGH | 8.2 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-83220 | Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe). Supp | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-90153 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: bound smb_check_perm_dacl() ACE walks by DAC | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90243 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down c | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90326 | In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix race between policy activation and | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90383 | In the Linux kernel, the following vulnerability has been resolved: misc: sgi-gru: remove interrupt-context page-table | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90407 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix overreads in ath11k_wmi_process_c | HIGH | 7.7 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-55887 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway Y | HIGH | 8.7 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-84581 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi | HIGH | 8.4 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-83096 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | HIGH | 7.9 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-90240 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Flush context cache with correct SID wh | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90371 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RXDMAD_C buffer recycling race The | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90380 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: fix use-after-free in mt76_rx_p | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90191 | In the Linux kernel, the following vulnerability has been resolved: mailbox: riscv-sbi-mpxy: validate RPMI notification | HIGH | 8.4 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90231 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unconfined user namespace restriction | HIGH | 8.4 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-83085 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.2 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-90051 | In the Linux kernel, the following vulnerability has been resolved: tcp: reject non zerocopy devmem tx Devmem tcp tx d | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90069 | In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - allocate async request context when | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90146 | In the Linux kernel, the following vulnerability has been resolved: bpf, xdp: move offload check into dev_xdp_install() | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90204 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate DIO orphan slot during inode read | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90205 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate orphan slot during inode read Patc | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90244 | In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Restore locking around msi_page_list Un | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90312 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check load-acquire src ptr type before the loa | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90324 | In the Linux kernel, the following vulnerability has been resolved: ublk: check import_ubuf() return value import_ubuf | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90343 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: stop PMSR before P2P and NAN teardo | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90429 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Synchronize the error ISR aga | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92518 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix kernel stack corruption in tailcall | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93079 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93122 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uac: validate rate list length before | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93154 | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Add refcounting to user ring MRs Preve | HIGH | 7.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90059 | In the Linux kernel, the following vulnerability has been resolved: net: stmmac: restore NET_IP_ALIGN in the RX DMA off | HIGH | 7.5 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90149 | In the Linux kernel, the following vulnerability has been resolved: NFSv4/flexfiles: fix NULL dereference for NFSv4.0 d | HIGH | 7.5 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90089 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btnxpuart: Validate the FW dump header l | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90145 | In the Linux kernel, the following vulnerability has been resolved: hinic3: Fix skb linearization mismatch and drop skb | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90161 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix interlaced ztailpacking pclusters On-di | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90260 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't clobber the extent buffer when | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-20336 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-93189 | In the Linux kernel, the following vulnerability has been resolved: HID: core: quiesce input in hid_hw_stop() to preven | HIGH | 8.8 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-66372 | The affected products use insufficiently random values, which allows web session tokens to be predictable, bounding toke | HIGH | 7.6 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-93203 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid CRC corruption due to parall | HIGH | 7.1 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-63127 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in cr | HIGH | 8.2 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-82438 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP com | HIGH | 8.1 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-19655 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-79298 | An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker | HIGH | 8.4 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-85892 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium- | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-57112 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, Tool | HIGH | 8.3 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-93190 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_typec: Reject out-of-bound | HIGH | 8.4 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-76692 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-93063 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: check SAP message length before | HIGH | 8.4 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-81897 | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not vali | HIGH | 7.7 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-86406 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a mem | HIGH | 7.5 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-90256 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use proto_lock for l2cap_data to | HIGH | 8.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-87767 | The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter bef | HIGH | 8.6 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-87770 | The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters before using | HIGH | 8.6 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-87771 | The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before using them | HIGH | 8.6 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-87774 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to | HIGH | 8.6 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-87775 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to | HIGH | 8.6 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-40857 | WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. T | HIGH | 8.4 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-87210 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.3 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-82786 | Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulner | HIGH | 8.2 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-55225 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | HIGH | 8.0 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-90093 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: access chan->conn safely in get/s | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90142 | In the Linux kernel, the following vulnerability has been resolved: virtio_net: Fix resize of the RX ring When a AF_XD | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90237 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: move custom expectation support | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90317 | In the Linux kernel, the following vulnerability has been resolved: bpf: Invalidate RCU pointers after final spin unloc | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90320 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate external xattr entries when reading | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93105 | In the Linux kernel, the following vulnerability has been resolved: esp: do not unref managed frag pages in esp_ssg_unr | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90172 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: destroy QP before mem pools on acce | HIGH | 7.5 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90234 | In the Linux kernel, the following vulnerability has been resolved: NFS: Return a delegation the client fails to record | HIGH | 7.5 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90132 | In the Linux kernel, the following vulnerability has been resolved: ntfs: reject unprivileged writes to reserved $LX* x | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90347 | In the Linux kernel, the following vulnerability has been resolved: arm64: ptrace: Keep 'orig_x0' in-sync with x0 on sy | HIGH | 8.4 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90651 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certific | HIGH | 8.1 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-83073 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 8.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-90268 | In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix error handling in sd_probe() after la | HIGH | 8.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90301 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: o2hb: quiesce negotiate handlers and timeout | HIGH | 8.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90111 | In the Linux kernel, the following vulnerability has been resolved: ip6mr: do not clone dst in ip6mr_cache_report() IP | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90118 | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix off-by-one page overflow in ntfs_decompre | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90177 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check pointer type for all atomic RMW paths A | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90210 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF in bpf_trampoline_multi_attach_free on | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90217 | In the Linux kernel, the following vulnerability has been resolved: bpf: Compare iterator types during state pruning A | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90289 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Resize MST HDCP per-connector arra | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90321 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate inline xattrs during inode block va | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-92485 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix WARNING in bpf_tracing_link_release The t | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93127 | In the Linux kernel, the following vulnerability has been resolved: bpf: Drop scalar id on sign-extending narrowing sta | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93147 | In the Linux kernel, the following vulnerability has been resolved: s390/bpf: Replace ly instruction with llgf cpu_nr | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93175 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in CRTC reset | HIGH | 7.8 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90288 | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: rcar-gen2: Fix double of_node_put on | HIGH | 7.4 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90131 | In the Linux kernel, the following vulnerability has been resolved: ntfs: serialize resident iomap reads with mrec_lock | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90174 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds read in ksmbd_alloc_u | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93176 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dangling pointer in plane rese | HIGH | 7.0 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-20683 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS | HIGH | 7.1 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-87232 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-93192 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Clear queue->active_job when v3d_fence_cre | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-85128 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration | HIGH | 7.5 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-64790 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-58200 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payloa | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-93196 | In the Linux kernel, the following vulnerability has been resolved: nvdimm: virtio_pmem: refcount requests for token li | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-54167 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8 | HIGH | 8.2 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-89994 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-edma: tracing: no ptr dereference du | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-86039 | libp2p is a JavaScript implementation of the libp2p networking stack. From 8.0.0 until 12.0.24, @libp2p/peer-store in pa | HIGH | 8.2 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2023-32803 | The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certai | HIGH | 7.5 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-62089 | Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affect | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-81902 | Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlo | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-73460 | On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject | HIGH | 7.0 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89913 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v3: take an LPI reference in vgic_ | HIGH | 8.8 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-85122 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor | HIGH | 8.8 | 8% | EPSS 8%ile | NVD | 2026-09-18 |
| CVE-2026-90934 | EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints t | HIGH | 8.7 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-80967 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting t | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-81017 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: sensorhub: Bound the EC-reported s | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89588 | In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: GHES: fix ARM section length accounting | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89781 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix out-of-bounds read in read_log_rec_bu | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89856 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Clamp MSI-X derived queue counts to | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89943 | In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI property | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89992 | In the Linux kernel, the following vulnerability has been resolved: cpuidle: dt_idle_genpd: kfree() the original name a | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89947 | In the Linux kernel, the following vulnerability has been resolved: clk: meson: align gxbb_32k_clk_sel number of parent | HIGH | 8.0 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-43691 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-84497 | A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 a | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-89720 | In the Linux kernel, the following vulnerability has been resolved: ubifs: fix out-of-bounds read in signature length c | HIGH | 7.7 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-68955 | The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there i | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-82049 | In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives con | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-80953 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: adi: initialize the lock before enabli | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-81004 | In the Linux kernel, the following vulnerability has been resolved: ipmi:msghandler: Cancel work cleanly on an error I | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89452 | In the Linux kernel, the following vulnerability has been resolved: iommu/msm: Unwind probe state on registration failu | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89877 | In the Linux kernel, the following vulnerability has been resolved: media: saa7164: fix cleanup on resource allocation | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89885 | In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Fix SCP device refcounti | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89904 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix acpi_package_ids[] array overflow W | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89980 | In the Linux kernel, the following vulnerability has been resolved: ALSA: harmony: initialize locks before requesting I | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89954 | In the Linux kernel, the following vulnerability has been resolved: mtd: afs: validate v2 image info bounds The AFS v2 | HIGH | 8.0 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-92248 | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photos | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-81016 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Propagate SMU errors and vali | HIGH | 7.7 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-90887 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-90986 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-61593 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 8.1 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89782 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: reject restart table growth beyond U16_MA | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89806 | In the Linux kernel, the following vulnerability has been resolved: drm/sysfb: ofdrm: Fix integer overflow in fb_size c | HIGH | 8.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-89927 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Clamp stimer deadline to avoid l | HIGH | 7.1 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90435 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix integer overflow of user QP buffer s | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93095 | In the Linux kernel, the following vulnerability has been resolved: hfsplus: validate thread record before delete key r | HIGH | 7.8 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-92522 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: validate MADT IOAPIC entry bounds | HIGH | 7.3 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-89510 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Cancel reg_work before freeing device o | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89609 | In the Linux kernel, the following vulnerability has been resolved: ecryptfs: hold msg ctx list lock when cleaning daem | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-81903 | Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without valida | HIGH | 7.0 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-82427 | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervi | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-57441 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, | HIGH | 8.4 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-87241 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.1 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-89646 | In the Linux kernel, the following vulnerability has been resolved: ceph: fix leaked inode reference on writeback abort | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-19885 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-89912 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Don't dereference a NULL coll | HIGH | 7.1 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-88825 | The iGMS Direct Booking WordPress plugin before 2.0 does not authorise or escape its widget appearance settings, allowin | HIGH | 8.8 | 7% | EPSS 7%ile | NVD | 2026-09-18 |
| CVE-2026-19781 | Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92510 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destr | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92511 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in ib_destr | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-89596 | In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix off-by-one when saving/restoring non | HIGH | 7.1 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89602 | In the Linux kernel, the following vulnerability has been resolved: erofs: skip sufficiently large global buffers when | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89668 | In the Linux kernel, the following vulnerability has been resolved: nfsd: move nfsd_debugfs_init() after nfsd4_init_sla | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-92230 | Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thr | HIGH | 7.5 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-8821 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel m | HIGH | 7.1 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-85127 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.8.15 does not restrict the type of files unauthentic | HIGH | 8.8 | 7% | EPSS 7%ile | NVD | 2026-09-18 |
| CVE-2026-19886 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allow | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92176 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92177 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92178 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92179 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-90025 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: displayport: Fix OOB altmode arra | HIGH | 7.7 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | HIGH | 8.1 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-89624 | In the Linux kernel, the following vulnerability has been resolved: HID: universal-pidff: stop the device when force-fe | HIGH | 7.8 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-12150 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | HIGH | 7.0 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-90398 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix stride mismatch in mac_phy_caps_p | HIGH | 8.4 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93045 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject arena frees below the arena base bpf_a | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90402 | In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Fix controller cleanup on EDL sysfs | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92488 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: complete object teardown when the destr | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-89579 | In the Linux kernel, the following vulnerability has been resolved: bpf: Harden bloom filter sizing and indexing on 32- | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-84505 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-31278 | An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0 | HIGH | 7.7 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90616 | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi | HIGH | 7.4 | 6% | EPSS 6%ile | NVD | 2026-09-12 |
| CVE-2026-20222 | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisc | HIGH | 7.4 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90367 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: hold dev->mt76.mutex while disa | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90379 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: Add PCIe AER handler support to | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90425 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Require exactly one Stream ID | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90423 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix UAF in ODP init error-handling path | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92751 | CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing | HIGH | 7.2 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-92806 | phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form ha | HIGH | 7.2 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-93112 | In the Linux kernel, the following vulnerability has been resolved: bpf: Require a BPF cpumask for bpf_cpumask_populate | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-50158 | yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool | HIGH | 7.7 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93116 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wmi: fix resource leaks on probe | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-89959 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix control domain removal in vfio_ap | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89733 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: fix dangling pointers in uvc_func | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89870 | In the Linux kernel, the following vulnerability has been resolved: media: zoran: Avoid freeing a registered video_devi | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89880 | In the Linux kernel, the following vulnerability has been resolved: media: rtl2832_sdr: release URBs and stream buffers | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89883 | In the Linux kernel, the following vulnerability has been resolved: media: rc: sunxi-cir: Unregister rc device on probe | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89887 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov7740: fix use-after-destroy in remove | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89893 | In the Linux kernel, the following vulnerability has been resolved: media: cx23885: cancel NetUP CI work before teardow | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89965 | In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: reject an arena whose nfree is below th | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89979 | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix race between non-atomic ops and trig | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89988 | In the Linux kernel, the following vulnerability has been resolved: kprobes: Protect kprobe_blacklist with RCU __withi | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89908 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Preserve memslot arch flags on KVM_ | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89929 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVM: Ensure INVVPID is emulated on the correct | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89932 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Always flush vpid02 on first use Make s | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89957 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix hot-unplug skipped when last AP a | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-80992 | In the Linux kernel, the following vulnerability has been resolved: net: ravb: avoid dereferencing an invalid PTP clock | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81000 | In the Linux kernel, the following vulnerability has been resolved: net: tun: bound receive headroom tun_get_user() us | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89440 | In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: stop card-detect handling on probe | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89557 | In the Linux kernel, the following vulnerability has been resolved: md: do overflow check for sb->bblog_shift in super_ | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89559 | In the Linux kernel, the following vulnerability has been resolved: libnvdimm/labels: Prevent integer overflow in __nd_ | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89574 | In the Linux kernel, the following vulnerability has been resolved: dm array: validate array block headers on read arr | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89585 | In the Linux kernel, the following vulnerability has been resolved: auxdisplay: charlcd: cancel backlight work on regis | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89594 | In the Linux kernel, the following vulnerability has been resolved: hsi: omap_ssi_core: fix missing DMA mask setup for | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89597 | In the Linux kernel, the following vulnerability has been resolved: fbdev: uvesafb: unregister connector callback on in | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89605 | In the Linux kernel, the following vulnerability has been resolved: ecryptfs: release message context on send failure | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89607 | In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject oversized encrypted_key_size in pa | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89723 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix slab-out-of-bounds in nilfs_direct_prop | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89724 | In the Linux kernel, the following vulnerability has been resolved: media: vicodec: fix out-of-bounds write in FWHT enc | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89738 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: at91_udc: drain polled-VBUS timer/work | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89741 | In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-dev: fix error handling in __vi | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89793 | In the Linux kernel, the following vulnerability has been resolved: ublk: clear VM_MAYWRITE on read-only ublk char devi | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89823 | In the Linux kernel, the following vulnerability has been resolved: drm: fix race between partial drm_dev_register() fa | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89890 | In the Linux kernel, the following vulnerability has been resolved: media: go7007: defer the ALSA v4l2 put until card r | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89894 | In the Linux kernel, the following vulnerability has been resolved: media: cx231xx: reject geometry changes while the V | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89922 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Take srcu when importing watchpoint data | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89961 | In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: fix wrong addr_pfn tracking in compound | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89998 | In the Linux kernel, the following vulnerability has been resolved: dm: fix race when loading and unloading a table If | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90001 | In the Linux kernel, the following vulnerability has been resolved: HID: bpf: serialize device reference release in str | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90007 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Use rollback index when freeing MSI-X | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-83244 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2025-15697 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of sev | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-91014 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-73459 | On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially c | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-73435 | On affected platforms running Arista EOS with Open Shortest Path First version 2 (OSPFv2) configured, a specially crafte | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89442 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate socket ID in clos_asso | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89501 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-43684 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, m | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-89803 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: unsubscribe the channel-kill event bef | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89819 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: validate plane degamma LUT size fo | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89825 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: fix firmware control interface bounds | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89899 | In the Linux kernel, the following vulnerability has been resolved: media: cec: disable delayed work before freeing an | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89902 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Avoid preempt count underflow without pr | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89903 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Do not save/restore percpu base register | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89986 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: fix sleeping allocation in alloc_page | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-93074 | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_acces | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-86038 | libp2p is a JavaScript implementation of the libp2p networking stack. From 15.0.0 until 16.0.5, @libp2p/gossipsub uses t | HIGH | 7.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-89445 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix UAF in selftest IOPF reporting IOMMUF | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89811 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add TLB flush after MES queue eviction/ | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-80929 | In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] t | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80950 | In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Check that the transfer is valid befo | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80961 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate kset key_num and intra-segment | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80962 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate geometry fields from on-disk ca | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80975 | In the Linux kernel, the following vulnerability has been resolved: mfd: qnap-mcu: keep the reply buffer alive past a c | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81015 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/pmc: Fix LPS0 and debugfs leaks wh | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89500 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Make cpu_buffer::free_page a buffer_da | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89503 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring_buffe | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89520 | In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-fligh | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89620 | In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: validate report | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89670 | In the Linux kernel, the following vulnerability has been resolved: nfsd: hold rcu across localio cmpxchg retry nfsd_f | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-84511 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-84568 | A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS S | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-83247 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-83294 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-89799 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in bpf_get_stackid The get | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89808 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix the case that vm range is hole at s | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89810 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix error path at svm_migrate_copy_to_r | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89814 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: clamp the isolation index for rings out | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89829 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to pass folio->index to f2fs_sanity_check | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89832 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to clear dirty flag on folio in error pat | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89841 | In the Linux kernel, the following vulnerability has been resolved: f2fs: only redirty pinned folios in redirty_blocks | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89906 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Refactor jump offset calculation in | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89920 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory corruption by not reinjecting | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90008 | In the Linux kernel, the following vulnerability has been resolved: scsi: megaraid_sas: Limit NVMe request size to the | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-24073 | Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-24074 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operat | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-64736 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6.1 and iPadOS | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-11929 | IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptograph | HIGH | 7.5 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-83155 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.3 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-93485 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPre | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-18 |
| CVE-2026-92025 | Use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefo | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92027 | Use-after-free in the DOM: Streams component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox E | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-83264 | Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). | HIGH | 8.4 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-36453 | Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra | HIGH | 7.4 | 6% | EPSS 6%ile | NVD | 2026-09-13 |
| CVE-2026-89777 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: clear vdev->msi_perm after freeing it on | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89960 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix stale pqap_hook pointer on error | HIGH | 8.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-80947 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtl8xxxu: fix use-after-free from rx_urb_wq o | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80971 | In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: clear the URB pointers on disconnect | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80982 | In the Linux kernel, the following vulnerability has been resolved: net/smc: fix use-after-free in smc_rx_pipe_buf_rele | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80991 | In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_i | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80994 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix flow mask use-after-free on f | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81001 | In the Linux kernel, the following vulnerability has been resolved: slip: fix use-after-free in sl_sync() slip_devs[] | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81008 | In the Linux kernel, the following vulnerability has been resolved: interconnect: Fix use after free in icc_get() and o | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89472 | In the Linux kernel, the following vulnerability has been resolved: power: supply: charger-manager: register regulators | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89690 | In the Linux kernel, the following vulnerability has been resolved: nfsd: defer vfree of compound ops to fix rpc_status | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89742 | In the Linux kernel, the following vulnerability has been resolved: rapidio: mport_cdev: fix use-after-free in dma_req_ | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89746 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free with same-name named tr | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89747 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on s | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89750 | In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state bef | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89789 | In the Linux kernel, the following vulnerability has been resolved: gtp: add synchronize_net() in gtp_newlink() error p | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89801 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/uvmm: fix premature region free on fail | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89854 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix cs84xx use-after-free on host te | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89888 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov02a10: fix endpoint parsing use-after | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89938 | In the Linux kernel, the following vulnerability has been resolved: iio: chemical: atlas-sensor: use iio_trigger_poll_n | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89940 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Tie IIO dma fence lock lifetime to the | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89941 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Make IIO DMA fence release RCU-safe T | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89942 | In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix potential use-after-free in anonym | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89997 | In the Linux kernel, the following vulnerability has been resolved: dm: fix resume-vs-remove race If the user issues t | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90003 | In the Linux kernel, the following vulnerability has been resolved: futex: Prevent rcuwait use-after-free during requeu | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-90022 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi2: fix use-after-free in string | HIGH | 7.8 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-89443 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate level in perf mask ioc | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89608 | In the Linux kernel, the following vulnerability has been resolved: ecryptfs: pass packet set buffer size to parser ec | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89818 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: fix integer overflow in dec_msg buf | HIGH | 7.1 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-76856 | Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config | HIGH | 7.0 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-83079 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | HIGH | 7.9 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-43688 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, mac | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-89928 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Consume the locked rmap value in the | HIGH | 8.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89795 | In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset | HIGH | 8.4 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-80955 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: fix use-after-free and invalid seg opera | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89545 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: defer rq_argp and rq_resp free until after | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89622 | In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: clear rxbuf after I2C/SMBus transfer | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-90002 | In the Linux kernel, the following vulnerability has been resolved: ftrace: Take trace_array reference before accessing | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90013 | In the Linux kernel, the following vulnerability has been resolved: tracing: Take trace_array reference when opening op | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-42784 | A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags su | HIGH | 7.4 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89731 | In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds A | HIGH | 7.1 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89826 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: harden firmware build-info bounds chec | HIGH | 7.1 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-92026 | Use-after-free in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR | HIGH | 8.8 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-84535 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS | HIGH | 8.2 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-24081 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enab | HIGH | 7.4 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-25281 | Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. | HIGH | 7.4 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-25294 | Transient DOS while parsing frame during channel usage. | HIGH | 7.4 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90381 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix handling channel context with diffe | HIGH | 8.8 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-92816 | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to ar | HIGH | 8.5 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-93111 | In the Linux kernel, the following vulnerability has been resolved: bpf: Mark tracing_multi trampolines as ftrace manag | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93125 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject rdonly/rdwr_buf_size kfunc arguments th | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93148 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject MEM_ALLOC BTF accesses past object boun | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90408 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix overreads in ath12k_wmi_process_c | HIGH | 7.7 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90427 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't fall back to a freed sm | HIGH | 7.4 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90401 | In the Linux kernel, the following vulnerability has been resolved: md: remove REQ_NOWAIT support from raid1/10/456 RE | HIGH | 7.1 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-87183 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.7 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-83277 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo | HIGH | 7.3 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-81632 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone ab | HIGH | 7.2 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-89804 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/dmem: fix mismatched DMA unmap size for | HIGH | 8.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89907 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Validate MSI data before routing it | HIGH | 8.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89615 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound page_lcns[] index by the log record | HIGH | 8.4 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-90895 | Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application | HIGH | 8.4 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-80954 | In the Linux kernel, the following vulnerability has been resolved: i3c: Fix unlocked dereference of dev->desc in i3c_d | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89584 | In the Linux kernel, the following vulnerability has been resolved: block: validate user space vectors during extractio | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89748 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix retry exhaustion in simple ring buffer | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89805 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: Fix folio allocation fallback and use- | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89815 | In the Linux kernel, the following vulnerability has been resolved: drm/ttm: Drop tt->restore after successful restore | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89836 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix folio_nr_pages() race after put in large | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89873 | In the Linux kernel, the following vulnerability has been resolved: media: v4l2-ctrls: validate HEVC EXT SPS RPS counts | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89875 | In the Linux kernel, the following vulnerability has been resolved: media: ti: vpe: quiesce overflow recovery before fr | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89882 | In the Linux kernel, the following vulnerability has been resolved: media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED i | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89919 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: keyop: use mmu_lock to read gmap->asce | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89967 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: avoid out-of-bounds writes for c | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89985 | In the Linux kernel, the following vulnerability has been resolved: memcg: keep folio's objcg same as its node memcg_r | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90009 | In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Fix TOCTOU in io_uring passthrough comma | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90010 | In the Linux kernel, the following vulnerability has been resolved: scsi: bsg: Cap io_uring sense copy to max_response_ | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90014 | In the Linux kernel, the following vulnerability has been resolved: tracing: Have show_event_filters/triggers files tak | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-43683 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-43783 | A race condition was addressed with improved locking. This issue is fixed in macOS Tahoe 26.6. A malicious app may be ab | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-90032 | In the Linux kernel, the following vulnerability has been resolved: media: usbtv: keep device alive while ALSA card exi | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-81474 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93456 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing | HIGH | 8.4 | 5% | EPSS 5%ile | NVD | 2026-09-18 |
| CVE-2026-89911 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap TLBI Range to the architu | HIGH | 7.9 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-89767 | In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mism | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-90026 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic: cancel reset_work on stop p | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90027 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: qcom-pmic-typec: disable cc_debounce_dw | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-43786 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-65362 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Ta | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-90030 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: clear forceRM when issuing EndTransfer | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-90047 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usab | HIGH | 7.8 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-78081 | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0 | HIGH | 7.1 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-57586 | CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default | HIGH | 8.6 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-81235 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high p | HIGH | 8.0 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-17133 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-89791 | In the Linux kernel, the following vulnerability has been resolved: perf: Fix use-after-free when perf mmap() revival r | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-84620 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-89705 | In the Linux kernel, the following vulnerability has been resolved: nfsd: restore rq_status_counter to even on all nfsd | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-90648 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platfor | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-13 |
| CVE-2026-89792 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds reads in share config | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-89838 | In the Linux kernel, the following vulnerability has been resolved: f2fs: limit recovery filename logging to stored len | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-71538 | @cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the Win | HIGH | 8.5 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-93337 | NetworkManager-l2tp contains an improper input validation vulnerability that allows local users with VPN connection crea | HIGH | 8.5 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-90894 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_s | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-43689 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-65359 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84580 | The issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tah | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-90044 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix Use-After-Free in AIO error | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-90045 | In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-89521 | In the Linux kernel, the following vulnerability has been resolved: sched/core: Handle pick_task() releasing the rq loc | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89456 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Propagate partial completion length acro | HIGH | 7.0 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-84584 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Golden Gate 27. An app may be | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-92903 | Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be int | HIGH | 8.2 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-82992 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation). Supported versions t | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-82996 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83018 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported version | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83024 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83071 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Lea | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83118 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities). Supported versions | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83147 | Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory). T | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83211 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83288 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search). | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83290 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83291 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83293 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN). Th | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83317 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installatio | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83336 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics S | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83337 | Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83420 | Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering). | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-87268 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-87271 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-87272 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-93201 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent m | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-81900 | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them int | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-89910 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Fix uninitialized stack variable is | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-78295 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. | HIGH | 8.8 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-81012 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix off-by-one write in h | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89465 | In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: quiesce delayed work before | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89470 | In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd: Limit port counts to EC_ | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89471 | In the Linux kernel, the following vulnerability has been resolved: power: supply: cros_usbpd-charger: bound the EC-rep | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89504 | In the Linux kernel, the following vulnerability has been resolved: regulator: as3722_get_regulator_dt_data: fix premat | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89599 | In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: panel-dsi-cm: initialize lock before | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89744 | In the Linux kernel, the following vulnerability has been resolved: device property: fix infinite loop in fwnode_for_ea | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-84546 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-89755 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freein | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89758 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: skip non-present PMDs when queueing f | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89764 | In the Linux kernel, the following vulnerability has been resolved: rust: devres: fix race between concurrent revokers | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-90043 | In the Linux kernel, the following vulnerability has been resolved: zram: fix slot lock bit position on big-endian 64-b | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-90046 | In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP P | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-89466 | In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: terminate the strings | HIGH | 7.7 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89743 | In the Linux kernel, the following vulnerability has been resolved: misc: nsm: bound the device-reported response lengt | HIGH | 7.7 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-19816 | A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE ( | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-73174 | Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserve | HIGH | 8.7 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-73177 | Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware | HIGH | 8.6 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-89603 | In the Linux kernel, the following vulnerability has been resolved: entry: Fix seccomp bypass after ptrace with TSYNC | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89587 | In the Linux kernel, the following vulnerability has been resolved: ACPI: pfr_update: fix stack buffer overflow in quer | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-92180 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vul | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-54692 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-81810 | The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of | HIGH | 7.2 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-90783 | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to i | HIGH | 8.5 | 4% | EPSS 4%ile | NVD | 2026-09-13 |
| CVE-2026-82430 | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the ent | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-17156 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-17416 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-80356 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Un | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-89840 | In the Linux kernel, the following vulnerability has been resolved: f2fs: validate MOVE_RANGE destination size F2FS_IO | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-54510 | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-54608 | MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-80932 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: flush works in dependency order virt | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89469 | In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8727: fix use-after-free in lp8727 | HIGH | 8.4 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-87243 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.0 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-89641 | In the Linux kernel, the following vulnerability has been resolved: cifs: clear tcon after cifsFileInfo_put() in cifs_f | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-83190 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-83193 | Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences). Supported ver | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-84548 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | HIGH | 7.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-90556 | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with decl | HIGH | 8.5 | 4% | EPSS 4%ile | NVD | 2026-09-12 |
| CVE-2026-89563 | In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_cow_head() in ip6_tnl_xmit() i | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89606 | In the Linux kernel, the following vulnerability has been resolved: ecryptfs: reject too-small tag 70 packets ecryptfs | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-89617 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate dirty page table on log replay | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-43702 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPa | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-65344 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84506 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-92838 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-19515 | The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micr | HIGH | 7.0 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-81192 | OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS | HIGH | 7.0 | 4% | EPSS 4%ile | GitHub | 2026-09-16 |
| CVE-2026-84578 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS | HIGH | 8.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-64701 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84515 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84575 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | HIGH | 7.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-86585 | The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01 | HIGH | 7.7 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-64752 | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, ma | HIGH | 7.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82964 | Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low- | HIGH | 8.8 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-93375 | Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker | HIGH | 8.1 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-89489 | In the Linux kernel, the following vulnerability has been resolved: openrisc: fix arbitrary kernel memory access via or | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89523 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel pending mlo_pm_work If | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89564 | In the Linux kernel, the following vulnerability has been resolved: ip: orphan prefetched skbs before multicast forward | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89619 | In the Linux kernel, the following vulnerability has been resolved: HID: intel-thc-hid: intel-quickspi: bound GET_REPOR | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-84566 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84565 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84577 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Golden Gate 27, macOS T | HIGH | 8.2 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-71180 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privi | HIGH | 8.2 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-81010 | In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_w | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89553 | In the Linux kernel, the following vulnerability has been resolved: nouveau/gem: reserve the bo in the info ioctl aroun | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-87216 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-58485 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-87219 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.4 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-87259 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com | HIGH | 8.4 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-89436 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix sentinel write | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89522 | In the Linux kernel, the following vulnerability has been resolved: media: staging/ipu7: fix async notifier UAF on prob | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-90978 | The Filter Gallery WordPress plugin before 1.1.5 does not verify the nonce on several of its AJAX handlers when the nonc | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-82429 | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-90947 | A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-65398 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-73450 | On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with a | HIGH | 7.0 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-57122 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signa | HIGH | 8.6 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-19477 | There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). This | HIGH | 8.6 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-55062 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget | HIGH | 8.4 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-65354 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | HIGH | 8.2 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-19624 | A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and v | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-87261 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com | HIGH | 7.3 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-80928 | In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80931 | In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C bl | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80933 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate default EEPROM firmwar | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80944 | In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Detach sync cmd buffer on interrupte | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80977 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't touch shared zerocopy state in s | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80978 | In the Linux kernel, the following vulnerability has been resolved: net: cap advertised IP tunnel headroom IP tunnel d | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80979 | In the Linux kernel, the following vulnerability has been resolved: net/smc: unregister the connection before draining | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89487 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: only skb_tx_error() a packet we are ab | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89497 | In the Linux kernel, the following vulnerability has been resolved: orangefs: skip leading spaces before parsing client | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89540 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: init gssp_lock before publishing proc entry | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89562 | In the Linux kernel, the following vulnerability has been resolved: ip6_gre: fix hardware header length for NBMA tunnel | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89573 | In the Linux kernel, the following vulnerability has been resolved: dm array: reject an array block whose value size is | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89580 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disable preemption in __bpf_get_stack get_per | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89581 | In the Linux kernel, the following vulnerability has been resolved: bpf, x86: Fix per-CPU address resolution into an ex | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-92786 | LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wr | HIGH | 8.5 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-56795 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A lo | HIGH | 8.2 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-37008 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vu | HIGH | 8.1 | 3% | EPSS 3%ile | NVD | 2026-09-13 |
| CVE-2026-75092 | A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). | HIGH | 7.3 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-89450 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Reject a vSID wider than the | HIGH | 8.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80936 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7925: cancel mlo_pm_work on stop mt7 | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80959 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: bound the persisted tail-position offset | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-81006 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Remove all sysfs files on registration failur | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89441 | In the Linux kernel, the following vulnerability has been resolved: mmc: via-sdmmc: cancel card-detect work on remove | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89507 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_write_cm_event( | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-83159 | Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported versions that | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-83253 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-84611 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | HIGH | 7.3 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84632 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | HIGH | 7.3 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84572 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-77407 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as | HIGH | 7.0 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-89560 | In the Linux kernel, the following vulnerability has been resolved: landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for w | HIGH | 8.4 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-80952 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix info leak and UAF in device unregi | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89488 | In the Linux kernel, the following vulnerability has been resolved: openvswitch: Fix CT limit teardown use-after-free | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89508 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Lock the handler in ucma_set_ib_path() | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89548 | In the Linux kernel, the following vulnerability has been resolved: SUNRPC: always drain cache_cleaner before destroyin | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89736 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix use-after-free on sound c | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-65357 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6 | HIGH | 7.8 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-81007 | In the Linux kernel, the following vulnerability has been resolved: ipmi: ipmb: validate write message length ipmb_wri | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89593 | In the Linux kernel, the following vulnerability has been resolved: hugetlb: only adjust reservation during unmapping i | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-89640 | In the Linux kernel, the following vulnerability has been resolved: cifs: fix loff_t underflow in cifs_remap_file_range | HIGH | 7.1 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-83016 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR). Supported version | HIGH | 7.2 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-81011 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: pass validated element co | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89639 | In the Linux kernel, the following vulnerability has been resolved: cifs: use cifs_invalidate_cache() in cifs_do_trunca | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89691 | In the Linux kernel, the following vulnerability has been resolved: nfsd: clear opcnt on compound arg release to preven | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-83219 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-89486 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Fix use-after-free of cmd_rcvr in _ipmi_destr | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89570 | In the Linux kernel, the following vulnerability has been resolved: cxl/mce: Make the MCE notifier per-region Flavien | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89600 | In the Linux kernel, the following vulnerability has been resolved: fanotify: fix use-after-free of file range info fs | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-64712 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Ta | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-80958 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: clamp the tail kset read to the segment | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89571 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: bound fwctl command payload to the in | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-59569 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to pot | HIGH | 8.1 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-89769 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_ | HIGH | 7.4 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-92582 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.js | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-16 |
| CVE-2026-89513 | In the Linux kernel, the following vulnerability has been resolved: RISC-V: KVM: Fix PMU event info array size overflow | HIGH | 8.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-56967 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote (pro | HIGH | 8.0 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-80995 | In the Linux kernel, the following vulnerability has been resolved: net: mctp: hold a reference to the route device in | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89499 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Stop remote reader update when page sw | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89761 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix out-of-bounds write when null termina | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89762 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix cred UAF caused by begin_current_labe | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89771 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffe | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-89754 | In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix stale walk->action escaping walk_p | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-87273 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 8.6 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83015 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager). Supporte | HIGH | 7.0 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83316 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.0 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-89763 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_t | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-84607 | A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 a | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-83240 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-84631 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27. An app may be | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-87182 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 8.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-81301 | Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider with | HIGH | 8.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-89760 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: don't free a hibernation slot that is in | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-83214 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83216 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported v | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83342 | Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sys | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83353 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-87269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-87270 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-87276 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | HIGH | 7.5 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-45720 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML. | HIGH | 7.0 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-86917 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequo | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2025-59607 | Memory Corruption when copying large input data exceeds normal allocation limits. | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-24075 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper sy | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-25280 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. | HIGH | 7.8 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-83004 | Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). | HIGH | 7.2 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-83158 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClon | HIGH | 7.1 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-25283 | Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. | HIGH | 8.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-91727 | Incorrect reference resolution in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a local attacker | HIGH | 8.1 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-23789 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 13 | HIGH | 7.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-25290 | Memory Corruption when validating large data buffers from external sources using addition to check buffer length. | HIGH | 7.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-86474 | The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions p | HIGH | 7.7 | 1% | EPSS 1%ile | NVD | 2026-09-16 |
| CVE-2026-81546 | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when pa | HIGH | 7.7 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-89459 | In the Linux kernel, the following vulnerability has been resolved: s390/percpu: Fix MVIY_PERCPU() with older binutils | HIGH | 7.0 | 1% | EPSS 1%ile | NVD | 2026-09-11 |
| CVE-2026-92718 | Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content | HIGH | 7.0 | 1% | EPSS 1%ile | NVD | 2026-09-16 |
| CVE-2026-90493 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is | HIGH | 8.5 | 1% | EPSS 1%ile | NVD | 2026-09-13 |
| CVE-2026-12518 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privile | HIGH | 8.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-25284 | Information Disclosure when a pointer is reused after being deallocated. | HIGH | 7.3 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-86901 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27. M | HIGH | 7.1 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-83150 | Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Difficult to ex | HIGH | 7.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-79994 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized work | HIGH | 8.7 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-54174 | melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to me | HIGH | 8.3 | 1% | EPSS 1%ile | NVD | 2026-09-11 |
| CVE-2026-33963 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. | HIGH | 7.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-91734 | Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execut | HIGH | 7.4 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-54447 | garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0. | HIGH | 8.4 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-57012 | In the Setup Wizard, there is a possible remote package install due to a missing permission check. This could lead to re | HIGH | 8.4 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2024-58383 | Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via | HIGH | 8.4 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-84507 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and | HIGH | 7.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-47773 | ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missin | HIGH | 7.2 | 1% | EPSS 1%ile | NVD | 2026-09-11 |
| CVE-2026-77404 | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CAC | HIGH | 8.7 | 1% | EPSS 1%ile | NVD | 2026-09-16 |
| CVE-2026-25282 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. | HIGH | 7.9 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-45726 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st | HIGH | 7.6 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-76159 | Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions bef | HIGH | 7.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-83249 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.8 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-66571 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. | HIGH | 7.1 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-83239 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | HIGH | 7.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-59570 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user | HIGH | 7.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-83323 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Se | HIGH | 7.5 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-50605 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insu | HIGH | 7.4 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-50609 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | HIGH | 7.4 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-50610 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense d | HIGH | 7.4 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-20323 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD So | HIGH | 8.3 | 0% | EPSS 0%ile | NVD | 2026-09-16 |
| CVE-2026-81429 | The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template | HIGH | 7.1 | 0% | EPSS 0%ile | NVD | 2026-09-12 |
| CVE-2026-87240 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-86836 | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIF | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-14 |
| CVE-2026-0189 | In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56881 | In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-25278 | Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copyi | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-17 |
| CVE-2026-40058 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability on | HIGH | 8.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0194 | In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escala | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56970 | In multiple locations, there is a possible permission bypass due to a missing permission check. This could lead to local | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58679 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible heap buffer overflow due to a logic error in the code. Thi | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58691 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to improper input validation. This could lead to lo | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55359 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58678 | In Bootloader, there is a possible permission bypass due to a logic error in the code. This could lead to local escalati | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56941 | In multiple functions of fpc_tee_hal.c, there is a possible use-after-free due to a logic error in the code. This could | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56982 | In VPU, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55301 | In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead t | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56978 | In get_global_config_item_addr of gc.c, there is a possible out-of-bounds read due to a missing bounds check. This could | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56985 | In multiple files, there is a possible way to obtain signatures due to type confusion. This could lead to local escalati | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56986 | In multiple files, there is a possible out-of-bounds read due to type confusion. This could lead to local escalation of | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58699 | In Vp9DecEndOfStream of vp9hwd_output.cc, there is a possible out-of-bounds read due to an incorrect bounds check. This | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0199 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55323 | In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55351 | In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privi | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-57014 | In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out-of-bounds write due to a missing | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58695 | In gmc_phy_lp3_exit_restore_registers of phy_power.c, there is a possible escalation of privilege due to a missing bound | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58766 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-40539 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1 | HIGH | 7.1 | 0% | EPSS 0%ile | NVD | 2026-09-18 |
| CVE-2026-85628 | Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-16 |
| CVE-2026-88622 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2025-14754 | IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-10575 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-11375 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-11378 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-11381 | IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to i | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-58197 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-33625 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 conta | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-81180 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-93759 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d | HIGH | 8.8 | — | — | NVD | 2026-09-18 |
| GHSA-xwmw-prc4-v3cr | Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion | HIGH | 8.8 | — | — | GitHub | 2026-09-18 |
| USN-8779-2 | USN-8779-2: Bubblewrap regression | HIGH | 8.8 | — | — | Ubuntu | 2026-09-17 |
| DSA 6501-1 | [SECURITY] [DSA 6501-1] firefox-esr security update | HIGH | 8.8 | — | — | Debian | 2026-09-16 |
| DSA 6503-1 | [SECURITY] [DSA 6503-1] thunderbird security update | HIGH | 8.8 | — | — | Debian | 2026-09-16 |
| CVE-2026-93592 | vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93599 | rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_str | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-77929 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93657 | hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-68914 | Mojolicious is a real-time web framework for Perl. Prior to 9.47, the pure-Perl implementation of Mojo::JSON does not li | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-81942 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-84398 | CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An att | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-86520 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-88259 | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93687 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attack | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93688 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstra | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93690 | uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-62943 | btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93748 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-s | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93749 | source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attacke | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93752 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to valida | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93753 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properl | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93761 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library ma | HIGH | 8.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93593 | ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver b | HIGH | 8.6 | — | — | NVD | 2026-09-18 |
| CVE-2025-61682 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | HIGH | 8.6 | — | — | NVD | 2026-09-18 |
| CVE-2026-93758 | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a | HIGH | 8.6 | — | — | NVD | 2026-09-18 |
| CVE-2026-61551 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaus | HIGH | 8.6 | — | — | NVD | 2026-09-18 |
| DSA 6502-1 | [SECURITY] [DSA 6502-1] mkvtoolnix security update | HIGH | 8.5 | — | — | Debian | 2026-09-16 |
| CVE-2026-56914 | In multiple locations, there is a possible use-after-free due to improper locking. This could lead to local escalation o | HIGH | 8.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-81943 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont | HIGH | 8.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-63638 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 8.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93765 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. In | HIGH | 8.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-63199 | Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the | HIGH | 8.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93760 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that | HIGH | 8.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93569 | HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority | HIGH | 8.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-86689 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | HIGH | 8.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-55556 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut | HIGH | 8.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-91127 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic | HIGH | 8.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-93750 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails t | HIGH | 8.2 | — | — | NVD | 2026-09-18 |
| DSA 6496-1 | [SECURITY] [DSA 6496-1] nginx security update | HIGH | 8.2 | — | — | Debian | 2026-09-12 |
| CVE-2026-10027 | IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-54148 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-61548 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-61833 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77239 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-62278 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-81179 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset | HIGH | 8.1 | — | — | NVD | 2026-09-18 |
| GHSA-5648-rgj9-v224 | @zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticate | HIGH | 8.1 | — | — | GitHub | 2026-09-15 |
| DSA 6496-2 | [SECURITY] [DSA 6496-2] nginx regression update | HIGH | 8.1 | — | — | Debian | 2026-09-16 |
| CVE-2026-56945 | In VPU, there is a possible out-of-bounds write due to a confused deputy. This could lead to local escalation of privile | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58744 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to | HIGH | 7.8 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-63419 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-63422 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-46655 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits | HIGH | 7.8 | — | — | NVD | 2026-09-18 |
| DSA 6498-1 | [SECURITY] [DSA 6498-1] network-manager-l2tp security update | HIGH | 7.8 | — | — | Debian | 2026-09-14 |
| FG-IR-26-144 | Linux Kernel vulnerability Dirty Frag | HIGH | 7.8 | — | — | Fortinet | 2026-06-03 |
| CVE-2026-81944 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 cont | HIGH | 7.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-67549 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | HIGH | 7.6 | — | — | NVD | 2026-09-18 |
| GHSA-jgh3-fggc-mcpm | Obot: Server-Side Request Forgery via remote MCP server URL | HIGH | 7.6 | — | — | GitHub | 2026-09-18 |
| CVE-2026-93563 | Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93572 | ## Summary `RedisArrayAggregator` recently added `maxElements` and `maxNestedArrayDepth` limits to fix public Redis r | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93575 | ### Summary Netty's fix for CVE-2026-44248 is incomplete. The decoder checks if the MQTT packet's `Remaining Length` ex | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93488 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93491 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93560 | STOMP codec content-length long-to-int truncation causes infinite decode loop DoS | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93558 | Unbounded Per-Connection Queue Growth in WebSocketServerExtensionHandler Leads to Denial of Service | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93564 | HAProxy PROXY-v2 nested-TLV grandchild ByteBuf reference-count leak (incomplete fix of PR #16881) | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93565 | ### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point <= 0x20, the | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93567 | HTTP/1 authority-form CONNECT is translated to malformed HTTP/2 CONNECT with Host-controlled :authority | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93568 | HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93576 | Netty netty-codec-smtp — SMTP command-name field is not CRLF-validated (incomplete fix of CVE-2025-59419) | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93652 | Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2025-14753 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-10744 | IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-10751 | IBM MQ Java and JMS client libraries could allow an authenticated attacker to execute arbitrary code on client applicati | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-10853 | IBM MQ could allow an authenticated attacker with cluster access to cause a denial of service or potentially execute arb | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-81945 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bfore 1.2412b260707 and 2.2412b260519 conta | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-84384 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-84446 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-84447 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden referenc | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-77301 | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-91149 | A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustain | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-32641 | Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/ht | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-69184 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poi | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-85058 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W | HIGH | 7.5 | — | — | NVD | 2026-09-18 |
| GHSA-39wr-7q6h-cf68 | LMDeploy has an SSRF bypass | HIGH | 7.5 | — | — | GitHub | 2026-09-18 |
| DSA 6505-1 | [SECURITY] [DSA 6505-1] bind9 security update | HIGH | 7.5 | — | — | Debian | 2026-09-17 |
| FG-IR-26-163 | HTTP/2 Bomb CVE-2026-49975 | HIGH | 7.5 | — | — | Fortinet | 2026-08-12 |
| CVE-2026-84444 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, he | HIGH | 7.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-84975 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT | HIGH | 7.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-93658 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership | HIGH | 7.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93591 | SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values | HIGH | 7.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-61552 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta | HIGH | 7.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-93594 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control ru | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93595 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93598 | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot s | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77927 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77928 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93660 | SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-10030 | IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93737 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-61672 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-81505 | Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-62279 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an aut | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-63445 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-63458 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenti | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93763 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93764 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level enc | HIGH | 7.1 | — | — | NVD | 2026-09-18 |
| USN-8761-2 | USN-8761-2: Linux kernel (Azure FIPS) vulnerabilities | HIGH | 7.1 | — | — | Ubuntu | 2026-09-18 |
| USN-8729-2 | USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilities | HIGH | 7.1 | — | — | Ubuntu | 2026-09-18 |
| CVE-2026-58701 | In trusty_dputc of generic-arm64-smcall.c, there is a possible out-of-bounds write due to a race condition. This could l | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58724 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation o | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58728 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalati | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58734 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could | HIGH | 7.0 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-7006 | Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege | HIGH | 7.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-81305 | CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity o | HIGH | 7.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-63349 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In | HIGH | 7.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-73863 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro | HIGH | 7.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-77874 | CVE-2026-77874 | HIGH | — | — | — | Red Hat | 2026-09-17 |
| CVE-2026-92828 | CVE-2026-92828 | HIGH | — | — | — | Red Hat | 2026-09-16 |
| GHSA-xjw9-38cr-6372 | djust: A template binding inherits a context safety grant it never earned (XSS) | HIGH | — | — | — | GitHub | 2026-09-17 |
| GHSA-9395-2g46-rj3f | djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) | HIGH | — | — | — | GitHub | 2026-09-17 |
| CVE-2026-76698 | A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gate | MEDIUM | 6.5 | 90% | EPSS 90%ile | NVD | 2026-09-15 |
| CVE-2026-90617 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerabilit | MEDIUM | 5.5 | 75% | EPSS 75%ile | NVD | 2026-09-14 |
| CVE-2026-90618 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the f | MEDIUM | 5.5 | 75% | EPSS 75%ile | NVD | 2026-09-14 |
| CVE-2026-90843 | A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This | MEDIUM | 5.5 | 71% | EPSS 71%ile | NVD | 2026-09-15 |
| CVE-2026-90619 | A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unkn | MEDIUM | 5.5 | 70% | EPSS 70%ile | NVD | 2026-09-14 |
| CVE-2026-93371 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne | MEDIUM | 5.5 | 70% | EPSS 70%ile | NVD | 2026-09-18 |
| CVE-2026-90690 | A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemen | MEDIUM | 5.5 | 70% | EPSS 70%ile | NVD | 2026-09-14 |
| CVE-2026-54645 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, | MEDIUM | 4.8 | 68% | EPSS 68%ile | NVD | 2026-09-17 |
| CVE-2026-76431 | A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC cou | MEDIUM | 4.9 | 65% | EPSS 65%ile | NVD | 2026-09-16 |
| CVE-2026-54644 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip | MEDIUM | 6.1 | 63% | EPSS 63%ile | NVD | 2026-09-17 |
| CVE-2023-40772 | A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information | MEDIUM | 4.3 | 62% | EPSS 62%ile | NVD | 2026-09-14 |
| CVE-2026-76433 | A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticate | MEDIUM | 5.3 | 59% | EPSS 59%ile | NVD | 2026-09-16 |
| CVE-2026-76432 | A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot | MEDIUM | 4.9 | 58% | EPSS 58%ile | NVD | 2026-09-16 |
| CVE-2026-51133 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to e | MEDIUM | 6.1 | 57% | EPSS 57%ile | NVD | 2026-09-15 |
| CVE-2026-86465 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled | MEDIUM | 6.5 | 55% | EPSS 55%ile | NVD | 2026-09-16 |
| CVE-2026-53717 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 52% | EPSS 52%ile | NVD | 2026-09-14 |
| CVE-2026-54177 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 6.6 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-90524 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995 | MEDIUM | 5.5 | 51% | EPSS 51%ile | NVD | 2026-09-13 |
| CVE-2026-53716 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-53719 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 51% | EPSS 51%ile | NVD | 2026-09-14 |
| CVE-2026-55701 | The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, th | MEDIUM | 6.9 | 50% | EPSS 50%ile | NVD | 2026-09-15 |
| CVE-2026-92399 | A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/uti | MEDIUM | 5.5 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-92401 | A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff | MEDIUM | 6.9 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-57173 | vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v | MEDIUM | 6.5 | 50% | EPSS 50%ile | NVD | 2026-09-16 |
| CVE-2026-16777 | The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to | MEDIUM | 4.9 | 50% | EPSS 50%ile | NVD | 2026-09-18 |
| CVE-2026-76151 | Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Gr | MEDIUM | 4.6 | 49% | EPSS 49%ile | NVD | 2026-09-16 |
| CVE-2026-69201 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode | MEDIUM | 5.9 | 49% | EPSS 49%ile | NVD | 2026-09-15 |
| CVE-2026-90504 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted e | MEDIUM | 5.5 | 49% | EPSS 49%ile | NVD | 2026-09-13 |
| CVE-2026-77360 | oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.8, th | MEDIUM | 6.3 | 48% | EPSS 48%ile | NVD | 2026-09-16 |
| CVE-2026-11748 | Central Dogma: LDAP injection in SearchFirstActiveDirectoryRealm enables authentication confusion and audit log evasion | MEDIUM | — | 48% | EPSS 48%ile | GitHub | 2026-09-11 |
| CVE-2026-81913 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft | MEDIUM | 5.3 | 47% | EPSS 47%ile | NVD | 2026-09-11 |
| CVE-2026-20282 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying oper | MEDIUM | 4.9 | 45% | EPSS 45%ile | NVD | 2026-09-16 |
| CVE-2026-90494 | A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/pl | MEDIUM | 6.9 | 45% | EPSS 45%ile | NVD | 2026-09-13 |
| CVE-2026-76705 | A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exp | MEDIUM | 5.5 | 44% | EPSS 44%ile | NVD | 2026-09-15 |
| CVE-2026-92114 | A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/ | MEDIUM | 6.9 | 44% | EPSS 44%ile | NVD | 2026-09-15 |
| CVE-2026-27553 | A low-privileged remote attacker can manipulate the schema path parameter in the /index.php/diagnostics_tab/ajax_diag_ta | MEDIUM | 6.5 | 44% | EPSS 44%ile | NVD | 2026-09-16 |
| CVE-2026-54582 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non | MEDIUM | 6.0 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-86522 | Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attack | MEDIUM | 6.3 | 44% | EPSS 44%ile | NVD | 2026-09-17 |
| CVE-2026-92220 | A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_ | MEDIUM | 6.9 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-54585 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did | MEDIUM | 6.0 | 43% | EPSS 43%ile | NVD | 2026-09-17 |
| CVE-2026-92363 | A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp | MEDIUM | 5.3 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-73169 | Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip | MEDIUM | 6.3 | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-92361 | A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdk | MEDIUM | 5.3 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-82426 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a serv | MEDIUM | 6.5 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-90565 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e0 | MEDIUM | 5.5 | 42% | EPSS 42%ile | NVD | 2026-09-13 |
| CVE-2026-19607 | A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial a | MEDIUM | 5.3 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-92362 | A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-clie | MEDIUM | 6.9 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-14277 | IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal | MEDIUM | 6.3 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-90522 | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938 | MEDIUM | 5.5 | 42% | EPSS 42%ile | NVD | 2026-09-13 |
| CVE-2026-90523 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0 | MEDIUM | 5.5 | 42% | EPSS 42%ile | NVD | 2026-09-13 |
| CVE-2026-50157 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorize | MEDIUM | 6.5 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-92091 | A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using | MEDIUM | 5.9 | 42% | EPSS 42%ile | NVD | 2026-09-16 |
| CVE-2026-90686 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loade | MEDIUM | 5.5 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-90698 | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_ | MEDIUM | 5.5 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-93295 | MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user | MEDIUM | 5.1 | 42% | EPSS 42%ile | NVD | 2026-09-17 |
| CVE-2026-17463 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could | MEDIUM | 6.5 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-54637 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the schedule | MEDIUM | 5.5 | 41% | EPSS 41%ile | NVD | 2026-09-15 |
| CVE-2026-20121 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adapt | MEDIUM | 5.3 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2023-29377 | An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By us | MEDIUM | 6.6 | 41% | EPSS 41%ile | NVD | 2026-09-14 |
| CVE-2026-84993 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 a | MEDIUM | 6.5 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-81176 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the | MEDIUM | 5.3 | 41% | EPSS 41%ile | NVD | 2026-09-16 |
| CVE-2026-59149 | @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only | MEDIUM | 6.5 | 41% | EPSS 41%ile | GitHub | 2026-09-11 |
| CVE-2026-90603 | A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unkn | MEDIUM | 6.9 | 40% | EPSS 40%ile | NVD | 2026-09-13 |
| CVE-2026-92366 | A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search | MEDIUM | 5.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-90710 | A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file co | MEDIUM | 5.5 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-92380 | A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file core | MEDIUM | 5.5 | 40% | EPSS 40%ile | NVD | 2026-09-16 |
| CVE-2026-57497 | webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in sessio | MEDIUM | 5.3 | 40% | EPSS 40%ile | NVD | 2026-09-14 |
| CVE-2026-61793 | Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthen | MEDIUM | 6.9 | 39% | EPSS 39%ile | NVD | 2026-09-17 |
| CVE-2026-54176 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-59157 | webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-69147 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-91848 | A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of | MEDIUM | 5.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-43791 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-65412 | A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7 | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-14 |
| CVE-2026-55776 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-76700 | Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a | MEDIUM | 5.9 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-76555 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it a | MEDIUM | 6.8 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-59944 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or | MEDIUM | 6.1 | 39% | EPSS 39%ile | NVD | 2026-09-16 |
| CVE-2026-76697 | A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote | MEDIUM | 6.5 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-90566 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. A | MEDIUM | 5.5 | 39% | EPSS 39%ile | NVD | 2026-09-13 |
| CVE-2026-53496 | ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-55770 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC | MEDIUM | 6.8 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-50024 | GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_ta | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-92216 | A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-81453 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res | MEDIUM | 6.5 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-91002 | A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of t | MEDIUM | 5.5 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-92003 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API auth | MEDIUM | 6.9 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-57581 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applic | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-86000 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, the selector parser in src | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-90513 | A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue | MEDIUM | 6.9 | 38% | EPSS 38%ile | NVD | 2026-09-13 |
| CVE-2026-86861 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested pat | MEDIUM | 6.0 | 38% | EPSS 38%ile | NVD | 2026-09-17 |
| CVE-2026-59823 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.9, an authenticated | MEDIUM | 5.3 | 38% | EPSS 38%ile | NVD | 2026-09-16 |
| CVE-2026-92879 | A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/ | MEDIUM | 5.3 | 37% | EPSS 37%ile | NVD | 2026-09-17 |
| CVE-2026-20283 | A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbi | MEDIUM | 6.5 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-40535 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synolo | MEDIUM | 6.5 | 37% | EPSS 37%ile | NVD | 2026-09-18 |
| CVE-2026-90526 | A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unk | MEDIUM | 5.5 | 37% | EPSS 37%ile | NVD | 2026-09-13 |
| CVE-2026-15797 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress | MEDIUM | 6.4 | 37% | EPSS 37%ile | NVD | 2026-09-18 |
| CVE-2026-90691 | A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The imp | MEDIUM | 5.5 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-90786 | A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the fil | MEDIUM | 5.5 | 37% | EPSS 37%ile | NVD | 2026-09-14 |
| CVE-2026-69215 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware uses unan | MEDIUM | 6.8 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76553 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data | MEDIUM | 6.5 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-81915 | Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::s | MEDIUM | 5.1 | 36% | EPSS 36%ile | NVD | 2026-09-11 |
| CVE-2026-79409 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and th | MEDIUM | 6.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76701 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote | MEDIUM | 5.9 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76694 | A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. | MEDIUM | 6.6 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-76706 | A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated rem | MEDIUM | 5.3 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-84439 | When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields int | MEDIUM | 5.3 | 36% | EPSS 36%ile | NVD | 2026-09-16 |
| CVE-2026-83097 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | MEDIUM | 6.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-90584 | A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFr | MEDIUM | 5.5 | 36% | EPSS 36%ile | NVD | 2026-09-13 |
| CVE-2026-90784 | A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of | MEDIUM | 5.5 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-90785 | A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/comp | MEDIUM | 5.5 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-91855 | A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality o | MEDIUM | 5.5 | 36% | EPSS 36%ile | NVD | 2026-09-15 |
| CVE-2026-84524 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 4.3 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-84179 | Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and retu | MEDIUM | 6.5 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-82433 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level author | MEDIUM | 6.5 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-47256 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating | MEDIUM | 5.3 | 36% | EPSS 36%ile | NVD | 2026-09-14 |
| CVE-2026-92936 | vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. | MEDIUM | 6.9 | 35% | EPSS 35%ile | NVD | 2026-09-17 |
| CVE-2026-19662 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send m | MEDIUM | 5.9 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-90840 | A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-54168 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8 | MEDIUM | 6.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-8030 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.3 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-77117 | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the | MEDIUM | 5.9 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-80489 | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the G | MEDIUM | 5.9 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-90516 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown f | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-13 |
| CVE-2026-90701 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-92405 | A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element i | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-92406 | A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown f | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-85652 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio | MEDIUM | 6.5 | 35% | EPSS 35%ile | NVD | 2026-09-18 |
| CVE-2026-90601 | A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_serv | MEDIUM | 6.9 | 35% | EPSS 35%ile | NVD | 2026-09-13 |
| CVE-2026-90881 | A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog. | MEDIUM | 5.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-28966 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 4.3 | 35% | EPSS 35%ile | NVD | 2026-09-14 |
| CVE-2026-92803 | LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated acc | MEDIUM | 6.9 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-56831 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts neg | MEDIUM | 6.5 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-20120 | A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adapt | MEDIUM | 5.8 | 35% | EPSS 35%ile | NVD | 2026-09-16 |
| CVE-2026-82837 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.1.8, 19.2 before 19.2.6, and | MEDIUM | 5.3 | 35% | EPSS 35%ile | NVD | 2026-09-15 |
| CVE-2026-90582 | A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file s | MEDIUM | 5.5 | 34% | EPSS 34%ile | NVD | 2026-09-13 |
| CVE-2026-93310 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect | MEDIUM | 5.5 | 34% | EPSS 34%ile | NVD | 2026-09-18 |
| CVE-2026-84501 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a cra | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-75029 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SO | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-19668 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular k | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-84397 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low- | MEDIUM | 5.4 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-83458 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON). Supported versions that are affecte | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-83459 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart). Supported versio | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-84596 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Go | MEDIUM | 6.5 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-55946 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut | MEDIUM | 6.1 | 34% | EPSS 34%ile | NVD | 2026-09-17 |
| CVE-2026-84536 | An integer underflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-90787 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is | MEDIUM | 5.5 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-92416 | A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_repo | MEDIUM | 5.3 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-47780 | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and H | MEDIUM | 6.9 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-76558 | The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database | MEDIUM | 6.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-84088 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link s | MEDIUM | 6.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-86784 | The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration befo | MEDIUM | 6.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-92140 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in | MEDIUM | 6.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-64684 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransp | MEDIUM | 6.8 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-43787 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS | MEDIUM | 5.9 | 34% | EPSS 34%ile | NVD | 2026-09-14 |
| CVE-2026-92081 | fastify is a fast and low-overhead web framework for Node.js. In versions before 5.12.5, when a route registers a respon | MEDIUM | 5.9 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-87793 | The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica. | MEDIUM | 5.1 | 34% | EPSS 34%ile | NVD | 2026-09-15 |
| CVE-2026-88255 | Improper Validation of Unsafe Equivalence in Input in ZenHive mpp allows an unauthenticated remote client to pass the Te | MEDIUM | 6.3 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-89186 | Use of Cache Containing Sensitive Information in ZenHive mpp allows a shared HTTP cache to store a paid response and ser | MEDIUM | 6.3 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-84554 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.9 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-48490 | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in | MEDIUM | 6.9 | 33% | EPSS 33%ile | NVD | 2026-09-11 |
| CVE-2026-90579 | A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http | MEDIUM | 5.5 | 33% | EPSS 33%ile | NVD | 2026-09-13 |
| CVE-2026-90620 | A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted elemen | MEDIUM | 5.5 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-84571 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden | MEDIUM | 4.3 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-54452 | safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the | MEDIUM | 6.3 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-62949 | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to | MEDIUM | 6.5 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-92356 | A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the f | MEDIUM | 5.3 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-92365 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the | MEDIUM | 5.3 | 33% | EPSS 33%ile | NVD | 2026-09-16 |
| CVE-2026-81829 | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by | MEDIUM | 5.3 | 33% | EPSS 33%ile | NVD | 2026-09-17 |
| CVE-2026-54355 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu | MEDIUM | 5.3 | 33% | EPSS 33%ile | NVD | 2026-09-17 |
| CVE-2026-92002 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exce | MEDIUM | 5.1 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-90819 | A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSe | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-53941 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-91966 | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-68570 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access | MEDIUM | 6.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-53556 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat | MEDIUM | 6.0 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2026-90593 | A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of t | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-13 |
| CVE-2026-92215 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.g | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-43761 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, m | MEDIUM | 6.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-76104 | Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerabi | MEDIUM | 5.5 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-92005 | Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16 | MEDIUM | 5.3 | 32% | EPSS 32%ile | NVD | 2026-09-15 |
| CVE-2026-92790 | Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper t | MEDIUM | 6.9 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-85732 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go a | MEDIUM | 4.7 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-54529 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.p | MEDIUM | 5.3 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-84538 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mac | MEDIUM | 6.5 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-56719 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unaut | MEDIUM | 6.3 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-78474 | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks | MEDIUM | 5.3 | 32% | EPSS 32%ile | NVD | 2026-09-16 |
| CVE-2026-75961 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the | MEDIUM | 4.9 | 32% | EPSS 32%ile | NVD | 2026-09-18 |
| CVE-2026-92976 | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A | MEDIUM | 5.1 | 31% | EPSS 31%ile | NVD | 2026-09-18 |
| CVE-2026-75015 | Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, | MEDIUM | 4.9 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-77883 | Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate | MEDIUM | 4.9 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-58196 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior | MEDIUM | 4.7 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-76556 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values | MEDIUM | 6.8 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-76557 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration | MEDIUM | 6.8 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-76695 | Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways t | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-52819 | Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user a | MEDIUM | 6.3 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-54150 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-vide | MEDIUM | 6.9 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-12759 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-11864 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0 | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83175 | Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-83443 | Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versi | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-90715 | A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the | MEDIUM | 5.5 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-91087 | A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compos | MEDIUM | 5.5 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-86879 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. A r | MEDIUM | 6.5 | 31% | EPSS 31%ile | NVD | 2026-09-14 |
| CVE-2026-20072 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta | MEDIUM | 4.9 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-40536 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology | MEDIUM | 4.3 | 31% | EPSS 31%ile | NVD | 2026-09-18 |
| CVE-2026-55828 | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stric | MEDIUM | 6.0 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-76428 | A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct | MEDIUM | 4.9 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-44282 | Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electio | MEDIUM | 4.8 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-77401 | Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untruste | MEDIUM | 6.8 | 31% | EPSS 31%ile | NVD | 2026-09-16 |
| CVE-2026-89027 | miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downg | MEDIUM | 6.9 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2023-46035 | The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents. | MEDIUM | 5.9 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-76865 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filt | MEDIUM | 6.9 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-76868 | Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a | MEDIUM | 6.9 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-92565 | Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns sched | MEDIUM | 6.9 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-84487 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | MEDIUM | 6.5 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-56830 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() | MEDIUM | 6.5 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-53555 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl | MEDIUM | 5.1 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-87076 | Tanium addressed an information disclosure vulnerability in Discover. | MEDIUM | 6.5 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-77281 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depe | MEDIUM | 6.5 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-83416 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | MEDIUM | 4.3 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-54688 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | MEDIUM | 6.5 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-90806 | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCase | MEDIUM | 5.3 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-53715 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 5.3 | 30% | EPSS 30%ile | NVD | 2026-09-14 |
| CVE-2026-90982 | @fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4 | MEDIUM | 5.3 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2026-20285 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Iden | MEDIUM | 4.3 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-20286 | A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticat | MEDIUM | 4.3 | 30% | EPSS 30%ile | NVD | 2026-09-16 |
| CVE-2026-78427 | The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of | MEDIUM | 4.3 | 30% | EPSS 30%ile | NVD | 2026-09-17 |
| CVE-2021-3030 | Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme G | MEDIUM | 6.1 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-17495 | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 thro | MEDIUM | 5.9 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-52822 | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/times | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-52828 | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportC | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-83347 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are | MEDIUM | 6.5 | 29% | EPSS 29%ile | NVD | 2026-09-15 |
| CVE-2026-91079 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing h | MEDIUM | 6.3 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-65395 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-92774 | Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based acce | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-44235 | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders | MEDIUM | 6.5 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-81917 | Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the | MEDIUM | 5.1 | 29% | EPSS 29%ile | NVD | 2026-09-11 |
| CVE-2026-90816 | A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c o | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-92402 | A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affect | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-85999 | Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.9, selector_iter in src/soups | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-84510 | A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 6.5 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-93013 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadat | MEDIUM | 5.3 | 29% | EPSS 29%ile | NVD | 2026-09-17 |
| CVE-2026-43687 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-90543 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a mis | MEDIUM | 6.9 | 28% | EPSS 28%ile | NVD | 2026-09-12 |
| CVE-2026-76426 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct | MEDIUM | 4.9 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-90569 | A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopic | MEDIUM | 4.8 | 28% | EPSS 28%ile | NVD | 2026-09-13 |
| CVE-2026-90570 | A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function Adm | MEDIUM | 4.8 | 28% | EPSS 28%ile | NVD | 2026-09-13 |
| CVE-2026-86882 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-16702 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-81911 | Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_templ | MEDIUM | 5.8 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-89064 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versi | MEDIUM | 5.3 | 28% | EPSS 28%ile | NVD | 2026-09-17 |
| CVE-2026-81918 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A us | MEDIUM | 4.8 | 28% | EPSS 28%ile | NVD | 2026-09-11 |
| CVE-2026-17607 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-18 |
| CVE-2026-19641 | On affected platforms running Arista EOS with password authentication configured, a specially crafted password can creat | MEDIUM | 6.9 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-84635 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-14 |
| CVE-2026-82567 | The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a conn | MEDIUM | 5.3 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-83200 | Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal O | MEDIUM | 6.5 | 28% | EPSS 28%ile | NVD | 2026-09-15 |
| CVE-2026-20248 | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software a | MEDIUM | 6.8 | 28% | EPSS 28%ile | NVD | 2026-09-16 |
| CVE-2026-28934 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoi | MEDIUM | 6.5 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-4036 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in | MEDIUM | 6.5 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-54246 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves clu | MEDIUM | 5.7 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-20350 | A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticat | MEDIUM | 4.7 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-92881 | A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory | MEDIUM | 5.3 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-12739 | The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas | MEDIUM | 4.3 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-90596 | A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_ | MEDIUM | 6.9 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2026-91997 | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always eval | MEDIUM | 6.9 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-89207 | A vulnerability has been identified in WTV676-HB6035 Web Interface (All versions < V3.94), WTV776-HB6035 Web Interface ( | MEDIUM | 6.9 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-44163 | fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0. | MEDIUM | 5.3 | 27% | EPSS 27%ile | NVD | 2026-09-15 |
| CVE-2026-61709 | OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return | MEDIUM | 5.3 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-86870 | A heap buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 6.5 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-90602 | A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is t | MEDIUM | 5.1 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2026-90517 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the | MEDIUM | 5.5 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2026-76427 | A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read | MEDIUM | 4.9 | 27% | EPSS 27%ile | NVD | 2026-09-16 |
| CVE-2026-84526 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 4.3 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-90472 | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively de | MEDIUM | 6.9 | 27% | EPSS 27%ile | NVD | 2026-09-12 |
| CVE-2026-85717 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | MEDIUM | 6.8 | 27% | EPSS 27%ile | NVD | 2026-09-17 |
| CVE-2026-40531 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690 | MEDIUM | 4.3 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-91099 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-76438 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an | MEDIUM | 6.5 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-54594 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/d | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-93296 | MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event Gene | MEDIUM | 5.1 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-13471 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc | MEDIUM | 4.3 | 26% | EPSS 26%ile | NVD | 2026-09-18 |
| CVE-2026-82124 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protect | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-86445 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative templa | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-86447 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-86449 | The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied pos | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-91967 | AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functi | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-90567 | A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function | MEDIUM | 5.1 | 26% | EPSS 26%ile | NVD | 2026-09-13 |
| CVE-2026-53718 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.4 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-49865 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulner | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-11 |
| CVE-2026-90809 | A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_comman | MEDIUM | 6.9 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-73445 | On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may | MEDIUM | 6.9 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-83140 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supporte | MEDIUM | 6.5 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-69206 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records last | MEDIUM | 5.9 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-76448 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-76449 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-16794 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19. | MEDIUM | 4.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-7514 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-76439 | A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-92298 | EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and camp | MEDIUM | 6.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-92141 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attack | MEDIUM | 4.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-54559 | PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c | MEDIUM | 6.9 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-17585 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-12 |
| CVE-2026-92778 | CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-63461 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and fac | MEDIUM | 5.3 | 26% | EPSS 26%ile | NVD | 2026-09-17 |
| CVE-2026-53954 | Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied w | MEDIUM | 4.3 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-54648 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-86338 | Ash field_policies are documented to protect against filter-based information disclosure: when a field the actor may not | MEDIUM | 6.0 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-40532 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1- | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-18 |
| CVE-2026-54254 | Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler | MEDIUM | 5.9 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-81916 | Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the po | MEDIUM | 5.1 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-68535 | Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's vali | MEDIUM | 5.1 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-90782 | S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items | MEDIUM | 6.0 | 25% | EPSS 25%ile | NVD | 2026-09-13 |
| CVE-2026-92217 | A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file | MEDIUM | 5.3 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-78223 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the | MEDIUM | 6.9 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-85718 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | MEDIUM | 5.9 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-12910 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 5.4 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-90443 | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate e | MEDIUM | 5.3 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-57120 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime asse | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-54723 | devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-84597 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, m | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-92927 | A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o | MEDIUM | 5.5 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-86341 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 | MEDIUM | 4.4 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-84519 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-73457 | Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) | MEDIUM | 6.0 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-44202 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListene | MEDIUM | 5.3 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-75017 | The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu | MEDIUM | 4.3 | 25% | EPSS 25%ile | NVD | 2026-09-18 |
| CVE-2026-49463 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom | MEDIUM | 6.5 | 25% | EPSS 25%ile | NVD | 2026-09-11 |
| CVE-2026-90852 | A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx | MEDIUM | 5.5 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-82775 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Cont | MEDIUM | 5.3 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-90707 | A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fall | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-93331 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-18 |
| CVE-2026-54165 | Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click st | MEDIUM | 6.4 | 24% | EPSS 24%ile | NVD | 2026-09-11 |
| CVE-2026-88932 | multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-81565 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0. | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-83109 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Suppo | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-59341 | A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modif | MEDIUM | 4.2 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-91922 | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/pa | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-80225 | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT readin | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-85501 | Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. T | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-54050 | Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/p | MEDIUM | 6.5 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-17628 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account d | MEDIUM | 5.4 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-90568 | A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSor | MEDIUM | 5.1 | 24% | EPSS 24%ile | NVD | 2026-09-13 |
| CVE-2026-90449 | When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party admin | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-11 |
| CVE-2026-90940 | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endp | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-83433 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supp | MEDIUM | 6.5 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-84048 | Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < | MEDIUM | 6.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-18065 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to gain access to sensitive information throu | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-90858 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Af | MEDIUM | 5.5 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-82125 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the mo | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-92915 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/use | MEDIUM | 6.9 | 24% | EPSS 24%ile | NVD | 2026-09-17 |
| CVE-2026-15924 | Zephyr's TLS socket layer in subsys/net/lib/sockets/sockets_tls.c keeps a single process-global array, client_cache, of | MEDIUM | 5.9 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-43677 | An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, | MEDIUM | 6.5 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-84509 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-17586 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img | MEDIUM | 6.4 | 24% | EPSS 24%ile | NVD | 2026-09-18 |
| CVE-2026-16435 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authentication bypass vulnerability when using XD or Int | MEDIUM | 5.9 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-8674 | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search li | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-17 |
| CVE-2026-83480 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket). Supported versions that are af | MEDIUM | 5.3 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-12758 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoi | MEDIUM | 5.4 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-54918 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the a | MEDIUM | 5.3 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-65365 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-76446 | A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific& | MEDIUM | 4.9 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-19619 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 4.7 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-83076 | Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Suppor | MEDIUM | 6.8 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-48987 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-81872 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the go.opentelemetry.io/otel/sdk/lo | MEDIUM | 6.3 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-29810 | CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic. | MEDIUM | 4.3 | 23% | EPSS 23%ile | NVD | 2026-09-13 |
| CVE-2026-88618 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-54604 | OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes | MEDIUM | 5.3 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | MEDIUM | 5.1 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-84564 | An uninitialized memory issue was addressed with improved memory initialization. This issue is fixed in iOS 26.7 and iPa | MEDIUM | 4.3 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-50018 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClie | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-11 |
| CVE-2026-61588 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-77490 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) | MEDIUM | 6.1 | 23% | EPSS 23%ile | NVD | 2026-09-11 |
| CVE-2026-19273 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6_2, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 and IBM Sterling File Gatewa | MEDIUM | 5.4 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-73444 | On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unau | MEDIUM | 5.3 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-43719 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS | MEDIUM | 6.5 | 23% | EPSS 23%ile | NVD | 2026-09-14 |
| CVE-2026-92764 | OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returni | MEDIUM | 5.3 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-54561 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_i | MEDIUM | 6.2 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-92357 | A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-proce | MEDIUM | 5.3 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-84859 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search e | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-85078 | Sanic is an opensource python web server/framework. In version 25.12.0, Sanic's core HTTP/1.1 chunked-body handling does | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-54181 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 5.4 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-82785 | Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a spe | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-91859 | Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because Ca | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-55795 | Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controll | MEDIUM | 6.9 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-93451 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo | MEDIUM | 6.9 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2026-92139 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includin | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-86358 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unau | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-52852 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups a | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-64753 | A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 2 | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-16588 | The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versi | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-73469 | When specific platforms are using Arista EOS with a loose Unicast Reverse Path Forwarding (uRPF) configuration, certain | MEDIUM | 6.9 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-40533 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager ( | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2025-68624 | N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user | MEDIUM | 4.3 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-83441 | Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported | MEDIUM | 6.8 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-92568 | MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-50022 | Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSo | MEDIUM | 5.8 | 22% | EPSS 22%ile | NVD | 2026-09-17 |
| CVE-2026-90509 | A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspec | MEDIUM | 5.5 | 22% | EPSS 22%ile | NVD | 2026-09-13 |
| CVE-2026-90510 | A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceI | MEDIUM | 5.5 | 22% | EPSS 22%ile | NVD | 2026-09-13 |
| CVE-2026-77702 | The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-73191 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is config | MEDIUM | 6.1 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-84532 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.4 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-55863 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-92813 | Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing una | MEDIUM | 6.9 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-90856 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts a | MEDIUM | 5.5 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-92991 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variou | MEDIUM | 5.4 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2026-85198 | The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic S | MEDIUM | 6.5 | 22% | EPSS 22%ile | NVD | 2026-09-12 |
| CVE-2026-90808 | A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._ | MEDIUM | 5.3 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-75523 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati | MEDIUM | 5.9 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-76703 | A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gatewa | MEDIUM | 5.5 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-89020 | MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-11984 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-76559 | The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during t | MEDIUM | 4.1 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-76444 | A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-91101 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-91103 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 5.1 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-20235 | A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view | MEDIUM | 4.9 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-56666 | ZITADEL: Auto-linking by email: IdP-side email verification is not checked | MEDIUM | 4.8 | 21% | EPSS 21%ile | GitHub | 2026-09-11 |
| CVE-2026-49446 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as | MEDIUM | 6.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-82720 | NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs | MEDIUM | 5.9 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-92461 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoin | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-77147 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequa | MEDIUM | 6.5 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-89307 | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject a | MEDIUM | 5.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-13277 | IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By | MEDIUM | 4.7 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-85349 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of board | MEDIUM | 4.3 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-85572 | The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its less | MEDIUM | 4.3 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-83460 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA). Supported versions that are affected | MEDIUM | 6.5 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2024-11222 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 1 | MEDIUM | 6.4 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-62132 | Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions. | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-11 |
| CVE-2026-90583 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-13 |
| CVE-2026-75792 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to view administrative use | MEDIUM | 4.3 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2026-88994 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a | MEDIUM | 6.6 | 21% | EPSS 21%ile | NVD | 2026-09-18 |
| CVE-2026-92358 | A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a diff | MEDIUM | 6.4 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-77190 | On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to | MEDIUM | 6.0 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-49462 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom | MEDIUM | 5.3 | 21% | EPSS 21%ile | NVD | 2026-09-11 |
| CVE-2026-92893 | A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an un | MEDIUM | 4.3 | 21% | EPSS 21%ile | NVD | 2026-09-17 |
| CVE-2026-12985 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Re | MEDIUM | 6.8 | 21% | EPSS 21%ile | NVD | 2026-09-14 |
| CVE-2020-15875 | An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the inf | MEDIUM | 5.0 | 21% | EPSS 21%ile | NVD | 2026-09-13 |
| CVE-2026-76858 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused | MEDIUM | 4.8 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-90498 | A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the fi | MEDIUM | 5.5 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-92184 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of th | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-83250 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | MEDIUM | 6.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-55636 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates | MEDIUM | 5.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-76447 | A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-91720 | Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside | MEDIUM | 4.7 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-18515 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Naviga | MEDIUM | 4.3 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-19542 | Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end | MEDIUM | 5.6 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-91982 | Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settin | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-15892 | The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete( | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-16188 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-17576 | The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, | MEDIUM | 6.5 | 20% | EPSS 20%ile | NVD | 2026-09-18 |
| CVE-2026-90841 | A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is a | MEDIUM | 5.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-90981 | The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting | MEDIUM | 6.1 | 20% | EPSS 20%ile | NVD | 2026-09-18 |
| CVE-2026-55591 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in sr | MEDIUM | 5.8 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-15758 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensit | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-73443 | On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-55617 | Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic | MEDIUM | 6.9 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-81303 | A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the | MEDIUM | 6.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-11918 | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mech | MEDIUM | 5.4 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-90527 | A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admi | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-90571 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-92455 | yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, a | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-87028 | Concrete CMS 9 through 9.5.3 did not confirm that a board InstanceItem submitted to the custom-slot preview endpoint bel | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-90977 | The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is e | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-18 |
| CVE-2026-54546 | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22. | MEDIUM | 5.0 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-89141 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Obje | MEDIUM | 6.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-90535 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/a | MEDIUM | 6.3 | 20% | EPSS 20%ile | NVD | 2026-09-12 |
| CVE-2026-14275 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute | MEDIUM | 6.3 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-14276 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute | MEDIUM | 6.3 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-92569 | Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that f | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-92933 | vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the | MEDIUM | 6.9 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-91980 | vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enu | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-87854 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-87896 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-87907 | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints tha | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-92237 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2 | MEDIUM | 6.5 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-91983 | Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails t | MEDIUM | 5.3 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-12751 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML cod | MEDIUM | 5.4 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-52820 | Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-52825 | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/ | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-91726 | Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memo | MEDIUM | 4.7 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-79700 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Pa | MEDIUM | 6.9 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-79701 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Bui | MEDIUM | 6.9 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-91143 | goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated | MEDIUM | 6.9 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-77161 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter | MEDIUM | 6.5 | 19% | EPSS 19%ile | NVD | 2026-09-12 |
| CVE-2026-76696 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduc | MEDIUM | 6.5 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-90876 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is | MEDIUM | 5.5 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-92926 | A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepar | MEDIUM | 5.5 | 19% | EPSS 19%ile | NVD | 2026-09-17 |
| CVE-2026-82782 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sen | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-92255 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by imp | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-89029 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-89030 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to l | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-82437 | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For | MEDIUM | 4.3 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-78227 | NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC | MEDIUM | 6.5 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2023-50462 | An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to veri | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-92458 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-90849 | A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by th | MEDIUM | 5.5 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-13635 | An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1- | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-18 |
| CVE-2026-89321 | Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limite | MEDIUM | 4.3 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-56665 | ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider | MEDIUM | 4.2 | 19% | EPSS 19%ile | GitHub | 2026-09-11 |
| CVE-2026-92249 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter i | MEDIUM | 6.1 | 19% | EPSS 19%ile | NVD | 2026-09-18 |
| CVE-2026-92554 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflecte | MEDIUM | 6.1 | 19% | EPSS 19%ile | NVD | 2026-09-18 |
| CVE-2026-76434 | A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE | MEDIUM | 4.9 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-82191 | Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-15 |
| CVE-2026-91707 | The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5. | MEDIUM | 5.3 | 19% | EPSS 19%ile | NVD | 2026-09-18 |
| CVE-2026-92894 | A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target Loo | MEDIUM | 4.3 | 19% | EPSS 19%ile | NVD | 2026-09-17 |
| CVE-2026-90514 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-90515 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unkn | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-90789 | A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown funct | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-90805 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Th | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-90844 | A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90846 | A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the fi | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90877 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90879 | A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-91004 | A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90848 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component St | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-83251 | Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp | MEDIUM | 6.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-88743 | Bacularis 4.7.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in director tags. | MEDIUM | 6.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-82778 | An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on t | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-86900 | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. M | MEDIUM | 6.5 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-14472 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Co | MEDIUM | 6.4 | 18% | EPSS 18%ile | NVD | 2026-09-18 |
| CVE-2026-53658 | Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP | MEDIUM | 6.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-91851 | Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. Da | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-32599 | Netmaker makes networks with WireGuard. Prior to version 1.5.0, the `sqliteDeleteRecord` function in Netmaker's database | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-54724 | Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalid | MEDIUM | 6.1 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90495 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance- | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-90854 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90855 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown f | MEDIUM | 5.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-69214 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a | MEDIUM | 6.8 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-1759 | Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escala | MEDIUM | 6.5 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90771 | joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function | MEDIUM | 6.3 | 18% | EPSS 18%ile | NVD | 2026-09-13 |
| CVE-2026-82561 | Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a cl | MEDIUM | 5.9 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-92781 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten he | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-85196 | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere ex | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-92214 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/c | MEDIUM | 5.1 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-84518 | This issue was addressed through improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO | MEDIUM | 4.3 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-57115 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the ini | MEDIUM | 6.5 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-52821 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{p | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-52826 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/ | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-90439 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL v | MEDIUM | 6.9 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-65355 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPa | MEDIUM | 4.3 | 18% | EPSS 18%ile | NVD | 2026-09-14 |
| CVE-2026-87267 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-89278 | The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is v | MEDIUM | 5.3 | 18% | EPSS 18%ile | NVD | 2026-09-18 |
| CVE-2026-86475 | The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission aga | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-56592 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a | MEDIUM | 6.5 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-90708 | A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file | MEDIUM | 5.5 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-86823 | The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-40537 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1- | MEDIUM | 4.3 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-85720 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | MEDIUM | 5.9 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-87169 | Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (componen | MEDIUM | 6.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-88976 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0. | MEDIUM | 6.1 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-15396 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requ | MEDIUM | 6.5 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-15634 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty are vulnerable to HTTP requ | MEDIUM | 6.5 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-12749 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent | MEDIUM | 6.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-12750 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent | MEDIUM | 6.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83419 | Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communicat | MEDIUM | 5.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-83488 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security). Supported | MEDIUM | 5.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2025-5802 | The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of use | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-86796 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request befo | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-86800 | The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-16187 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitiv | MEDIUM | 6.5 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-10148 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via m | MEDIUM | 6.4 | 17% | EPSS 17%ile | NVD | 2026-09-12 |
| CVE-2026-15402 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S | MEDIUM | 6.4 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-91993 | Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoin | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-55375 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQuery | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-92754 | PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where th | MEDIUM | 5.3 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-92904 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_ | MEDIUM | 4.3 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-87113 | Tanium addressed an improper access controls vulnerability in Threat Response. | MEDIUM | 6.3 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-76704 | A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticate | MEDIUM | 5.5 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-2380 | On affected platforms running Arista EOS with OpenConfig-related services (i.e., gNMI, gNSI, RESTCONF and NETCONF), sens | MEDIUM | 5.1 | 17% | EPSS 17%ile | NVD | 2026-09-16 |
| CVE-2026-91081 | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-12106 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, | MEDIUM | 6.4 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-10556 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entr | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-76450 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-76451 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a | MEDIUM | 4.9 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-91740 | Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin | MEDIUM | 4.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-70755 | Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File down | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87116 | Tanium addressed a server-side request forgery vulnerability in Threat Response. | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-78318 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. | MEDIUM | 6.1 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-92880 | A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/c | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-91944 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the for | MEDIUM | 5.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-65352 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPad | MEDIUM | 4.3 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-91100 | HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several | MEDIUM | 6.8 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-57570 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-86869 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-90614 | A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_mode | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-92949 | vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowin | MEDIUM | 6.3 | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-79705 | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar arch | MEDIUM | 4.5 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-55847 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js | MEDIUM | 6.1 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-11355 | The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a m | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2024-38639 | An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the | MEDIUM | 4.8 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-91198 | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by una | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-81910 | Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated | MEDIUM | 5.9 | 16% | EPSS 16%ile | NVD | 2026-09-11 |
| CVE-2026-16750 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-90547 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark p | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-89021 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractio | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-54676 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-18120 | Concrete CMS before 9.5.3 exposed a legacy Express entry search endpoint that returned entry result JSON without invokin | MEDIUM | 6.3 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-91962 | FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values fr | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-92622 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode | MEDIUM | 6.4 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-52724 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2 | MEDIUM | 5.8 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-15004 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Sc | MEDIUM | 5.4 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-18441 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I | MEDIUM | 4.3 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-90536 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoin | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-90539 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in t | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-90541 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMen | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-90550 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-77169 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed | MEDIUM | 6.5 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2024-58384 | Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return | MEDIUM | 6.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-87828 | The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-upda | MEDIUM | 5.7 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-69216 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-siz | MEDIUM | 5.4 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-91981 | Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-90473 | msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MA | MEDIUM | 6.9 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-92132 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected i | MEDIUM | 5.4 | 16% | EPSS 16%ile | NVD | 2026-09-16 |
| CVE-2026-78152 | The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the str | MEDIUM | 5.3 | 16% | EPSS 16%ile | NVD | 2026-09-12 |
| CVE-2026-76796 | The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service accepts a file path parame | MEDIUM | 5.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-83354 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha | MEDIUM | 6.3 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-84588 | A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27. Mo | MEDIUM | 6.5 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-88910 | The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauth | MEDIUM | 5.3 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-92714 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inclu | MEDIUM | 6.5 | 15% | EPSS 15%ile | NVD | 2026-09-18 |
| CVE-2026-13276 | IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 | MEDIUM | 6.1 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2023-50459 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for | MEDIUM | 5.4 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2023-50460 | An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticate | MEDIUM | 5.4 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-93395 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc | MEDIUM | 6.9 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-91714 | Observable discrepancy in Fonts in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engi | MEDIUM | 5.3 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-91725 | Observable discrepancy in CSS in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to leak sensitive inform | MEDIUM | 5.3 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-92583 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate | MEDIUM | 6.9 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-90551 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_fr | MEDIUM | 6.9 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-82847 | The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting | MEDIUM | 6.8 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-83532 | The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes b | MEDIUM | 6.8 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-86790 | The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a | MEDIUM | 6.8 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-86788 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the s | MEDIUM | 6.8 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-91011 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites | MEDIUM | 6.8 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-53708 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for M | MEDIUM | 6.6 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-55832 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2 | MEDIUM | 6.1 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-54521 | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP | MEDIUM | 6.1 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-92213 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/we | MEDIUM | 5.1 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-69212 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware stri | MEDIUM | 5.9 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-54613 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | MEDIUM | 5.4 | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-45056 | matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix cli | MEDIUM | 6.9 | 15% | EPSS 15%ile | NVD | 2026-09-11 |
| CVE-2026-15814 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount o | MEDIUM | 6.5 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-5132 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpa | MEDIUM | 6.5 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-84909 | The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scri | MEDIUM | 6.4 | 15% | EPSS 15%ile | NVD | 2026-09-18 |
| CVE-2026-55235 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a r | MEDIUM | 5.9 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-90548 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGalle | MEDIUM | 6.9 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-73436 | On affected platforms running Arista EOS with OSPFv2 and OSPFv2 segment routing configured, a specially crafted OSPFv2 p | MEDIUM | 6.0 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-77753 | The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Ap | MEDIUM | 5.5 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-90486 | A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by th | MEDIUM | 5.3 | 15% | EPSS 15%ile | NVD | 2026-09-12 |
| CVE-2026-90941 | novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that all | MEDIUM | 5.3 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-90957 | Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains | MEDIUM | 5.1 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-54503 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type | MEDIUM | 4.3 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-73497 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0 | MEDIUM | 6.5 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-90820 | A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function Authorizat | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-91744 | Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who ha | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-89031 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records o | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-73245 | Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth | MEDIUM | 6.5 | 14% | EPSS 14%ile | GitHub | 2026-09-17 |
| CVE-2026-16593 | The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them | MEDIUM | 6.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-54248 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and | MEDIUM | 6.5 | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-83077 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp | MEDIUM | 6.4 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81443 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab | MEDIUM | 6.4 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-92561 | The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in | MEDIUM | 6.1 | 14% | EPSS 14%ile | NVD | 2026-09-18 |
| CVE-2026-12742 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted | MEDIUM | 5.4 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-16582 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-92932 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in | MEDIUM | 5.1 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-90467 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESM | MEDIUM | 6.3 | 14% | EPSS 14%ile | NVD | 2026-09-12 |
| CVE-2026-90936 | Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authent | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-81566 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 | MEDIUM | 5.1 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-93379 | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio | MEDIUM | 4.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2023-34854 | HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function. | MEDIUM | 6.6 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-81479 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A | MEDIUM | 5.8 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-55374 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUr | MEDIUM | 4.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-5920 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' para | MEDIUM | 6.4 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-62114 | Unauthenticated Broken Access Control in Passster <= 4.3.13 versions. | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-62140 | Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions. | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-66676 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-74017 | Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-54247 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes | MEDIUM | 4.3 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-91746 | Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin | MEDIUM | 4.3 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-54495 | The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh | MEDIUM | 4.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-83278 | Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j). Supported ver | MEDIUM | 6.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-83491 | Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported | MEDIUM | 6.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-91181 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team obje | MEDIUM | 6.5 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-7208 | Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows aut | MEDIUM | 6.0 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-89138 | The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1. | MEDIUM | 4.3 | 14% | EPSS 14%ile | NVD | 2026-09-18 |
| CVE-2026-73965 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway). Supported versions | MEDIUM | 6.8 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-87253 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client). The supported version th | MEDIUM | 6.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-18555 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Refl | MEDIUM | 6.1 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-76081 | ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permission | MEDIUM | 5.5 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-7884 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 allows a non-privileged user to edit their | MEDIUM | 5.4 | 14% | EPSS 14%ile | NVD | 2026-09-14 |
| CVE-2026-83431 | Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions | MEDIUM | 5.4 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-92973 | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that f | MEDIUM | 5.3 | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-90453 | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Refe | MEDIUM | 5.1 | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-93386 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging soci | MEDIUM | 5.4 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-93383 | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin d | MEDIUM | 4.3 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-93387 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-orig | MEDIUM | 4.3 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-13265 | IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 | MEDIUM | 6.8 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-67071 | HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted proper | MEDIUM | 6.5 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-54642 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored- | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-91942 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns u | MEDIUM | 5.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-88261 | Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3. | MEDIUM | 5.1 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-91019 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payme | MEDIUM | 4.9 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-77689 | The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actua | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-12 |
| CVE-2026-43696 | An authorization issue was addressed with improved entitlement checks. This issue is fixed in macOS Golden Gate 27. An a | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-15412 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attack | MEDIUM | 6.5 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-92133 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API to | MEDIUM | 5.4 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-90884 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v | MEDIUM | 5.4 | 13% | EPSS 13%ile | NVD | 2026-09-18 |
| CVE-2026-76863 | Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth pl | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-90976 | The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an acco | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-18 |
| CVE-2026-92627 | A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a | MEDIUM | 4.6 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-92131 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to | MEDIUM | 4.2 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-90455 | A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later revert | MEDIUM | 6.3 | 13% | EPSS 13%ile | NVD | 2026-09-11 |
| CVE-2026-90450 | The application's role-authorization lookup defaults to granting access when a request handler's name is not present in | MEDIUM | 5.3 | 13% | EPSS 13%ile | NVD | 2026-09-11 |
| CVE-2026-85188 | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Condition | MEDIUM | 6.9 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-91991 | Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary | MEDIUM | 6.3 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-54643 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph | MEDIUM | 5.4 | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-91742 | Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging | MEDIUM | 4.8 | 13% | EPSS 13%ile | NVD | 2026-09-15 |
| CVE-2026-13407 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted throu | MEDIUM | 5.4 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-12765 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-12767 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthentic | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-93385 | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informat | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-69211 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-inf | MEDIUM | 4.8 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-86348 | Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenti | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-86349 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-90534 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/no | MEDIUM | 6.1 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-84600 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS | MEDIUM | 5.4 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-16189 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to inject forged log entries into the server | MEDIUM | 4.8 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-43674 | An authentication issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27. An at | MEDIUM | 4.6 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-29812 | CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list. | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-13 |
| CVE-2026-90546 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the li | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-90538 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in pl | MEDIUM | 6.9 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-27378 | Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions. | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-90790 | A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_not | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-66575 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-74000 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-74002 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-78528 | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-54677 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-79713 | The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page- | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-18 |
| CVE-2026-90935 | Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-92802 | kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-92839 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the applicat | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-18317 | The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to a | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-18 |
| CVE-2026-62597 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-20287 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-52823 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id} | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-11993 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce t | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-12882 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown aut | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-13417 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-55837 | dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_ | MEDIUM | 6.8 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-15650 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S | MEDIUM | 6.4 | 12% | EPSS 12%ile | NVD | 2026-09-18 |
| CVE-2026-81907 | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function | MEDIUM | 6.1 | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89330 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for | MEDIUM | 6.1 | 12% | EPSS 12%ile | NVD | 2026-09-18 |
| CVE-2026-90552 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlist | MEDIUM | 5.3 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-9812 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a pr | MEDIUM | 6.5 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-21822 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handl | MEDIUM | 6.3 | 12% | EPSS 12%ile | NVD | 2026-09-18 |
| CVE-2026-62280 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoin | MEDIUM | 6.1 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-92611 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at | MEDIUM | 4.8 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-54551 | WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2. | MEDIUM | 4.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-73999 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | MEDIUM | 5.4 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-82980 | Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The D | MEDIUM | 6.3 | 11% | EPSS 11%ile | NVD | 2026-09-18 |
| CVE-2026-91984 | Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task' | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90461 | OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is conf | MEDIUM | 6.3 | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-82190 | Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0 | MEDIUM | 6.3 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90446 | An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path o | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-90454 | A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list o | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2025-63842 | A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote | MEDIUM | 5.4 | 11% | EPSS 11%ile | NVD | 2026-09-14 |
| CVE-2026-87916 | The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists st | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-12 |
| CVE-2026-77773 | The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-13 |
| CVE-2026-88995 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-13 |
| CVE-2026-18232 | The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90549 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndr | MEDIUM | 6.9 | 11% | EPSS 11%ile | NVD | 2026-09-12 |
| CVE-2026-92963 | vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL gl | MEDIUM | 6.9 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-11996 | The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Fie | MEDIUM | 6.4 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-16185 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication on an admin console | MEDIUM | 6.4 | 11% | EPSS 11%ile | NVD | 2026-09-14 |
| CVE-2026-80355 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabi | MEDIUM | 5.4 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-40534 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Sy | MEDIUM | 5.4 | 11% | EPSS 11%ile | NVD | 2026-09-18 |
| CVE-2026-91986 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attacke | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-19033 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer | MEDIUM | 6.5 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-87892 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment metho | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-12 |
| CVE-2026-92584 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticat | MEDIUM | 5.3 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-90563 | A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the fil | MEDIUM | 5.1 | 11% | EPSS 11%ile | NVD | 2026-09-13 |
| CVE-2026-87891 | The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when s | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-12 |
| CVE-2026-82985 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolder | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-18 |
| CVE-2026-36989 | A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. | MEDIUM | 5.8 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-82784 | Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* | MEDIUM | 6.9 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-54258 | ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-14855 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all | MEDIUM | 6.4 | 10% | EPSS 10%ile | NVD | 2026-09-18 |
| CVE-2026-75016 | The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's client | MEDIUM | 6.4 | 10% | EPSS 10%ile | NVD | 2026-09-18 |
| CVE-2026-15893 | net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reach | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-91958 | FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo | MEDIUM | 6.9 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-81237 | Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthe | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-91199 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetch | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-91773 | Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-91774 | Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in us | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-92810 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allo | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-55093 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1 | MEDIUM | 6.1 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-73463 | On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured | MEDIUM | 6.0 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90528 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality o | MEDIUM | 5.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90529 | A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of | MEDIUM | 5.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90564 | A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatM | MEDIUM | 5.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-18063 | The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter i | MEDIUM | 6.4 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-62088 | Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-81871 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlplogg | MEDIUM | 6.3 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-21848 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticat | MEDIUM | 5.0 | 10% | EPSS 10%ile | NVD | 2026-09-18 |
| CVE-2026-62113 | Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions. | MEDIUM | 4.3 | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-73437 | On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenti | MEDIUM | 6.5 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-86311 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip | MEDIUM | 6.4 | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92595 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAcc | MEDIUM | 6.0 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-92809 | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authentica | MEDIUM | 5.3 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2025-13533 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an | MEDIUM | 4.4 | 10% | EPSS 10%ile | NVD | 2026-09-18 |
| CVE-2026-90533 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any auth | MEDIUM | 6.0 | 10% | EPSS 10%ile | NVD | 2026-09-12 |
| CVE-2026-76864 | NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_ | MEDIUM | 4.8 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-91146 | Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, a | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-53495 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the | MEDIUM | 6.8 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-20309 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic | MEDIUM | 6.1 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2025-11395 | A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create | MEDIUM | 5.5 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-89267 | starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an emp | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-12 |
| CVE-2026-87894 | The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-12 |
| CVE-2026-87918 | The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-12 |
| CVE-2026-91016 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-87919 | The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its pr | MEDIUM | 4.9 | 9% | EPSS 9%ile | NVD | 2026-09-12 |
| CVE-2026-13623 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Sy | MEDIUM | 4.8 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-85125 | The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebVie | MEDIUM | 5.1 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-76873 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display a | MEDIUM | 5.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-91739 | Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had | MEDIUM | 4.2 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-92082 | By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute for | MEDIUM | 6.3 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-91713 | Missing authorization in Browser in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised t | MEDIUM | 4.2 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-55244 | ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes Bas | MEDIUM | 5.0 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-15609 | The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via | MEDIUM | 6.4 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-93394 | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and | MEDIUM | 6.3 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-55073 | WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restri | MEDIUM | 6.2 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-20290 | A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense ( | MEDIUM | 5.8 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-86898 | A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO | MEDIUM | 5.4 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-92234 | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Res | MEDIUM | 5.1 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-79035 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 | MEDIUM | 6.1 | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2023-51769 | Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages. | MEDIUM | 6.1 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-19941 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an | MEDIUM | 5.9 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-77119 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure deleg | MEDIUM | 5.9 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-82773 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this v | MEDIUM | 5.1 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-82776 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary scri | MEDIUM | 5.1 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-86889 | A certificate validation issue was addressed with improved certificate validation. This issue is fixed in macOS Golden G | MEDIUM | 4.8 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-19857 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress s | MEDIUM | 4.8 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-84522 | A race condition was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may b | MEDIUM | 5.9 | 9% | EPSS 9%ile | NVD | 2026-09-14 |
| CVE-2026-92588 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endp | MEDIUM | 5.9 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-62137 | Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions. | MEDIUM | 5.3 | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-82982 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing | MEDIUM | 4.3 | 8% | EPSS 8%ile | NVD | 2026-09-18 |
| CVE-2026-50166 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2 | MEDIUM | 5.5 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-90893 | MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, set | MEDIUM | 5.1 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-28836 | A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with phy | MEDIUM | 6.1 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-92920 | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain a | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-78415 | IBM Sterling Secure Proxy 6.2.0.0 through 6.2.1.2 could allow a remote authenticated attacker to perform UI spoofing and | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-55226 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-68526 | Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concret | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-91772 | Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate t | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-92587 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relativ | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-92921 | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivatio | MEDIUM | 6.9 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-16147 | The ITE IT82xx2 USB device-controller driver (drivers/usb/udc/udc_it82xx2.c) mishandles multi-packet OUT transfers on no | MEDIUM | 6.8 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-14986 | The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGE | MEDIUM | 6.8 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-87252 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server). The supported ve | MEDIUM | 6.8 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-15887 | IBM WebSphere Application Server 9.0, and 8.5 is affected by blind server-side request forgery when processing SOAP requ | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-50025 | Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mous | MEDIUM | 6.9 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-85131 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk a | MEDIUM | 6.5 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-39038 | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (tru | MEDIUM | 6.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-11757 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Tec | MEDIUM | 6.1 | 8% | EPSS 8%ile | NVD | 2026-09-18 |
| CVE-2026-78301 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker in | MEDIUM | 5.8 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-16186 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-12766 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticat | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-87959 | The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI | MEDIUM | 5.4 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90922 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported b | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-91015 | The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX actio | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-76867 | Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT conf | MEDIUM | 5.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-76872 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL man | MEDIUM | 5.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-92257 | Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages t | MEDIUM | 5.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-48737 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/p | MEDIUM | 4.9 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-4103 | Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered w | MEDIUM | 6.4 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-64756 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden | MEDIUM | 5.5 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-90781 | alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes o | MEDIUM | 4.8 | 8% | EPSS 8%ile | NVD | 2026-09-13 |
| CVE-2026-73451 | On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Vi | MEDIUM | 6.3 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-81912 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard | MEDIUM | 5.7 | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-90545 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the co | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-12 |
| CVE-2026-92360 | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of | MEDIUM | 5.3 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-62135 | Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions. | MEDIUM | 5.3 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-62136 | Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 vers | MEDIUM | 5.3 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-65382 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m | MEDIUM | 5.5 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-14311 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and | MEDIUM | 5.4 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-54907 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy | MEDIUM | 5.3 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92581 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowin | MEDIUM | 5.3 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-89332 | Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version | MEDIUM | 6.7 | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-86885 | An input validation issue was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27. An | MEDIUM | 6.5 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-19543 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input valid | MEDIUM | 6.2 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-65407 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, i | MEDIUM | 5.5 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-83198 | Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supporte | MEDIUM | 5.4 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-83346 | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Suppo | MEDIUM | 5.4 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-91857 | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affec | MEDIUM | 5.3 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-63225 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the spl | MEDIUM | 4.4 | 7% | EPSS 7%ile | NVD | 2026-09-16 |
| CVE-2026-81441 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio | MEDIUM | 4.0 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-56590 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c | MEDIUM | 6.4 | 7% | EPSS 7%ile | NVD | 2026-09-18 |
| CVE-2024-23176 | An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss | MEDIUM | 5.4 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-89268 | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping | MEDIUM | 5.1 | 7% | EPSS 7%ile | NVD | 2026-09-12 |
| CVE-2026-93454 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu | MEDIUM | 5.1 | 7% | EPSS 7%ile | NVD | 2026-09-18 |
| CVE-2026-80072 | The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redi | MEDIUM | 4.7 | 7% | EPSS 7%ile | NVD | 2026-09-13 |
| CVE-2026-84489 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iO | MEDIUM | 5.5 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-90931 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated | MEDIUM | 5.1 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-82769 | Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary s | MEDIUM | 4.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-82771 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary scri | MEDIUM | 4.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-66608 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= | MEDIUM | 6.4 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-65380 | An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fix | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-92259 | Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the by | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-15923 | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O l | MEDIUM | 4.6 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-16148 | The ITE it82xx2 USB device-controller driver initialized its bus-suspend detection work with k_work_init_delayable(&priv | MEDIUM | 4.6 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-57442 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, | MEDIUM | 6.9 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-86890 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27. | MEDIUM | 4.6 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-76707 | A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view s | MEDIUM | 4.3 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-90923 | The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unaut | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-85575 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widg | MEDIUM | 6.4 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-65413 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-84902 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when | MEDIUM | 6.8 | 6% | EPSS 6%ile | NVD | 2026-09-18 |
| CVE-2026-26947 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privileg | MEDIUM | 6.7 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-43664 | This issue was addressed with improved data protection. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPad | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-65405 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26 | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-71568 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requir | MEDIUM | 5.3 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90679 | Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity int | MEDIUM | 4.3 | 6% | EPSS 6%ile | NVD | 2026-09-13 |
| CVE-2026-62110 | Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-62111 | Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-66572 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66573 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66574 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66576 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66577 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66578 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66579 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-66617 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-78294 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-76699 | A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking Edge | MEDIUM | 6.4 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-82767 | Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be exe | MEDIUM | 4.8 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-86472 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3 | MEDIUM | 4.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-86818 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parse | MEDIUM | 4.8 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-57128 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praison | MEDIUM | 4.3 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-55236 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-cre | MEDIUM | 5.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-64714 | A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18. | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-76781 | A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL po | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-81868 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati | MEDIUM | 6.5 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-84517 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 5.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90485 | A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IUReg | MEDIUM | 5.4 | 6% | EPSS 6%ile | NVD | 2026-09-12 |
| CVE-2026-91819 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-sec | MEDIUM | 6.9 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-84537 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, | MEDIUM | 6.6 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2024-53922 | An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. L | MEDIUM | 5.7 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-28899 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-65377 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-84523 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-90540 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListA | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-12 |
| CVE-2026-90544 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the vi | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-12 |
| CVE-2026-92585 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-92586 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the se | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-92589 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-49439 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoin | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-49992 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request for | MEDIUM | 6.3 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-65408 | An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 2 | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-84552 | The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadO | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-86910 | A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequ | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-92579 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without | MEDIUM | 5.3 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-2585 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para | MEDIUM | 6.4 | 5% | EPSS 5%ile | NVD | 2026-09-18 |
| CVE-2026-84541 | An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mac | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-61589 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to | MEDIUM | 6.3 | 5% | EPSS 5%ile | NVD | 2026-09-16 |
| CVE-2026-45057 | matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matri | MEDIUM | 4.9 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-84570 | A logic issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS | MEDIUM | 4.4 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-43737 | An authorization issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 a | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-82788 | Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be | MEDIUM | 5.1 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2025-24890 | gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats r | MEDIUM | 6.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-65402 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, i | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-88993 | The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it | MEDIUM | 6.8 | 5% | EPSS 5%ile | NVD | 2026-09-18 |
| CVE-2026-82920 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-84513 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-78547 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app f | MEDIUM | 4.4 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-62134 | Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-87797 | The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-12 |
| CVE-2026-14259 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board crea | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-14344 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board- | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-91010 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-87829 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-87831 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate t | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-77170 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va | MEDIUM | 4.3 | 5% | EPSS 5%ile | NVD | 2026-09-18 |
| CVE-2026-28968 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-83279 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-93493 | A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by prov | MEDIUM | 5.9 | 5% | EPSS 5%ile | NVD | 2026-09-18 |
| CVE-2026-89172 | Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052 | MEDIUM | 5.6 | 5% | EPSS 5%ile | NVD | 2026-09-12 |
| CVE-2026-43762 | The issue was addressed with improved checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionO | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-84534 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an | MEDIUM | 5.5 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-82792 | Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vu | MEDIUM | 4.8 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-87248 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor | MEDIUM | 6.7 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-55846 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP ser | MEDIUM | 6.2 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-65376 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82764 | Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page wh | MEDIUM | 5.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-78546 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: bef | MEDIUM | 4.8 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-47215 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4. | MEDIUM | 4.8 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-89038 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co | MEDIUM | 6.9 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-28933 | A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-12763 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context | MEDIUM | 4.2 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-85009 | The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on | MEDIUM | 6.5 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-75944 | A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the Acl | MEDIUM | 5.6 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-43808 | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, m | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84540 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84593 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 27 and iPadOS 27. An ap | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-85123 | The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stor | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-85350 | The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-87966 | The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauth | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-87965 | The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appoi | MEDIUM | 4.8 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-75025 | Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict serv | MEDIUM | 4.7 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-73449 | On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured wi | MEDIUM | 5.9 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-43741 | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-88798 | The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-65404 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7. | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-86878 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27. An app may | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84906 | The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is appli | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-87860 | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that c | MEDIUM | 4.3 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-65411 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-90542 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access li | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-12 |
| CVE-2026-43788 | An integer overflow was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27. Processin | MEDIUM | 6.6 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-87282 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 6.0 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-87285 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 6.0 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-43785 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84560 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS | MEDIUM | 6.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-91021 | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share ren | MEDIUM | 5.4 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-50604 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The | MEDIUM | 4.9 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-18251 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper validation of | MEDIUM | 4.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-18151 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race c | MEDIUM | 4.2 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-87278 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 6.1 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-65403 | This issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, ma | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84491 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-86911 | This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app ma | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-91201 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82781 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary scr | MEDIUM | 5.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82795 | SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vuln | MEDIUM | 5.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82796 | SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, | MEDIUM | 5.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84551 | A logic issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, | MEDIUM | 4.4 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-48496 | OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages | MEDIUM | 6.2 | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-84624 | A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-85657 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu | MEDIUM | 5.4 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-85104 | In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation | MEDIUM | 5.3 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields | MEDIUM | 5.1 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-82763 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerabili | MEDIUM | 4.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-82790 | Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY | MEDIUM | 4.8 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84569 | An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in mac | MEDIUM | 5.5 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-88764 | The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal pay | MEDIUM | 5.4 | 4% | EPSS 4%ile | NVD | 2026-09-13 |
| CVE-2026-90984 | The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch | MEDIUM | 5.8 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-81320 | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log lev | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-50291 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-54689 | mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through | MEDIUM | 6.3 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-84622 | A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26 | MEDIUM | 6.2 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-18069 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain ownership of arbitrary file system objects due to a | MEDIUM | 6.0 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-54586 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mp | MEDIUM | 6.0 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-65406 | A logic issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84514 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84583 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84621 | An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-87280 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 4.2 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-54633 | PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col | MEDIUM | 6.9 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-93376 | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social en | MEDIUM | 6.3 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-44940 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecu | MEDIUM | 5.7 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-65369 | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-86897 | This issue was addressed with additional entitlement checks. This issue is fixed in Safari 27, iOS 26.7 and iPadOS 26.7, | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-85641 | The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user las | MEDIUM | 4.3 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2023-45023 | The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the | MEDIUM | 4.2 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-23792 | An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, | MEDIUM | 4.0 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2022-42917 | In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the config | MEDIUM | 6.7 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-91786 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to vali | MEDIUM | 6.1 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-84576 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Ta | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-86886 | A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-55650 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 | MEDIUM | 4.4 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-62138 | Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions. | MEDIUM | 6.5 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-62133 | Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions. | MEDIUM | 5.4 | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2024-27123 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit t | MEDIUM | 5.2 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-54565 | rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e | MEDIUM | 4.7 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-79699 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. v | MEDIUM | 4.4 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-87279 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 6.1 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-84527 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Ga | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-10542 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel a | MEDIUM | 5.0 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84586 | An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 2 | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-86902 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84533 | A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS G | MEDIUM | 5.3 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-65383 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27. An app may bypass Gatekeeper | MEDIUM | 4.4 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-77955 | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) | MEDIUM | 4.4 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-82783 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker | MEDIUM | 4.1 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-92615 | A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-reposito | MEDIUM | 6.6 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-77164 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta | MEDIUM | 6.2 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-65345 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-65393 | A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An ap | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84521 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, i | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-84555 | An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-81869 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.10.0 until 1.33.0, the sdk/trace/span.go attr | MEDIUM | 5.1 | 3% | EPSS 3%ile | NVD | 2026-09-16 |
| CVE-2026-84589 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27. An app may | MEDIUM | 5.5 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-90557 | Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processin | MEDIUM | 6.9 | 2% | EPSS 2%ile | NVD | 2026-09-12 |
| CVE-2026-81447 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerabil | MEDIUM | 6.8 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-88819 | In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID. | MEDIUM | 6.3 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-65348 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-81326 | QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the aff | MEDIUM | 6.8 | 2% | EPSS 2%ile | NVD | 2026-09-16 |
| CVE-2026-84525 | A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84567 | The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84585 | A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app ma | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-65409 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84559 | A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84612 | An authorization issue was addressed with improved access control. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-19280 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth | MEDIUM | 5.2 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84531 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 27 and iPadOS 27, m | MEDIUM | 6.2 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84573 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Ta | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84587 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Golden Gate 27, macOS Sequo | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84558 | A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app m | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84602 | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and i | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-86883 | A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27. | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84619 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, m | MEDIUM | 6.1 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-86892 | This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-83274 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-17047 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper req | MEDIUM | 5.4 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-48785 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix | MEDIUM | 4.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-88912 | The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changin | MEDIUM | 4.2 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-90994 | A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, | MEDIUM | 4.0 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-89329 | A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this | MEDIUM | 6.2 | 2% | EPSS 2%ile | NVD | 2026-09-11 |
| CVE-2026-54575 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used ra | MEDIUM | 5.8 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-84628 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-65399 | A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 a | MEDIUM | 4.4 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-19504 | Fabric.js loadFromJSON Server-Side Request Forgery Vulnerability. This vulnerability allows remote attackers to disclose | MEDIUM | 4.0 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-25261 | Memory corruption while processing rear sensor IOCTL calls. | MEDIUM | 6.7 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-43695 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84556 | An authorization issue was addressed with improved access control. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84603 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, visionOS 27 | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84618 | A permissions issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 1 | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-86903 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 27 and iPadOS 27, macOS G | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84574 | A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Seq | MEDIUM | 4.4 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-55102 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src | MEDIUM | 5.8 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-28937 | This issue was addressed through improved state management. This issue is fixed in macOS Golden Gate 27. An app may be a | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-65361 | This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Ta | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-86876 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26. | MEDIUM | 5.2 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90554 | vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video | MEDIUM | 6.9 | 2% | EPSS 2%ile | NVD | 2026-09-12 |
| CVE-2026-84023 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy | MEDIUM | 6.5 | 2% | EPSS 2%ile | NVD | 2026-09-12 |
| CVE-2026-76702 | A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local | MEDIUM | 5.8 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-86924 | A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-87275 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 4.6 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-87283 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 6.0 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-65353 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.6 and iPadOS 26.6, ma | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84616 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84617 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | MEDIUM | 5.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-78296 | Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. | MEDIUM | 5.3 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-90955 | Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user ac | MEDIUM | 4.6 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-91826 | Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to | MEDIUM | 4.4 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2025-36591 | Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken o | MEDIUM | 4.4 | 2% | EPSS 2%ile | NVD | 2026-09-16 |
| CVE-2026-90996 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to th | MEDIUM | 4.0 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84615 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-84636 | An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, tvOS 2 | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-86884 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-84492 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-87274 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | MEDIUM | 4.4 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-90995 | A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Plug | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-43690 | A race condition was addressed with improved locking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, m | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-86909 | A logic issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app may be a | MEDIUM | 4.4 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-16726 | Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows attackers to stop Windows. | MEDIUM | 6.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2025-70819 | Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as | MEDIUM | 6.3 | 1% | EPSS 1%ile | NVD | 2026-09-13 |
| CVE-2026-92758 | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive | MEDIUM | 5.7 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-84601 | A permissions issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. An app ma | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-74005 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | MEDIUM | 5.4 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-65358 | A race condition was addressed with improved state handling. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden G | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-84630 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-92138 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callb | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-16 |
| CVE-2026-90463 | A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec | MEDIUM | 4.0 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-56975 | In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (pr | MEDIUM | 6.5 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-89050 | The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the confi | MEDIUM | 4.3 | 1% | EPSS 1%ile | NVD | 2026-09-13 |
| CVE-2026-58767 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th | MEDIUM | 6.7 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-54576 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used | MEDIUM | 5.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-54587 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE | MEDIUM | 5.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-48722 | Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth lo | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-86824 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy a | MEDIUM | 4.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-91009 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation an | MEDIUM | 4.3 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-23788 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DR | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-86443 | Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an | MEDIUM | 6.9 | 1% | EPSS 1%ile | NVD | 2026-09-16 |
| CVE-2026-86905 | This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate | MEDIUM | 5.5 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-62139 | Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions. | MEDIUM | 4.3 | 1% | EPSS 1%ile | NVD | 2026-09-11 |
| CVE-2026-84024 | The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowin | MEDIUM | 4.3 | 1% | EPSS 1%ile | NVD | 2026-09-12 |
| CVE-2026-33964 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occ | MEDIUM | 6.4 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-84550 | A race condition was addressed with additional validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15 | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-90890 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. | MEDIUM | 6.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-64717 | A race condition was addressed with improved state handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS | MEDIUM | 6.3 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-73465 | On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear tex | MEDIUM | 6.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-73466 | On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to lo | MEDIUM | 6.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-73467 | On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal A | MEDIUM | 6.0 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-91717 | Missing authorization in Android in Google Chrome on on Android prior to 153.0.8010.47 allowed a local attacker to obtai | MEDIUM | 5.1 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-33957 | An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory fro | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-90457 | The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one au | MEDIUM | 6.9 | 1% | EPSS 1%ile | NVD | 2026-09-11 |
| CVE-2026-65360 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and | MEDIUM | 4.7 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-23787 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26 | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-23790 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26 | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-23791 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26 | MEDIUM | 4.2 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-90452 | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exch | MEDIUM | 6.0 | 0% | EPSS 0%ile | NVD | 2026-09-11 |
| CVE-2026-65401 | A race condition was addressed with improved state handling. This issue is fixed in macOS Golden Gate 27, macOS Tahoe 26 | MEDIUM | 5.5 | 0% | EPSS 0%ile | NVD | 2026-09-14 |
| CVE-2026-90891 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authe | MEDIUM | 6.8 | 0% | EPSS 0%ile | NVD | 2026-09-14 |
| CVE-2026-88922 | The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decomp | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55302 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56979 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0186 | In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0187 | In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the c | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55304 | In addr_remap_address_map of remap.c, there is a possible escalation of privilege due to a logic error in the code. This | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56889 | In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escala | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56973 | In multiple locations, there is a possible escalation of privilege due to a logic error in the code. This could lead to | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58726 | In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to l | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58751 | In multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58755 | In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the cod | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56888 | In multiple locations, there is a possible permission bypass due to side channel information disclosure. This could lead | MEDIUM | 6.2 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-84562 | A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.6. An app may be able t | MEDIUM | 4.7 | 0% | EPSS 0%ile | NVD | 2026-09-14 |
| CVE-2026-0179 | In Bootloader, there is a possible permission bypass due to a missing permission check. This could lead to local escalat | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0192 | In Bootloader, there is a possible escalation of privilege due to a missing permission check. This could lead to local e | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55317 | In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55332 | In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to loca | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-55365 | In multiple functions of remap.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could l | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56879 | In gmc_mb_msg_handler of gmc_mba.c, there is a possible memory corruption due to a confused deputy. This could lead to l | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56907 | In VPU, there is a possible shared memory overwrite due to improper input validation. This could lead to local escalatio | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56922 | In CPM, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56932 | In Trusted Execution Environment, there is a possible memory corruption due to improper input validation. This could lea | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56972 | In multiple locations, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to loca | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56989 | In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local e | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56992 | In multiple files, there is a possible permission bypass due to a confused deputy. This could lead to local escalation o | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-57035 | In multiple locations, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local e | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-57042 | In multiple functions of DreamPickerReceiver.kt, there is a possible permission bypass due to a confused deputy. This co | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58698 | In ap_pmic_poll_msg_handler of ap_pmic_ipc.c, there is a possible permission bypass due to a confused deputy. This could | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58718 | In smmu_detach_dev_nested of arm-smmu-v3.c, there is a possible escalation of privilege due to improper input validation | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58739 | In platform_msg_handler_init of default_msg_handlers.c, there is a possible confused deputy due to a confused deputy. Th | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58747 | In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58765 | In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of p | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56892 | In ReadDataElement of common.c, there is a possible information disclosure due to an incorrect bounds check. This could | MEDIUM | 6.2 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58731 | In multiple functions of physmem_extmem_linux.c, there is a possible out-of-bounds read due to uninitialized data. This | MEDIUM | 6.2 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-50603 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The | MEDIUM | 4.9 | 0% | EPSS 0%ile | NVD | 2026-09-17 |
| CVE-2026-0177 | In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This cou | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0183 | In CPM, there is a possible information disclosure due to a confused deputy. This could lead to local information disclo | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-0197 | In VPU, there is a possible information dislclosure due to a logic error in the code. This could lead to local informati | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56950 | In validate_ns_buf of mbu_class.rs, there is a possible information disclosure due to improper input validation. This co | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-57006 | In acfw_ffa.c, there is a possible secret read due to a logic error in the code. This could lead to local information di | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58721 | In multiple locations, there is a possible information disclosure due to uninitialized memory use. This could lead to lo | MEDIUM | 4.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-93604 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-77960 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-93338 | Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows una | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-93559 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-77396 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-93751 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon | MEDIUM | 6.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-92756 | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this prov | MEDIUM | 6.8 | 0% | EPSS 0%ile | NVD | 2026-09-17 |
| CVE-2026-92757 | Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may in | MEDIUM | 6.8 | 0% | EPSS 0%ile | NVD | 2026-09-17 |
| CVE-2026-75883 | The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up t | MEDIUM | 6.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-93689 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device contro | MEDIUM | 6.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-61794 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida | MEDIUM | 6.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-61795 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU | MEDIUM | 6.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-64847 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri | MEDIUM | 6.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-58716 | In multiple locations, there is a possible time-of-check to time-of-use due to a race condition. This could lead to loca | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-58773 | In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This co | MEDIUM | 6.7 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-81627 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem | MEDIUM | 6.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-81946 | PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use | MEDIUM | 6.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-93561 | Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-62282 | OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93566 | ### Summary Netty skips strict chunk size line validation when the line has no chunk extension (`;`), so a chunk size l | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93573 | Netty split Transfer-Encoding fields bypass final-chunked validation and enable request smuggling | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2025-33141 | IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information fr | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-54147 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvid | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-59156 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-84451 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of un | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93579 | A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, s | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-71537 | Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Se | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-77386 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker cou | MEDIUM | 6.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-56915 | In bigo_worker_thread of bigo.c, there is a possible escalation of privilege due to a race condition. This could lead to | MEDIUM | 6.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56923 | In handle_unmap_req of tipc_virtio_dev.c, there is a possible memory corruption due to a race condition. This could lead | MEDIUM | 6.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56964 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation o | MEDIUM | 6.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-56988 | In multiple functions of bluetooth_cco.cc, there is a possible use-after-free due to a race condition. This could lead t | MEDIUM | 6.4 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-93589 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t | MEDIUM | 6.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93590 | ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy chec | MEDIUM | 6.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-79294 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2025-36147 | IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.16 is vulnerable to cross- | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-1025 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-1031 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-1037 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-59181 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-59956 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77606 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77607 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77608 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77609 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77610 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77616 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-84992 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93432 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails | MEDIUM | 6.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93578 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-93602 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onl | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2024-56344 | IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain se | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-10832 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2025-33147 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 could allow an attacker on a shared networ | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2025-36421 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-63405 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher- | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-63406 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemet | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-91147 | A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Serv | MEDIUM | 5.9 | — | — | NVD | 2026-09-18 |
| CVE-2026-56958 | In gf_algo_get_cached_dump_data of gf_algo.c, there is a possible out-of-bounds read due to a missing bounds check. This | MEDIUM | 5.5 | 0% | EPSS 0%ile | NVD | 2026-09-15 |
| CVE-2026-93653 | A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t | MEDIUM | 5.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-63420 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-63635 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-65969 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-92768 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM | MEDIUM | 5.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93685 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti | MEDIUM | 5.4 | — | — | NVD | 2026-09-18 |
| CVE-2025-36178 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass inpu | MEDIUM | 5.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-1029 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro | MEDIUM | 5.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-93492 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93504 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93596 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the Datab | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93597 | ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2025-13882 | IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2025-1350 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitiv | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93506 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/ | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-65970 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93736 | Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated att | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93533 | A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93534 | A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file ap | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-69186 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NS | MEDIUM | 5.3 | — | — | NVD | 2026-09-18 |
| GHSA-pr6h-vr44-xq8j | Obot: MCP Registry API readable without authentication | MEDIUM | 5.3 | — | — | GitHub | 2026-09-18 |
| CVE-2026-93505 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media- | MEDIUM | 5.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-77339 | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen | MEDIUM | 5.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-92745 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met | MEDIUM | 5.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-92747 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running p | MEDIUM | 5.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-28199 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly | MEDIUM | 4.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-93587 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU | MEDIUM | 4.8 | — | — | NVD | 2026-09-18 |
| CVE-2026-16515 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rul | MEDIUM | 4.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-25684 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatio | MEDIUM | 4.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-16514 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2025-36045 | IBM TS4300 1.1.0.1 through 1.7.1.1 could allow an authenticated user to cause a denial of service in the email service d | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2025-36076 | IBM Cognos Analytics 12.1.0 through 12.1.3 FP1, and 12.0.4 through 12.0.4 FP2 stores sensitive information in source cod | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-11537 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the fi | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-1030 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error m | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-84450 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-77385 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core | MEDIUM | 4.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-85511 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oau | MEDIUM | 4.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-10841 | IBM WebSphere Application Server 8.5, 9.0, and Liberty are vulnerable to HTTP request smuggling. | MEDIUM | 4.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-77568 | Mojolicious is a real-time web framework for Perl. Prior to 9.48, the Mojolicious CSRF helpers csrf_field, csrf_token, a | MEDIUM | 4.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-81182 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a | MEDIUM | 4.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-84448 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inli | MEDIUM | 4.0 | — | — | NVD | 2026-09-18 |
| CVE-2026-92382 | CVE-2026-92382 | MEDIUM | — | — | — | Red Hat | 2026-09-17 |
| CVE-2026-90788 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown | LOW | 2.0 | 74% | EPSS 74%ile | NVD | 2026-09-14 |
| CVE-2026-90704 | A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/for | LOW | 2.0 | 74% | EPSS 74%ile | NVD | 2026-09-14 |
| CVE-2026-90705 | A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/forms | LOW | 2.0 | 74% | EPSS 74%ile | NVD | 2026-09-14 |
| CVE-2026-90706 | A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. | LOW | 2.0 | 74% | EPSS 74%ile | NVD | 2026-09-14 |
| CVE-2026-90492 | A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function c | LOW | 2.1 | 73% | EPSS 73%ile | NVD | 2026-09-13 |
| CVE-2026-92993 | A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of | LOW | 2.1 | 72% | EPSS 72%ile | NVD | 2026-09-17 |
| CVE-2026-91853 | A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvp | LOW | 2.1 | 71% | EPSS 71%ile | NVD | 2026-09-15 |
| CVE-2026-90621 | A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the | LOW | 2.1 | 64% | EPSS 64%ile | NVD | 2026-09-14 |
| CVE-2026-90880 | A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /c | LOW | 2.1 | 63% | EPSS 63%ile | NVD | 2026-09-15 |
| CVE-2023-24035 | An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing c | LOW | 3.5 | 54% | EPSS 54%ile | NVD | 2026-09-14 |
| CVE-2026-35867 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LI | LOW | 3.1 | 43% | EPSS 43%ile | NVD | 2026-09-13 |
| CVE-2026-90818 | A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the f | LOW | 2.1 | 42% | EPSS 42%ile | NVD | 2026-09-14 |
| CVE-2026-81637 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim' | LOW | 2.3 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-54649 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr | LOW | 2.1 | 40% | EPSS 40%ile | NVD | 2026-09-17 |
| CVE-2026-90575 | A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login | LOW | 2.9 | 39% | EPSS 39%ile | NVD | 2026-09-13 |
| CVE-2026-44778 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | LOW | 2.9 | 39% | EPSS 39%ile | NVD | 2026-09-15 |
| CVE-2026-55774 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/l | LOW | 2.1 | 38% | EPSS 38%ile | NVD | 2026-09-15 |
| CVE-2026-90795 | A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function o | LOW | 2.1 | 38% | EPSS 38%ile | NVD | 2026-09-14 |
| CVE-2026-92413 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is | LOW | 2.1 | 37% | EPSS 37%ile | NVD | 2026-09-16 |
| CVE-2026-81866 | Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not en | LOW | 0.5 | 34% | EPSS 34%ile | NVD | 2026-09-16 |
| CVE-2026-90572 | A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient | LOW | 2.0 | 34% | EPSS 34%ile | NVD | 2026-09-13 |
| CVE-2026-90521 | A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Th | LOW | 2.1 | 33% | EPSS 33%ile | NVD | 2026-09-13 |
| CVE-2026-90490 | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the compone | LOW | 2.1 | 33% | EPSS 33%ile | NVD | 2026-09-13 |
| CVE-2026-90792 | A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegr | LOW | 2.1 | 33% | EPSS 33%ile | NVD | 2026-09-14 |
| CVE-2026-91091 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of | LOW | 2.1 | 33% | EPSS 33%ile | NVD | 2026-09-15 |
| CVE-2026-45723 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat | LOW | 2.7 | 32% | EPSS 32%ile | NVD | 2026-09-17 |
| CVE-2023-24034 | An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a ma | LOW | 3.1 | 32% | EPSS 32%ile | NVD | 2026-09-14 |
| CVE-2026-18422 | Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in th | LOW | 2.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-81925 | Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages | LOW | 2.1 | 31% | EPSS 31%ile | NVD | 2026-09-15 |
| CVE-2026-91842 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o | LOW | 1.2 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-90520 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa6 | LOW | 2.1 | 30% | EPSS 30%ile | NVD | 2026-09-13 |
| CVE-2026-68534 | Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in sto | LOW | 2.3 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-55775 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities o | LOW | 2.3 | 30% | EPSS 30%ile | NVD | 2026-09-15 |
| CVE-2026-90507 | A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is th | LOW | 2.1 | 29% | EPSS 29%ile | NVD | 2026-09-13 |
| CVE-2026-44162 | fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads | LOW | 2.7 | 29% | EPSS 29%ile | NVD | 2026-09-14 |
| CVE-2026-92385 | A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown fun | LOW | 1.9 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-92527 | A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controll | LOW | 2.1 | 29% | EPSS 29%ile | NVD | 2026-09-16 |
| CVE-2026-93312 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J | LOW | 2.1 | 27% | EPSS 27%ile | NVD | 2026-09-18 |
| CVE-2026-90525 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the f | LOW | 2.1 | 27% | EPSS 27%ile | NVD | 2026-09-13 |
| CVE-2025-26790 | Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memo | LOW | 3.7 | 27% | EPSS 27%ile | NVD | 2026-09-14 |
| CVE-2026-69200 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fiel | LOW | 3.7 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-90793 | A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/ | LOW | 2.1 | 26% | EPSS 26%ile | NVD | 2026-09-14 |
| CVE-2026-91957 | FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread c | LOW | 2.3 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-92418 | A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff | LOW | 2.0 | 26% | EPSS 26%ile | NVD | 2026-09-16 |
| CVE-2026-91086 | A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_proc | LOW | 2.1 | 26% | EPSS 26%ile | NVD | 2026-09-15 |
| CVE-2026-87031 | n Concrete CMS 9.2.0 through 9.5.3, the REST API user creation endpoint (POST /ccm/api/1.0/users, the add() method of co | LOW | 2.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-90574 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of | LOW | 2.1 | 25% | EPSS 25%ile | NVD | 2026-09-13 |
| CVE-2026-90712 | A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file | LOW | 2.1 | 25% | EPSS 25%ile | NVD | 2026-09-14 |
| CVE-2026-92364 | A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown | LOW | 2.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-93311 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun | LOW | 2.1 | 25% | EPSS 25%ile | NVD | 2026-09-18 |
| CVE-2026-85716 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT | LOW | 3.7 | 25% | EPSS 25%ile | NVD | 2026-09-17 |
| CVE-2026-3855 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and | LOW | 3.1 | 25% | EPSS 25%ile | NVD | 2026-09-16 |
| CVE-2026-54450 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior | LOW | 2.9 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-90813 | A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand | LOW | 2.1 | 24% | EPSS 24%ile | NVD | 2026-09-14 |
| CVE-2026-92381 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/ | LOW | 2.0 | 24% | EPSS 24%ile | NVD | 2026-09-16 |
| CVE-2026-91836 | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/sta | LOW | 0.9 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-81926 | Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's dupli | LOW | 2.0 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-81927 | Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processin | LOW | 1.8 | 24% | EPSS 24%ile | NVD | 2026-09-15 |
| CVE-2026-90878 | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/comp | LOW | 2.1 | 23% | EPSS 23%ile | NVD | 2026-09-15 |
| CVE-2026-93307 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll | LOW | 2.1 | 23% | EPSS 23%ile | NVD | 2026-09-17 |
| CVE-2026-93309 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t | LOW | 2.1 | 23% | EPSS 23%ile | NVD | 2026-09-18 |
| CVE-2026-86071 | Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/git | LOW | 3.7 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-86448 | The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serv | LOW | 3.7 | 23% | EPSS 23%ile | NVD | 2026-09-16 |
| CVE-2026-93308 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-18 |
| CVE-2026-92247 | A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename o | LOW | 2.0 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-90687 | A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-90791 | A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the f | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-90794 | A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file sce | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-91089 | A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegrap | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-86089 | Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API | LOW | 2.3 | 22% | EPSS 22%ile | NVD | 2026-09-16 |
| CVE-2026-90807 | A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-14 |
| CVE-2026-18424 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a h | LOW | 2.1 | 22% | EPSS 22%ile | NVD | 2026-09-15 |
| CVE-2026-82126 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the | LOW | 2.7 | 21% | EPSS 21%ile | NVD | 2026-09-16 |
| CVE-2026-18423 | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search p | LOW | 2.1 | 21% | EPSS 21%ile | NVD | 2026-09-15 |
| CVE-2026-49254 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/ro | LOW | 2.9 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-90499 | A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of | LOW | 2.1 | 20% | EPSS 20%ile | NVD | 2026-09-13 |
| CVE-2026-92992 | A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio | LOW | 2.1 | 20% | EPSS 20%ile | NVD | 2026-09-17 |
| CVE-2026-54541 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to | LOW | 3.7 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-54542 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to | LOW | 3.7 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-90615 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unkn | LOW | 2.1 | 20% | EPSS 20%ile | NVD | 2026-09-14 |
| CVE-2026-91854 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the fil | LOW | 2.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-77860 | In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a dou | LOW | 3.7 | 20% | EPSS 20%ile | NVD | 2026-09-16 |
| CVE-2026-91849 | A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /in | LOW | 2.1 | 20% | EPSS 20%ile | NVD | 2026-09-15 |
| CVE-2026-84905 | The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker | LOW | 2.7 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-92221 | A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affecte | LOW | 2.0 | 19% | EPSS 19%ile | NVD | 2026-09-16 |
| CVE-2026-90714 | A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the f | LOW | 2.1 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-90623 | A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the fil | LOW | 2.9 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-90716 | A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of t | LOW | 2.0 | 19% | EPSS 19%ile | NVD | 2026-09-14 |
| CVE-2026-68533 | Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluatin | LOW | 2.3 | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-73440 | On affected platforms running Arista EOS with Simple Network Management Protocol (SNMP) configured, SNMPv3 local or remo | LOW | 2.3 | 18% | EPSS 18%ile | NVD | 2026-09-16 |
| CVE-2026-68530 | Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area | LOW | 2.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-50607 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | LOW | 2.7 | 17% | EPSS 17%ile | NVD | 2026-09-17 |
| CVE-2026-68531 | Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file m | LOW | 2.1 | 17% | EPSS 17%ile | NVD | 2026-09-15 |
| CVE-2026-13683 | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler | LOW | 2.7 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-90796 | A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file | LOW | 2.1 | 17% | EPSS 17%ile | NVD | 2026-09-14 |
| CVE-2026-40538 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager | LOW | 3.7 | 17% | EPSS 17%ile | NVD | 2026-09-18 |
| CVE-2026-93313 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTabl | LOW | 2.1 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-93314 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of t | LOW | 2.1 | 16% | EPSS 16%ile | NVD | 2026-09-18 |
| CVE-2026-91747 | Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rendere | LOW | 3.1 | 16% | EPSS 16%ile | NVD | 2026-09-15 |
| CVE-2026-90491 | A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the fil | LOW | 2.1 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-90581 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpd | LOW | 2.1 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-90815 | A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function set | LOW | 2.1 | 16% | EPSS 16%ile | NVD | 2026-09-14 |
| CVE-2026-90505 | A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the fu | LOW | 1.3 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-90506 | A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts a | LOW | 1.3 | 16% | EPSS 16%ile | NVD | 2026-09-13 |
| CVE-2026-18421 | Concrete CMS 9 through 9.5.2 does not perform an authorization check in three actions of the Boards data source dashboar | LOW | 2.1 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-68529 | Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard act | LOW | 2.1 | 15% | EPSS 15%ile | NVD | 2026-09-15 |
| CVE-2026-90709 | A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the fi | LOW | 2.0 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2026-84907 | The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) paym | LOW | 3.7 | 15% | EPSS 15%ile | NVD | 2026-09-16 |
| CVE-2026-90697 | A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the fi | LOW | 2.1 | 15% | EPSS 15%ile | NVD | 2026-09-14 |
| CVE-2025-64059 | Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is | LOW | 1.8 | 14% | EPSS 14%ile | NVD | 2026-09-13 |
| CVE-2026-91926 | A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE messa | LOW | 3.7 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-83369 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK). Supported versi | LOW | 3.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81922 | Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the | LOW | 2.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-81923 | In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving | LOW | 2.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-92359 | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_a | LOW | 2.3 | 14% | EPSS 14%ile | NVD | 2026-09-16 |
| CVE-2026-18426 | Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control | LOW | 2.0 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-91730 | Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised | LOW | 3.1 | 14% | EPSS 14%ile | NVD | 2026-09-15 |
| CVE-2026-90488 | A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of | LOW | 2.1 | 14% | EPSS 14%ile | NVD | 2026-09-13 |
| CVE-2026-90580 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fi | LOW | 2.1 | 14% | EPSS 14%ile | NVD | 2026-09-13 |
| CVE-2026-90598 | A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2 | LOW | 2.1 | 14% | EPSS 14%ile | NVD | 2026-09-13 |
| CVE-2023-22631 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor. | LOW | 2.7 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2023-22632 | PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor. | LOW | 2.7 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-82019 | TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows u | LOW | 2.3 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2023-32778 | An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload. | LOW | 3.3 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-90812 | A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function chec | LOW | 2.1 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-92814 | changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary marku | LOW | 2.3 | 13% | EPSS 13%ile | NVD | 2026-09-16 |
| CVE-2026-55866 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34 | LOW | 3.7 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2026-25832 | In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadver | LOW | 3.7 | 13% | EPSS 13%ile | NVD | 2026-09-14 |
| CVE-2025-13166 | The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered us | LOW | 3.7 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-46696 | October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 hav | LOW | 3.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-82519 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allow | LOW | 2.3 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-92945 | vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix | LOW | 2.3 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-79300 | SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced | LOW | 3.5 | 12% | EPSS 12%ile | NVD | 2026-09-12 |
| CVE-2026-92130 | Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not set the appropriate context for credentials | LOW | 3.1 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-93384 | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l | LOW | 3.7 | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-85387 | Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the sta | LOW | 2.0 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90518 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-13 |
| CVE-2026-90519 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the f | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-13 |
| CVE-2026-90594 | A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function Per | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-13 |
| CVE-2026-90595 | A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function Online | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-13 |
| CVE-2026-90810 | A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-90814 | A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function git | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-14 |
| CVE-2026-90851 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includ | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-90857 | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown funct | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-91005 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-73442 | On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged i | LOW | 2.1 | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90850 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown function | LOW | 1.9 | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-89327 | The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user th | LOW | 3.8 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-89328 | The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges bef | LOW | 3.8 | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-81921 | Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, w | LOW | 2.3 | 11% | EPSS 11%ile | NVD | 2026-09-15 |
| CVE-2026-90487 | A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the fi | LOW | 2.1 | 11% | EPSS 11%ile | NVD | 2026-09-12 |
| CVE-2026-93378 | Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised t | LOW | 3.1 | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90600 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the f | LOW | 2.1 | 11% | EPSS 11%ile | NVD | 2026-09-13 |
| CVE-2026-90842 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown f | LOW | 2.9 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-90500 | A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90501 | A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.u | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90496 | A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_orde | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90597 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an un | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-13 |
| CVE-2026-90700 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown functi | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-92526 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/ | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90604 | A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-90694 | A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-90695 | A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknow | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-90696 | A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-90835 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-90845 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the | LOW | 2.0 | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-23793 | An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vu | LOW | 3.5 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-33970 | An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 21 | LOW | 3.5 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2023-37252 | An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames th | LOW | 3.1 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2023-37253 | An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppre | LOW | 3.1 | 10% | EPSS 10%ile | NVD | 2026-09-14 |
| CVE-2026-92383 | A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControl | LOW | 2.1 | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-61700 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3 | LOW | 3.7 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-13666 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Man | LOW | 3.5 | 9% | EPSS 9%ile | NVD | 2026-09-18 |
| CVE-2026-19640 | On affected platforms running Arista EOS, an authenticated user with access to the gNMI (gRPC Network Management Interfa | LOW | 2.3 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-90511 | A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerabil | LOW | 2.1 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-81920 | Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The rese | LOW | 2.3 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-90489 | A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobi | LOW | 2.0 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-90497 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functio | LOW | 2.0 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-90502 | A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/ | LOW | 2.0 | 9% | EPSS 9%ile | NVD | 2026-09-13 |
| CVE-2026-93380 | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r | LOW | 3.1 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-68532 | Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in c | LOW | 2.3 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-16592 | The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its sho | LOW | 2.7 | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-87836 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderat | LOW | 2.7 | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-81870 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider em | LOW | 2.0 | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-87026 | Tanium addressed an improper access controls vulnerability in Threat Response. | LOW | 3.8 | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-81439 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A l | LOW | 3.7 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2025-70820 | Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | LOW | 3.5 | 8% | EPSS 8%ile | NVD | 2026-09-13 |
| CVE-2026-49400 | October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, th | LOW | 3.3 | 8% | EPSS 8%ile | NVD | 2026-09-14 |
| CVE-2026-82851 | The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a us | LOW | 2.7 | 8% | EPSS 8%ile | NVD | 2026-09-12 |
| CVE-2026-86407 | The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its member | LOW | 3.7 | 8% | EPSS 8%ile | NVD | 2026-09-13 |
| CVE-2026-86446 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is c | LOW | 3.7 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-81438 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algori | LOW | 3.7 | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-81924 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation featu | LOW | 2.1 | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-54471 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileg | LOW | 3.5 | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-90824 | A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegra | LOW | 1.9 | 7% | EPSS 7%ile | NVD | 2026-09-14 |
| CVE-2026-90577 | A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of | LOW | 1.9 | 7% | EPSS 7%ile | NVD | 2026-09-13 |
| CVE-2026-91723 | Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements | LOW | 3.1 | 7% | EPSS 7%ile | NVD | 2026-09-15 |
| CVE-2026-92962 | vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepare | LOW | 2.1 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-91008 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization | LOW | 3.7 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-75588 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is inte | LOW | 2.6 | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90829 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the f | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-81919 | Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() ac | LOW | 2.3 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-86891 | An authorization issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS | LOW | 3.5 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90599 | A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affec | LOW | 2.1 | 6% | EPSS 6%ile | NVD | 2026-09-13 |
| CVE-2026-91708 | Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the rend | LOW | 3.1 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-90576 | A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of th | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-13 |
| CVE-2026-90578 | A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/lis | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-13 |
| CVE-2026-90622 | A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90825 | A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90827 | A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/b | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-90831 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the fi | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-14 |
| CVE-2026-92472 | A vulnerability was determined in GPAC 26.08-DEV. The affected element is the function gf_node_deactivate_ex of the file | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-92473 | A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src | LOW | 1.9 | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-56597 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe | LOW | 3.1 | 6% | EPSS 6%ile | NVD | 2026-09-18 |
| CVE-2026-18425 | Concrete CMS 9 before 9.5.3 authorized the dashboard sitemap reorder action (Concrete\Controller\Backend\Dashboard\Sitem | LOW | 2.1 | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-52296 | FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in lib | LOW | 2.9 | 5% | EPSS 5%ile | NVD | 2026-09-13 |
| CVE-2026-90830 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of t | LOW | 1.9 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-16190 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability. | LOW | 3.1 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-90826 | A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegrap | LOW | 0.9 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2025-45480 | Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary. | LOW | 3.0 | 5% | EPSS 5%ile | NVD | 2026-09-13 |
| CVE-2026-84025 | The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data b | LOW | 2.2 | 5% | EPSS 5%ile | NVD | 2026-09-12 |
| CVE-2026-54577 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted lo | LOW | 2.0 | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90713 | A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenToke | LOW | 1.9 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-90828 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible | LOW | 1.9 | 5% | EPSS 5%ile | NVD | 2026-09-14 |
| CVE-2026-84903 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password | LOW | 2.7 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-92474 | A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src | LOW | 1.9 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-65371 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 26.6 and iPadOS 26 | LOW | 3.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-84530 | An information disclosure issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadO | LOW | 3.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-56595 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he | LOW | 3.1 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-20071 | A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated | LOW | 3.8 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-87281 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | LOW | 3.2 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-82723 | Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of us | LOW | 1.8 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-81340 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability | LOW | 3.8 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-84904 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform per-object authorization checks on a gro | LOW | 3.8 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-86888 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, macOS Golde | LOW | 3.3 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-50608 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | LOW | 1.2 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-92475 | A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/ut | LOW | 1.9 | 4% | EPSS 4%ile | NVD | 2026-09-16 |
| CVE-2026-87284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th | LOW | 3.2 | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-68493 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships | LOW | 3.1 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-89008 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform an authorization check on o | LOW | 2.7 | 4% | EPSS 4%ile | NVD | 2026-09-18 |
| CVE-2026-77191 | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricte | LOW | 2.1 | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-54579 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without valida | LOW | 2.3 | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-88844 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that the requesting user owns the c | LOW | 2.7 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-89007 | The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.5 does not perform a capability check in one o | LOW | 2.7 | 3% | EPSS 3%ile | NVD | 2026-09-18 |
| CVE-2026-90801 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c | LOW | 1.9 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-12284 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a m | LOW | 3.7 | 3% | EPSS 3%ile | NVD | 2026-09-17 |
| CVE-2026-57583 | OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin | LOW | 3.3 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-91782 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynre | LOW | 1.9 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-91781 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_inde | LOW | 1.9 | 3% | EPSS 3%ile | NVD | 2026-09-15 |
| CVE-2026-75943 | A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the cle | LOW | 2.1 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-75945 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. | LOW | 2.1 | 3% | EPSS 3%ile | NVD | 2026-09-14 |
| CVE-2026-90682 | A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90803 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_ | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-83413 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-71181 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin | LOW | 3.0 | 2% | EPSS 2%ile | NVD | 2026-09-16 |
| CVE-2026-71182 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Lin | LOW | 3.0 | 2% | EPSS 2%ile | NVD | 2026-09-16 |
| CVE-2025-64031 | libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field | LOW | 2.5 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-91090 | A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the f | LOW | 0.9 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-19086 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An auth | LOW | 3.3 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-86887 | A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iP | LOW | 3.3 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2023-24284 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() fun | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2023-24285 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when a | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2023-24287 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command. | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2023-24291 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length par | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-38924 | In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier obser | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-83414 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha | LOW | 2.5 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-90573 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-90611 | A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_man | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-84626 | An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS | LOW | 3.3 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-25827 | An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any res | LOW | 2.3 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-90609 | A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegrap | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90610 | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegrap | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90612 | A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scen | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90613 | A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampl | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90683 | A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/ | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-91779 | A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-91780 | A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file b | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-90804 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_fram | LOW | 0.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-78426 | The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding | LOW | 3.7 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2026-38332 | TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectAre | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-52297 | FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-91088 | A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file | LOW | 2.4 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-55061 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget | LOW | 1.0 | 2% | EPSS 2%ile | NVD | 2026-09-17 |
| CVE-2023-24283 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to | LOW | 2.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90681 | A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c o | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90802 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the | LOW | 1.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90508 | A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability i | LOW | 1.8 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-91835 | A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the | LOW | 0.9 | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-90503 | A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 | LOW | 1.8 | 2% | EPSS 2%ile | NVD | 2026-09-13 |
| CVE-2026-90684 | A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of | LOW | 0.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2026-90685 | A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of t | LOW | 0.9 | 2% | EPSS 2%ile | NVD | 2026-09-14 |
| CVE-2023-24288 | An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via c | LOW | 2.9 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-86893 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 27 and iPadOS 27, tvOS 27, vi | LOW | 3.3 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-54578 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue aft | LOW | 2.0 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-90773 | procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command | LOW | 2.4 | 1% | EPSS 1%ile | NVD | 2026-09-13 |
| CVE-2026-90811 | A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManage | LOW | 1.9 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2023-24286 | Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description | LOW | 2.9 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-82759 | Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audi | LOW | 1.8 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-91017 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming | LOW | 3.7 | 1% | EPSS 1%ile | NVD | 2026-09-17 |
| CVE-2026-86701 | Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its component | LOW | 1.8 | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-33962 | An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-33966 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-33956 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a m | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-33960 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W9 | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-33967 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-33968 | An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2023-37366 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Ex | LOW | 2.8 | 1% | EPSS 1%ile | NVD | 2026-09-14 |
| CVE-2026-23786 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 26 | LOW | 2.8 | 0% | EPSS 0%ile | NVD | 2026-09-14 |
| CVE-2026-50606 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. | LOW | 1.2 | 0% | EPSS 0%ile | NVD | 2026-09-17 |
| CVE-2026-84449 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() | LOW | 3.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-44639 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c | LOW | 3.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-81181 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro | LOW | 3.7 | — | — | NVD | 2026-09-18 |
| CVE-2026-91142 | A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse | LOW | 3.6 | — | — | NVD | 2026-09-18 |
| CVE-2026-81178 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public no | LOW | 3.5 | — | — | NVD | 2026-09-18 |
| CVE-2026-93676 | xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio | LOW | 3.2 | — | — | NVD | 2026-09-18 |
| CVE-2026-21806 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows | LOW | 3.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-16512 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched | LOW | 3.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-85478 | A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical | LOW | 2.4 | — | — | NVD | 2026-09-18 |
| CVE-2026-93588 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re | LOW | 2.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-84400 | CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote d | LOW | 2.3 | — | — | NVD | 2026-09-18 |
| CVE-2026-93586 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau | LOW | 2.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93600 | rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore | LOW | 2.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93601 | rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorr | LOW | 2.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93531 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vu | LOW | 2.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-93532 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf7 | LOW | 2.1 | — | — | NVD | 2026-09-18 |
| CVE-2026-61633 | NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp | LOW | 2.0 | — | — | NVD | 2026-09-18 |
| GHSA-rf68-8gjr-36q7 | Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty | LOW | — | — | — | GitHub | 2026-09-15 |
| CVE-2024-53920 | Emacs arbitrary code execution: incomplete fix for CVE-2024-53920 | UNKNOWN | — | 49% | EPSS 49%ile | OSS-Security | 2026-09-14 |
| CVE-2026-38999 | A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0 | UNKNOWN | — | 43% | EPSS 43%ile | NVD | 2026-09-16 |
| CVE-2026-55630 | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted | NONE | 0.0 | 25% | EPSS 25%ile | NVD | 2026-09-15 |
| CVE-2026-60163 | CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution | UNKNOWN | — | 19% | EPSS 19%ile | OSS-Security | 2026-09-15 |
| CVE-2026-79551 | Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. | UNKNOWN | — | 18% | EPSS 18%ile | NVD | 2026-09-15 |
| CVE-2026-49292 | Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBV | NONE | 0.0 | 18% | EPSS 18%ile | NVD | 2026-09-17 |
| CVE-2026-90169 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: free preauth sessions on connection teardown | UNKNOWN | — | 16% | EPSS 16%ile | NVD | 2026-09-17 |
| CVE-2026-90360 | In the Linux kernel, the following vulnerability has been resolved: regulator: core: use system_freezable_wq for init c | UNKNOWN | — | 15% | EPSS 15%ile | NVD | 2026-09-17 |
| CVE-2026-89575 | In the Linux kernel, the following vulnerability has been resolved: dm raid1: reserve space for NUL-terminator in build | UNKNOWN | — | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-89732 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent deadlock during ep0 read | UNKNOWN | — | 14% | EPSS 14%ile | NVD | 2026-09-11 |
| CVE-2026-90393 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix potential UAF in bpf_netns_link_update_pro | UNKNOWN | — | 14% | EPSS 14%ile | NVD | 2026-09-17 |
| CVE-2026-90198 | In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix use-after-free in snd_card_do_free( | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-90219 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Free debugfs on registration failure c | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-90283 | In the Linux kernel, the following vulnerability has been resolved: hugetlbfs: release subpool on fill_super failure h | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-90314 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: fix OOB read via signed offset in rsc_t | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-89621 | In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: validate report size in mcp2221_raw_e | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-11 |
| CVE-2026-93141 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: r8a66597: avoid double free of ep0_req | UNKNOWN | — | 13% | EPSS 13%ile | NVD | 2026-09-17 |
| CVE-2026-79303 | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-92240 | A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untag | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-15 |
| CVE-2026-93131 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-privacy: Fix race condition Acc | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93136 | In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Fix device refcount leak in the error | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93142 | In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/rcar: Fix error checking in probe() | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90006 | In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: handle damon_stop() failure d | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89749 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix crash passing ERR_PTR to kthread_stop( | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89855 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize flash version read in rese | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89936 | In the Linux kernel, the following vulnerability has been resolved: iio: dac: m62332: Fix regulator reference count imb | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90055 | In the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initializati | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90056 | In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90058 | In the Linux kernel, the following vulnerability has been resolved: net/sched: bound qdisc_pkt_len to prevent qdisc sof | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90070 | In the Linux kernel, the following vulnerability has been resolved: tpm: st33zp24: Return zero on status read failure | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90073 | In the Linux kernel, the following vulnerability has been resolved: net/sched: hhf: clamp quantum before hhf_change() t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90075 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_codel: clamp default quantum and mtu | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90081 | In the Linux kernel, the following vulnerability has been resolved: net/rds: use wq_has_sleeper() in rds_cong_map_updat | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90088 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn( | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90107 | In the Linux kernel, the following vulnerability has been resolved: net/smc: free pending qentry in smc_llc_flow_stop() | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90126 | In the Linux kernel, the following vulnerability has been resolved: rtc: pcf8563: fix clock provider leak on unbind pc | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90214 | In the Linux kernel, the following vulnerability has been resolved: ASoC: xilinx: formatter_pcm: fix stream_data leak o | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90245 | In the Linux kernel, the following vulnerability has been resolved: fbdev: kyro: Validate overlay viewport coordinates | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90249 | In the Linux kernel, the following vulnerability has been resolved: iio: light: gp2ap002: Fix unbalanced runtime PM on | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90295 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: imx6q: fix out-of-bounds write when probed | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90297 | In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: crtc: Propagate layer initialization err | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90302 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: synchronize heartbeat callbacks with o2net t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90327 | In the Linux kernel, the following vulnerability has been resolved: phonet: pep: do not write beyond optlen in getsocko | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90348 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: snoc: use memcpy_fromio() for MSA ram | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90386 | In the Linux kernel, the following vulnerability has been resolved: i3c: dw: avoid shift-out-of-bounds when DAA assigns | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90394 | In the Linux kernel, the following vulnerability has been resolved: power: supply: sc2731_charger: cancel work on remov | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93048 | In the Linux kernel, the following vulnerability has been resolved: mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_par | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93098 | In the Linux kernel, the following vulnerability has been resolved: rpmsg: glink: fix deadlock in endpoint destroy duri | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93108 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ipoib: Drain RCU callbacks during module teard | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93140 | In the Linux kernel, the following vulnerability has been resolved: udf: Mark LVID buffer as uptodate before marking it | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93167 | In the Linux kernel, the following vulnerability has been resolved: csky: Fix a4/a5 restoration in syscall trace path | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93183 | In the Linux kernel, the following vulnerability has been resolved: drm/lima: call drm_mm_init() with a valid allocatio | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-80941 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Fix potential memory leak in rtw_txq_p | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-80966 | In the Linux kernel, the following vulnerability has been resolved: ALSA: portman2x4: Check card index validity at prob | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-80968 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mts64: Check card index validity at probe Al | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-80969 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mpu401: Check card index validity at probe m | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-80973 | In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: bound the MIDI event length from the d | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89491 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_live | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89512 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: scp: Fix device reference leak on faile | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89576 | In the Linux kernel, the following vulnerability has been resolved: dm-era: fix shadowed superblock leak on take-snap f | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89595 | In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix stale object mask after concurrent ma | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89730 | In the Linux kernel, the following vulnerability has been resolved: fpga: altera-cvp: Avoid out-of-bounds read in trail | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-11 |
| CVE-2026-89780 | In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: restore skb->dev on deaggrega | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89851 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix FCE trace enable parsing in debu | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89876 | In the Linux kernel, the following vulnerability has been resolved: media: tda18250: fix possible integer overflow Int | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89895 | In the Linux kernel, the following vulnerability has been resolved: media: cobalt: Avoid freeing ALSA private data twic | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89925 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix memory leak in guest debug handling | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89949 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: avoid unaligned fault in IP extrac | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-89964 | In the Linux kernel, the following vulnerability has been resolved: parisc: eisa: Fix infinite loop when parsing invali | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90054 | In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segment | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90061 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: skip double clone set express | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90068 | In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix off-by-one check on the second enum | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90072 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sfq: clamp quantum to avoid signed overf | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90074 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: clamp default quantum to avoid s | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90114 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: Reject descending VLAN tunnel ranges | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90128 | In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: fix wrong list iterated in add_direct_ch | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90157 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject negative optlen in cgroup getsockopt ho | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90160 | In the Linux kernel, the following vulnerability has been resolved: lwt_bpf: Restore reserved headroom after xmit progr | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90202 | In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid freeing unallocated PCIe SGL b | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90218 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix WARNING in res_to_rt syzbot reported | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90222 | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: hold a reference to the request skb dur | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90226 | In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: avoid userspace overflow on invalid optl | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90251 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MSFT: validate evt_prefix_len against th | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90261 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90281 | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: snps-femto-v2: Fix possible NULL-deref o | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90284 | In the Linux kernel, the following vulnerability has been resolved: firmware_loader: do not queue completed sysfs fallb | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90285 | In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Remove redundant VPD flash read in s | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90290 | In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: Restore DAIF state on error Sash | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90296 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: imx6q: fix devres accumulation across driv | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90298 | In the Linux kernel, the following vulnerability has been resolved: drm/sun4i: tcon: Drop TCON TOP device reference of | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90303 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9485/1: mm: acquire mmap write lock around sho | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90307 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: fix heap information leak on a truncated | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90318 | In the Linux kernel, the following vulnerability has been resolved: fat: release buffer head after rebuilding parent f | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90319 | In the Linux kernel, the following vulnerability has been resolved: rapidio: clear mport->net when rio_add_net() fails | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90334 | In the Linux kernel, the following vulnerability has been resolved: tty: clear cdev pointer after cdev_add() failure t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90361 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix leak in ath11k_service_ready_ext_ | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90362 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/dsi: Drop dev_pm_opp_set_rate(0) dev_pm_op | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90382 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt76x02: do not WARN on invalid rx desc | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90391 | In the Linux kernel, the following vulnerability has been resolved: lib/test_hmm: fail dmirror_fault() when the mirrore | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90411 | In the Linux kernel, the following vulnerability has been resolved: nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90416 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix stack out-of-bounds read in cc_param | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90420 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix infinite loop in nilfs_clean_segments() | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90431 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: Prevent crash handling to race with rpr | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-90434 | In the Linux kernel, the following vulnerability has been resolved: isofs: release zisofs block pointer buffer head zi | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-92496 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: Avoid buffer overread in ath11k_wmi_t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-92524 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_dom | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93049 | In the Linux kernel, the following vulnerability has been resolved: mtd: mtdswap: Avoid freeing registered blktrans dev | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93051 | In the Linux kernel, the following vulnerability has been resolved: misc: ad525x_dpot: use driver core groups for sysfs | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93061 | In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Avoid stack over-read in debug output | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93120 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: fix out-of-bounds read of qw | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93145 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: gdsc: tear down per-domain genpds in gds | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93159 | In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix heap info leak on I2C t | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-93180 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix NPD issue on partial unmap of an e | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-89828 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_in | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-16 |
| CVE-2026-90200 | In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix integer overflow in MFT cluster valid | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-92495 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page | UNKNOWN | — | 12% | EPSS 12%ile | NVD | 2026-09-17 |
| CVE-2026-89623 | In the Linux kernel, the following vulnerability has been resolved: HID: mcp2221: stop device IO before hid_hw_stop Qu | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-90339 | In the Linux kernel, the following vulnerability has been resolved: powerpc/syscall: Fix syscall skip handling for secc | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-89592 | In the Linux kernel, the following vulnerability has been resolved: accel/rocket: fix NULL dereference and integer over | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-89983 | In the Linux kernel, the following vulnerability has been resolved: i2c: core: fix debugfs UAF on adapter removal i2c_ | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-90053 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_htb: limit htb_classify inner-class | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90063 | In the Linux kernel, the following vulnerability has been resolved: virtio-net: Ensure that TCP packets don't overflow | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90078 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_skbmod: fix length calculations and | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90090 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtksdio: Fix out-of-bounds DMA read in | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90122 | In the Linux kernel, the following vulnerability has been resolved: clk: visconti: Make sure clk_init_data is fully ini | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90124 | In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-rzg2l: Fix loss of interrupt rzg2l | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90180 | In the Linux kernel, the following vulnerability has been resolved: block: mtip32xx: synchronize ioctls with device rem | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90209 | In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister Unregis | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90253 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the mesh send cancel command | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90287 | In the Linux kernel, the following vulnerability has been resolved: phy: sunplus: fix error handling in sp_uphy_init() | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92476 | In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requ | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93109 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Drain RCU callbacks during module teardo | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93115 | In the Linux kernel, the following vulnerability has been resolved: platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION( | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93161 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qa | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93185 | In the Linux kernel, the following vulnerability has been resolved: ASoC: rt700-sdw: always drain jack work on remove | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-80951 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: bound IBI payload to the requeste | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-89444 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Don't hex dump attri | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-89463 | In the Linux kernel, the following vulnerability has been resolved: power: supply: ucs1002: fix use-after-free on remov | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-89475 | In the Linux kernel, the following vulnerability has been resolved: power: supply: bq24257: fix use-after-free on remov | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-11 |
| CVE-2026-89776 | In the Linux kernel, the following vulnerability has been resolved: vxlan: vnifilter: enforce exact length of GROUP/GRO | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-89824 | In the Linux kernel, the following vulnerability has been resolved: drm/panel-edp: fix i2c adapter leak on probe failur | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-89926 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Fix length check __import_wp_info() str | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-16 |
| CVE-2026-90108 | In the Linux kernel, the following vulnerability has been resolved: net/smc: free stashed qentry before overwrite in RE | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90140 | In the Linux kernel, the following vulnerability has been resolved: cuse: wait for pending RCU callbacks on module exit | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90184 | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute updates with | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90185 | In the Linux kernel, the following vulnerability has been resolved: null_blk: serialize configfs attribute stores with | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90186 | In the Linux kernel, the following vulnerability has been resolved: null_blk: reject per-device queue resize for shared | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90188 | In the Linux kernel, the following vulnerability has been resolved: null_blk: free global tag_set on init error path I | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90190 | In the Linux kernel, the following vulnerability has been resolved: null_blk: use DEFINE_MUTEX for the file-scope mutex | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90194 | In the Linux kernel, the following vulnerability has been resolved: ACPI: scan: fix bus ID cleanup on device_add() fail | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90196 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: validate topology volume range before al | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90221 | In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_I | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90248 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: fix teardown of an adopted prot | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90254 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: free the advertising instance | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90257 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: virtio_bt: avoid OOB read of build info | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90352 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: release hif2 reference on probe | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92481 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind m | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92494 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix buffer_head leak in ext4_init_orphan_info | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92514 | In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Fix CEQ tasklet use-after-free on remov | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93050 | In the Linux kernel, the following vulnerability has been resolved: ipack: ipoctal: fix UAF, null-ptr-deref, and use-af | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93052 | In the Linux kernel, the following vulnerability has been resolved: misc: bcm-vk: Use acquire/release for msgq_inited | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93117 | In the Linux kernel, the following vulnerability has been resolved: usb: fix UAF when probe runs concurrent to dyn ID r | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93130 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix resource leak on m | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93149 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211_hwsim: avoid NULL skb in stop queue | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93152 | In the Linux kernel, the following vulnerability has been resolved: nvme-apple: Use acquire/release for queue enabled s | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-93182 | In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix overflow in update_tg_cfs_runnable( | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90181 | In the Linux kernel, the following vulnerability has been resolved: ublk: avoid teardown retry loop on xarray allocatio | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-90299 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix sleepable check for tracing/lsm prog When | UNKNOWN | — | 11% | EPSS 11%ile | NVD | 2026-09-17 |
| CVE-2026-92126 | Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrat | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89527 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Use svc_xprt_put to free listener on creat | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-90236 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Release the export reference when reaping ope | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90384 | In the Linux kernel, the following vulnerability has been resolved: iomap: release the folio batch on iomap callback fa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-80974 | In the Linux kernel, the following vulnerability has been resolved: mfd: sm501: Fix potential memory leaks during remov | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-80984 | In the Linux kernel, the following vulnerability has been resolved: net/smc: do not dereference an unset send buffer on | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89438 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Validate logical CPU id and clo | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89439 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: ISST: Add a NULL check for sst_inst[] | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89451 | In the Linux kernel, the following vulnerability has been resolved: iommu/sva: Set handle->dev before the SVA handle is | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89453 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89454 | In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89455 | In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix use-after-free of event IRQs during | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89484 | In the Linux kernel, the following vulnerability has been resolved: lockd: fix NULL dereference on lockowner allocation | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89502 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Free cpu_buffer::free_page with subbuf | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89566 | In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy check | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89673 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix XDR padding calculation in ff_encode_getd | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89794 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound re | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89807 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: guard against NULL restore_mqd in CRIU | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89830 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix valid block count leak on data block allo | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89834 | In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to migrate all curseg types during free_s | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89835 | In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid NULL checkpoint thread access in sysfs | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89886 | In the Linux kernel, the following vulnerability has been resolved: media: intel/ipu6: fix async notifier cleanup leak | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89909 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Free init resources if kvm_init() f | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89931 | In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89944 | In the Linux kernel, the following vulnerability has been resolved: ASoC: hdac_hda: Fix hlink refcount leak on componen | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89950 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: mcast: linearize skbuff for packet gene | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89958 | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: Fix dereference matrix_mdev->kvm with | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89963 | In the Linux kernel, the following vulnerability has been resolved: powerpc/kexec_file: Fix null-ptr-def in extra size | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90021 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: initialize work in f_midi_allo | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90060 | In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED l | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90065 | In the Linux kernel, the following vulnerability has been resolved: net/smc: release the internal TCP sock on IPPROTO_S | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90066 | In the Linux kernel, the following vulnerability has been resolved: samples/ftrace: Fix kthread_stop() on ERR_PTR in ft | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90076 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: add overflow bounds to quantum and i | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90085 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix NULL deref in NIX TM tree debugfs | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90101 | In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix call to hardware monitoring event hand | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90109 | In the Linux kernel, the following vulnerability has been resolved: net: sched: fix 32-bit backlog wrap in gred, bfifo | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90112 | In the Linux kernel, the following vulnerability has been resolved: net: qlcnic: validate unified ROM sections before l | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90115 | In the Linux kernel, the following vulnerability has been resolved: xsk: fix NULL pointer dereference in __xsk_rcv() I | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90119 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ice1712: Fix the card leak at probe error wit | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90125 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix request buffer leak in smb2_new_re | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90130 | In the Linux kernel, the following vulnerability has been resolved: vdpa_sim: fix cleanup after worker creation failure | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90135 | In the Linux kernel, the following vulnerability has been resolved: net: add missing ref_tracker_dir_exit() to alloc_ne | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90138 | In the Linux kernel, the following vulnerability has been resolved: vsock: don't check the listener's sk_err in vsock_a | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90139 | In the Linux kernel, the following vulnerability has been resolved: fuse: check for NULL root inode in fuse_fill_super_ | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90147 | In the Linux kernel, the following vulnerability has been resolved: clk: devres: fix cleanup in devm_clk_get_optional_e | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90148 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: Fix incorrect argument passed to nfs4_delete | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90150 | In the Linux kernel, the following vulnerability has been resolved: pnfs/blocklayout: Fix device leaks on parse failure | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90152 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix session leak in ksmbd_session_regis | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90158 | In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90159 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX g | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90165 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix invalid pointer dereference in ksmb | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90166 | In the Linux kernel, the following vulnerability has been resolved: smb/server: fix null-ptr-deref in ksmbd_ipc_tree_co | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90170 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate ipc response length before derefere | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90187 | In the Linux kernel, the following vulnerability has been resolved: null_blk: free zones array on device power-off nul | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90192 | In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: handle NULL data in send_data | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90193 | In the Linux kernel, the following vulnerability has been resolved: mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock i | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90195 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix missing sign-ext for signed 1-byte | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90201 | In the Linux kernel, the following vulnerability has been resolved: net: page_pool: fix UAF in __page_pool_release_netm | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90213 | In the Linux kernel, the following vulnerability has been resolved: firewire: core: fix memory leak in error path of bu | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90220 | In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Don't leak the extension cell pointer in | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90262 | In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle f | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90279 | In the Linux kernel, the following vulnerability has been resolved: md/raid5: round bitmap stripes with sector division | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90282 | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb-legacy: Fix possible NULL-deref | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90306 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9481/2: breakpoint: CFI breakpoints only on de | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90322 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/cluster: keep heartbeat local node stable o2 | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90364 | In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Unregister cpufreq notifier on ini | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90368 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: unwind state on add_interface f | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90370 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_ge | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90373 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: clear wcid mask under mutex aft | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90374 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: validate RX band_idx before der | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90385 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: create serial pool adding rdev to array w | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90389 | In the Linux kernel, the following vulnerability has been resolved: md: scope memalloc_noio to allocation critical sect | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90390 | In the Linux kernel, the following vulnerability has been resolved: md/bitmap: resume array on backlog_store() error pa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90404 | In the Linux kernel, the following vulnerability has been resolved: platform/chrome: cros_ec_debugfs: Unregister panic | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90426 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Free the error IRQ before tea | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92506 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix requested device removal ra | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92515 | In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve unique-field state across nested stru | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93062 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: guard against division by zero in iw | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93072 | In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip le | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93097 | In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Break poison list loop on an empty payloa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93119 | In the Linux kernel, the following vulnerability has been resolved: usb: ljca: bound bank_num in ljca_enumerate_gpio() | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93123 | In the Linux kernel, the following vulnerability has been resolved: serial: qcom-geni: do not advance stale DMA complet | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93126 | In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom_q6v5_adsp: Fix reference leak for | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93128 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: lg-laptop: Fix LED resource handling | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93132 | In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop han | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93133 | In the Linux kernel, the following vulnerability has been resolved: ACPI: RISC-V: Check acpi_get_handle() status in ris | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93134 | In the Linux kernel, the following vulnerability has been resolved: printk: Fix possible console use-after-free When e | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93155 | In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Fix AEAD unregister count in erro | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93156 | In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - fail ahash requests on HASH idle t | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93162 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - cancel work on re-enable SR-IOV timeo | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93163 | In the Linux kernel, the following vulnerability has been resolved: hwrng: core - fix rng list on registration error h | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93172 | In the Linux kernel, the following vulnerability has been resolved: mm/mm_init: handle alloc_percpu failure in free_are | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93184 | In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_audmix: rework runtime PM handling in pro | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-80990 | In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was han | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-90050 | In the Linux kernel, the following vulnerability has been resolved: net/sched: fq: clamp quantum and initial_quantum in | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90175 | In the Linux kernel, the following vulnerability has been resolved: smb: server: fix leak of ksmbd_ipc_login_request_ex | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90250 | In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix storage null-ptr-deref after repla | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90280 | In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: Fix possible NULL-deref on earl | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90313 | In the Linux kernel, the following vulnerability has been resolved: bpf, cgroup: Fix invalid storage access after __cgr | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90344 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: disconnect on CSA to channel 0 The | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90397 | In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: scm: Fix NULL dereference in IRQ ha | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92484 | In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix use-after-free in find_pos_and_ways | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92519 | In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix memory leak in bpf_jit_free When b | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93082 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox set | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93085 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Reject out of range DT protocol | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93086 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Avoid IDR updates while cleanin | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93150 | In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: Make nr_deadline_tasks an atomic_t | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-80956 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: only hand out initialized cache segments | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-80960 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate on-media seg_num against the ca | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-80970 | In the Linux kernel, the following vulnerability has been resolved: ALSA: FCP: do not copy out an uninitialised init re | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89446 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Release current IOAS on xa_store() failure | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89509 | In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Embed counter driver data in rdma_count | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89517 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix rq->core_pick corruption under core | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89543 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix use-after-free in __rpc_clnt_handle_eve | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89556 | In the Linux kernel, the following vulnerability has been resolved: module: validate string table section types In elf | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89577 | In the Linux kernel, the following vulnerability has been resolved: dm-io: report non-retryable errors separatedly The | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89578 | In the Linux kernel, the following vulnerability has been resolved: dm-io: clone the source bio instead of copying its | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89591 | In the Linux kernel, the following vulnerability has been resolved: accel/rocket: initialize job domain before cleanup | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89629 | In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Check size of status and firmwar | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89698 | In the Linux kernel, the following vulnerability has been resolved: nfsd: widen nfsd_genl_rqstp address fields to socka | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89714 | In the Linux kernel, the following vulnerability has been resolved: NFS: fix delegation_hash_table leak when nfs4_serve | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89715 | In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file fail | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89716 | In the Linux kernel, the following vulnerability has been resolved: zram: validate deflate params We must validate use | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89721 | In the Linux kernel, the following vulnerability has been resolved: phy: rockchip-samsung-dcphy: fix out-of-range max_r | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89722 | In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Fix out-of-bounds read in pci_write_lega | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89739 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: gadget: Fix use-after-free in dwc3_gadge | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-89790 | In the Linux kernel, the following vulnerability has been resolved: ipv6: avoid divide by zero in rt6_multipath_rebalan | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89798 | In the Linux kernel, the following vulnerability has been resolved: rpcrdma: arm rn_done before publishing the notifica | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89820 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix dc_lock leak on GPU reset erro | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89869 | In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: use disable_irq() during power-o | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89889 | In the Linux kernel, the following vulnerability has been resolved: media: i2c: imx415: Release runtime PM reference on | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89917 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle VNCR TLB invalidation race with | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89921 | In the Linux kernel, the following vulnerability has been resolved: KVM: s390: Zero initialize data structures for inje | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89935 | In the Linux kernel, the following vulnerability has been resolved: iio: light: apds9306: fix PM reference leak in apds | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89978 | In the Linux kernel, the following vulnerability has been resolved: accel/amdxdna: return early from a zero-length flus | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89991 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix infinite loop in pcpu_freelist push with o | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-89996 | In the Linux kernel, the following vulnerability has been resolved: dma-buf: dma-heap: don't publish fd before copy_to_ | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90005 | In the Linux kernel, the following vulnerability has been resolved: samples/damon/wsse: handle damon_start() failure P | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-90077 | In the Linux kernel, the following vulnerability has been resolved: net: fix a resource leak in copy_net_ns() error han | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90080 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on r | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90083 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ife: Only operate on Ethernet frames | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90084 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-vf: fix workqueue and netdev race in prob | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90086 | In the Linux kernel, the following vulnerability has been resolved: xsk: honor XDP_TX_METADATA in zero-copy path The z | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90094 | In the Linux kernel, the following vulnerability has been resolved: arm64: process: Fix context switching MTE store-onl | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90097 | In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Skip VMBus module cleanup for n | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90100 | In the Linux kernel, the following vulnerability has been resolved: ptp: netc: fix period truncation and potential divi | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90113 | In the Linux kernel, the following vulnerability has been resolved: netdevsim: update queue NAPI association on queue r | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90116 | In the Linux kernel, the following vulnerability has been resolved: ALSA: mtpav: shut down output timer before card tea | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90127 | In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: time out alarm requests RTC class ope | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90129 | In the Linux kernel, the following vulnerability has been resolved: virtio_balloon: quiesce balloon work before device | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90136 | In the Linux kernel, the following vulnerability has been resolved: platform/x86/amd/hsmp: Reject negative power cap wr | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90179 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix deadlock in complain-mode change_hat | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90197 | In the Linux kernel, the following vulnerability has been resolved: HID: haptic: don't write an uninitialized value to | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90211 | In the Linux kernel, the following vulnerability has been resolved: bpf, s390: Clear fetch destination on faulting aren | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90232 | In the Linux kernel, the following vulnerability has been resolved: amt: Don't support cross-netns setup. When a lower | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90233 | In the Linux kernel, the following vulnerability has been resolved: nvme-pci: release descriptor pools on probe failure | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90247 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock leak in irq_work path stack_map | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90252 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: free the HCI command when it is ca | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90258 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers W | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90259 | In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qg | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90264 | In the Linux kernel, the following vulnerability has been resolved: btrfs: always wait for ordered extents to avoid OE | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90265 | In the Linux kernel, the following vulnerability has been resolved: btrfs: defrag: fix deadlock between defrag and dela | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90269 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject load-acquire from pointers requiring fa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90272 | In the Linux kernel, the following vulnerability has been resolved: perf: arm_pmuv3: Zero initialize hw_id branch stack | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90276 | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: stop daemon timer rearm on destroy | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90277 | In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: prevent create failure bitmap UAF | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90278 | In the Linux kernel, the following vulnerability has been resolved: md: wait for behind writes before destroying bitmap | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90328 | In the Linux kernel, the following vulnerability has been resolved: HID: steam: Reject short reads Steam Controller FE | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90338 | In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: keep console clock enabled for | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90349 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix out-of-bounds link array ac | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90350 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: reject out-of-range link ids in mt76_vi | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90351 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: do not attach hif2 WED when the | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90356 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: free vif links after clearing w | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90363 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: don't tear down KMS twice when KMS init fa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90376 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF T | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90396 | In the Linux kernel, the following vulnerability has been resolved: block: fix dio leak on metadata mapping error A fa | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90406 | In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: handle runtime PM resume failure | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90422 | In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: pllfh: Fix IO remapping leak in regi | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90430 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Publish an LVCMDQ only after | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92486 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix CFI mismatch in task work callback BPF su | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92492 | In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynami | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92499 | In the Linux kernel, the following vulnerability has been resolved: ext4: validate readdir offset before accessing dire | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92505 | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix undefined behavior in devid_write de | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92513 | In the Linux kernel, the following vulnerability has been resolved: RDMA/mana_ib: drain QP references after partial tab | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92516 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix offset warn check for bpf_res_spin_lock S | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-92517 | In the Linux kernel, the following vulnerability has been resolved: bpf, riscv: Fix extable handling for arena load_acq | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93058 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Only fini scheduler after successful init | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93059 | In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix task_struct reference leak in recover_ | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93068 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix DM I2C teardown race DM I2C a | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93077 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Clamp Get Feature output size to the | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93078 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Set Features output buffer sma | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93080 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix transport device teardown l | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93106 | In the Linux kernel, the following vulnerability has been resolved: crash_dump: release keyring reference at the correc | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93146 | In the Linux kernel, the following vulnerability has been resolved: time/namespace: Validate nanosecond field in proc_t | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93157 | In the Linux kernel, the following vulnerability has been resolved: hwrng: xilinx-trng - propagate timeout before any d | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-93169 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: zynqmp_dma: fix race between runtime PM | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-90034 | In the Linux kernel, the following vulnerability has been resolved: usb: image: mdc800: change kmalloc() to kzalloc() | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-93191 | In the Linux kernel, the following vulnerability has been resolved: smack: fix incorrect task context in smack_msg_queu | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-89765 | In the Linux kernel, the following vulnerability has been resolved: timers/itimer: Zero-init old itimerval before copy | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-11 |
| CVE-2026-90040 | In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Forcefully invalidate SNP VMSA if its bac | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-16 |
| CVE-2026-93188 | In the Linux kernel, the following vulnerability has been resolved: HID: roccat: bound device-supplied profile index k | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-17 |
| CVE-2026-88742 | Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field. | UNKNOWN | — | 10% | EPSS 10%ile | NVD | 2026-09-15 |
| CVE-2026-93204 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: atomically update mac addresses W | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-89827 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: avoid force-completing uninitialized UV | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89867 | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Defer job_finish() only | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89905 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Move arena register slot below TCC | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89966 | In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb_cma: fix null nodemask dereference in hu | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-90004 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: handle region split failure in apply | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-90064 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Reject page faults from non-fault-mode scra | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90095 | In the Linux kernel, the following vulnerability has been resolved: fuse: Fix the condition to enable over-io-uring Th | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90098 | In the Linux kernel, the following vulnerability has been resolved: net: sparx5: fix sleep in atomic context in MAC tab | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90105 | In the Linux kernel, the following vulnerability has been resolved: vxlan: fix reading neigh ha Currently arp/neigh_re | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90121 | In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Clear per-CPU IRS data on teardown | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90134 | In the Linux kernel, the following vulnerability has been resolved: ntfs: fix kmap_local_page() usage in compress Seve | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90154 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope session state changes to bound connect | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90156 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: safely discard unregistered deferred locks | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90164 | In the Linux kernel, the following vulnerability has been resolved: smb/server: abort initialization when proc setup fa | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90167 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize oplock close with pending break ow | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90182 | In the Linux kernel, the following vulnerability has been resolved: blk-iocost: clear delay state when freeing policy d | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90305 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9483/1: select HAVE_POSIX_CPU_TIMERS_TASK_WORK | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90310 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90311 | In the Linux kernel, the following vulnerability has been resolved: thermal: hwmon: Remove hwmon class device along wit | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90330 | In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix FF device cleanup on init | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90346 | In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: clean up color-change beacon data on | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90355 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: clear stale link state on full | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90359 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject >8 byte return values on return-reading | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90417 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Fix dereg_skb leak and double free in w | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90432 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handl | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-92503 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix ABBA deadlock in ext4_xattr_inode_cache_f | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93047 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Associate BOs with every job that accesses | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93069 | In the Linux kernel, the following vulnerability has been resolved: OPP: Fix cleanup ordering Commit 173e02d67494 ("OP | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93094 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dp_link_peer dangling references | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93129 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-base: Fix handling of ultra | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93153 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bng_re: return a timeout when firmware respons | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93164 | In the Linux kernel, the following vulnerability has been resolved: uprobes/x86: Move optimized uprobe from nop5 to nop | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-89518 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix this_rq() assumptions in dispatch kf | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-89519 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-89529 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Reject oversized Read segments at decode t | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-89568 | In the Linux kernel, the following vulnerability has been resolved: kho: fix size calculation in kho_preserved_memory_r | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-89661 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent post-shutdown use-after-free in unloc | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-11 |
| CVE-2026-88620 | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/query | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-88621 | OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.p | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-15 |
| CVE-2026-89831 | In the Linux kernel, the following vulnerability has been resolved: f2fs: protect critical_task_priority updates with s | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89866 | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Resume device before set | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89976 | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix job completion fence cleanup eth | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89977 | In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: check MMIO mapping errors in probe d | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-89981 | In the Linux kernel, the following vulnerability has been resolved: arm64: Don't read GMID_EL1 when MTE is disabled __ | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-16 |
| CVE-2026-90079 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix cn20k mailbox lifetime on repeate | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90082 | In the Linux kernel, the following vulnerability has been resolved: net: mana: Cap MSI-X vectors to the device MSI-X ta | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90087 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: do not leak an hci_conn when a second LE | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90096 | In the Linux kernel, the following vulnerability has been resolved: fuse: invalidate the correct range after O_APPEND d | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90099 | In the Linux kernel, the following vulnerability has been resolved: net/sched: account classifier filter allocations to | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90106 | In the Linux kernel, the following vulnerability has been resolved: net: bridge: arp/nd proxy: fix reading neigh ha Cu | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90117 | In the Linux kernel, the following vulnerability has been resolved: ntfs: validate usa_ofs before preserving the update | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90123 | In the Linux kernel, the following vulnerability has been resolved: irqchip/ast2700-intc: Avoid allocating in the irq_d | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90144 | In the Linux kernel, the following vulnerability has been resolved: dpll: fix NULL deref in dpll_device_ops() during te | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90155 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: detach blocked lock requests before freeing | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90163 | In the Linux kernel, the following vulnerability has been resolved: smb/server: call ksmbd_proc_cleanup() on module ini | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90168 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90171 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: release pending child sockets outsi | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90183 | In the Linux kernel, the following vulnerability has been resolved: blk-iolatency: clear delay state when freeing polic | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90206 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix max_qid race between configfs and contro | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90208 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/samsung_pwm: Switch to raw_spin | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90238 | In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: fix self-deadlock in isp4sd_pwron | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90239 | In the Linux kernel, the following vulnerability has been resolved: media: amd: isp4: release partial allocations in is | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90242 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix iopf_refcount leak on RID domain re | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90263 | In the Linux kernel, the following vulnerability has been resolved: btrfs: check if root is readonly when setting posix | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90266 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't force read-only on transient -E | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90271 | In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Fix a NULL pointer dereference on unbindi | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90300 | In the Linux kernel, the following vulnerability has been resolved: bpf: Clear buf on error in __bpf_get_task_stack Bo | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90304 | In the Linux kernel, the following vulnerability has been resolved: ARM: 9484/1: enable interrupts when unhandled user | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90315 | In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Add lockdown checks to legacy I/O and me | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90323 | In the Linux kernel, the following vulnerability has been resolved: ublk: validate auto buf reg before taking uring_cmd | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90331 | In the Linux kernel, the following vulnerability has been resolved: HID: asus: refactor the two workqueues and init seq | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90336 | In the Linux kernel, the following vulnerability has been resolved: serial: core: clear freed pointers on uart_register | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90337 | In the Linux kernel, the following vulnerability has been resolved: serial: core: do fallible allocations before the co | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90340 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: generic: free maps on pinctrl_generic_to_m | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90405 | In the Linux kernel, the following vulnerability has been resolved: media: stm32: dcmi: fix some error handling bugs in | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90409 | In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Add vm_bind region with kbo range over | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90412 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix return status of RMI log page on allocat | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-90421 | In the Linux kernel, the following vulnerability has been resolved: PCI: Fix UAF when probe runs concurrent to dyn ID r | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-92478 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate connected lane counts Th | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-92482 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-92487 | In the Linux kernel, the following vulnerability has been resolved: exfat: fix valid_size extension over a shared writa | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93038 | In the Linux kernel, the following vulnerability has been resolved: iio: dac: ad5686: missing NULL check on match data | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93060 | In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: fix use after free on error path in | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93081 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetim | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93096 | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Serialize multi-part Get/Set Feature | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93099 | In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Fix UAF from worker threads when domain | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93135 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject programs with inlined helpers if JIT is | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93139 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: Fix hung_queue_db_array loop limit | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93166 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: debug: fix off by on in rtw89_ppdu_str | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93171 | In the Linux kernel, the following vulnerability has been resolved: leds: lp5860: Fix a potential double-unlock In lp5 | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-93181 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix uncore_box ref/unref ord | UNKNOWN | — | 9% | EPSS 9%ile | NVD | 2026-09-17 |
| CVE-2026-89759 | In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup when scanning task s | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-39039 | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and se | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2025-56565 | DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-93186 | In the Linux kernel, the following vulnerability has been resolved: cxl/mbox: Clamp mailbox output allocation to the pa | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-89525 | In the Linux kernel, the following vulnerability has been resolved: udf: reject VAT indexes equal to the entry count U | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89766 | In the Linux kernel, the following vulnerability has been resolved: pidfd: hold exec_update_lock around namespace ioctl | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89868 | In the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Add timeout while stop_s | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90029 | In the Linux kernel, the following vulnerability has been resolved: usb: storage: realtek_cr: fix use-after-free on dis | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90039 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Guard admin state-revocation walks with NFSD_ | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-93179 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/powerplay: fix VoltageObjectInfo zero-strid | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93193 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: analogix_dp: Fix OF node reference le | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93194 | In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Release core resources Core r | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93195 | In the Linux kernel, the following vulnerability has been resolved: drm/bridge: synopsys: dw-dp: Support unregistering | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93198 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate the persisted dirty_tail chain | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93199 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Do not treat master device as a duplic | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-81013 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empt | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-92238 | A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety viol | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-92239 | A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbir | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-15 |
| CVE-2026-93073 | In the Linux kernel, the following vulnerability has been resolved: dax: read holder_ops once in dax_holder_notify_fail | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2025-56566 | MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-80930 | In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-80963 | In the Linux kernel, the following vulnerability has been resolved: dm-stats: fix a crash if allocation of per-cpu data | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-80965 | In the Linux kernel, the following vulnerability has been resolved: ALSA: serial-u16550: Check card index validity at p | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-80988 | In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP lin | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89457 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Guard sysfs discipline callbacks against | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89458 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: Do not complete a failed ESE read as suc | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89490 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix readdir position truncation on 32-bit ke | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89496 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: always run deallocs on copy-on-write complet | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89498 | In the Linux kernel, the following vulnerability has been resolved: orangefs: fix double-free of trailer_buf on readdir | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89515 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fill in DMA padding bytes in scsi_alloc | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-89752 | In the Linux kernel, the following vulnerability has been resolved: mm: memcg: stop reclaim when a limit update is supe | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-11 |
| CVE-2026-90028 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: hd3ss3220: track VBUS enable state per | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-16 |
| CVE-2026-90216 | In the Linux kernel, the following vulnerability has been resolved: ubi: Fix rollback for explicit UBI device numbers | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-90395 | In the Linux kernel, the following vulnerability has been resolved: power: supply: isp1704_charger: cancel work on remo | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-90415 | In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: free STAG index when TPT entry write fa | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-92498 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: avoid buffer overreads in WMI event h | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-92501 | In the Linux kernel, the following vulnerability has been resolved: ext4: drain in-flight DIO before buffered write fal | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-92521 | In the Linux kernel, the following vulnerability has been resolved: ACPI: PCI: Clear driver_data on all paths that free | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93040 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize channel state checks | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93041 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Serialize abort state updates | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93053 | In the Linux kernel, the following vulnerability has been resolved: speakup: keyhelp: guard letter_offsets possible out | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93055 | In the Linux kernel, the following vulnerability has been resolved: UDF symlink pathComponent header OOB read udf_syml | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93056 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_uac1_legacy: remove broken string co | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93067 | In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tc358767: clamp the reported AUX read s | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93103 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Preserve unit 0 on allocation failure h | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93110 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Wait for RCU callbacks before unloading | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93158 | In the Linux kernel, the following vulnerability has been resolved: crypto: sa2ul - stop probe if context pool creation | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-93160 | In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-73638 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-73639 | Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR | UNKNOWN | — | 8% | EPSS 8%ile | NVD | 2026-09-17 |
| CVE-2026-89447 | In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unm | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89772 | In the Linux kernel, the following vulnerability has been resolved: btrfs: write-protect folios during data writeback | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89773 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip Update HDCP Config In Transit | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-92500 | In the Linux kernel, the following vulnerability has been resolved: ext4: use fsdata to track inline data write state a | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93187 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Return error for invalid | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93197 | In the Linux kernel, the following vulnerability has been resolved: memcg: move LRU size accounting on reparenting inst | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-89618 | In the Linux kernel, the following vulnerability has been resolved: eventfs: Initialize ei->children and ei->list in in | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89683 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix dentry ref leak on V4ROOT export filehand | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89514 | In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spi | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89589 | In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER wor | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-93143 | In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix pm_runtime refcount leak | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-80938 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7615: avoid waiting for mac work unde | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-80964 | In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-80972 | In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Check card index validity at probe al | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89464 | In the Linux kernel, the following vulnerability has been resolved: power: supply: twl4030_charger: cancel workers via | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89474 | In the Linux kernel, the following vulnerability has been resolved: power: supply: bq256xx: drain usb_work before freei | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89710 | In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: fix layout segment leak on the pnfs_layout | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-89751 | In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix off-by-one in port I/O handling handl | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-11 |
| CVE-2026-90189 | In the Linux kernel, the following vulnerability has been resolved: null_blk: register configfs subsystem after creatin | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-90274 | In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: fix underflow for usage of (nrseq | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-90354 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix double hif2 init on the non | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-90378 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt792x: Fix memory leak in SDIO TX path | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92477 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: debugfs: Reserve space for a string term | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92483 | In the Linux kernel, the following vulnerability has been resolved: liveupdate: Remember FLB retrieve() status LUO kee | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92509 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix potential use after free in counter_ | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92512 | In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Fix use after free in ib_query_qp() Whe | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-92523 | In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: validate dynamic counter attribute leng | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93064 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: fix off-by-one in TXF key sanit | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93102 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Free RX data on late probe failure hfi1 | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93114 | In the Linux kernel, the following vulnerability has been resolved: platform/surface: acpi-notify: Check ACPI companion | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-93118 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed_udc: check endpoint DMA allocat | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-17 |
| CVE-2026-75157 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `E | UNKNOWN | — | 7% | EPSS 7%ile | NVD | 2026-09-18 |
| CVE-2026-80940 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: pci: fix resource leak on failed NAPI | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80942 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81014 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read in sk_s | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89460 | In the Linux kernel, the following vulnerability has been resolved: s390/cpum_cf: Handle CPU hotplug via prepare/dead c | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89468 | In the Linux kernel, the following vulnerability has been resolved: power: supply: lp8788-charger: fix use-after-free o | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89552 | In the Linux kernel, the following vulnerability has been resolved: params: fix charp corruption on allocation failure | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89666 | In the Linux kernel, the following vulnerability has been resolved: nfsd: reject out-of-range nseconds in NFSv3 SETATTR | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89735 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: midi2: remove default configfs groups | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-92019 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 115. | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-90178 | In the Linux kernel, the following vulnerability has been resolved: hwmon: (coretemp) Fix core_data leak on CPUs withou | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90215 | In the Linux kernel, the following vulnerability has been resolved: mtd: ubi: Release device reference on busy detach | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90275 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: don't set array_frozen in raid1_takeover( | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90366 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: reserve space for the CSA-abort | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90375 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix non-AQL packet accounting for MLO s | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90400 | In the Linux kernel, the following vulnerability has been resolved: md: recheck spare changes before starting sync rem | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90410 | In the Linux kernel, the following vulnerability has been resolved: spi: davinci: switch to managed controller allocati | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90418 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirt | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90428 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Don't run the error ISR befor | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90433 | In the Linux kernel, the following vulnerability has been resolved: spi: oc-tiny: switch to managed controller allocati | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92490 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unrequest devices if driver reg | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92491 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Roll back partial protocol tabl | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92497 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Avoid buffer overread in ath12k_wmi_o | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92502 | In the Linux kernel, the following vulnerability has been resolved: ext4: clear stale xarray tags on folios skipped dur | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93065 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix counter type in iwl_fwrt_dump_er | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93071 | In the Linux kernel, the following vulnerability has been resolved: media: bcm2835-unicam: Fix asc leaked in error/remo | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93083 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setu | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93084 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Drop handle on protocol bind fa | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93089 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Free transport channel on IDR f | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93090 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Clean up channels on setup fail | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93091 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Quiesce notifications before te | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93092 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unregister device notifier befo | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93093 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Publish channel state before ca | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93101 | In the Linux kernel, the following vulnerability has been resolved: media: v4l2-async: Unregister sub-device if asc_lis | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93113 | In the Linux kernel, the following vulnerability has been resolved: clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CL | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93173 | In the Linux kernel, the following vulnerability has been resolved: bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hook | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93174 | In the Linux kernel, the following vulnerability has been resolved: bpf: Copy per-CPU map value padding in copy_map_val | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-88593 | kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-16 |
| CVE-2026-79362 | Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6 | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80927 | In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_t | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80934 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: fix TX DMA mapping leak for Add | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80939 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: pci: add .shutdown callback to stop rf | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80946 | In the Linux kernel, the following vulnerability has been resolved: fuse: copy request headers via a stack buffer for i | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80957 | In the Linux kernel, the following vulnerability has been resolved: dm-pcache: detect a cycle in the last-kset chain du | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-80993 | In the Linux kernel, the following vulnerability has been resolved: net: phylink: correctly validate returned PCS in ph | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-81009 | In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89437 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: int1092: Fix potential memory leak in | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89449 | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix dev_iommu memory leak when device_add fa | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89467 | In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: fix use-after-free qc | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89506 | In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_R | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89590 | In the Linux kernel, the following vulnerability has been resolved: accel/rocket: Fix error path handling in rocket_job | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89644 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O writ | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89693 | In the Linux kernel, the following vulnerability has been resolved: nfsd: check nfsd4_acl_to_attr() return value in nfs | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89700 | In the Linux kernel, the following vulnerability has been resolved: nfsd: validate sockaddr length per family in listen | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89701 | In the Linux kernel, the following vulnerability has been resolved: nfsd: validate nseconds in TIME_DELEG decode paths | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89717 | In the Linux kernel, the following vulnerability has been resolved: zram: set default primary compressor in zram_destro | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89719 | In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in read_block_state( | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89734 | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: uvc: Fix null pointer dereference in u | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89737 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: thunderbolt: Disable work before freein | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-90333 | In the Linux kernel, the following vulnerability has been resolved: dm-integrity: replace forgeable discard filler with | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90377 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix RX data queuing of RRO 3.0 For RRO | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-90424 | In the Linux kernel, the following vulnerability has been resolved: iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-f | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92493 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate-ut: Skip tests when amd-pstate | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-92520 | In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93066 | In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Take cpa_lock around large-page collaps | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-93100 | In the Linux kernel, the following vulnerability has been resolved: fs/resctrl: Prevent use-after-free in rdtgroup_kn_p | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-17 |
| CVE-2026-89572 | In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix OPP table cleanup apple_so | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-92030 | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firef | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-89505 | In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Guard legacy bundles without method_el | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-89516 | In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't BUG_ON a destroyed DSQ in process_ | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-11 |
| CVE-2026-92018 | Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firef | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92022 | Use-after-free in the DOM: HTML Parser component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firef | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92023 | Use-after-free in the XML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16 | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92024 | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16 | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92028 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firef | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92029 | Use-after-free in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16 | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92038 | Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153. | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92039 | Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92041 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92074 | Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunde | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-92075 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbi | UNKNOWN | — | 6% | EPSS 6%ile | NVD | 2026-09-15 |
| CVE-2026-89728 | In the Linux kernel, the following vulnerability has been resolved: i3c: renesas: Fix out-of-bounds access for newdevs | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-92016 | Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92031 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92032 | Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ES | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-89718 | In the Linux kernel, the following vulnerability has been resolved: zram: fix out-of-bounds access in writeback_store() | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89727 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_ | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-89745 | In the Linux kernel, the following vulnerability has been resolved: debugfs: Fix lockdown check for mmap_prepare Commi | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-11 |
| CVE-2026-90212 | In the Linux kernel, the following vulnerability has been resolved: arm64/efi: Avoid voluntary preemption with efi_mm i | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90267 | In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix special_vec mempool leak when scsi_al | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90270 | In the Linux kernel, the following vulnerability has been resolved: arm_mpam: Disable driver unbind to avoid UAF When | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90273 | In the Linux kernel, the following vulnerability has been resolved: coresight: etm4x: missing cscfg_csdev_disable_activ | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90335 | In the Linux kernel, the following vulnerability has been resolved: tty: skip cdev_del() when no cdev is registered TT | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90342 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix mmap_lock deadlock on arena lock failure | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90345 | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix P2P action frame handling witho | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90365 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: cancel reset and rc work on device unre | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-90369 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix out-of-bounds access in mmio copy h | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-92479 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: Avoid NULL CQE dereference when reportin | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-92480 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Validate string descriptors The s | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93043 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for gotox insn | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93044 | In the Linux kernel, the following vulnerability has been resolved: bpf: Disallow interpreter fallback for arena-relate | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93057 | In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Avoid possible memory reclaim dead | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93075 | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear pgmap ops and owner on unbind fsd | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93076 | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear vmemmap_shift when binding static | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93104 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rvt: Return NULL after port allocation failure | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93124 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: asus-wireless: Fail probe when there | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93168 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_ | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93200 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix use-after-free of master->this sy | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-93202 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix recursive locking during device re | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2025-55787 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-17 |
| CVE-2026-11927 | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party service | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-39040 | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (tru | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92035 | Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 1 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92042 | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92044 | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92045 | Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92046 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92048 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92076 | Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153. | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92077 | Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92021 | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 140.16 and Thunderbi | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92034 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92036 | Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunder | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92037 | Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbi | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92040 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156 | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92057 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2026-92079 | Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunde | UNKNOWN | — | 5% | EPSS 5%ile | NVD | 2026-09-15 |
| CVE-2025-69904 | Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on t | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-52483 | The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11( | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-17 |
| CVE-2026-13272 | IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-14 |
| CVE-2026-25825 | An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-25826 | An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be s | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-89770 | In the Linux kernel, the following vulnerability has been resolved: iomap: don't free integrity payload that doesn't ex | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-11 |
| CVE-2026-92049 | Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbi | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92056 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderb | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92058 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 15 | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92059 | Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153 | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92060 | Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Th | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92064 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92065 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92067 | Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92068 | Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thund | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92069 | Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunder | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92070 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92071 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Fire | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92072 | Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 1 | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92078 | Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92050 | Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunder | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92051 | Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunder | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92061 | Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92063 | Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-92066 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-12101 | IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-90969 | Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authent | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-90971 | Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier all | UNKNOWN | — | 4% | EPSS 4%ile | NVD | 2026-09-15 |
| CVE-2026-81018 | In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Free system certificate si | UNKNOWN | — | 3% | EPSS 3%ile | NVD | 2026-09-11 |
| CVE-2026-13327 | Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier all | UNKNOWN | — | 2% | EPSS 2%ile | NVD | 2026-09-15 |
| CVE-2026-84850 | Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolution | UNKNOWN | — | 1% | EPSS 1%ile | NVD | 2026-09-15 |
| CVE-2026-49030 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. | UNKNOWN | — | — | — | NVD | 2026-09-13 |
| CVE-2026-87087 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r | UNKNOWN | — | — | — | NVD | 2026-09-14 |
| CVE-2013-1446 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issu | UNKNOWN | — | — | — | NVD | 2026-09-14 |
| CVE-2026-87730 | Rejected reason: this is rejected | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-66789 | Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerabil | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-66790 | Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerabil | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-10145 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-10149 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-10150 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-15 |
| CVE-2026-61396 | Rejected reason: Did not need CVE ID | UNKNOWN | — | — | — | NVD | 2026-09-16 |
| CVE-2026-92571 | Rejected reason: CVE ID reserved in error and not assigned to a vulnerability. The correct CVE ID is CVE-2026-92574. | UNKNOWN | — | — | — | NVD | 2026-09-16 |
| CVE-2026-85789 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-16 |
| CVE-2026-11874 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-53679 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-53681 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-9314 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-57846 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2025-62167 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33626. Reason: This candidate is a | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-10594 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-11314 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-49137 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-57847 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-11432 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-78668 | Rejected reason: reserved but not needed | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-65323 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-17 |
| CVE-2026-88623 | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us | UNKNOWN | — | — | — | NVD | 2026-09-18 |
| CVE-2026-93018 | Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas | UNKNOWN | — | — | — | NVD | 2026-09-18 |
| CVE-2026-60115 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | UNKNOWN | — | — | — | NVD | 2026-09-18 |
| CVE-2026-91863 | CVE-2026-91863: Apache Neethi: Uncontrolled recursion while parsing crafted WS-Policy documents allows denial of servic | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| CVE-2026-91864 | CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass element/attribute limits causing memory exhaustion | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| CVE-2026-91865 | CVE-2026-91865: Apache Neethi: Crafted policy references cause exponential expansion during normalization leading to de | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| CVE-2026-91866 | CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded work during intersection leading to denial of service | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| CVE-2026-91867 | CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total timeout, allowing a slow server to hang the request in | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| USN-8782-1 | USN-8782-1: Rclone vulnerability | UNKNOWN | — | — | — | Ubuntu | 2026-09-18 |
| USN-8730-3 | USN-8730-3: Linux kernel (Azure) vulnerability | UNKNOWN | — | — | — | Ubuntu | 2026-09-18 |
| USN-8715-2 | USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities | UNKNOWN | — | — | — | Ubuntu | 2026-09-18 |
| DSA 6494-1 | [SECURITY] [DSA 6494-1] kamailio security update | UNKNOWN | — | — | — | Debian | 2026-09-11 |
| DSA 6495-1 | [SECURITY] [DSA 6495-1] spip security update | UNKNOWN | — | — | — | Debian | 2026-09-11 |
| DSA 6497-1 | [SECURITY] [DSA 6497-1] xorg-server security update | UNKNOWN | — | — | — | Debian | 2026-09-12 |
| DSA 6499-1 | [SECURITY] [DSA 6499-1] cjose security update | UNKNOWN | — | — | — | Debian | 2026-09-15 |
| DSA 6500-1 | [SECURITY] [DSA 6500-1] tor security update | UNKNOWN | — | — | — | Debian | 2026-09-16 |
| DSA 6504-1 | [SECURITY] [DSA 6504-1] libapache2-mod-auth-openidc security update | UNKNOWN | — | — | — | Debian | 2026-09-17 |
| DSA 6506-1 | [SECURITY] [DSA 6506-1] chromium security update | UNKNOWN | — | — | — | Debian | 2026-09-17 |
| OSS-20260918-3 | A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| OSS-20260918-4 | Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| OSS-20260918-5 | Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| OSS-20260918-6 | Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| OSS-20260918-15 | Re: A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill | UNKNOWN | — | — | — | OSS-Security | 2026-09-18 |
| OSS-20260917-4 | The GNU C Library security advisories update for 2026-09-17 | UNKNOWN | — | — | — | OSS-Security | 2026-09-17 |
| OSS-20260916-3 | Unbound: 1.26.1 addresses multiple CVE items | UNKNOWN | — | — | — | OSS-Security | 2026-09-16 |
| OSS-20260916-5 | Multiple vulnerabilities in Jenkins plugins | UNKNOWN | — | — | — | OSS-Security | 2026-09-16 |
| OSS-20260914-26 | graphql-go/graphql <= 0.8.1: quadratic CPU-exhaustion DoS via OverlappingFieldsCanBeMergedRule | UNKNOWN | — | — | — | OSS-Security | 2026-09-14 |
| OSS-20260914-31 | The GNU C Library security advisories update for 2026-09-14 | UNKNOWN | — | — | — | OSS-Security | 2026-09-14 |
| OSS-20260913-1 | Fwd: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations | UNKNOWN | — | — | — | OSS-Security | 2026-09-13 |
| OSS-20260913-2 | Re: UnrealIRCd 6.2.7 released & hot-patch to fix security issues for existing installations | UNKNOWN | — | — | — | OSS-Security | 2026-09-13 |
| OSS-20260913-5 | GNU GRUB 2.14: serial-MMIO lockdown bypass in Canonical-signed gcdx64.efi | UNKNOWN | — | — | — | OSS-Security | 2026-09-13 |
| OSS-20260912-1 | Local Privilege Escalation (LPE) in FolkPatch due to Hardcoded Default SuperKey | UNKNOWN | — | — | — | OSS-Security | 2026-09-12 |
| OSS-20260912-2 | [vim-security] Ex Command Injection in sign_jump() in Vim < v9.2.1090 | UNKNOWN | — | — | — | OSS-Security | 2026-09-12 |
| GHSA-7jxh-36q5-gcqv | GHSA-7jxh-36q5-gcqv | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6444 | GO-2026-6444 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6454 | GO-2026-6454 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6455 | GO-2026-6455 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6465 | GO-2026-6465 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6466 | GO-2026-6466 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6467 | GO-2026-6467 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| GO-2026-6468 | GO-2026-6468 | UNKNOWN | — | — | — | OSV | 2026-09-17 |
| RUSTSEC-2026-0285 | RUSTSEC-2026-0285 | UNKNOWN | — | — | — | OSV | 2026-09-14 |
| FG-IR-26-165 | Arbitrary process termination from exposed minifilter communication port | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-164 | Broken Access control on Websocket streams | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-167 | Cron Job Injection in Remote Backup | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-168 | Improper Authentication of FortiPAM Server | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-170 | JWT used for authentication in web GUI signed with static key | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-173 | Null Pointer Dereference in Log Report | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-169 | Open Redirect on FortiSIEM | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-166 | Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-172 | Uncontrolled Resource Consumption in SNMP | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-171 | Workflow session email approval process bypass | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-174 | ZTNA Portal Improper Certificate Validation | UNKNOWN | — | — | — | Fortinet | 2026-09-08 |
| FG-IR-26-158 | Broken access control in the RADIUS type admin group | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-157 | Content-Encoding WAF Evasion | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-160 | FGFM Authentication Weakening via CLI Configuration | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-156 | Heap overflow in kernel driver due to missing size validation | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-159 | Server-Side Request Forgery (SSRF) | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-161 | Stack buffer overflow in WAD | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-162 | UI DoS attack | UNKNOWN | — | — | — | Fortinet | 2026-08-12 |
| FG-IR-26-154 | Buffer overread in authd and wad daemon | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-149 | Cross-Site Scripting in Domain parameter | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-152 | Header injection in Web Filter warning page | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-153 | Header injection in captive portal authentication form | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-147 | Missed certificate verification in AD Connector communication with FortiClient EMS | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-146 | Out of bounds read in GUI | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-151 | Path traversal in CLI command allows deletion of root file system | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-150 | SSL-VPN Reflected XSS | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-148 | Stack Buffer Overflow in Log Report | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-155 | Supers override fails to properly override supervisor address | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-26-145 | Unauthenticated VNC access exposed on all interfaces | UNKNOWN | — | — | — | Fortinet | 2026-07-14 |
| FG-IR-25-1052 | LDAP authentication bypass in Agentless VPN and FSSO | UNKNOWN | — | — | — | Fortinet | 2026-02-10 |
| FG-IR-26-140 | Improper access control in API endpoints | UNKNOWN | — | — | — | Fortinet | 2026-06-09 |
| FG-IR-26-143 | Restricted CLI escape using Lua | UNKNOWN | — | — | — | Fortinet | 2026-06-09 |
| FG-IR-26-141 | Second-Order OS Command Injection via JSON Input on start vnc feature | UNKNOWN | — | — | — | Fortinet | 2026-06-09 |
| FG-IR-24-452 | Insertion of Sensitive 2FA Information in logs and debug command | UNKNOWN | — | — | — | Fortinet | 2025-10-14 |
| FG-IR-25-545 | Trusted hosts bypass via SSH | UNKNOWN | — | — | — | Fortinet | 2025-11-18 |
| FG-IR-26-139 | Linux Kernel Vulnerability copy.fail - CVE-2026-31431 | UNKNOWN | — | — | — | Fortinet | 2026-05-13 |
| FG-IR-26-138 | Arbitrary log file read in administrative interface | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-131 | Command injection in CLI | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-137 | DoS due to unsafe function in signal handler | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-129 | Hardcoded Encryption Key Used for VPN Saved Passwords | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-128 | Improper access control on API endpoints | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-136 | Incorrect global authorization | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-133 | OS command injection in CLI | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-130 | OTP Disclosure via Exported TokenContentProvider | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
| FG-IR-26-123 | Out-of-bounds access in CAPWAP daemon | UNKNOWN | — | — | — | Fortinet | 2026-05-12 |
Updated 2026-09-18. Sources: NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB and more. JSON API available for automation.