--===============8050327280383293692==
Content-Type: multipart/alternative; boundary="===============0436581685986125891=="
MIME-Version: 1.0
--===============0436581685986125891==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Cybersecurity and Infrastructure Security Agency (CISA)
You are subscribed to Vulnerability Bulletins for Cybersecurity and Infrast= ructure Security Agency. This information has recently been updated and is = now available.
The CISA Vulnerability Bulletin provides a summary of new vulnerabilities t= hat have been recorded in the past week. In some cases, the vulnerabilities=
in the bulletin may not yet have assigned CVSS scores.
Vulnerabilities are based on the=C2=A0Common Vulnerabilities and Exposures =
[
https://www.cve.org/ ]=C2=A0(CVE) vulnerability naming standard and are o= rganized according to severity, determined by the=C2=A0Common Vulnerability=
Scoring System [
https://www.cve.org/about/relatedefforts ]=C2=A0(CVSS) st= andard. The division of high, medium, and low severities correspond to the = following scores:
* *High*: vulnerabilities with a CVSS base score of 7.0=E2=80=9310.0=20
* *Medium*: vulnerabilities with a CVSS base score of 4.0=E2=80=936.9=20
* *Low*: vulnerabilities with a CVSS base score of 0.0=E2=80=933.9=20
Entries may include additional information provided by organizations and ef= forts sponsored by CISA. This information may include identifying informati= on, values, definitions, and related links. Patch information is provided w= hen available. Please note that some of the information in the bulletin is = compiled from external, open-source reports and is not a direct result of C= ISA analysis.
=C2=A0
Vulnerability Summary for the Week of August 31, 2026 [
https://www.cisa.go= v/news-events/bulletins/sb26-250 ] 09/08/2026 03:40 PM EDT=20
High Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 1Hive--garde= ns-v2 Gardens v2 is a modular governance framework that enables communities=
to create and manage multiple governance pools with customizable parameter=
s and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is=
funded, the cluster of streaming contracts moves real pool funds into the = proposal's StreamingEscrow to back the Superfluid constant flow agreement (= the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the=
escrow's GDA member units but never reclaims that parked balance, and the = permissionless claim() forwards the escrow's entire balance, including the = pool funded buffer, to the beneficiary. The beneficiary is chosen by the pr= oposal submitter and defaults to the submitter. The only path that returns = escrow funds to the pool is drainToStrategy, which is onlyStrategy and is r= eached solely from the dispute reject ruling, never from cancel or natural = completion. At time of publication, there are no publicly known patches. 20= 26-09-03 7.7 CVE-2026-55658 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5= 5658 ] : Shane Bishop--EWWW Image Optimizer Unauthenticated Cross Site Scri= pting (XSS) in EWWW Image Optimizer <=3D 8.7.6 versions. 2026-09-03 7.2 CVE= -2026-84773 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84773 ] @fastify/= http-proxy--@fastify/http-proxy @fastify/http-proxy versions before 11.6.2 =
do not validate proxied HTTP request paths for backslash based dot-segments=
before forwarding them to the configured upstream. The plain HTTP request = handler skips the destination validation that the WebSocket path performs, = and the underlying reply-from library only rejects forward-slash traversal,=
so a request containing backslash dot-segments can escape the boundary set=
by the prefix and rewritePrefix options. An unauthenticated network attack=
er can use this to reach upstream paths that were meant to stay hidden behi=
nd the proxy, resulting in disclosure of internal endpoints. This is a path=
traversal issue (CWE-22). Users should upgrade to @fastify/http-proxy 11.6=
.2 or later. 2026-09-03 7.5 CVE-2026-85124 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-85124 ] @fastify/middie--@fastify/middie @fastify/middie vers= ions >=3D 9.1.0 and before 9.3.4 decide whether to run path-scoped middlewa=
re by matching against the raw request target, while the Fastify router res= olves an absolute-form request target to its path before dispatching. Becau=
se the two layers evaluate different strings, a request using an absolute-f= orm target reaches the route handler while the path-scoped middleware, such=
as authentication or authorization, is skipped. An unauthenticated network=
attacker can use this to bypass path-based access controls in a Fastify ap= plication that relies on middie for those controls. Users should upgrade to=
@fastify/middie 9.3.4 or later. 2026-09-04 9.1 CVE-2026-85184 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85184 ] aaif-goose--goose goose 1.37.0 ex= ecutes arbitrary commands from recipe stdio extensions and retry.checks wit= hout security inspection. Attackers can distribute malicious recipes that e= xecute shell commands as the user running goose, bypassing the recipe secur= ity scan which does not inspect extensions or retry configurations. 2026-09= -04 8.8 CVE-2026-85623 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85623 =
] Acato--Email Essentials Unauthenticated Cross Site Scripting (XSS) in Ema=
il Essentials <=3D 6.0.6 versions. 2026-08-31 7.1 CVE-2026-81764 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-81764 ] Adobe--Adobe Substance 3D Sampl=
er Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulner= ability that could result in arbitrary code execution in the context of the=
current user. Exploitation of this issue requires user interaction in that=
a victim must open a malicious file. 2026-09-03 7.8 CVE-2026-83959 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-83959 ] Adobe--ColdFusion 2025 ColdF= usion is affected by an Improper Authentication vulnerability that could re= sult in privilege escalation. An attacker could leverage this vulnerability=
to gain limited read and write access. The vulnerable component is restric= ted to an administrative network zone by default. Exploitation of this issu=
e does not require user interaction. Scope is changed. 2026-09-03 7.1 CVE-2= 026-83961 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83961 ] Advanced Cu= stom Fields: Extended--Advanced Custom Fields: Extended The Advanced Custom=
Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the = requester is authorized to edit the targeted user account in the update-use=
r action of its front-end Forms module; it only checks a capability when th=
e submitted role is administrator or super_admin. On a site that exposes a = publicly reachable front-end form whose user-update action targets an exist= ing administrator (a fixed target, or one mapped to a visitor-submitted fie= ld) and maps the password to a visitor-submitted field, an unauthenticated = visitor can overwrite that administrator's password and take over the accou= nt. The default target is the submitting user, so exploitation depends on t=
he form being configured to target another account. 2026-09-02 8.1 CVE-2026= -12526 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12526 ] Advanced Custo=
m Fields: Extended--Advanced Custom Fields: Extended The Advanced Custom Fi= elds: Extended WordPress plugin before 0.9.2.7 does not restrict the role s= ubmitted through its front-end user forms to the roles the form actually of= fers, and its safeguard against privileged roles is incomplete, allowing un= authenticated visitors to register an account with elevated capabilities an=
d then escalate it to administrator. 2026-09-02 8.1 CVE-2026-80467 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-80467 ] advanpix--WP QuickLaTeX Unaut= henticated Cross Site Scripting (XSS) in WP QuickLaTeX <=3D 3.8.8 versions.=
2026-09-03 7.1 CVE-2026-81776 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-81776 ] agentscope-ai--agentscope AgentScope through 2.0.7.post1 contains=
a path traversal vulnerability in LocalWorkspace.add_skill that copies arb= itrary server directories into the agent workspace via an unconfined source=
path parameter. Attackers can supply any directory path in the skill_path = request parameter to copy files into the skills directory, making them acce= ssible through the workspace skill listing. 2026-09-04 7.5 CVE-2026-85685 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85685 ] AI Website Builder (Gi= tHub build)--AI Website Builder (GitHub build) The AI Website Builder WordP= ress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonc=
e check on its REST API routes, allowing unauthenticated attackers to insta=
ll and activate plugins and themes, import content from a URL under their c= ontrol, write a file of their choosing into the uploads directory, and dele=
te site content and media. On a host that serves PHP from the uploads direc= tory, that file write is remote code execution. 2026-09-04 9.8 CVE-2026-829=
23 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82923 ] Aider-AI--aider ai= der (aider-chat) automatically loads a .aider.conf.yml configuration file f= rom the root of the git repository it is launched in. A crafted repository = can set test-cmd (executed at startup) or lint-cmd (executed on the first f= ile edit), which aider runs through a shell (subprocess with shell=3DTrue) = without any user confirmation, LLM interaction, or API key. Consequently, a=
user who clones and runs aider inside an attacker-supplied repository achi= eves arbitrary command execution on their machine. The behavior is long-sta= nding and was confirmed on 0.86.3.dev (current main). 2026-09-04 7.8 CVE-20= 26-85674 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85674 ] aimhubio--ai=
m Aim 3.29.1 remote tracking server fails to authenticate requests and disp= atches arbitrary methods through getattr without allowlist validation. Unau= thenticated attackers can register clients, instantiate Repo resources, and=
invoke arbitrary methods to read experiments or delete runs. 2026-09-04 9.=
8 CVE-2026-85663 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85663 ] Amaz= on-- EFS CSI Driver
=C2=A0 Unverified ownership of a storage access point in the volume deletio=
n component of the Amazon EFS CSI Driver before v3.4.1 might allow an authe= nticated Kubernetes user with PersistentVolume creation privileges to cause=
recursive deletion of directories on an EFS filesystem they are not author= ized to access, via a crafted PersistentVolume volumeHandle that pairs an a= ccess point from one filesystem with a different target filesystem. To reme= diate this issue, users should upgrade to version v3.4.1. 2026-09-04 8.7 CV= E-2026-85781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85781 ] Amazon--= awslabs.dynamodb-mcp-server Improper neutralization of special elements use=
d in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-= server before 2.1.6 might allow a context-dependent actor to execute arbitr= ary code on the host that deploys the generated application via crafted tab= le, index, or attribute names in a data model file. 2026-09-04 7.8 CVE-2026= -85654 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85654 ] Amazon--ion-c =
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.=
6 that might allow a remote unauthenticated actor to craft Ion data that ex= hausts the native call stack and crashes the application using the library,=
resulting in a denial of service. 2026-09-03 7.5 CVE-2026-84851 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84851 ] Amazon--ion-java
=C2=A0 Improper handling of highly compressed data in Amazon ion-java befor=
e 1.12.1 might allow remote attackers to cause a denial of service via a cr= afted compressed Ion document that expands to an arbitrarily large size upo=
n decompression due to insufficient coverage of the GZIP auto-decompression=
opt-out introduced for CVE-2026-75936. To remediate this issue, users shou=
ld upgrade to version 1.12.1. 2026-09-04 7.5 CVE-2026-85786 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85786 ] Amazon--log4j-cve-2021-44228-hotpatc=
h An OS command injection issue in the log4j-cve-2021-44228-hotpatch packag=
e in Amazon Linux before 1.3-9 might allow a local user to execute arbitrar=
y commands with root privileges via a Java process whose executable path co= ntains embedded newline characters. 2026-09-04 7.8 CVE-2026-85656 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-85656 ] AMD--2nd Gen AMD EPYC Processo=
rs A heap overflow in SMM module may allow an attacker with access to a sec= ond vulnerability that enables writing to SPI flash, potentially resulting =
in arbitrary code execution. 2026-09-02 7.4 CVE-2023-20577 [
https://www.cv= e.org/CVERecord?id=3DCVE-2023-20577 ] AMD--AMD Ryzen 3000 Series Desktop Pr= ocessors Insufficient Verification of Data Authenticity in AGESA=C3=A2=E2= =80=9E=C2=A2 may allow an attacker to update SPI ROM data potentially resul= ting in denial of service or privilege escalation. 2026-09-02 7.7 CVE-2023-= 20576 [
https://www.cve.org/CVERecord?id=3DCVE-2023-20576 ] Ankara Hosting-= -Site Management Panel Improper neutralization of special elements used in =
an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Manag= ement Panel allows SQL Injection. This issue affects Site Management Panel:=
through 15062026. 2026-08-31 8.8 CVE-2026-5956 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-5956 ] apache -- wicket Apache Wicket enforces the uploa=
d limits configured on a form or upload field while parsing a multipart req= uest with Apache Commons FileUpload. If the request body has already been c= onsumed by another component, Commons FileUpload returns no items and Wicke=
t falls back to reading the upload through HttpServletRequest#getParts(). T=
he per-file size limit (for example Form#setFileMaxSize) and the file count=
limit (Form#setFileCountMax) are not applied to the parts obtained that wa=
y, and no exception is raised, so the upload is processed as though those l= imits had been satisfied. A remote uploader can therefore submit files that=
are larger, or more numerous, than the application permits, up to whatever=
the component that parsed the request allows. A part carrying no Content-T= ype header is additionally read into memory in full during parsing, so the = size of that allocation is determined by the request and bounded only by th= ose same external limits. The total upload size limit (Form#setMaxSize) is = not affected. Commons FileUpload compares the declared Content-Length again=
st it before reading the body, so a request declaring an oversized length i=
s rejected before the fallback is reached. The fallback is reached in deplo= yments where a servlet or filter has already parsed the request body - for = example a servlet annotated with @MultipartConfig, Spring Boot's multipart = resolver, or any filter that calls HttpServletRequest#getParameter() on a m= ultipart request. It applies to the Wicket components that accept uploads o=
n that path, including Form with FileUploadField, FileUploadToResourceField=
and AjaxFileDropBehavior. Applications that configure neither a per-file n=
or a file-count limit are not affected, as Wicket applies neither by defaul=
t. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 = through 9.23.0, from 10.0.0 through 10.10.0. Users are recommended to upgra=
de to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue. Users of Apac=
he Wicket 7.x or older, which are no longer supported, should upgrade to a = supported version. As a workaround, configure equivalent limits in the comp= onent that parses the request - for example spring.servlet.multipart.max-fi= le-size and max-request-size, or maxFileSize and maxRequestSize in @Multipa= rtConfig or in the web.xml <multipart-config> element. 2026-08-31 7.5 CVE-2= 026-71257 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71257 ] Apache Soft= ware Foundation--Apache Allura Apache Allura: exposure of non-public inform= ation via search. This issue affects Apache Allura: through 1.20.0. Users a=
re recommended to upgrade to version 1.21.0, which fixes the issue. 2026-09= -04 7.5 CVE-2026-81270 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81270 =
] apitable--apitable APITable through 1.13.0-beta.1 exposes the internal or= ganization loadOrSearch endpoint without authentication, allowing unauthent= icated attackers to retrieve member names, email addresses, and team hierar= chy. Attackers can query the endpoint with space identifiers obtained from = shared links or public templates to enumerate the complete member directory=
of any workspace. 2026-09-02 7.5 CVE-2026-84485 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-84485 ] AppFlowy-IO--AppFlowy-Cloud AppFlowy-Cloud 0.9.=
64 fails to verify that requested collab objects belong to the workspace in=
authorization checks, allowing attackers to access documents and database = rows across workspaces. Attackers can supply a victim's object ID with thei=
r own workspace ID to bypass access controls and read, modify, or delete cr= oss-workspace data. 2026-09-04 7.5 CVE-2026-85619 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-85619 ] AresIT--WP Compress Unauthenticated Settings C= hange in WP Compress <=3D 7.21.28 versions. 2026-09-03 8.2 CVE-2026-84757 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-84757 ] argneshu--appium-mcp-s= erver appium-mcp-server through 0.1.61 fails to validate or normalize file = paths in the write_file and write_files_batch tools, allowing attackers to = write files outside the intended PROJECT_ROOT directory. Attackers can supp=
ly absolute paths or relative paths with parent directory segments to overw= rite arbitrary files with the server user's privileges, including shell pro= files and configuration files in the home directory. 2026-09-01 7.1 CVE-202= 6-84201 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84201 ] arubanetworks=
-- fabric_composer Vulnerabilities have been identified in the API of HPE = Networking Fabric Composer that could potentially allow an unauthenticated = remote attacker to circumvent existing authentication controls. Successful = exploitation could allow an attacker to gain administrative privileges lead= ing to complete compromise of the HPE Networking Fabric Composer host. 2026= -09-01 10 CVE-2026-76657 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7665=
7 ] arubanetworks -- fabric_composer A vulnerability has been identified in=
the SSH daemon of HPE Networking Fabric Composer that could allow an unaut= henticated remote attacker to gain administrative access to vulnerable AFC = hosts. Successful exploitation could allow an attacker to execute arbitrary=
commands as a privileged user on the underlying operating system leading t=
o complete system compromise. 2026-09-01 10 CVE-2026-76658 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-76658 ] arubanetworks -- fabric_composer An a= uthentication bypass vulnerability exists in the underlying operating syste=
m of HPE Networking Fabric Composer. Successful exploitation could allow an=
unauthenticated adjacent attacker to execute arbitrary code as a privilege=
d user on the underlying operating system, leading to complete compromise o=
f the AFC host. 2026-09-01 9.6 CVE-2026-19766 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-19766 ] arubanetworks -- fabric_composer A vulnerability i=
n the web-based management interface of HPE Networking Fabric Composer coul=
d allow an authenticated low privilege operator user to conduct a stored cr= oss-site scripting (XSS) attack against an administrative user of the inter= face. A successful exploit could allow an attacker to execute arbitrary scr= ipt code in a victim's browser in the context of the affected interface. 20= 26-09-01 9 CVE-2026-73700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-737=
00 ] arubanetworks -- fabric_composer An unauthenticated remote code execut= ion vulnerability exists in the underlying operating system of HPE Networki=
ng Fabric Composer and could be exploited if certain preconditions outside =
of the attacker's control are met. Successful exploitation of this vulnerab= ility could allow an unauthenticated remote attacker to execute arbitrary c= ode as a privileged user on the underlying operating system, leading to com= plete compromise of the HPE Networking Fabric Composer host. 2026-09-01 9 C= VE-2026-73701 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73701 ] arubane= tworks -- fabric_composer A privilege escalation vulnerability exists in th=
e API of HPE Networking Fabric Composer. Successful exploitation could allo=
w an authenticated low privilege operator user to escalate their permission=
s to those of an administrative user, leading to complete system compromise=
. 2026-09-01 8.8 CVE-2026-73702 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-73702 ] arubanetworks -- fabric_composer A vulnerability in the web-base=
d management interface of HPE Networking Fabric Composer could allow an una= uthenticated adjacent attacker to conduct a stored cross-site scripting (XS=
S) attack against a user of the interface. A successful exploit could allow=
an attacker to execute arbitrary script code in a victim's browser in the = context of the affected interface. 2026-09-01 8.8 CVE-2026-73703 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-73703 ] arubanetworks -- fabric_compose=
r A command sanitization bypass exists in the API of HPE Networking Fabric = Composer. Successful exploitation could allow an authenticated low privileg=
e operator user to escalate their permissions to those of an administrative=
user, leading to complete compromise of the affected system. 2026-09-01 8.=
8 CVE-2026-73704 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73704 ] arub= anetworks -- fabric_composer An arbitrary file write vulnerability in the A=
PI of HPE Networking Fabric Composer could allow an authenticated low privi= lege operator user to escalate privileges. Successful exploitation of this = vulnerability may enable the attacker to execute arbitrary commands on the = underlying operating system, leading to complete compromise of the affected=
system. 2026-09-01 8.8 CVE-2026-73705 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-73705 ] arubanetworks -- fabric_composer A vulnerability in the=
API of HPE Networking Fabric Composer could allow an unauthenticated remot=
e attacker to obtain limited system information and to change the state of = certain settings of a vulnerable system. Successful exploitation could allo=
w an attacker to gain insight into internal services and workflows and to m= ake unauthorized changes that may disrupt the normal operation of the affec= ted service. 2026-09-01 8.6 CVE-2026-73706 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-73706 ] arubanetworks -- fabric_composer Privilege escalation=
vulnerabilities exist in the API of HPE Networking Fabric Composer. Succes= sful exploitation could allow an authenticated low privilege operator user =
to complete state-changing actions that should not be allowed by their curr= ent level of authorization on the platform, including changes to the config= uration of systems managed by the affected product. 2026-09-01 8.5 CVE-2026= -73707 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73707 ] arubanetworks =
-- fabric_composer A business logic vulnerability exists in the API of HPE = Networking Fabric Composer. Successful exploitation could allow an authenti= cated low privilege operator user to obtain elevated privileges and modify = settings beyond what is authorized by the user's existing privilege level o=
n a vulnerable system. 2026-09-01 8.3 CVE-2026-73708 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-73708 ] arubanetworks -- fabric_composer A vulnerab= ility in the underlying operating system of HPE Networking Fabric Composer = could allow an unauthenticated adjacent attacker to run arbitrary commands =
on the underlying host if certain preconditions outside of the attacker's c= ontrol are met. Successful exploitation could allow an attacker to execute = arbitrary commands on the underlying operating system. 2026-09-01 8.3 CVE-2= 026-73709 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73709 ] arubanetwor=
ks -- fabric_composer Vulnerabilities in an API endpoint of HPE Networking = Fabric Composer could allow an unauthenticated remote attacker to conduct a=
denial of service attack. Successful exploitation could allow an attacker =
to make limited unauthorized modifications to the underlying operating syst=
em and disrupt the availability of the affected system, requiring manual in= tervention to restore functionality. 2026-09-01 8.2 CVE-2026-73710 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-73710 ] arubanetworks -- fabric_compo= ser A privilege escalation vulnerability exists in the API endpoint of HPE = Networking Fabric Composer. Successful exploitation could allow an unauthen= ticated remote attacker to gain administrative privileges leading to comple=
te compromise of the HPE Networking Fabric Composer host. 2026-09-01 8.1 CV= E-2026-73711 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73711 ] arubanet= works -- fabric_composer A vulnerability in the API of HPE Networking Fabri=
c Composer could allow an unauthenticated remote attacker to run arbitrary = commands on the underlying host if certain preconditions outside of the att= acker's control are met. Successful exploitation of this vulnerability coul=
d allow an attacker to execute arbitrary commands on the underlying operati=
ng system leading to complete system compromise. 2026-09-01 8.1 CVE-2026-73= 712 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73712 ] arubanetworks -- = fabric_composer Local privilege-escalation vulnerabilities have been discov= ered in HPE Networking Fabric Composer. Successful exploitation of these vu= lnerabilities could allow a local attacker to achieve arbitrary code execut= ion with root privileges on the underlying operating system of the affected=
system. 2026-09-01 7.8 CVE-2026-73713 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-73713 ] arubanetworks -- fabric_composer A sensitive informatio=
n disclosure vulnerability exists in the API of HPE Networking Fabric Compo= ser. Successful exploitation could allow an authenticated low privilege ope= rator user to access data beyond what is authorized by the user's existing = privilege level, potentially leading to further unauthorized access. 2026-0= 9-01 7.6 CVE-2026-73714 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73714=
] arubanetworks -- fabric_composer A vulnerability in the API of HPE Netwo= rking Fabric Composer could allow an unauthenticated remote attacker to con= duct a denial of service attack. Successful exploitation could allow an att= acker to disrupt the availability of the affected interface. 2026-09-01 7.5=
CVE-2026-73715 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73715 ] aruba= networks -- fabric_composer A remote code execution vulnerability exists in=
the underlying operating system of HPE Networking Fabric Composer that cou=
ld allow an unauthenticated remote attacker to run arbitrary commands on th=
e underlying host if certain preconditions outside of the attacker's contro=
l are met. Successful exploitation could allow an attacker to execute arbit= rary commands as a privileged user on the underlying operating system, lead= ing to complete compromise of the HPE Networking Fabric Composer host. 2026= -09-01 7.5 CVE-2026-73716 [
https://www.cve.org/CVERecord?id=3DCVE-2026-737=
16 ] arubanetworks -- fabric_composer A command injection vulnerability exi= sts in the web-based management interface of HPE Networking Fabric Composer=
that could allow an unauthenticated remote attacker to run arbitrary comma= nds on the underlying host if certain preconditions outside of the attacker=
's control are met. Successful exploitation could allow an attacker to exec= ute arbitrary commands on the underlying operating system leading to comple=
te system compromise. 2026-09-01 7.5 CVE-2026-73717 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-73717 ] arubanetworks -- fabric_composer A vulnerabi= lity in the web-based management interface of HPE Networking Fabric Compose=
r could allow an unauthenticated remote attacker to access sensitive inform= ation if the attacker can convince an authenticated user of the interface t=
o interact with a specially crafted URL. Successful exploitation could allo=
w an attacker to retrieve information which could be used to potentially ga=
in further access to network services supported by HPE Networking Fabric Co= mposer. 2026-09-01 7.4 CVE-2026-73718 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-73718 ] arubanetworks -- fabric_composer An arbitrary file write v= ulnerability exists in the API of HPE Networking Fabric Composer and could = allow an authenticated administrative user to escalate privileges. Successf=
ul exploitation of this vulnerability may enable the attacker to execute ar= bitrary system commands with root privileges on the underlying operating sy= stem. 2026-09-01 7.2 CVE-2026-73719 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-73719 ] arubanetworks -- fabric_composer Insecure file operations in=
the API of HPE Networking Fabric Composer could allow an authenticated rem= ote attacker to achieve remote code execution. Successful exploitation coul=
d allow an attacker to execute arbitrary commands as a privileged user on t=
he underlying operating system. 2026-09-01 7.2 CVE-2026-73720 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-73720 ] arubanetworks -- fabric_composer V= ulnerabilities in the API of HPE Networking Fabric Composer could allow an = authenticated remote attacker to conduct SQL injection attacks against the = HPE Networking Fabric Composer instance. An attacker could exploit these vu= lnerabilities to obtain and modify sensitive information in the underlying = database potentially leading to complete compromise of the HPE Networking F= abric Composer host. 2026-09-01 7.2 CVE-2026-73721 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-73721 ] arubanetworks -- fabric_composer Command inje= ction vulnerabilities in the web-based management interface of HPE Networki=
ng Fabric Composer could allow an authenticated remote attacker to perform = command injection against the affected system. Successful exploitation coul=
d allow an attacker to execute arbitrary commands as a privileged user on t=
he underlying operating system. 2026-09-01 7.2 CVE-2026-73722 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-73722 ] arubanetworks -- fabric_composer A=
privilege escalation vulnerability exists in the web-based management inte= rface of HPE Networking Fabric Composer. Successful exploitation could allo=
w an authenticated low privilege operator user to complete state-changing a= ctions that should not be allowed by their current level of authorization o=
n the platform. 2026-09-01 7.1 CVE-2026-73723 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-73723 ] arubanetworks -- fabric_composer Privilege escalat= ion vulnerabilities exist in the API of HPE Networking Fabric Composer. Suc= cessful exploitation could allow an authenticated low privilege operator us=
er to change the state of certain settings of a vulnerable system. 2026-09-=
01 7.1 CVE-2026-73724 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73724 ]=
arubanetworks -- fabric_composer A local privilege-escalation vulnerabilit=
y has been discovered in HPE Networking Fabric Composer. Successful exploit= ation of this vulnerability could allow a local attacker to achieve arbitra=
ry code execution with root privileges, leading to a complete compromise of=
the affected host. 2026-09-01 7 CVE-2026-73725 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-73725 ] AS203038--looking-glass Looking Glass is a moder=
n, stateless network-diagnostic platform - a single self-contained Go binar=
y that fronts a fleet of routers over SSH and exposes ping / traceroute / B=
GP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, a=
nd a lg-cli client. Prior to version 1.3.5, there is an OS Command Injectio=
n vulnerability resulting from an unanchored regular expression in the inpu=
t validation layer. This issue has been patched in version 1.3.5. 2026-09-0=
2 9.8 CVE-2026-53611 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53611 ] = Auto x LINE--Auto x LINE The Auto x LINE WordPress plugin through 1.0.0 doe=
s not have authorization checks in some of its REST endpoints, allowing una= uthenticated users to call them and update the plugin settings, clear logs = etc 2026-09-02 8.2 CVE-2025-15485 [
https://www.cve.org/CVERecord?id=3DCVE-= 2025-15485 ] AutoAgent --AutoAgent
=C2=A0 AutoAgent contains an unauthenticated remote code execution vulnerab= ility in the TCP server that binds to all interfaces and executes attacker-= supplied commands as root. Attackers can connect to the exposed communicati=
on port and execute arbitrary bash commands within the container, gaining a= ccess to bind-mounted host workspace directories. 2026-09-05 9.8 CVE-2026-8= 6124 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86124 ] Automattic--WooC= ommerce Improper Neutralization of Special Elements used in an SQL Command = ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL = Injection. This issue affects WooCommerce: from n/a before 11.0. 2026-09-04=
7.6 CVE-2026-57777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57777 ] A= utorius E-goi--Smart Marketing SMS and Newsletters Forms Unauthenticated SQ=
L Injection in Smart Marketing SMS and Newsletters Forms <=3D 5.1.24 versio= ns. 2026-08-31 9.3 CVE-2026-81756 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-81756 ] Avaiga--taipy Taipy configures its socket.io server with wildc= ard CORS origin and credential flag enabled, allowing any web page to estab= lish credentialed WebSocket connections to victim applications. Attackers c=
an open socket.io sessions from arbitrary domains and invoke state variable=
modifications and action callbacks without CSRF protection. 2026-09-03 9.3=
CVE-2026-85183 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85183 ] AVide=
o --AVideo with YPTSocket plugin
=C2=A0 AVideo with YPTSocket plugin enabled contains a cross-site scripting=
vulnerability allowing unauthenticated attackers to execute arbitrary Java= Script in other users' browsers via the websocket callback mechanism. Attac= kers can send crafted socket messages with callback names resolving to glob=
al functions like avideoConfirmHTML that accept untrusted data and assign i=
t to innerHTML, achieving script execution in the victim's origin without a= uthentication or user interaction. 2026-09-05 7.2 CVE-2026-86188 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-86188 ] AWS--@amazon-codecatalyst/bluep= rints.blueprint Improper neutralization of special elements used in an OS c= ommand (CWE-78) in the blueprint resynthesis framework in Amazon Web Servic=
es codecatalyst-blueprints before 0.3.156 might allow a user with permissio=
n to commit to a repository in the project to execute arbitrary commands in=
the blueprint resynthesis environment via shell metacharacters in the owne=
r field of a [local] merge strategy entry in a crafted .ownership-file. Ver= sion 0.3.156 removes shell interpretation of the owner field, running the c= ommand directly rather than through a shell, and rejects values outside an = allowlisted command form. This eliminates shell metacharacter command injec= tion. To remediate this issue, users should upgrade to version 0.3.156 or l= ater. No action is required for use of the Amazon CodeCatalyst service. Res= ynthesis runs in an isolated per-project environment with scoped credential=
s, and the service applies server-side validation there that rejects [local=
] merge strategy commands outside a restricted allowlisted form, including = for blueprint versions published before 0.3.156. 2026-09-03 8 CVE-2026-8501=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85012 ] AWS--aws-fpga Creat= ion of a temporary file in a directory with insecure permissions in the FPG=
A management tool installation component in AWS FPGA Development Kit (aws-f= pga) before 2.3.4 might allow local users to execute arbitrary code with ro=
ot privileges via crafted shell content placed at a predictable path in a w= orld-writable temporary directory, which the installation step reads after = elevating its own privileges. To remediate this issue, users should upgrade=
to version 2.3.4. 2026-09-03 7.8 CVE-2026-85028 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-85028 ] AWS--sagemaker-python-sdk Cleartext storage of = sensitive information in the @step and @remote decorator pipeline component=
in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an = authenticated remote user to extract the HMAC signing key from SageMaker De= scribePipeline API responses and forge valid integrity signatures for speci= ally crafted function payloads, achieving code execution in another user's = pipeline execution context within the same AWS account. 2026-09-01 7.2 CVE-= 2026-83551 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83551 ] Axolotl--A= xolotl=C2=A0
=C2=A0 Axolotl through 0.18.0 contains a remote code execution vulnerabilit=
y in the multipack patch path where trust_remote_code defaults to None inst= ead of False, causing the security guard to be bypassed. Attackers can exec= ute arbitrary Python code by crafting a malicious Hugging Face model reposi= tory selected as base_model, which is loaded with hardcoded trust_remote_co= de=3DTrue during AutoModelForCausalLM.from_pretrained. 2026-09-05 8.8 CVE-2= 026-86169 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86169 ] B&R Industr= ial Automation GmbH--mapp Services Use of Weak Credentials vulnerability in=
B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issu=
e affects mapp Audit used in mapp Services: before 6.8.0. 2026-09-03 8.7 CV= E-2026-79679 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79679 ] bdthemes= --SigmaForms Pro AI Generated Forms The SigmaForms Pro - AI Generated Forms=
plugin for WordPress is vulnerable to arbitrary file deletion due to insuf= ficient file path validation in the delete_submission_files function in all=
versions up to, and including, 1.4.11. This makes it possible for unauthen= ticated attackers to delete arbitrary files on the server, which can easily=
lead to remote code execution when the right file is deleted (such as wp-c= onfig.php). The malicious path traversal URL is submitted via form upload f= ield and stored in the database, with deletion triggered when an administra= tor deletes the submission record from the admin panel. 2026-09-02 9.8 CVE-= 2026-78657 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78657 ] Bifrost HT=
TP transport --Bifrost HTTP transport
=C2=A0 Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin=
whose path is an HTTP URL through unauthenticated POST /api/plugins when m= anagement authentication is disabled (the default, governance.auth_config.i= s_enabled=3Dfalse). The shared-object loader treats an http-prefixed path a=
s a download URL, writes the body to a temporary .so, and passes it to Go's=
plugin.Open. After a successful open, optional Init runs immediately with = the supplied config as the Bifrost process user. On documented dynamically = linked builds (DYNAMIC=3D1 / no static-link flags), which the vendor requir=
es for custom Go plugins, plugin.Open is expected to succeed and this is un= authenticated remote code execution. On the published statically linked Doc= ker image, plugin.Open fails with Dynamic loading not supported, so that bu= ild class is only server-side request forgery. Attack complexity is High be= cause the attacker cannot force RCE on the default static image and a loada= ble plugin must match the host Go version, OS, architecture, and linkage. T=
he 1.6.x HTTP transport line through 1.6.11 does not contain the fix. 2026-= 09-06 8.1 CVE-2026-86242 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8624=
2 ] Bilibili Desktop--Bilibili Desktop
=C2=A0 Bilibili Desktop through 1.18.0 disables TLS certificate verificatio=
n process-wide and executes unsigned remote JavaScript configuration withou=
t integrity checks. An attacker in an on-path network position can intercep=
t configuration fetches, inject arbitrary JavaScript executed in the render=
er with access to the privileged IPC bridge, and execute system commands or=
steal login credentials. 2026-09-05 8 CVE-2026-86185 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-86185 ] BinaryMuse--toml-node toml-node is a TOML = parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/com= piler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, = allowing traversal from a scalar value into Number.prototype and Object.pro= totype. The currentPath tracking value uses both arrays and strings, so val= ueAssignments records a comma-joined path such as a,b.y while deepRef check=
s the dot-joined path a.b.y, allowing the duplicate-key guard to miss and a= ttacker-controlled keys to be written to Object.prototype. A table-array pr= efix-clearing path in addTableArray can also erase guard state before the s= ame __proto__ traversal. Injected properties become visible throughout the = Node.js process and can cause denial of service, logic or authorization byp= ass, or code execution when an application contains a suitable gadget. This=
issue is fixed in version 4.1.2. 2026-09-03 8.2 CVE-2026-63376 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-63376 ] BinaryMuse--toml-node toml-node =
is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() = uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whos=
e peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions=
recurse through nested arrays and inline tables without a depth limit. A r= emote unauthenticated application parsing an attacker-controlled TOML docum= ent containing a few thousand nested arrays or inline tables can exhaust th=
e Node.js call stack, raise an unexpected RangeError rather than the parser=
's SyntaxError, and terminate an unprotected request worker or process. The=
corresponding grammar source is src/toml.pegjs, where the generated parser=
must be bounded. This issue is fixed in version 4.2.0. 2026-09-03 7.5 CVE-= 2026-77465 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77465 ] BishopFox-= -joro Joro is a web exploitation framework. Prior to version 1.1.1, Joro's = default proxy mode exposes a local API on 127.0.0.1:9090 that performs no a= uthentication and applies a wildcard CORS policy. Because plugin uploads us=
e the CORS-safelisted multipart/form-data content type, cross-origin JavaSc= ript on any page the operator visits can reach privileged endpoints - inclu= ding uploading a native plugin and triggering a restart - directly through = the operator's browser, with no preflight or credentials. Since plugins exe= cute on load, this yields unauthenticated remote code execution as the oper= ator's user from a single page visit. This issue has been patched in versio=
n 1.1.1. 2026-09-02 9.6 CVE-2026-53649 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53649 ] blinkospace--blinko Blinko 1.8.7 contains an authorizat= ion bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, = message.update, message.delete, message.clearAfter in server/routerTrpc/mes= sage.ts and conversation.clearMessages in server/routerTrpc/conversation.ts=
). Although these procedures require authentication, they query the databas=
e by caller-supplied conversation or message ID without verifying that the = resource belongs to the requesting account. Any authenticated user can ther= efore read another user's full AI chat history, modify individual message c= ontent, and delete or wipe entire conversations by enumerating sequential i= nteger IDs. 2026-09-04 8.8 CVE-2026-85607 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85607 ] bluewave-labs--Checkmate Checkmate through 3.11.0 omit=
s the isAllowed role guard middleware on maintenance-window, notification, = and check-deletion routes, allowing read-only users to perform administrati=
ve actions. Attackers with user-role sessions can create arbitrary maintena= nce windows to silence alerts, modify notification channels, and delete mon= itor check history to erase incident evidence. 2026-09-03 7.1 CVE-2026-8539=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85390 ] bookstackapp--books= tack BookStack before 26.05.4 contains a stored cross-site scripting vulner= ability in the drawing upload endpoint that accepts unvalidated base64 cont= ent and stores it without content inspection. Attackers with editor permiss= ions can upload SVG files containing scripts that execute in administrator = browsers when accessed through the image gallery API without content-type v= alidation or CSP headers. 2026-09-02 8.7 CVE-2026-84695 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-84695 ] BPF--BPF=C2=A0
=C2=A0 In BPF instructions that load/store a value from/to a scratch memory=
register the register index is an unsigned 32-bit integer and must not exc= eed 15, but libpcap BPF interpreter does not validate the value. In particu= lar uncommon use cases a crafted filter program can cause the interpreter t=
o try reading and writing the OS process memory in the 16GiB starting at th=
e current stack frame on 64-bit architectures and in the entire address spa=
ce on 32-bit architectures. 2026-09-05 8.7 CVE-2026-0799 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-0799 ] Bricksforge.--Bricksforge Subscriber Pri= vilege Escalation in Bricksforge <=3D 3.1.8.8 versions. 2026-09-03 9.8 CVE-= 2026-84814 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84814 ] brightvess= eldev--Quick Event Manager Unauthenticated Broken Access Control in Quick E= vent Manager <=3D 9.17 versions. 2026-09-03 7.5 CVE-2026-84847 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84847 ] brightvesseldev--Quick Event Mana= ger Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <=3D = 9.17 versions. 2026-09-03 7.1 CVE-2026-84848 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-84848 ] c-ares--c-ares c-ares is an asynchronous resolver l= ibrary. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-a= res' query-completion handling. The same flaw - a query's callback being in= voked while the query is still linked in the channel's internal lookup stru= ctures - is present at multiple points in the resend/finish path (timeout h= andling, response handling, and query dispatch). If the query, or for ares_= getaddrinfo() the owning host_query, is freed as a side effect of that call= back, it is then accessed and/or freed a second time. This vulnerability is=
fixed in ver 1.34.7. 2026-09-03 7.5 CVE-2026-33630 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-33630 ] camel-ai--owl OWL's DocumentProcessingToolki=
t contains a server-side request forgery vulnerability in the extract_docum= ent_content tool that fetches caller-supplied URLs with no scheme, host, or=
IP filtering. Attackers can inject malicious URLs through prompt injection=
to make the server fetch internal resources, with responses returned to th=
e agent context. 2026-09-04 7.5 CVE-2026-85675 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-85675 ] Canva--Canva The Canva Android App before 2.376.0=
allowed an external origin to be loaded in a privileged WebView. A threat = actor who controls the page loaded by the user is able to communicate with = Canva using the user's session. 2026-09-04 9.6 CVE-2026-85085 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85085 ] Canva--Canva The Canva Android App=
before 2.376.0 did not restrict the headers returned to an external origin=
running in a privileged WebView. A threat actor with control of the WebVie=
w could access a user's session. 2026-09-04 8.8 CVE-2026-85094 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85094 ] Casdoor--Casdoor A vulnerability = has been found in Casdoor up to 4.0.0. This affects an unknown function of = the file controllers/resource.go of the component upload-resource API. Such=
manipulation leads to missing authentication. It is possible to launch the=
attack remotely. The exploit has been disclosed to the public and may be u= sed. The vendor deleted the GitHub issue for this vulnerability without any=
explanation. Afterwards the vendor was contacted early about this disclosu=
re via email but did not respond in any way. 2026-09-01 7.3 CVE-2026-84423 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84423 ] Chanjet--CRM A flaw h=
as been found in Chanjet CRM up to 20260707. This issue affects some unknow=
n processing of the file jxf_dump_table.php. This manipulation of the argum= ent gblOrgID causes sql injection. Remote exploitation of the attack is pos= sible. The exploit has been published and may be used. The vendor was conta= cted early about this disclosure but did not respond in any way. 2026-09-01=
7.3 CVE-2026-84111 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84111 ] c= hewkeanho--software-actualizer (Holloway) Chew, Kean Ho's Actualizer v1.2.0=
and earlier contains a fail-open password validation vulnerability in the = Alpha user and root user password loops of Shell/debian-minbase-install.sh.=
The installer invokes mkpasswd to generate yescrypt password hashes but do=
es not check the command's return value and unconditionally accepts the res= ult. If mkpasswd fails to generate a yescrypt hash, for example because an = incompatible mkpasswd implementation or an environment without yescrypt sup= port is used, the resulting password hash variable can be empty and the bui=
ld proceeds. The resulting image can therefore contain empty password field=
s for the root and alpha accounts, potentially permitting passwordless auth= entication depending on the authentication configuration. 2026-09-04 7.9 CV= E-2026-85649 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85649 ] chroma-c= ore--chroma Chroma 1.5.9 fails to validate maximum bounds on HNSW index par= ameters max_neighbors, ef_construction, and ef_search in collection-create = requests. Unauthenticated attackers can supply arbitrarily large parameter = values to exhaust server memory and cause denial of service during index co= mpaction. 2026-09-04 7.5 CVE-2026-85664 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85664 ] Cisco--Cisco IOS XR Software As part of Cisco's ongoing=
commitment to proactive security and product quality, the Cisco IOS XR Sof= tware engineering team has conducted a comprehensive internal security revi= ew. This review resulted in a software hardening releases that address mult= iple internally discovered vulnerabilities. The vulnerabilities tracked by = CVE-2026-20274 are related to improper resource control issues that are gro= uped under the Common Weakness Enumeration (CWE) CWE-664. 2026-09-02 9.8 CV= E-2026-20274 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20274 ] Cisco--C= isco IOS XR Software As part of Cisco's ongoing commitment to proactive sec= urity and product quality, the Cisco IOS XR Software engineering team has c= onducted a comprehensive internal security review. This review resulted in =
a software hardening releases that address multiple internally discovered v= ulnerabilities. The vulnerabilities tracked by CVE-2026-20279 are related t=
o improper access control issues that are grouped under the Common Weakness=
Enumeration (CWE) CWE-284. 2026-09-02 9.8 CVE-2026-20279 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-20279 ] Cisco--Cisco IOS XR Software As part o=
f Cisco's ongoing commitment to proactive security and product quality, the=
Cisco IOS XR Software engineering team has conducted a comprehensive inter= nal security review. This review resulted in a software hardening releases = that address multiple internally discovered vulnerabilities. The vulnerabil= ities tracked by CVE-2026-20275 are related to incorrect calculation issues=
that are grouped under the Common Weakness Enumeration (CWE) CWE-682. 2026= -09-02 8.8 CVE-2026-20275 [
https://www.cve.org/CVERecord?id=3DCVE-2026-202=
75 ] Cisco--Cisco IOS XR Software As part of Cisco's ongoing commitment to = proactive security and product quality, the Cisco IOS XR Software engineeri=
ng team has conducted a comprehensive internal security review. This review=
resulted in a software hardening releases that address multiple internally=
discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 = are related to insufficient control flow management issues that are grouped=
under the Common Weakness Enumeration (CWE) CWE-691. 2026-09-02 8.6 CVE-20= 26-20276 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20276 ] Cisco--Cisco=
IOS XR Software As part of Cisco's ongoing commitment to proactive securit=
y and product quality, the Cisco IOS XR Software engineering team has condu= cted a comprehensive internal security review. This review resulted in a so= ftware hardening releases that address multiple internally discovered vulne= rabilities. The vulnerabilities tracked by CVE-2026-20277 are related to pr= otection mechanism failure issues that are grouped under the Common Weaknes=
s Enumeration (CWE) CWE-693. 2026-09-02 8.2 CVE-2026-20277 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-20277 ] Cisco--Cisco IOS XR Software As part =
of Cisco's ongoing commitment to proactive security and product quality, th=
e Cisco IOS XR Software engineering team has conducted a comprehensive inte= rnal security review. This review resulted in a software hardening releases=
that address multiple internally discovered vulnerabilities. The vulnerabi= lities tracked by CVE-2026-20278 are related to improper neutralization iss= ues that are grouped under the Common Weakness Enumeration (CWE) CWE-707. 2= 026-09-02 8.8 CVE-2026-20278 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 20278 ] Cisco--Cisco IOS XR Software As part of Cisco's ongoing commitment =
to proactive security and product quality, the Cisco IOS XR Software e= ngineering team has conducted a comprehensive internal security review. Thi=
s review resulted in a software hardening releases that address multiple in= ternally discovered vulnerabilities. The vulnerabilities tracked by CVE-202= 6-20280 are related to improper checking or handling of exceptional conditi=
on issues that are grouped under the Common Weakness Enumeration (CWE) CWE-= 703. 2026-09-02 8.8 CVE-2026-20280 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-20280 ] Cisco--Cisco NX-OS Software A vulnerability in the Silicon On=
e integration for Cisco Nexus 9000 Series Switches could allow an unauthent= icated, remote attacker to execute code with root privileges. This vul= nerability exists because TCP ports 43210 and 43211 are accessible in the d= efault Layer 3 (L3) virtual routing and forwarding (VRF). A successful expl= oit could allow the attacker to connect to an affected device and send craf= ted input that could be executed as code with root privileges. The exp= loitation of this vulnerability could also cause the S1HAL process to crash=
, which could cause the device to reload. 2026-09-02 9.8 CVE-2026-20212 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-20212 ] Cisco--Cisco Session Ini= tiation Protocol (SIP) Software A vulnerability in Cisco Desk Phone 9800 Se= ries, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that = are running Cisco Session Initiation Protocol (SIP) Software could allow an=
unauthenticated, remote attacker to cause a denial of service (DoS) condit= ion on an affected device. This vulnerability is due to improper memory man= agement when an affected device processes HTTP packets. An attacker could e= xploit this vulnerability by sending a continuous stream of crafted HTTP pa= ckets to the device. A successful exploit could allow the attacker to cause=
the affected device to continuously consume memory, resulting in a DoS con= dition. A manual reboot of the device is required to recover from this=
condition. Note: For this vulnerability to be exploitable, the phone must =
be registered to Cisco Unified Communications Manager (Unified CM) and have=
Web Access enabled. Web Access is disabled by default. 2026-09-02 7.5 CVE-= 2026-20281 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20281 ] Classified=
Listing--Classified Listing The Classified Listing WordPress plugin before=
6.1.1 does not verify that the caller owns or can edit the target listing = before its AI image-editing AJAX action deletes or attaches media, allowing=
any authenticated user, including a subscriber, to permanently delete atta= chments from, and attach files to, any listing owned by another user. 2026-= 09-04 7.1 CVE-2026-16281 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1628=
1 ] Cleo--Harmony A vulnerability was found in Cleo Harmony up to 5.8.1.10.=
The affected element is an unknown function of the file /api/connections o=
f the component JWT Refresh Token Handler. Performing a manipulation of the=
argument Bearer results in improper privilege management. The attack is po= ssible to be carried out remotely. The exploit has been made public and cou=
ld be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. =
It is recommended to upgrade the affected component. 2026-09-01 8.3 CVE-202= 6-84115 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84115 ] cleverange_au= th--cleverange_auth v0.1.10 An issue in cleverange_auth v.0.1.10 allows a r= emote attacker to cause a denial of service via the account_verification fu= nction and the accounts/models.py component 2026-09-01 7.5 CVE-2026-51788 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-51788 ] Cobham--SATCOM VSAT709=
0 Maritime Satellite Router A vulnerability was detected in Cobham SATCOM V= SAT7090 Maritime Satellite Router up to 20260704. This issue affects the fu= nction c_set_reports_decode of the file mail-report.sh of the component JSO=
N Parsing. The manipulation of the argument sender/recipients results in co= mmand injection. It is possible to launch the attack remotely. The exploit =
is now public and may be used. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-09-01 9.9 CVE-2026-83772 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-83772 ] code-projects-- Content M= anagement System 1.0 A security flaw has been discovered in code-projects C= ontent Management System 1.0. The affected element is an unknown function o=
f the file /login.php. The manipulation of the argument user_name results i=
n sql injection. The attack can be executed remotely. The exploit has been = released to the public and may be used for attacks. 2026-09-06 7.3 CVE-2026= -86168 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86168 ] code-projects-= -Doctor Appointment System A vulnerability was identified in code-projects = Doctor Appointment System 1.0. This vulnerability affects unknown code of t=
he file /patient_login.php. The manipulation of the argument email leads to=
sql injection. The attack may be initiated remotely. The exploit is public=
ly available and might be used. 2026-09-03 7.3 CVE-2026-85225 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85225 ] code-projects--Doctor Appointment = System A vulnerability was detected in code-projects Doctor Appointment Sys= tem 1.0. This vulnerability affects unknown code of the file /patient/booki= ng.php. The manipulation of the argument doc_id results in sql injection. T=
he attack may be launched remotely. The exploit is now public and may be us= ed. 2026-09-04 7.3 CVE-2026-85402 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-85402 ] code-projects--Doctor Appointment System A flaw has been found=
in code-projects Doctor Appointment System 1.0. This issue affects some un= known processing of the file /contactus.php. This manipulation of the argum= ent firstname causes sql injection. Remote exploitation of the attack is po= ssible. The exploit has been published and may be used. 2026-09-04 7.3 CVE-= 2026-85403 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85403 ] code-proje= cts--Hospital Information System A vulnerability was determined in code-pro= jects Hospital Information System 1.0. This impacts the function findBySear=
ch of the file addReq.php. This manipulation of the argument Search causes = sql injection. It is possible to initiate the attack remotely. The exploit = has been publicly disclosed and may be utilized. 2026-09-04 7.3 CVE-2026-85= 397 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85397 ] code-projects--Ho= spital Information System A vulnerability was identified in code-projects H= ospital Information System 1.0. Affected is the function viewReq of the fil=
e viewReq.php. Such manipulation of the argument ID leads to sql injection.=
It is possible to launch the attack remotely. The exploit is publicly avai= lable and might be used. 2026-09-04 7.3 CVE-2026-85398 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-85398 ] code-projects--Hospital Information Syste=
m A security flaw has been discovered in code-projects Hospital Information=
System 1.0. Affected by this vulnerability is the function getSinglePresp =
of the file includes/presp/PrespController.php. Performing a manipulation o=
f the argument ID results in sql injection. The attack can be initiated rem= otely. The exploit has been released to the public and may be used for atta= cks. 2026-09-04 7.3 CVE-2026-85399 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85399 ] code-projects--Online Shopping System A vulnerability was det= ermined in code-projects Online Shopping System 1.0. Affected by this issue=
is some unknown functionality of the file /action.php of the component Sea= rch Functionality. This manipulation of the argument keyword causes sql inj= ection. It is possible to initiate the attack remotely. The exploit has bee=
n publicly disclosed and may be utilized. 2026-08-31 7.3 CVE-2026-82701 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-82701 ] code-projects--Task Mana= gement System
=C2=A0 A vulnerability has been found in code-projects Task Management Syst=
em In PHP 1.0. Affected by this vulnerability is an unknown functionality o=
f the file /index.php of the component Login. The manipulation of the argum= ent email leads to sql injection. The attack can be initiated remotely. The=
exploit has been disclosed to the public and may be used. 2026-09-06 7.3 C= VE-2026-86180 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86180 ] code-pr= ojects--Vehicle Management System A vulnerability was detected in code-proj= ects Vehicle Management System 1.0. The affected element is an unknown func= tion of the file /busprofile.php. Performing a manipulation of the argument=
busid results in sql injection. It is possible to initiate the attack remo= tely. The exploit is now public and may be used. 2026-09-04 7.3 CVE-2026-85= 516 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85516 ] Colorful--iGameCe= nter A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulne= rability affects the function sub_11504 in the library WinRing0x64.sys of t=
he component IOCTL Dispatch. Performing a manipulation of the argument Phys= icalAddress/AlignNumer/AlignSize results in improper privilege management. = Attacking locally is a requirement. 2026-08-31 8.8 CVE-2026-82628 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82628 ] Coolify --Coolify=C2=A0
=C2=A0 Coolify through 4.3.17 contains an authentication bypass vulnerabili=
ty in the OAuth callback handler that signs users into existing accounts ba= sed solely on email address without verifying provider assertions or bindin=
g OAuth identities. Attackers can register a victim's email address on any = enabled OAuth provider to obtain authenticated sessions as that user, bypas= sing password requirements and two-factor authentication. 2026-09-05 8.1 CV= E-2026-86117 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86117 ] coollabs= io--coolify Coolify before 4.2.0 fails to properly escape environment varia= ble key names in Docker commands executed over SSH on managed servers. Auth= enticated attackers can inject shell metacharacters into environment variab=
le keys to execute arbitrary commands on the server host outside containers=
. 2026-09-02 8.8 CVE-2026-84694 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-84694 ] Cozmoslabs--Profile Builder Plugin A vulnerability was found in = Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted e= lement is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-= ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a m= anipulation results in unrestricted upload. The attack is possible to be ca= rried out remotely. The exploit has been made public and could be used. Upg= rading to version 3.16.2 is sufficient to resolve this issue. It is suggest=
ed to upgrade the affected component. 2026-08-31 7.3 CVE-2026-82607 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-82607 ] cpanel -- cpanel Eval inject= ion in cPanel 11.138.0.0 and earlier allows remote authenticated users to e= xecute arbitrary code as root. 2026-09-01 8.8 CVE-2026-65643 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-65643 ] craftcms--cms Craft CMS before 5.10= .11 fails to validate the admin flag during user registration, allowing it =
to persist from deactivated admin accounts. Attackers can register with a d= eactivated admin's email address to inherit administrator privileges when p= ublic registration and disabled email verification are configured. 2026-09-=
02 9.8 CVE-2026-84795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84795 ]=
craftcms--cms Craft CMS versions before 5.10.11 contain a site scope bypas=
s vulnerability in GraphQL entry mutation resolvers that fail to validate s= iteId through ArgumentManager::prepareArguments(). Attackers with tokens sc= oped to one site can read, modify, or delete entries across unauthorized si= tes by passing siteId directly in mutation arguments. 2026-09-02 8.8 CVE-20= 26-84796 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84796 ] craftcms--cm=
s Craft CMS versions before 5.10.11 fail to validate admin status in the ac= tionGetPasswordResetUrl endpoint, allowing non-admin users with administrat= eUsers permission to mint password reset URLs for administrator accounts. A= ttackers can generate a valid reset URL for any admin user and set a new pa= ssword via actionSetPassword, which validates only the verification code wi= thout checking the caller's session, enabling complete control-panel takeov= er. 2026-09-02 8.8 CVE-2026-84801 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84801 ] craftcms--cms Craft CMS versions before 5.10.11 lack authoriza= tion checks in the assets/move-asset endpoint when force=3D1 is supplied. A= uthenticated users without peer asset permissions can move their own assets=
into other users' folders and force deletion of conflicting files, allowin=
g unauthorized asset deletion and replacement. 2026-09-02 7.1 CVE-2026-8479=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84794 ] craftcms--cms Craft=
CMS versions >=3D 5.0.0-RC1 and < 5.10.11 fail to perform an independent a= uthorization check in ElementsController::actionDeleteForSite(). The method=
loads an element with checkForProvisionalDraft enabled and runs the deleti=
on authorization check against the user's own provisional draft (which only=
verifies draft ownership), then propagates the deletion to the canonical e= lement without re-checking permissions. As a result, an authenticated user = who has viewEntries, viewPeerEntries, saveEntries, savePeerEntries, and edi= tSite permissions but lacks the deleteEntriesForSite permission can hard-de= lete a canonical entry's site record (and, for single-site entries, the ful=
l element and content), which is irrecoverable via Craft's recycle bin. 202= 6-09-02 7.1 CVE-2026-84798 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84= 798 ] craftcms--cms Craft CMS versions >=3D 5.0.0-RC1 and < 5.10.11 contain=
a missing authorization vulnerability in AssetsController::actionReplaceFi= le. When a request supplies sourceAssetId and targetFilename but omits asse= tId, the target asset is resolved by folder and filename after the permissi=
on checks execute, so the replacePeerFiles permission is never enforced. An=
authenticated low-privilege author with only the replaceFiles permission o=
n a shared folder can overwrite the content of a peer's asset file (located=
in the same folder) with attacker-controlled bytes. Fixed in 5.10.11. 2026= -09-02 7.1 CVE-2026-84800 [
https://www.cve.org/CVERecord?id=3DCVE-2026-848=
00 ] crcn--sift.js sift (sift.js) 17.1.3 enumerates query keys with for...i=
n, which walks the object prototype chain, and dispatches any matched opera= tor key including $where. The $where operation compiles a string value into=
a function using new Function unless CSP_ENABLED is set (not set by defaul= t). As a result, if a prototype-pollution primitive elsewhere in the proces=
s sets Object.prototype.$where to a malicious string, even benign filter ca= lls such as sift({}) execute arbitrary JavaScript. Additionally, passing an=
untrusted query object containing a string $where directly to sift results=
in code execution under the default configuration. 2026-09-04 8.1 CVE-2026= -85625 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85625 ] crmeb--CRMEB C= RMEB contains an authentication bypass vulnerability in the verifyAuth() me= thod of SystemRoleServices.php that returns true from both conditional bran= ches. Sub-administrators and accounts with no roles can access restricted a= dmin endpoints by exploiting the inert role check that always permits reque= sts. 2026-09-03 8.3 CVE-2026-85212 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85212 ] crystaldba--postgres-mcp Postgres MCP Pro 0.3.0 contains a re= stricted-mode bypass vulnerability where function-name validation is not ap= plied to RangeFunction nodes in FROM clauses. Attackers can execute file-re= ading functions like pg_read_file through FROM-clause syntax to read arbitr= ary files despite restricted-mode protections. 2026-09-04 8.6 CVE-2026-8562=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85620 ] cu--silicon A vulne= rability was identified in cu silicon up to 0.1.5. Affected by this vulnera= bility is the function create_app of the file views.py of the component edi=
t Endpoint. Such manipulation leads to missing authentication. The attack m=
ay be performed from remote. The exploit is publicly available and might be=
used. The vendor was contacted early about this disclosure but did not res= pond in any way. 2026-08-31 7.3 CVE-2026-82919 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-82919 ] Cua computer-server--Cua computer-server=C2=A0
=C2=A0 Cua computer-server versions before 0.3.42 skip authentication when = the CONTAINER_NAME environment variable is unset and bind to all interfaces=
by default, allowing unauthenticated attackers to execute arbitrary comman= ds. Attackers can reach TCP port 8000 to run shell commands via the run_com= mand endpoint, read and write arbitrary files through file operation endpoi= nts, and access interactive PTY shells without authentication. 2026-09-05 9=
.8 CVE-2026-86121 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86121 ] cya= nheads--git-mcp-server git-mcp-server 2.15.1 contains an argument injection=
vulnerability in the ref and object parameters of git_log, git_diff, and g= it_show tools that lack leading-dash validation. Attackers can inject git c= ommand-line options like --output=3D to write files outside the repository =
to arbitrary paths accessible by the process. 2026-09-04 7.5 CVE-2026-85626=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85626 ] cypht-org--cypht Cyp=
ht before 2.12.2 contains a PHP object injection vulnerability that allows = authenticated attackers to execute arbitrary operating system commands by s= upplying a crafted PHP object graph in the back_query GET parameter of the = logout handler. Attackers can pass a base64-encoded serialized payload thro= ugh this parameter, which is decoded and passed directly to unserialize() w= ithout an allow-list, signature check, or type restriction, enabling gadget= -chain exploitation to achieve remote code execution as the web server proc= ess. 2026-09-01 8.8 CVE-2026-71981 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-71981 ] D-Link--DIR-825M A flaw has been found in D-Link DIR-825M 1.1= .8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpg= radeFibocom of the component LTE Module Firmware Upgrade. This manipulation=
of the argument fota_url causes stack-based buffer overflow. The attack is=
possible to be carried out remotely. The exploit has been published and ma=
y be used. 2026-08-31 9.9 CVE-2026-82593 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82593 ] D-Link--DIR-825M A vulnerability was found in D-Link DI= R-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of = the file /boafrm/formSysCmd of the component System Command Execution. Perf= orming a manipulation of the argument sysCmd results in command injection. =
It is possible to initiate the attack remotely. The exploit has been made p= ublic and could be used. 2026-08-31 7.4 CVE-2026-82595 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-82595 ] D-Link--DNS-320 ShareCenter A vulnerabili=
ty was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an un= known part of the file /cgi/file_sharing.cgi of the component File Sharing.=
Executing a manipulation of the argument fileurl can lead to os command in= jection. The attack can be launched remotely. The exploit has been publicly=
disclosed and may be utilized. 2026-09-03 9.1 CVE-2026-85224 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85224 ] D-Link--DNS-320L A vulnerability w=
as detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 202607= 17. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi o=
f the component ISO Image Handler. The manipulation of the argument upIsoRo= otPath results in os command injection. The attack can be executed remotely=
. The exploit is now public and may be used. 2026-08-31 9.9 CVE-2026-82689 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82689 ] D-Link--DNS-320L A vu= lnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-3=
45 up to 20260717. Affected by this issue is some unknown functionality of = the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipul= ation of the argument f_ups_ip leads to os command injection. The attack ma=
y be performed from remote. The exploit has been disclosed to the public an=
d may be used. 2026-08-31 9.1 CVE-2026-82691 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82691 ] D-Link--DNS-327L A flaw has been found in D-Link DN= S-327L and DNS-340L up to 20260717. Affected by this vulnerability is an un= known functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of t=
he argument f_dev causes os command injection. The attack is possible to be=
carried out remotely. The exploit has been published and may be used. 2026= -08-31 9.1 CVE-2026-82690 [
https://www.cve.org/CVERecord?id=3DCVE-2026-826=
90 ] D-Link--DNS-340L A security vulnerability has been detected in D-Link = DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unkn= own function of the file /cgi-bin/virtual_vol.cgi of the component Virtual = Volume Handler. The manipulation of the argument f_sharename/f_target/f_nam=
e leads to os command injection. Remote exploitation of the attack is possi= ble. The exploit has been disclosed publicly and may be used. 2026-08-31 9.=
1 CVE-2026-82688 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82688 ] D-Li= nk--DNS-340L A vulnerability was found in D-Link DNS-340L and DNS-345 up to=
20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi.=
Performing a manipulation of the argument alias/username/password/volume_l= ocation results in os command injection. It is possible to initiate the att= ack remotely. The exploit has been made public and could be used. 2026-08-3=
1 9.9 CVE-2026-82692 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82692 ] = D-Link--DNS-340L A vulnerability has been found in D-Link DNS-340L 1.01B04.=
Affected by this vulnerability is an unknown functionality of the file /cg= i-bin/addon_center.cgi of the component Add-On Center. Such manipulation of=
the argument f_name/f_url/f_flag/f_login_user leads to os command injectio=
n. It is possible to launch the attack remotely. The exploit has been discl= osed to the public and may be used. 2026-09-03 9.1 CVE-2026-85222 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-85222 ] D-Link--DNS-340L A vulnerabili=
ty was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unk= nown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Ha= ndler. Performing a manipulation of the argument callback_url/sync_interval=
results in os command injection. The attack can be initiated remotely. The=
exploit has been made public and could be used. 2026-09-03 9.9 CVE-2026-85= 223 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85223 ] D-Link--DSM-G600 =
A weakness has been identified in D-Link DSM-G600 1.01. This affects an unk= nown function of the file /load_file.cgi of the component Multipart Handler=
. Executing a manipulation can lead to out-of-bounds write. The attack may =
be launched remotely. The exploit has been made available to the public and=
could be used for attacks. 2026-08-31 8.8 CVE-2026-82680 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-82680 ] datalab-to--marker marker through 2.0.=
0 contains a path traversal vulnerability in the FastAPI /marker/upload han= dler that fails to sanitize the file.filename parameter. Unauthenticated at= tackers can supply filenames containing directory traversal sequences to wr= ite arbitrary files to any location or delete existing files on the system.=
2026-09-04 9.1 CVE-2026-85684 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-85684 ] datalab-to--surya surya 0.22.1 screenshot server contains an unau= thenticated arbitrary file read vulnerability in the /info, /page, and /pro= cess routes that accept raw file_path parameters. Attackers can read any im= age or PDF file on the host by supplying arbitrary file paths to Image.open=
or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using = /info as an existence oracle. 2026-09-04 7.5 CVE-2026-85687 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85687 ] dbgate--dbgate DbGate fails to valid= ate jslid parameters in the jsldata controller, allowing authenticated user=
s to read and write arbitrary files via file:// scheme resolution. Attacker=
s can exploit getJslFileName() to bypass directory containment and access s= ensitive files including encrypted database credentials stored in connectio=
ns configuration. 2026-09-03 8.8 CVE-2026-85176 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-85176 ] Delinea--Secret Server (On-Prem) Under specific = conditions, an attacker can register an attacker-controlled FIDO2 credentia=
l against a target account and then authenticate as that user. This issue a= ffects on-premises deployments only. 2026-09-02 9.8 CVE-2026-19117 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-19117 ] Dell--PowerProtect Data Manag=
er Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a s= tack buffer overflow vulnerability in file-level restore agent. A high priv= ileged remote attacker could potentially exploit this vulnerability, leadin=
g to Information disclosure. 2026-09-03 7.8 CVE-2026-73600 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-73600 ] Dell--PowerStore 500T Dell PowerStore=
contains a Missing Authentication for Critical Function vulnerability. An = unauthenticated attacker with network access to the restricted management i= nterface could potentially exploit this vulnerability to read internal syst=
em information from the appliance filesystem. This is a Critical vulnerabil= ity as it could expose sensitive information and credentials which allow fu=
ll administrative access to the array. 2026-08-31 9.8 CVE-2026-58574 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-58574 ] Dell--PowerStore 500T Dell = PowerStore SDNAS contains a Missing Authentication for Critical Function vu= lnerability. An unauthenticated attacker with remote access could potential=
ly exploit this vulnerability, leading to Filesystem access. 2026-09-01 9 C= VE-2026-79687 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79687 ] Dell--P= owerStore 500T Dell PowerStore, an Incorrect Authorization vulnerability. A=
low privileged attacker with remote access could potentially exploit this = vulnerability, leading to Elevation of privileges. 2026-09-01 8.8 CVE-2026-= 58566 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58566 ] Dell--PowerStor=
e 500T Dell PowerStore contains an OS Command Injection vulnerability. An a= uthenticated user with limited privileges could potentially exploit this vu= lnerability to execute arbitrary commands with root privileges. 2026-09-01 = 8.8 CVE-2026-58567 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58567 ] De= ll--PowerStore 500T Dell PowerStore contains an Inclusion of Functionality = from Untrusted Control Sphere vulnerability. An authenticated user with lim= ited privileges could potentially exploit this vulnerability to execute arb= itrary code with root privileges.. 2026-09-01 8.8 CVE-2026-58569 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-58569 ] Dell--PowerStore 500T Dell Powe= rStore contains an OS Command Injection vulnerability. An authenticated use=
r with limited privileges could potentially exploit this vulnerability to e= xecute arbitrary commands with root privileges. 2026-09-01 8.8 CVE-2026-585=
71 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58571 ] Dell--PowerStore 5= 00T Dell PowerStore contains a Code Injection vulnerability. An authenticat=
ed user with limited privileges could potentially exploit this vulnerabilit=
y to execute arbitrary code with root privileges. 2026-09-01 8.8 CVE-2026-5= 8572 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58572 ] Dell--PowerStore=
500T Dell PowerStore contains an Authentication Bypass by Spoofing vulnera= bility. An authenticated attacker could potentially exploit this vulnerabil= ity to escalate privileges to Administrator. 2026-09-01 8.8 CVE-2026-58575 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-58575 ] Dell--PowerStore 500T=
Dell PowerStore contains an Incorrect Authorization vulnerability. An auth= enticated attacker with low privileges could potentially exploit this vulne= rability to invoke administrator-only operations, leading to privilege esca= lation. 2026-09-01 8.8 CVE-2026-76111 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-76111 ] Dell--PowerStore 500T Dell PowerStore contains a Command I= njection vulnerability. An authenticated user with limited privileges could=
potentially exploit this vulnerability to execute arbitrary commands with = root privileges. 2026-09-01 8.8 CVE-2026-79682 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-79682 ] Dell--PowerStore 500T Dell PowerStore contains a = Protection Mechanism Failure vulnerability. An authenticated user with limi= ted privileges could potentially exploit this vulnerability to write attack= er-controlled content to arbitrary filesystem paths. 2026-09-01 8.8 CVE-202= 6-79683 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79683 ] Dell--PowerSt= ore 500T Dell PowerStore contains a Protection Mechanism Failure vulnerabil= ity. An authenticated user with limited privileges could potentially exploi=
t this vulnerability to bypass access restrictions and gain escalated privi= leges. 2026-09-01 8.8 CVE-2026-79684 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-79684 ] Dell--PowerStore 500T Dell PowerStore contains a Protection=
Mechanism Failure vulnerability. An authenticated user with limited privil= eges could potentially exploit this vulnerability to bypass access restrict= ions and gain escalated privileges. 2026-09-01 8.8 CVE-2026-79686 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-79686 ] Developer Tools--Developer Too=
ls The Developer Tools WordPress plugin through 1.1.3 contains an unauthent= icated arbitrary file upload vulnerability in the bundled SWFUpload compone=
nt 2026-09-02 9.8 CVE-2025-9314 [
https://www.cve.org/CVERecord?id=3DCVE-20= 25-9314 ] devitemsllc--Support Genix Helpdesk, AI Chatbot, Knowledge Base &=
Customer Support Ticketing System The Support Genix - Helpdesk, AI Chatbot=
, Knowledge Base & Customer Support Ticketing System plugin for WordPress i=
s vulnerable to Authentication Bypass leading to Administrator Account Take= over in all versions up to, and including, 1.4.52 via the `guest_ticket_log= in()` function and its `p` parameter. This is due to the site-wide AES-256-= CBC encryption key being derived from only three two-digit `wp_rand(10, 99)=
` values and a Unix timestamp via `md5()` - yielding approximately 19.5 bit=
s of entropy - combined with a deterministic IV derived from the password, =
no authentication tag on the ciphertext, and no capability check, nonce, or=
session validation on the publicly reachable `/sgnix/?p=3D<token>` endpoin=
t. This makes it possible for authenticated attackers, with subscriber-leve=
l access and above, who can obtain a single legitimate guest ticket token a=
s a known-plaintext oracle and bound the plugin activation timestamp, to ex= haust the ~729,000-candidate keyspace entirely offline, recover the site-wi=
de encryption key, and forge a self-consistent `{ticket_id, ticket_user}` t= oken targeting any administrator-owned ticket. Submitting the forged token =
to the unprotected endpoint causes `wp_set_auth_cookie()` to be called for = that administrator, granting the attacker full administrative access to the=
WordPress site. 2026-09-01 8.8 CVE-2026-19806 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-19806 ] devtron-labs--devtron Devtron through 2.2.0 fails=
to enforce authorization checks on the GET /orchestrator/api-token/webhook=
endpoint, allowing authenticated users to retrieve admin API tokens. Attac= kers with any authenticated account can query the endpoint with arbitrary p= roject, environment, and application parameters to retrieve plaintext super= -admin JWT tokens for full platform control. 2026-08-31 8.8 CVE-2026-82882 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82882 ] dianping--cat CAT use=
s Java String.hashCode as the sole integrity check for session cookies with= out server-side keying, allowing attackers to forge valid checksums offline=
. Attackers can set the x-forwarded-for header to bypass IP binding validat= ion and create admin sessions with full configuration access. 2026-09-03 9.=
8 CVE-2026-85181 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85181 ] digi= talbazaar--forge node-forge through 1.4.0 fails to validate element count i=
n nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verific= ation. Attackers can embed garbage bytes inside the DigestAlgorithm sequenc=
e to forge valid signatures for arbitrary messages using low-exponent RSA k= eys. This is an incomplete fix for CVE-2026-33894. 2026-09-03 7.5 CVE-2026-= 85393 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85393 ] Divi Engine--Di=
vi Ajax Filter The Divi Ajax Filter plugin for WordPress is vulnerable to L= ocal File Inclusion in all versions up to, and including, 5.1.2 via the 'cu= stom_loop_template' parameter parameter. This makes it possible for unauthe= nticated attackers to include and execute arbitrary .php files on the serve=
r, allowing the execution of any PHP code in those files. This can be used =
to bypass access controls, obtain sensitive data, or achieve code execution=
in cases where .php file types can be uploaded and included. This vulnerab= ility is only exploitable when the loop_templates parameter is set to 'cust= om-template'. 2026-09-04 9.8 CVE-2026-11613 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-11613 ] DocsGPT--DocsGPT In DocsGPT 0.15.0 and below, the ap= plication provides a custom prompt feature that allows users to define prom=
pt content used during chatbot interactions. This functionality renders use= r-supplied prompt data using Jinja templates without input sanitization or = sandboxing. An unauthenticated attacker can inject malicious template expre= ssions, leading to a server-side template injection (SSTI) vulnerability th=
at can be exploited to achieve full remote code execution (RCE). 2026-09-04=
9.8 CVE-2026-31020 [
https://www.cve.org/CVERecord?id=3DCVE-2026-31020 ] D= okploy--Dokploy A vulnerability was detected in Dokploy up to 0.29.7. This = issue affects the function writeTraefikConfigInPath of the file packages/se= rver/src/utils/traefik/application.ts of the component Settings. The manipu= lation of the argument path results in path traversal. The attack can be la= unched remotely. The exploit is now public and may be used. The vendor was = contacted early about this disclosure but did not respond in any way. 2026-= 08-31 9.9 CVE-2026-82954 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8295=
4 ] domainaware--parsedmarc parsedmarc before 11.0.1 decompresses gzip and = ZIP attachments in a single unbounded read with no limit on decompressed ou= tput size. Because parsedmarc automatically processes incoming DMARC report=
emails without user interaction, an unauthenticated remote attacker can se=
nd a crafted email with a highly compressed attachment to the monitored mai= lbox, causing the parsedmarc process to allocate memory proportional to the=
uncompressed size and exhaust available RAM. 2026-09-03 7.5 CVE-2026-82520=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82520 ] Dotstore--WooCommerc=
e Product Attachment Unauthenticated Sensitive Data Exposure in WooCommerce=
Product Attachment <=3D 2.3.3 versions. 2026-09-02 7.5 CVE-2026-81774 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-81774 ] dplugins--DevKit Pro The = DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in v= ersions up to, and including, 2.3.0. This is due to a missing capability ch= eck and missing nonce validation in the DPDEV_install_themes_func() functio=
n registered on the wp_ajax_DPDEV_install_themes action. This makes it poss= ible for authenticated attackers, with Subscriber-level access and above, t=
o install arbitrary theme ZIP packages containing PHP files that are extrac= ted into the web-accessible wp-content/themes/ directory, which may make re= mote code execution possible. 2026-09-02 8.8 CVE-2026-14357 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-14357 ] Drupal--Commerce PayPal Incorrect Au= thorization vulnerability in Drupal Commerce PayPal allows Forceful Browsin=
g. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from = 2.0.0 to 2.1.3. 2026-09-02 9.1 CVE-2026-73475 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-73475 ] Drupal--Screenshot Vulnerability in Drupal Screens= hot. This issue affects Screenshot versions: *.*. 2026-09-02 7.3 CVE-2026-7= 6759 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76759 ] Drupal--Screensh=
ot Vulnerability in Drupal Screenshot. This issue affects Screenshot versio= ns: *.*. 2026-09-02 7.3 CVE-2026-76782 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-76782 ] DSpace--DSpace DSpace open source software is a reposit= ory application which provides durable access to digital resources. From ve= rsions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 1= 0-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used =
by DSpace for COAR Notify/LDN messages. This issue has been patched in vers= ions 8.4, 9.3, and 10.0. 2026-09-02 8 CVE-2026-49832 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-49832 ] e4jvikwp--VikAppointments Services Booking = Calendar Unauthenticated SQL Injection in VikAppointments Services Booking = Calendar <=3D 1.2.20 versions. 2026-09-03 9.3 CVE-2026-84768 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84768 ] EASYBYTE Software--Konga Konga befo=
re 2.1.0 contains a privilege escalation vulnerability that allows low-priv= ileged local attackers to execute arbitrary code by planting attacker-contr= olled OpenSSL configuration or library files in a hardcoded filesystem path=
absent from default installations. On Windows, the missing directory resid=
es in a location writable by any authenticated local user, enabling attacke=
rs to create the directory and place malicious files that execute at the pr= ivilege level of the user or service account that launches Konga, facilitat= ing privilege escalation. 2026-09-01 7.8 CVE-2026-45221 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-45221 ] EasyCorp--EasyAdminBundle EasyAdmin is a=
fast and modern admin generator for Symfony applications. From 4.0.0 until=
4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single = dashboard route and, for custom actions (Action::linkToRoute() and MenuItem= ::linkToRoute()), swaps the executed controller based on the routeName quer=
y parameter on the kernel.controller event. The swap happens after Symfony'=
s security firewall has already evaluated access_control against the origin=
al dashboard URL, and the routeName value was not validated. As a result, a=
path-based access_control rule protecting the target route was never evalu= ated, so a low-privilege backend user who can reach a single EasyAdmin URL = and knows a target route's name can execute that route's controller, bypass= ing the path-based rule. Only path-based protections are bypassed. Routes w= hose controller enforces its own authorization with #[IsGranted] or denyAcc= essUnlessGranted() remain protected because those checks are recomputed aga= inst the swapped-in controller. This issue is fixed in versions 4.29.16 and=
5.5.1. 2026-08-31 8.1 CVE-2026-81892 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-81892 ] Ebyte--Ebyte NA111-M Firmware The affected=C2=A0Ebyte prod= uct's vendor configuration utility permits access to administrative functio=
ns without verifying the operator's identity under certain credential condi= tions. An unauthenticated attacker on the adjacent network could modify cri= tical settings or change access credentials, potentially preventing legitim= ate administrators from managing the device. 2026-08-31 9.8 CVE-2026-73819 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-73819 ] Ebyte--Ebyte NA111-M = Firmware The affected=C2=A0Ebyte product uses a deprecated hashing algorith=
m in an authentication-related operation. Under conditions where an attacke=
r can manipulate or predict the authentication exchange, the weak construct= ion may reduce the assurance provided by the authentication mechanism and f= acilitate unauthorized access. 2026-08-31 9.8 CVE-2026-76133 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-76133 ] Ebyte--Ebyte NA111-M Firmware The a= ffected=C2=A0Ebyte product=C2=A0does not provide separation between limited=
and administrative management functions. A low privileged authenticated at= tacker could access security sensitive configuration functions and modify s= ettings that affect the confidentiality, integrity, or availability of the = device. 2026-08-31 8.8 CVE-2026-77966 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-77966 ] Eclipse Foundation--Eclipse Theia In Eclipse Theia version=
s 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change to= ols (writeFileContent, suggestFileContent, and the replacement and state he= lpers) resolved a model-supplied file path without a workspace-containment = check. A crafted relative path such as ../.bashrc, an absolute path, or a ~= -expanded path could therefore write or delete files outside the workspace = with the privileges of the Theia backend OS user. Because the path argument=
is influenced by model output, it can be steered through indirect prompt i= njection, and in Agent Mode writes are applied without a confirmation dialo=
g. Writing to a host-executed file such as a shell startup file or ~/.ssh/a= uthorized_keys can escalate to code execution on the backend. 2026-08-31 8.=
8 CVE-2026-82217 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82217 ] elas= tic -- elastic_agent Incorrect Permission Assignment for Critical Resource = (CWE-732) in Elastic Agent can lead to local privilege escalation via Repla=
ce Binaries (CAPEC-642). On Windows systems where Elastic Agent is installe=
d in unprivileged mode, resources used by the agent service are created wit=
h access controls broader than required. A local user could take advantage =
of this to cause the service to execute code of their choosing, ultimately = obtaining SYSTEM-level privileges on the host. 2026-09-02 7.8 CVE-2026-7860=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78604 ] elastic -- elastics= earch Deserialization of Untrusted Data (CWE-502) in the Elasticsearch mach= ine learning component can lead to remote code execution via Object Injecti=
on (CAPEC-586). A specially crafted trained model artifact could cause atta= cker-controlled logic to execute with a materially broader system-call surf= ace than intended. Exploitation requires an authenticated user with suffici= ent privileges to create and deploy trained models. 2026-09-01 8.8 CVE-2026= -72649 [
https://www.cve.org/CVERecord?id=3DCVE-2026-72649 ] elastic -- kib= ana Incorrect Authorization (CWE-863) in Kibana can lead to privilege escal= ation via Exploiting Incorrectly Configured Access Control Security Levels = (CAPEC-180). A user holding workflow edit permissions could cause scheduled=
workflow executions to run with the privileges of a different, higher-priv= ileged user, allowing access to and modification of data beyond their own a= uthorization scope. 2026-09-01 8.3 CVE-2026-63137 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-63137 ] elastic -- kibana Improper Limitation of a Pat= hname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana F= leet feature can lead to the unauthorized deletion of privileged resources = via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Setting=
s write access could cause a subsequent administrative action to act on uni= ntended internal resources, resulting in the deletion of privileged resourc=
es such as user accounts and other organizational assets. Exploitation requ= ires an administrator to interact with the affected Fleet interface. 2026-0= 9-02 7.3 CVE-2026-78590 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78590=
] elastic -- kibana Improper Limitation of a Pathname to a Restricted Dire= ctory ('Path Traversal') (CWE-22) in Kibana can lead to the unauthorized de= letion of privileged resources via Path Traversal (CAPEC-126). A low-privil= eged user holding tag creation privileges could cause a subsequent administ= rative action in the tag management interface to act on an unintended targe=
t, resulting in the deletion of privileged resources including administrati=
ve accounts and other organizational assets. Exploitation requires an admin= istrator to interact with the affected interface. 2026-09-01 7.3 CVE-2026-7= 8592 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78592 ] Elastic--Elastic=
Security A local vulnerability in the Winlogbeat Windows installer caused = runtime files to be placed in a directory writable by unprivileged users. A=
low-privileged attacker with existing access to the system could pre-posit= ion malicious filesystem links, causing a subsequent elevated Winlogbeat op= eration to write to or delete arbitrary files. Successful exploitation coul=
d result in a denial of service. 2026-09-01 7.2 CVE-2024-14047 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2024-14047 ] Elastic--Kibana Incorrect Authori= zation (CWE-863) in Kibana can lead to privilege escalation via Input Data = Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations orig= inating from integration packages were not validated before being used to m= int credentials for enrolled Elastic Agents. A user holding Fleet managemen=
t privileges could therefore cause every Elastic Agent on a targeted policy=
to receive a credential carrying arbitrarily elevated Elasticsearch cluste=
r privileges, up to and including full cluster administration. 2026-09-03 8=
.1 CVE-2026-78583 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78583 ] Ela= stic--Kibana Incorrect Authorization (CWE-863) in Kibana can lead to unauth= orized configuration modification via Exploiting Incorrectly Configured Acc= ess Control Security Levels (CAPEC-180). 2026-09-03 8.1 CVE-2026-82302 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-82302 ] Elementor--Activity Log U= nauthenticated Cross Site Request Forgery (CSRF) in Activity Log <=3D 2.13.=
1 versions. 2026-09-02 7.1 CVE-2026-84759 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-84759 ] ellite--Wallos Wallos is an open-source, self-hostable=
personal subscription tracker. From version 4.0.0 to before version 4.9.6,=
Wallos's OIDC login links an incoming OIDC identity to an existing local a= ccount by matching the email claim alone, without verifying that the IdP ma= rked that email as verified (email_verified). When Wallos is configured aga= inst an IdP that lets a user present an arbitrary or unverified email (mult= i-tenant IdPs, IdPs with open self-registration, or any IdP the attacker pa= rtly controls), an attacker with no Wallos account can authenticate with th=
e admin's email and be logged in as the admin - full account takeover, no p= assword needed. This issue has been patched in version 4.9.6. 2026-08-31 8.=
1 CVE-2026-61641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61641 ] elli= te--Wallos Wallos is an open-source, self-hostable personal subscription tr= acker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m= 6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/s= earch.php by disabling cURL proxying (CURLOPT_PROXY =3D '' + CURLOPT_NOPROX=
Y =3D '*'). However, Wallos ships a second, near-identical, unauthenticated=
logo-image search endpoint - endpoints/payments/search.php - that was not = given the same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY enviro= nment variable straight into CURLOPT_PROXY. This issue has been patched in = version 5.0.0. 2026-08-31 8.2 CVE-2026-77348 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-77348 ] ellite--Wallos Wallos is an open-source, self-hosta= ble personal subscription tracker. Prior to version 4.9.4, endpoints/db/mig= rate.php executes database schema migrations when called over HTTP with zer=
o authentication. Any unauthenticated attacker can trigger pending migratio=
n files against the live SQLite database. This issue has been patched in ve= rsion 4.9.4. 2026-08-31 7.5 CVE-2026-54598 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-54598 ] Embed HTML5 Game--Embed HTML5 Game The Embed HTML5 Ga=
me WordPress plugin through 1.3 does not properly restrict who can upload f= iles via the plugin, as well as what can be uploaded, making it possible fo=
r unauthenticated attackers to upload PHP backdoors on affected sites. 2026= -09-02 10 CVE-2026-4357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4357 =
] Estatik--Estatik Unauthenticated Cross Site Scripting (XSS) in Estatik <=
=3D 4.3.4 versions. 2026-09-02 7.1 CVE-2026-81775 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-81775 ] Evil0ctal--Douyin_TikTok_Download_API Douyin_T= ikTok_Download_API through 4.1.2 contains a server-side request forgery vul= nerability in the /api/download and /api/hybrid/video_data endpoints that a= llows unauthenticated attackers to fetch arbitrary URLs by supplying a url = query parameter. Attackers can request internal services including cloud me= tadata endpoints and retrieve response bodies containing sensitive credenti= als through error messages. 2026-09-04 7.5 CVE-2026-85608 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-85608 ] eyecix--JobSearch Unauthenticated PHP = Object Injection in JobSearch <=3D 3.2.0 versions. 2026-09-03 9.8 CVE-2026-= 84834 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84834 ] F5--BIG-IP BIG-=
IP has a vulnerability where an authenticated user of any role may be able =
to create administrative user accounts through an undisclosed request to Tr= affic Management User Interface (TMUI). Impact: This vulnerability may allo=
w an authenticated attacker with network access to the BIG-IP management in= terface to escalate privileges by creating administrative accounts on the B= IG-IP system. There is no data plane exposure; this is a control plane issu=
e only. Note: Software versions which have reached End of Technical Support=
(EoTS) are not evaluated. 2026-09-02 8.8 CVE-2026-66842 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-66842 ] F5--NGINX Gateway Fabric Description: W= hen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an=
injection vulnerability exists in the NGINX configuration generator compon= ent of NGINX Gateway Fabric. User-supplied string values from the Authentic= ation Filter Custom Resource Definition clientID or cookieName fields, or i=
n the clientSecret field of a Secret referenced by an Authentication Filter=
, are rendered directly into NGINX configuration templates without sanitiza= tion or escaping. Impact: An authenticated attacker with permission to crea=
te or modify these resources may craft values that inject arbitrary NGINX c= onfiguration directives. This is a control plane issue; there is no data pl= ane exposure. 2026-09-02 8.1 CVE-2026-66362 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-66362 ] F5--NGINX Ingress Controller When NGINX Ingress Cont= roller is configured with Ingress annotations, an injection vulnerability e= xists in the configuration generator of NGINX Ingress Controller. Multiple = user-controllable fields are written into the generated NGINX configuration=
without sanitization. An authenticated attacker with permission to create =
or modify these annotations may craft values that inject arbitrary NGINX co= nfiguration directives. Impact: An authenticated attacker granted write acc= ess to NGINX Ingress Controller Ingress annotations through the Kubernetes = API may be able to inject arbitrary NGINX configuration directives, create =
or delete files, or disable services. There is no data plane exposure; this=
is a control plane issue only. Note: Software versions which have reached = End of Technical Support (EoTS) are not evaluated. 2026-09-02 8.3 CVE-2026-= 77180 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77180 ] F5--NGINX JavaS= cript Description NGINX JavaScript (njs)=C2=A0and QuickJS (qjs) engines=C2= =A0have a vulnerability when a js_access handler performs asynchronous requ= est body processing and an exception is thrown during asynchronous access-c= ontrol evaluation before an explicit access denial is returned. An unauthen= ticated attacker can exploit this vulnerability by sending a crafted HTTP r= equest that triggers an error condition in the access validation logic. Thi=
s may cause the js_access phase to fail open, allowing the request to proce=
ed instead of being denied, resulting in an authentication or authorization=
bypass and unauthorized access to protected resources. Impact This vulnera= bility may allow remote attackers to bypass js_access controls. There is no=
control plane exposure; this is a data plane issue only. Note: Software ve= rsions which have reached End of Technical Support (EoTS) are not evaluated=
. 2026-09-02 8.2 CVE-2026-18329 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-18329 ] F5--NGINX JavaScript Description NGINX JavaScript (njs) has a vu= lnerability in the XML module's namespace prefix list parser, reachable thr= ough the xml.exclusiveC14n() method. An unauthenticated remote attacker can=
trigger it when an affected NGINX configuration passes an externally contr= olled XML namespace prefix list to that method. Both the njs and the QuickJ=
S (qjs) engines are affected. A crafted prefix list causes an out-of-bounds=
write past the end of a heap allocation. With the njs engine, which is the=
engine used when the js_engine directive is absent, this corrupts adjacent=
objects and crashes the NGINX worker. With the QuickJS engine, the same ca=
ll additionally leaks the prefix list on every invocation, causing worker m= emory to grow across requests. The official nginxinc/nginx-saml reference i= mplementation is affected during SAML signature verification. It reads Incl= usiveNamespaces/@PrefixList from an untrusted SAML message and passes it to=
xml.exclusiveC14n() before the signature has been verified, so a valid SAM=
L signature is not required. A crafted SAML Response, Assertion, LogoutRequ= est, or LogoutResponse is sufficient. Code execution has not been demonstra= ted and cannot be ruled out for all platforms, as the effect of the out-of-= bounds write depends on conditions beyond the attacker's control. =C2=A0 Im= pact This vulnerability allows remote attackers to cause a denial of servic=
e on the NGINX system, either through repeatable worker restarts or through=
worker memory growth or possibly trigger code execution. There is no contr=
ol plane exposure; this is a data plane issue only. Note: Software versions=
which have reached End of Technical Support (EoTS) are not evaluated. 2026= -09-02 8.1 CVE-2026-78689 [
https://www.cve.org/CVERecord?id=3DCVE-2026-786=
89 ] F5--NGINX JavaScript A vulnerability exists in NGINX JavaScript where =
a malformed HTTP response received by ngx.fetch() can crash an NGINX worker=
when trusted JavaScript reads Response.statusText. Exploitation requires c= ontrol or influence over the fetched HTTP response. Impact: This vulnerabil= ity may allow remote attackers to cause a denial-of-service (DoS) on the NG= INX system. There is no control plane exposure; this is a data plane issue = only. Note: Software versions which have reached End of Technical Support (= EoTS) are not evaluated. 2026-09-02 7.5 CVE-2026-78222 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-78222 ] facefusion--facefusion facefusion through=
3.6.1 fails to normalize job identifiers in get_job_file_name, allowing at= tackers to write files outside the jobs directory. Attackers can supply tra= versal sequences in the job identifier parameter through the unauthenticate=
d HTTP API to create files at arbitrary locations. 2026-09-02 7.5 CVE-2026-= 84702 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84702 ] Fahad Mahmood--= Keep Backup Daily Keep Backup Daily plugin for WordPress before 2.1.4 conta= ins a sensitive information exposure vulnerability that allows unauthentica= ted attackers to trigger a full MySQL database dump by accessing the public=
ly exposed `kbd_cron_process` parameter without authentication. Attackers c=
an predict the partially predictable dump filename based on the database na= me, a limited random range, and the current Unix timestamp to download the = generated backup from the publicly accessible uploads directory. 2026-08-31=
7.5 CVE-2026-75133 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75133 ] F=
AQ Builder AYS--FAQ Builder AYS The FAQ Builder AYS WordPress plugin before=
1.8.5 does not sanitize or escape content submitted by unauthenticated vis= itors before storing it and outputting it in an admin area page, and the es= caping it does apply is undone by a subsequent decoding step, leading to St= ored XSS which will execute in the context of a logged in administrator. 20= 26-09-02 8.8 CVE-2026-81737 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 1737 ] fast-note-sync-service--fast-note-sync-service An issue in fast-note= -sync-service <=3D2.13.7 allows a remote attacker to escalate privileges vi=
a the admin configuration endpoint exposes authTokenKey 2026-09-01 9.8 CVE-= 2026-52111 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52111 ] fastify--f= astify fastify versions before 5.12.2 treat the object resolved by a succes= sful Ajv async validator as the value result protocol used by custom valida= tor compilers. If a request that passes its route schema contains a propert=
y named value at the root, fastify replaces the entire request body with th=
at property's value before the handler runs, so the handler receives a diff= erent object than the one that satisfied the schema. An authenticated low-p= rivilege caller can use this to make nested data replace the validated body=
and trigger an operation the route schema did not authorize, leading to un= authorized state changes and data disclosure. Users should upgrade to fasti=
fy 5.12.2 or later. 2026-09-04 8.1 CVE-2026-84504 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84504 ] fastify--fastify fastify versions >=3D 4.0.0 a=
nd before 5.12.2 can route a malformed URL sent under one plugin prefix to = the custom not-found handler of a different sibling plugin, and invoke it w= ithout the preHandler hook declared for that handler. The internal not-foun=
d router for encapsulated handlers dispatches malformed paths through a sin= gle shared handler pointer before URL decoding, ignoring the prefix and ski= pping the selected handler's normal lifecycle. An unauthenticated attacker = can therefore reach an authentication-protected private fallback through an=
unrelated public prefix and read its full response, bypassing the authenti= cation hook and breaking prefix encapsulation. Users should upgrade to fast= ify 5.12.2 or later. 2026-09-04 7.5 CVE-2026-76169 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-76169 ] fastify--fastify fastify versions before 5.12=
.2 implement the case-insensitive nature of HTTP header names by lowercasin=
g names in a route's header schema before compiling it, but the transformat= ion is incomplete: it lowercases the properties keys and the root-level req= uired array, and does not lowercase the trigger and dependent names inside = the JSON Schema Draft 7 dependencies keyword. Because Node stores request h= eader names in lowercase, a canonical-case dependency such as requiring an = authentication header whenever a privileged-mode header is present never ma= tches, and the presence assertion is silently skipped. An unauthenticated r= emote client can therefore send the header that activates a privileged bran=
ch while omitting the header the dependency was meant to require, bypassing=
the conditional check. Users should upgrade to fastify 5.12.2 or later. 20= 26-09-04 7.5 CVE-2026-84428 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 4428 ] fastify--fastify fastify versions before 5.12.2 decide whether to co= mpile a request schema based on JavaScript truthiness, but JSON Schema Draf=
t 7 defines the boolean false as a valid schema that rejects every instance=
. When an application assigns false to a route's body, querystring, params,=
or headers schema to deny all input, fastify treats it as a missing schema=
, compiles no validator, and runs the route handler on any request. An unau= thenticated remote client can therefore reach a handler that a valid deny-a=
ll schema was intended to make unreachable, a complete validation bypass th=
at can lead to unauthorized state changes or execution of disabled operatio= ns. Users should upgrade to fastify 5.12.2 or later. 2026-09-04 7.5 CVE-202= 6-84469 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84469 ] firecrawl--fi= recrawl-mcp-server firecrawl-mcp-server 3.20.2 contains an arbitrary local = file read vulnerability in the firecrawl_parse tool that accepts unconstrai= ned filePath arguments without directory containment validation. Attackers = can supply absolute paths or directory traversal sequences to read sensitiv=
e files like credentials and environment variables, which are then uploaded=
and returned to the model context. 2026-09-04 7.5 CVE-2026-85606 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-85606 ] FreeIPMI--FreeIPMI FreeIPMI be= fore 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_= sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.=
c via malformed Fujitsu SEL long-text responses. 2026-09-04 9.8 CVE-2026-85= 504 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85504 ] FreeIPMI--FreeIPM=
I ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _= get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info sub= command to dell get-system-info). 2026-09-04 9.8 CVE-2026-85506 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-85506 ] FreeIPMI--FreeIPMI ipmi-oem in F= reeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_sys= tem_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell = get-system-info). 2026-09-04 9.8 CVE-2026-85507 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-85507 ] FreeIPMI--FreeIPMI ipmi-oem in FreeIPMI before 1= .6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv= 6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-sy= stem-info). 2026-09-04 9.8 CVE-2026-85508 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85508 ] FreeIPMI--FreeIPMI FreeIPMI before 1.6.19 has a stack-= based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when =
a BMC returns more bytes than requested. 2026-09-04 9.8 CVE-2026-85509 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85509 ] FreeIPMI--FreeIPMI ipmi-o=
em in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem= _fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC = provides a short response, a different vulnerability than CVE-2026-50031 (w= hich has different affected versions). 2026-09-04 7.5 CVE-2026-85505 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85505 ] fs-code--FS Poster - WordPr= ess Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pin= terest] The FS-Poster plugin for WordPress is vulnerable to Remote Code Exe= cution in versions up to and including 8.0.1. This is due to insufficient i= nput sanitization of the FFmpeg path parameter before passing it to the exe= c() function, combined with missing authorization checks on the REST API en= dpoints. This makes it possible for authenticated attackers, with subscribe= r-level access and above, to execute arbitrary commands on the underlying s= erver. 2026-09-01 8.8 CVE-2026-10195 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-10195 ] GastroMenum--GastroMenum Web Panel Observable response disc= repancy vulnerability in GastroMenum GastroMenum Web Panel allows Account F= ootprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. 2= 026-09-04 7.5 CVE-2026-19205 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 19205 ] geonetwork--core-geonetwork GeoNetwork is a catalog application to = manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17,=
the Saxon XSLT processor used to render formatters is configured without s= ecure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java e= xtension functions (`ALLOW_EXTERNAL_FUNCTIONS`). Any stylesheet loaded by G= eoNetwork can therefore invoke `java.lang.Runtime.exec()` or `java.lang.Pro= cessBuilder` directly, achieving arbitrary command execution as the GeoNetw= ork process user. A user with sufficient privileges to upload a formatter c=
an deliver a `.xsl` file containing Java extension call that execute arbitr= ary OS commands with the privileges of the GeoNetwork process. The issue is=
patched in GeoNetwork versions 4.4.12 and 4.2.17. 2026-09-03 9.1 CVE-2026-= 58400 [
https://www.cve.org/CVERecord?id=3DCVE-2026-58400 ] geonetwork--cor= e-geonetwork GeoNetwork is a catalog application to manage spatially refere= nced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for c= reating a new formatter via file upload is unprotected and allows the uploa=
d of external uncontrolled files. An unauthenticated attacker can upload ar= bitrary `.xsl` or `.zip` formatter files to the server. An unauthenticated = attacker can write arbitrary files into the GeoNetwork formatter directory.=
On its own this constitutes unauthorized write access to server storage. T=
he issue is patched in GeoNetwork versions 4.4.12 and 4.2.17. 2026-09-03 8.=
6 CVE-2026-63219 [
https://www.cve.org/CVERecord?id=3DCVE-2026-63219 ] getg= rav--grav Grav before 2.0.18 (affected versions <=3D 2.0.17) contains a rem= ote code execution vulnerability in the Twig sort filter. The sortFunc wrap= per in GravExtension.php hardcodes Twig's isSandboxed argument to false, so=
unlike |map/|filter/|reduce, |sort accepts a plain function name inside th=
e sandbox; the remaining denylist misses spl_autoload, which performs a PHP=
include. An authenticated user with only page-write rights (admin.pages or=
api.pages.write) can supply a crafted payload (e.g., via form frontmatter = rendered by the Email plugin) that invokes spl_autoload through the sort fi= lter, resulting in arbitrary PHP execution as the web server user. 2026-09-=
04 8.8 CVE-2026-85604 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85604 ]=
getgrav--grav Grav Shortcode Core before 6.2.5 contains stored cross-site = scripting vulnerabilities in the [lorem] tag parameter and [details] summar=
y parameter that are written to rendered pages without escaping. Attackers = with page-edit access can inject arbitrary HTML and JavaScript that execute=
s in the browsers of all page visitors, including administrators. 2026-09-0=
4 7.2 CVE-2026-85599 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85599 ] = getomni-ai--zerox zerox 1.1.20 contains an OS command injection vulnerabili=
ty in the file download mechanism where the temporary file extension derive=
d from document URLs is interpolated unsanitized into shell commands execut=
ed by poppler utilities. Attackers can craft document URLs with malicious f= ile extensions containing command substitution syntax to execute arbitrary =
OS commands before document processing occurs. 2026-09-04 9.8 CVE-2026-8567=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85672 ] ggml -- llama.cpp l= lama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common= /json-schema-to-grammar.cpp, resulting in a denial of service. 2026-09-01 7=
.5 CVE-2026-52130 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52130 ] ggm=
l -- llama.cpp llama.cpp b5693 and before has a Reachable Assertion via the=
gguf_reader::read function. 2026-09-01 7.5 CVE-2026-52131 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-52131 ] ggml -- llama.cpp llama.cpp through c= ommit 97f06e9, when started with the --reranking flag, allows remote attack= ers to cause a denial of service (std::bad_alloc and HTTP 500) via a negati=
ve top_n value in a POST request to /rerank. 2026-09-01 7.5 CVE-2026-52132 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-52132 ] GNOME--gvfs A flaw wa=
s found in the SFTP backend in gvfs. When mounting a share and reading a fi= le, a malicious SFTP server can cause read_reply() to process a length that=
exceeds the size requested by the client. The function does not verify the=
server-provided length against the allocated buffer size, causing the oper= ation to write past the intended boundaries. This issue allows a malicious = server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting=
in a denial of service as the process aborts upon detecting the heap corru= ption or potentially allowing arbitrary code execution. 2026-09-01 8.8 CVE-= 2026-84268 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84268 ] golang -- = crypto Previously, after a channel has been established, a malicious peer c= ould send crafted messages that would deadlock the entire connection. Now, =
we handle all RFC 4254 channel messages; global requests are handled explic= itly. Then, treat all other messages as a protocol error and tear the conne= ction down instead of buffering and blocking. 2026-09-02 7.5 CVE-2026-56855=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-56855 ] golang -- crypto Pre= viously, a channel registered in the mux's chanList is not usable until it =
is established. A malicious peer was able flood the channel's incomingReque= sts, deadlocking the entire connection. Now, we add an atomic established s= tate, set when a channel becomes usable. Until such a time, handlePacket dr= ops every packet other than the open confirmation/failure, without blocking=
and without tearing down the connection. 2026-09-02 7.5 CVE-2026-78662 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-78662 ] google -- chrome Use aft=
er free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote a= ttacker to execute arbitrary code outside the sandbox via crafted network t= raffic. (Chromium security severity: High) 2026-09-02 9 CVE-2026-84324 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-84324 ] google -- chrome Improper=
input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 a= llowed a remote attacker leveraging social engineering to bypass system acc= ess restrictions via a co-installed app. (Chromium security severity: High)=
2026-09-02 9.8 CVE-2026-84325 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-84325 ] google -- chrome Incorrect authorization in FileSystem in Google = Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social e= ngineering to execute arbitrary code outside the sandbox via a crafted HTML=
page. (Chromium security severity: High) 2026-09-02 9.6 CVE-2026-84354 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84354 ] google -- chrome Uniniti= alized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a rem= ote attacker to execute arbitrary code inside the sandbox via a crafted HTM=
L page. (Chromium security severity: High) 2026-09-02 8.8 CVE-2026-84326 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84326 ] google -- chrome Incorr= ect authorization in Chromoting in Google Chrome on on Windows prior to 152= .0.7977.75 allowed a local attacker to execute arbitrary code outside the s= andbox via a local program. (Chromium security severity: Medium) 2026-09-02=
8.1 CVE-2026-84334 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84334 ] g= oogle -- chrome Incorrect authorization in TabStrip in Google Chrome prior =
to 152.0.7977.75 allowed a remote attacker who had compromised the renderer=
process and leveraged social engineering to potentially execute arbitrary = code outside the sandbox via a crafted HTML page. (Chromium security severi= ty: Medium) 2026-09-02 8.3 CVE-2026-84335 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-84335 ] google -- chrome Use after free in WebRTC in Google Ch= rome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary = code inside the sandbox via a crafted HTML page. (Chromium security severit=
y: Medium) 2026-09-02 8.8 CVE-2026-84347 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84347 ] google -- chrome Use after free in Browser in Google Ch= rome prior to 152.0.7977.75 allowed a remote attacker who had compromised t=
he renderer process to execute arbitrary code outside the sandbox via a cra= fted HTML page. (Chromium security severity: High) 2026-09-02 8.3 CVE-2026-= 84349 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84349 ] google -- chrom=
e Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowe=
d a remote attacker leveraging social engineering to execute arbitrary code=
outside the sandbox via UI Interaction. (Chromium security severity: Low) = 2026-09-02 8.8 CVE-2026-84350 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84350 ] google -- chrome Buffer overflow in GPU in Google Chrome on on Win= dows prior to 152.0.7977.75 allowed a remote attacker who had compromised t=
he renderer process to execute arbitrary code outside the sandbox via a cra= fted HTML page. (Chromium security severity: High) 2026-09-02 8.3 CVE-2026-= 84351 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84351 ] google -- chrom=
e Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a re= mote attacker to execute arbitrary code inside the sandbox via a crafted HT=
ML page. (Chromium security severity: High) 2026-09-03 8.8 CVE-2026-85046 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85046 ] Google--Chrome Use aft=
er free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allow=
ed a remote attacker to execute arbitrary code outside the sandbox via a cr= afted HTML page. (Chromium security severity: High) 2026-09-02 9.6 CVE-2026= -84333 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84333 ] Google--Chrome=
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977= .75 allowed a remote attacker to execute arbitrary code outside the sandbox=
via a crafted HTML page. (Chromium security severity: Critical) 2026-09-02=
9.6 CVE-2026-84352 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84352 ] G= oogle--Chrome Use after free in Shared Tab Groups in Google Chrome on on An= droid prior to 152.0.7977.75 allowed a remote attacker leveraging social en= gineering to execute arbitrary code outside the sandbox via a crafted HTML = page. (Chromium security severity: Critical) 2026-09-02 9.6 CVE-2026-84353 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84353 ] Google--Chrome Use af= ter free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remo=
te attacker to execute arbitrary code outside the sandbox via a crafted HTM=
L page. (Chromium security severity: High) 2026-09-03 9.6 CVE-2026-85042 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85042 ] Google--Chrome Incomple=
te cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a rem= ote attacker to bypass system access restrictions via crafted network traff= ic. (Chromium security severity: High) 2026-09-03 9.1 CVE-2026-85043 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85043 ] Google--Chrome Improper inp=
ut validation in Transactions Platform in Google Chrome on on iOS prior to = 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary co=
de outside the sandbox via a crafted HTML page. (Chromium security severity=
: Medium) 2026-09-03 9.6 CVE-2026-85047 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85047 ] Google--Chrome Out of bounds write in WebGL in Google C= hrome on on Android prior to 152.0.7977.82 allowed a remote attacker to exe= cute arbitrary code outside the sandbox via a crafted HTML page. (Chromium = security severity: High) 2026-09-03 9.6 CVE-2026-85050 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-85050 ] Google--Chrome Use after free in Composit= ing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who h=
ad compromised the renderer process to execute arbitrary code outside the s= andbox via a crafted HTML page. (Chromium security severity: High) 2026-09-=
03 8.3 CVE-2026-85048 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85048 ]=
Google--Chrome Use after free in Skia in Google Chrome prior to 152.0.7977= .82 allowed a remote attacker to execute arbitrary code inside the sandbox = via a crafted HTML page. (Chromium security severity: High) 2026-09-03 8.8 = CVE-2026-85049 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85049 ] Google= --Chrome Type confusion in Compositing in Google Chrome prior to 152.0.7977= .82 allowed a remote attacker to execute arbitrary code inside the sandbox = via a crafted HTML page. (Chromium security severity: High) 2026-09-03 8.8 = CVE-2026-85051 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85051 ] Google= --Chrome Improper resource exposure in CacheStorage in Google Chrome prior =
to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside=
the sandbox via a crafted HTML page. (Chromium security severity: High) 20= 26-09-03 8.8 CVE-2026-85053 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 5053 ] Google--Chrome Race condition in V8 in Google Chrome prior to 152.0.= 7977.82 allowed a remote attacker to execute arbitrary code inside the sand= box via a crafted HTML page. (Chromium security severity: High) 2026-09-03 = 7.5 CVE-2026-85045 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85045 ] Gr= afana--Grafana Enterprise Only self-managed Grafana instances with Auth Pro=
xy authentication and identity caching enabled (sync_ttl greater than zero)=
are affected. The Auth Proxy cache key concatenated the username and forwa= rded identity attributes without a delimiter, so distinct identities could = collide on one key. An authenticated user who shapes their own attributes t=
o collide with a higher-privileged user's, while that user's cache entry is=
live, is authenticated as that user, up to Administrator (authentication b= ypass by spoofing). 2026-09-02 7.1 CVE-2026-14199 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-14199 ] Grashjs Atlas--CMMS A Broken Object Level Auth= orization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An au= thenticated user from one tenant can read and modify another tenant's compa=
ny record by changing only the numeric ID in the /company/{id} endpoint. Th=
e application does not enforce tenant-level ownership checks when accessing=
or updating company objects, allowing cross-tenant access and modification=
of company profile data. 2026-09-01 8.1 CVE-2026-51956 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-51956 ] Gravity Forms--Gravity Forms The Gravity=
Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all v= ersions up to, and including, 3.0.2. This is due to insufficient validation=
of multi-file upload chunk state in the `GFAsyncUpload::upload()` function=
, where public form state URL hashes can be reused as chunk continuation ha= shes and attacker-controlled temporary filenames are accepted before saniti= zation. This makes it possible for unauthenticated attackers, when a public=
form contains a File Upload field with Multiple Files enabled, to upload a=
valid PNG/PDF polyglot to an attacker-selected public `.php` or `.html` fi= lename in the Gravity Forms temporary upload directory. This can lead to re= mote code execution on WordPress systems that use NGINX or other non `.htac= cess` respecting web servers. NOTE: During installation and activation, the=
Gravity Forms plugin places a `.htaccess` file in this directory, which pr= events this vulnerability from being exploited despite the PHP file being w= ritten to the temporary upload directory. In these cases where PHP executio=
n is blocked, attacker-written HTML can result in stored same-origin cross-= site scripting if a victim visits the generated file URL. 2026-09-01 8.1 CV= E-2026-19513 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19513 ] grokabil= ity--snipe-it Snipe-IT versions before 8.6.2 contain an authorization bypas=
s vulnerability in checkout-acceptance report actions when Full Multiple Co= mpany Support is enabled. Authenticated users with reports.view permission = can enumerate sequential acceptance IDs and soft-delete or trigger reminder=
emails for acceptances belonging to other companies by exploiting a null c= heck on the legacy users.company_id column. 2026-09-04 8.5 CVE-2026-85616 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85616 ] grokability--snipe-it = snipe-it versions before 8.6.3 contain an authorization bypass vulnerabilit=
y in the bulk delete functionality that allows restricted users to soft-del= ete users outside their authorized scope. Attackers can include unauthorize=
d user IDs in bulk delete requests to bypass instance-level restrictions an=
d modify or disable accounts they should not access. 2026-09-04 8.8 CVE-202= 6-85617 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85617 ] h3 --h3=C2=A0 =C2=A0 h3 versions before 2.0.1-rc.18 fail to validate the chunk count pars=
ed from user-controlled cookie values in setChunkedCookie() and deleteChunk= edCookie() functions. Attackers can send a crafted cookie header with an ex= tremely large chunk count to trigger an O(n=C3=82=C2=B2) cleanup loop that = hangs the server process. 2026-09-06 7.5 CVE-2026-86250 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-86250 ] haris-musa--excel-mcp-server excel-mcp-s= erver 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILE= S_PATH is unset, allowing attackers to read and write arbitrary files. Atta= ckers can supply unchecked file paths to read and write tools to access any=
file accessible to the process. 2026-09-04 9.8 CVE-2026-85661 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85661 ] hashthemes--Hash Form Unauthentic= ated Arbitrary File Upload in Hash Form <=3D 1.4.2 versions. 2026-08-31 10 = CVE-2026-81780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81780 ] Helico= ne--helicone Helicone's VaultManager.getDecryptedProviderKeyById() function=
in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the re= quester's organization against the vault key's organization identifier. Att= ackers with admin or owner privileges in any organization can retrieve decr= ypted upstream provider credentials for other tenants, including plaintext = OpenAI, Anthropic, and Bedrock API keys. 2026-09-03 7.7 CVE-2026-85178 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85178 ] Hewlett Packard Enterpris=
e (HPE)--AOS-CX Vulnerabilities exist in the authentication module that may=
improperly process malformed or truncated input. An authenticated remote a= ttacker could exploit these vulnerabilities by providing specially crafted = input from a compromised or hostile authentication server. Successful explo= itation could result in a Denial-of-Service or potential remote code execut= ion with elevated privileges. 2026-09-01 8.8 CVE-2026-73750 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-73750 ] Hewlett Packard Enterprise (HPE)--AO= S-CX An authenticated user with low-privileged access could submit crafted = input through the web-based management interface to execute arbitrary comma= nds on the underlying operating system. 2026-09-01 8.8 CVE-2026-73751 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-73751 ] Hewlett Packard Enterprise=
(HPE)--AOS-CX Exploitation through affected command-line operations could = allow an authenticated low-privileged user to execute arbitrary commands as=
a privileged user on the underlying operating system. 2026-09-01 8.8 CVE-2= 026-73753 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73753 ] Hewlett Pac= kard Enterprise (HPE)--AOS-CX A vulnerability exists in the Credential Mana= ger component that may allow for unauthorized administrative access. An una= uthenticated remote attacker could exploit this vulnerability on a device i=
n its factory-default or post-ZTP state before any administrator has config= ured credentials by providing a predictable factory-default password. Succe= ssful exploitation could result in full administrative control of the affec= ted device during the initial setup process. 2026-09-01 8.1 CVE-2026-73778 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-73778 ] Hewlett Packard Enter= prise (HPE)--AOS-CX A vulnerability exists in a management component that c= ould allow an unauthenticated adjacent attacker to execute arbitrary comman= ds. Successful exploitation could result in remote execution of arbitrary c= ommands in the context of the affected utility. 2026-09-01 7.1 CVE-2026-737=
63 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73763 ] highwarden--Super = Store Finder Unauthenticated Cross Site Scripting (XSS) in Super Store Find=
er <=3D 7.10 versions. 2026-08-31 7.1 CVE-2026-81768 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-81768 ] hiyouga--LlamaFactory LLaMA-Factory contain=
s a server-side request forgery vulnerability in the OpenAI-compatible API = multimodal media URL handler that allows unauthenticated attackers to bypas=
s SSRF validation. The check_ssrf_url guard validates URLs once but request= s.get follows redirects and re-resolves DNS without re-validation, enabling=
attackers to use HTTP redirects or DNS rebinding to access internal addres= ses and cloud metadata endpoints. 2026-09-04 7.5 CVE-2026-85673 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-85673 ] hpe -- arubaos-cx Multiple vulne= rabilities exist in a daemon of AOS-CX that may allow for improper processi=
ng of malformed input. An unauthenticated remote attacker could exploit the=
se vulnerabilities by sending specially crafted packets to the affected ser= vice. Successful exploitation could result in remote code execution with el= evated privileges. 2026-09-01 9.8 CVE-2026-73749 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-73749 ] hpe -- arubaos-cx An unauthenticated arbitrary = file write vulnerability exists in an API endpoint of AOS-CX. Successful ex= ploitation of this vulnerability allows an attacker to write arbitrary file=
s to the underlying operating system, which could lead to remote code execu= tion. 2026-09-01 8.8 CVE-2026-73752 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-73752 ] hpe -- arubaos-cx Vulnerabilities have been identified in th=
e API endpoint of AOS-CX switches that could potentially allow an unauthent= icated remote actor to circumvent existing authentication controls. 2026-09= -01 8.1 CVE-2026-73777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73777 =
] hpe -- arubaos-cx Vulnerabilities have been identified in the operating s= ystem of AOS-CX switches that could potentially allow an unauthenticated re= mote actor to circumvent existing authentication controls. Successful explo= itation could compromise system integrity and further expose sensitive info= rmation. 2026-09-01 8.2 CVE-2026-73779 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-73779 ] hpe -- arubaos-cx A vulnerability in the web-based mana= gement interface of AOS-CX switches exposes some sessions to a lack of Cros= s-Site Request Forgery (CSRF) protection. This could allow a remote unauthe= nticated attacker to execute arbitrary input against the affected interface=
if the attacker can convince an authenticated user of the interface to int= eract with a specially crafted URL. 2026-09-01 8.3 CVE-2026-73780 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-73780 ] hpe -- arubaos-cx A vulnerabil= ity in the web-based management interface of AOS-CX could allow an authenti= cated remote attacker to conduct a stored cross-site scripting (XSS) attack=
against an administrative user of the interface. A successful exploit allo=
ws an attacker to execute arbitrary script code in a victim's browser in th=
e context of the affected interface. 2026-09-01 8.4 CVE-2026-73781 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-73781 ] hpe -- arubaos-cx A format st= ring vulnerability exists in the command line interface of AOS-CX that coul=
d lead to unauthenticated remote code execution. Successful exploitation of=
this vulnerability results in the ability to execute arbitrary code as a p= rivileged user on the underlying operating system. 2026-09-01 8.8 CVE-2026-= 73782 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73782 ] hpe -- arubaos-=
cx Vulnerabilities have been identified in the operating system of AOS-CX s= witches that could potentially allow an unauthenticated remote actor to cir= cumvent existing authentication controls. In some cases this could enable u= nauthorized modification of affected resources and limited disruption of af= fected services. 2026-09-01 7.1 CVE-2026-73764 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-73764 ] hpe -- arubaos-cx Authenticated path traversal vu= lnerabilities exist in API endpoints of AOS-CX. Successful exploitation of = these vulnerabilities allows an attacker to write arbitrary files to the un= derlying operating system, which could lead to remote code execution. 2026-= 09-01 7.2 CVE-2026-73765 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7376=
5 ] hpe -- arubaos-cx Command injection vulnerabilities in the API endpoint=
of AOS-CX could allow an authenticated remote attacker with administrative=
privileges to inject arbitrary commands. Successful exploitation could all=
ow an attacker to execute arbitrary commands as a privileged user on the un= derlying operating system. 2026-09-01 7.2 CVE-2026-73766 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-73766 ] hpe -- arubaos-cx Authenticated command=
injection vulnerabilities exist in the command line interface of AOS-CX. S= uccessful exploitation of these vulnerabilities results in the ability to e= xecute arbitrary commands as a privileged user on the underlying operating = system. 2026-09-01 7.2 CVE-2026-73767 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-73767 ] hpe -- arubaos-cx A vulnerability exists in the command li=
ne interface of AOS-CX that may allow for improper processing of malformed = input. Successful exploitation could result in the execution of arbitrary c= ommands with root privileges. 2026-09-01 7.3 CVE-2026-73768 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-73768 ] hpe -- arubaos-cx An authenticated a= rbitrary file write vulnerability exists in AOS-CX. Successful exploitation=
could allow an authenticated malicious actor, under specific conditions ou= tside the attacker's control and following a required action by another use=
r, to create or modify arbitrary files and execute arbitrary commands as a = privileged user on the underlying operating system. 2026-09-01 7.3 CVE-2026= -73770 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73770 ] hpe -- arubaos= -cx An authentication vulnerability exists in the AOS-CX management interfa=
ce and API that may allow improper authentication processing. An unauthenti= cated remote attacker could exploit this vulnerability under specific condi= tions to bypass authentication controls or exhaust system resources. Succes= sful exploitation could result in unauthorized access or denial of service = affecting the management interface. 2026-09-01 7.5 CVE-2026-73771 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-73771 ] hpe -- arubaos-cx An unauthent= icated Denial-of-Service (DoS) vulnerability exists in the API endpoint of = AOS-CX. Successful exploitation of this vulnerability results in the abilit=
y to interrupt the normal operation of the affected service. 2026-09-01 7.5=
CVE-2026-73773 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73773 ] hpe -=
- arubaos-cx A buffer overflow vulnerability exists in the underlying opera= ting system of AOS-CX that could lead to unauthenticated disclosure of sens= itive information by sending specially crafted packets to the affected syst= em. Successful exploitation of this vulnerability could result in limited d= isclosure or modification of information and disruption of the affected sys= tem. 2026-09-01 7.6 CVE-2026-73774 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-73774 ] hpe -- arubaos-cx Vulnerabilities in the API endpoint of AOS-=
CX could allow a remote attacker authenticated with low privileges to acces=
s sensitive information. A successful exploit allows an attacker to retriev=
e information which could be used to potentially gain further access to net= work services supported by AOS-CX. 2026-09-01 7.7 CVE-2026-73775 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-73775 ] hpe -- arubaos-cx A signature v= erification bypass vulnerability exists in the command line interface of AO= S-CX. Successful exploitation could allow an authenticated malicious actor = with administrative privileges to execute arbitrary code on the underlying = operating system, when certain pre-conditions outside of the attacker=C3=83= =C2=A2=C3=A2=E2=80=9A=C2=AC=C3=A2=E2=80=9E=C2=A2s control are met. 2026-09-=
01 7.9 CVE-2026-73776 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73776 ]=
HTML::FormFu--HTML::FormFu HTML::FormFu versions through 2.08 for Perl all=
ow resource exhaustion via an unbounded repeat count from the query string =
in Repeatable elements. When a Repeatable element has counter_name set, its=
process method reads the repeat count from the named query string paramete=
r, checks only that it is a positive integer, and passes it to repeat, whic=
h deep-clones the element's child subtree once per iteration. Nothing caps = the value, and no attribute lets an application impose a limit. The count i=
s read on every request, before the form decides whether it was submitted, =
so a plain GET reaches the clone loop with no credentials, no session and n=
o request body. Nesting multiplies: a Repeatable inside a Repeatable takes =
a counter at each level, so an outer and an inner value of 100 build 10,000=
clones. Once the form is submitted, each cloned field's constraints scan t=
he whole element tree in _find_field_value, so cost grows faster than linea= rly with the count. A single request exhausts memory and CPU. The latest re= lease on CPAN is 2.07, from 2018. Version 2.08 exists only in the git repos= itory. 2026-08-31 7.5 CVE-2026-19873 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-19873 ] Hugging Face--Transformers A vulnerability in Hugging Face = Transformers (versions >=3D 4.49.0 and <=3D 5.8.1) allows remote Python fil=
es to be written to local disk without user consent when using GenerativePr= eTrainedModel.load_custom_generate(). The function fetches and caches a rem= ote module file before performing the required trust_remote_code consent ch= eck, inverting the security model enforced by other code-loading paths (suc=
h as AutoConfig, AutoModel, and AutoTokenizer). As a result, attacker-contr= olled Python code from custom_generate/generate.py is copied into the user'=
s ~/.cache/huggingface/modules directory even if the user declines the trus=
t prompt. Although execution is correctly gated, the file write is not reve= rsible and can persist across sessions. This can lead to persistent, unauth= orized files on disk and stale cache collisions where cached attacker code = may later be executed during trusted model loads. The issue stems from an u= nconditional file write in dynamic_module_utils.py prior to any trust verif= ication. 2026-09-01 7.8 CVE-2026-80047 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80047 ] hulumi--drift @hulumi/drift versions before 1.3.2 accep=
t externally supplied execute plans without sufficient provenance validatio=
n, allowing untrusted reconciliation input to be treated as trusted. Attack= ers can supply malicious execute plans that bypass security checks to perfo=
rm unsafe reconciliation operations. 2026-08-31 9.8 CVE-2026-82858 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-82858 ] hulumi--policies @hulumi/poli= cies versions before 1.3.2 contain an evidence validation bypass vulnerabil= ity in Cloudflare and deployment-governance validators that allows attacker=
s to suppress violations by submitting unrelated compliant evidence. Attack= ers can use evidence from different zones, hostnames, origins, or repositor= ies to bypass security guardrails for unrelated resources in the same stack=
. 2026-08-31 9.8 CVE-2026-82855 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-82855 ] hulumi--policies @hulumi/policies versions before 1.3.2 fail to = properly validate set-qualified AWS IAM condition operators in GitHub OIDC = trust policies. Attackers can use ForAnyValue:StringLike operators to hide = wildcard GitHub Actions OIDC subject conditions from security guardrails. 2= 026-08-31 9.8 CVE-2026-82856 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 82856 ] hulumi--policies @hulumi/policies versions before 1.3.2 fail to ful=
ly inspect inline and attached IAM policy evidence for the administrator-po= licy guardrail. Attackers can craft admin-equivalent policy paths that bypa=
ss policy evaluation controls. 2026-08-31 9.8 CVE-2026-82860 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82860 ] hulumi--policies @hulumi/policies v= ersions before 1.3.2 contain a parent spoof bypass vulnerability that allow=
s attackers to submit spoofed SecureBucket parent evidence during policy ev= aluation. Attackers can bypass security policy checks by providing falsifie=
d evidence, causing the validator to miss unsafe bucket configurations. 202= 6-08-31 7.5 CVE-2026-82861 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 861 ] HumanSignal--label-studio Label Studio through 1.23.0 fails to valida=
te webhook URLs, allowing authenticated users to dispatch requests to inter= nal services including RFC 1918 addresses and cloud metadata endpoints. Att= ackers can create webhooks targeting private networks and exfiltrate annota= tion data by enabling payload transmission in outbound requests. 2026-09-03=
8.5 CVE-2026-85179 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85179 ] H= umanSignal--label-studio Label Studio fails to apply organization filters w= hen resolving storage URIs for tasks and projects in proxy_api.py endpoints=
. Attackers can access other tenants' cloud storage objects by creating a s= eparate organization and supplying arbitrary file URIs to presign or stream=
bucket contents. 2026-09-03 7.7 CVE-2026-85211 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-85211 ] Hummingbird Performance--Hummingbird Performance=
The Hummingbird Performance WordPress plugin before 3.21.2 does not restri=
ct a network-wide setting to network administrators, allowing an administra= tor of any single site on a multisite network to execute arbitrary code acr= oss the entire network. 2026-09-04 7.2 CVE-2026-19224 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-19224 ] hyperledger-firefly--firefly A vulnerabili=
ty was found in hyperledger-firefly firefly up to 1.4.0. The impacted eleme=
nt is the function ValidateOptions of the file internal/events/webhooks/web= hooks.go of the component Webhook Subscription. Performing a manipulation o=
f the argument url results in server-side request forgery. Remote exploitat= ion of the attack is possible. The exploit has been made public and could b=
e used. The vendor was contacted early about this disclosure but did not re= spond in any way. 2026-08-31 7.3 CVE-2026-82957 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-82957 ] IBM--App Connect Enterprise IBM App Connect Ente= rprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM I= ntegration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable=
to an XML external entity (XXE) attack. 2026-09-04 7.7 CVE-2026-81832 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-81832 ] IBM--ContextForge MCP Gat= eway IBM ContextForge MCP Gateway <=3D v1.0.7 MCP Context Forge could allow=
a remote authenticated attacker to obtain sensitive credentials and escala=
te privileges due to improper validation of jq filters. 2026-09-04 8.8 CVE-= 2026-18486 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18486 ] IBM--Conte= xtForge MCP Gateway IBM ContextForge MCP Gateway could allow a remote authe= nticated attacker to obtain sensitive information due to server-side reques=
t forgery via DNS rebinding. 2026-09-04 8.2 CVE-2026-77822 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-77822 ] IBM--ContextForge MCP Gateway (`mcp-c= ontextforge-gateway`) IBM ContextForge MCP Gateway (`mcp-contextforge-gatew= ay`) <=3D v1.0.6 MCP Context Forge could allow a remote authenticated attac= ker to obtain sensitive information due to a DNS rebinding vulnerability du= ring tool invocation. 2026-09-04 7.7 CVE-2026-18905 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-18905 ] IBM--ContextForge MCP Gateway - Translate ut= ility IBM ContextForge MCP Gateway - Translate utility <=3D 1.0.8 MCP Conte=
xt Forge could allow a remote attacker to obtain sensitive information from=
other sessions due to exposure of data elements to the wrong session. 2026= -09-04 7.4 CVE-2026-18489 [
https://www.cve.org/CVERecord?id=3DCVE-2026-184=
89 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to m= anipulate database transactions due to improper authorization in the DDM ta= rget dispatcher. 2026-09-04 8.1 CVE-2026-18175 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-18175 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a=
remote attacker to gain unauthorized access due to improper validation of = client-supplied authentication parameters. 2026-09-04 8.1 CVE-2026-18221 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-18221 ] IBM--Langflow OSS IBM L= angflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacke=
r to execute arbitrary code due to an authorization bypass in the flow buil=
d process. 2026-09-04 8.8 CVE-2026-19298 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-19298 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 through 1.11.2=
could allow a remote authenticated attacker to delete arbitrary local file=
s or directories due to improper limitation of a pathname to a restricted d= irectory. 2026-09-04 8.1 CVE-2026-19303 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-19303 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 through 1.11.2=
could allow a remote attacker to obtain sensitive information due to serve= r-side request forgery. 2026-09-04 8.6 CVE-2026-19305 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-19305 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 t= hrough 1.11.2 could allow a remote attacker to obtain sensitive information=
due to incomplete scrubbing of sensitive credential fields. 2026-09-04 7.5=
CVE-2026-19300 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19300 ] IBM--= Langflow OSS IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote aut= henticated attacker to obtain sensitive information from internal services = due to a URL parser discrepancy. 2026-09-04 7.7 CVE-2026-19304 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-19304 ] IBM--Langflow OSS IBM Langflow OS=
S 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary f= iles from the server filesystem - including server secret material (secret_= key, JWT signing keys, the application database, /proc/self/environ, and ot= her tenants' upload directories) - by supplying absolute paths or traversal=
sequences in the files parameter of an authenticated build request. The fi=
le contents were embedded as text attachments in the language model prompt = and transmitted to the configured model endpoint, resulting in confidential=
data exfiltration. This bypassed the LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS= =3Dtrue containment boundary, which was enforced for other file-reading com= ponents but not for the Chat Input to Message attachment pipeline. 2026-09-=
04 7.7 CVE-2026-19306 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19306 ]=
IBM--Netezza Software IBM Netezza Software 11.3.0.3 through Interim Fix 00=
2 has credentials that are hardcoded in the application source code, allowi=
ng unauthorized access to the container registry. The exposed secret enable=
s attackers to pull private container images, potentially revealing proprie= tary code, configuration details, and other sensitive information. 2026-09-=
03 7.5 CVE-2026-8862 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8862 ] I= BM--Observability with Instana (Agent) IBM Observability with Instana (Agen=
t) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an = authenticated Kubernetes tenant to hijack or permanently destroy another te= nant's cluster-level RBAC permissions, caused by cluster-scoped RBAC object=
s being keyed solely by the bare CR name with no namespace disambiguation, = allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace=
to silently overwrite the shared `ClusterRoleBinding` or delete it outrigh=
t and revoke the victim agent's cluster monitoring access. 2026-09-04 9.6 C= VE-2026-19274 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19274 ] IBM--Ob= servability with Instana (Agent) IBM Observability with Instana (Agent) Bui=
ld 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authen= ticated remote attacker to obtain sensitive information, caused by missing = destination namespace validation when copying etcd mTLS client credentials = from the openshift-etcd system namespace into an attacker-controlled namesp= ace. 2026-09-04 7.7 CVE-2026-19283 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-19283 ] IBM--Operational Decision Manager IBM Operational Decision Ma= nager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 =
is vulnerable to SQL injection. An unauthenticated attacker can execute arb= itrary SQL statements and leverage database functionality to write a web sh= ell to the application web root, resulting in remote code execution. 2026-0= 9-04 9.8 CVE-2026-18658 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18658=
] Icegram--Email Subscribers & Newsletters Unauthenticated Cross Site Scri= pting (XSS) in Email Subscribers & Newsletters <=3D 5.9.33 versions. 2026-0= 8-31 7.1 CVE-2026-81290 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81290=
] ICP DAS--UA-2200 A flaw has been found in ICP DAS UA-2200 and UA-5200 up=
to 20260704. The affected element is the function ArmAngstromInstructionSe=
t of the file /CGI?RestApi=3DSetHostname. Executing a manipulation of the a= rgument ParameterArray can lead to command injection. The attack can be exe= cuted remotely. The exploit has been published and may be used. The vendor = was contacted early about this disclosure but did not respond in any way. 2= 026-09-01 7.4 CVE-2026-84059 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84059 ] Ido Kobelkowsky--Simple Payment Unauthenticated Cross Site Scriptin=
g (XSS) in Simple Payment <=3D 2.5.1 versions. 2026-09-03 7.1 CVE-2026-8129=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81292 ] ieungSoft--Ultra RA= MDisk Pro A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.8=
2. This issue affects some unknown processing in the library URDSCSI.sys of=
the component Kernel Driver. This manipulation causes improper privilege m= anagement. The attack needs to be launched locally. The exploit has been pu= blicly disclosed and may be utilized. The vendor was contacted early about = this disclosure but did not respond in any way. 2026-08-31 8.8 CVE-2026-828=
07 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82807 ] Ignition --Ignitio=
n =C2=A08.1.5.3
=C2=A0 In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)"=
setting shipped blank, which permitted any authenticated user to create pr= ojects (if they can execute gateway scripts). Ignition 8.1.54 restricts pro= ject creation to Designer sessions and no longer relies on this setting. Th=
e 8.3 series is not affected. 2026-09-04 8.8 CVE-2026-77393 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-77393 ] ILIAS-eLearning e.V.--ILIAS ILIAS be= fore versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability =
in the repository trash table where the table navigation sort field from HT=
TP requests is passed directly into the ORDER BY clause of a SQL query with= out validation against declared sortable columns. Authenticated users with = write permission on any container can inject arbitrary SQL through the sort=
parameter, and because multi-statement execution is enabled in the databas=
e layer, stacked queries enable full database read and write access as well=
as administrator account takeover. 2026-09-04 8.8 CVE-2026-82538 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82538 ] Inbox Foundry--ActiveInbox Ext= ension A vulnerability was identified in Inbox Foundry ActiveInbox Extensio=
n up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist= /service-worker.production-esm.js of the component Google OAuth Client Secr= et. Such manipulation leads to hard-coded credentials. The attack can be ex= ecuted remotely. The exploit is publicly available and might be used. The v= endor was informed beforehand about the issue. The support explains, that "= [a]t the moment, the [bug bounty] programme is on hold while we work throug=
h a large number of existing reports." 2026-08-31 7.3 CVE-2026-82808 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-82808 ] Insyde Software--InsydeH2O = HDD password plaintext is stored in a UEFI variable. 2026-09-03 8.2 CVE-202= 1-38489 [
https://www.cve.org/CVERecord?id=3DCVE-2021-38489 ] Interinfo--Dr= eamMaker DreamMaker developed by Interinfo has a SQL Injection vulnerabilit=
y. Authenticated remote attackers can inject arbitrary SQL commands to read=
, modify, and delete database contents. 2026-09-04 8.8 CVE-2026-85540 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-85540 ] Invicti Security Corp.--Ac= unetix Acunetix 25.11.251107123 for Windows contains a local privilege esca= lation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) th=
at allows low-privileged local attackers to execute arbitrary code as SYSTE=
M by exploiting a missing hardcoded directory path for OpenSSL-related file=
s. Attackers can create the missing directory, place a malicious file at th=
e expected path, and cause the SYSTEM-level wvsc.exe process to load and ex= ecute it, resulting in full privilege escalation. 2026-09-04 7.8 CVE-2026-6= 958 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6958 ] iova.mihai--SliceW=
P Unauthenticated Cross Site Scripting (XSS) in SliceWP <=3D 1.2.10 version=
s. 2026-08-31 7.1 CVE-2026-82224 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-82224 ] itsourcecode--Online Medicine Delivery System A security flaw h=
as been discovered in itsourcecode Online Medicine Delivery System 1.0. Aff= ected is the function Employee::employeeAuthentication of the file /rider/l= ogin.php of the component Login Interface. The manipulation of the argument=
emp_email results in sql injection. It is possible to launch the attack re= motely. The exploit has been released to the public and may be used for att= acks. 2026-08-31 7.3 CVE-2026-82610 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-82610 ] itsourcecode--Online Medicine Delivery System A weakness has=
been identified in itsourcecode Online Medicine Delivery System 1.0. Affec= ted by this vulnerability is the function Customer::cusAuthentication of th=
e file /login.php of the component Customer Login Interface. This manipulat= ion of the argument U_USERNAME causes sql injection. The attack can be init= iated remotely. The exploit has been made available to the public and could=
be used for attacks. 2026-08-31 7.3 CVE-2026-82611 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-82611 ] itsourcecode--Online Medicine Delivery Syste=
m A security vulnerability has been detected in itsourcecode Online Medicin=
e Delivery System 1.0. Affected by this issue is the function loadResultLis=
t of the file /index.php?q=3Dsingle-item of the component Product Detail Pa= ge. Such manipulation of the argument ID leads to sql injection. The attack=
can be launched remotely. The exploit has been disclosed publicly and may =
be used. 2026-08-31 7.3 CVE-2026-82612 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82612 ] itsourcecode--Online Medicine Delivery System A vulnera= bility was detected in itsourcecode Online Medicine Delivery System 1.0. Th=
is affects the function loadResultList of the file /index.php?q=3Dproduct o=
f the component Product Search Interface. Performing a manipulation of the = argument Search results in sql injection. The attack may be initiated remot= ely. The exploit is now public and may be used. 2026-08-31 7.3 CVE-2026-826=
13 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82613 ] itsourcecode--Onli=
ne Medicine Delivery System A flaw has been found in itsourcecode Online Me= dicine Delivery System 1.0. This vulnerability affects the function loadRes= ultList of the file /index.php?q=3Dproduct of the component Product Categor=
y Filter Interface. Executing a manipulation of the argument Category can l= ead to sql injection. The attack may be launched remotely. The exploit has = been published and may be used. 2026-08-31 7.3 CVE-2026-82614 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-82614 ] itsourcecode--Online Medicine Deli= very System A vulnerability has been found in itsourcecode Online Medicine = Delivery System 1.0. This issue affects the function Customer::find_phone o=
f the file /passwordrecover.php of the component Password Recovery Interfac=
e. The manipulation of the argument phonenumber leads to sql injection. Rem= ote exploitation of the attack is possible. The exploit has been disclosed =
to the public and may be used. 2026-08-31 7.3 CVE-2026-82615 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82615 ] itsourcecode--Online Medicine Deliv= ery System A security vulnerability has been detected in itsourcecode Onlin=
e Medicine Delivery System 1.0. Affected by this issue is the function Orde= r::pupdate of the file /rider/orders/controller.php?action=3Dedit&actions= =3Dconfirm of the component Order Status Update. The manipulation of the ar= gument ID leads to sql injection. It is possible to initiate the attack rem= otely. The exploit has been disclosed publicly and may be used. 2026-09-03 = 7.3 CVE-2026-85187 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85187 ] it= sourcecode--Online Medicine Delivery System A security flaw has been discov= ered in itsourcecode Online Medicine Delivery System 1.0. The affected elem= ent is the function doInsert of the file /rider/orders/controller.php?actio= n=3Dadd of the component Order Management Controller. Performing a manipula= tion of the argument image results in unrestricted upload. Remote exploitat= ion of the attack is possible. The exploit has been released to the public = and may be used for attacks. 2026-09-03 7.3 CVE-2026-85208 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-85208 ] IXON--VPN Client
=C2=A0 Improper neutralization of CRLF sequences in IXON VPN Client before = version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Con= figuration values accepted by the local service are written to a file later=
consumed by a privileged subprocess, without line-ending sequences being n= eutralized, which allows additional directives to be introduced into that f= ile. The configuration interface accepts changes without authenticating or = verifying the origin of the requester. The injected configuration persists =
on disk across restarts of the client and the operating system, and the VPN=
connection continues to function normally, so there is no behavioral chang=
e visible to the user. 2026-09-04 9.6 CVE-2026-75925 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-75925 ] Jenkins Project--Jenkins In Jenkins 2.579 a=
nd earlier, LTS 2.568.2 and earlier, objects of types marked as storing the=
ir configuration in independent top-level configuration files in Jenkins (s= uch as the global configuration and jobs) can appear as nested field values=
in user-submitted `config.xml` documents and subsequently handle HTTP requ= ests via Stapler, resulting in remote code execution. 2026-09-02 8.8 CVE-20= 26-84645 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84645 ] Jenkins Proj= ect--Jenkins In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.v= d7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earli= er, Stapler does not restrict the types of objects that can be instantiated=
via form data binding to those compatible with the expected field type, al= lowing attackers with Overall/Read permission to instantiate types related =
to configuration for which that field type was not intended. 2026-09-02 8.8=
CVE-2026-84647 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84647 ] Jenki=
ns Project--Jenkins In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, = the system log viewer does not escape log record metadata (source, level, a=
nd timestamp) resulting in a stored cross-site scripting (XSS) vulnerabilit=
y exploitable by attackers in control of agent processes. 2026-09-02 8.8 CV= E-2026-84648 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84648 ] Jenkins = Project--Jenkins In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed3=
17 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2= .447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both incl= usive), an HTTP endpoint serving dynamically generated JavaScript resources=
embeds the user's cross-site request forgery (CSRF) token (crumb) as a str= ing literal, allowing attackers with control over a page hosted on the same=
site as Jenkins to obtain a valid crumb for the targeted user's session an=
d perform actions on their behalf. 2026-09-02 8.8 CVE-2026-84649 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84649 ] Jenkins Project--Jenkins In Jen= kins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be=
excluded from deserialization, allowing attackers able to submit configura= tion updates to specify the values of transient fields that will be deseria= lized, the impact depending on how those fields are used. 2026-09-02 8.8 CV= E-2026-84650 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84650 ] Jenkins = Project--Jenkins In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jen= kins does not rotate the session when a user is authenticated via the "reme= mber me" cookie, allowing attackers able to serve content on the same site =
as Jenkins to set a known session cookie in the victim's browser, which aft=
er the victim authenticates via the "remember me" cookie, grants the attack=
er access to Jenkins as that user. 2026-09-02 7.3 CVE-2026-84652 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84652 ] Jenkins Project--Jenkins Allure=
Plugin A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and = earlier allows attackers with Item/Read permission on jobs that publish All= ure report results to read arbitrary files on the Jenkins controller's file=
system. 2026-09-02 8.8 CVE-2026-84669 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84669 ] Jenkins Project--Jenkins Customizable Header Plugin Jen= kins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows ove= rwriting the plugin's appearance configuration through Stapler data binding=
, allowing attackers to configure a custom SVG icon containing inline JavaS= cript, resulting in a stored cross-site scripting (XSS) vulnerability. 2026= -09-02 8.8 CVE-2026-84673 [
https://www.cve.org/CVERecord?id=3DCVE-2026-846=
73 ] Jenkins Project--Jenkins File Parameter Plugin Jenkins File Parameter = Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary lo= cations on the Jenkins controller file system through Stapler data binding,=
which can lead to remote code execution. 2026-09-02 8.8 CVE-2026-84671 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84671 ] Jenkins Project--Jenkins=
Microsoft Entra ID (previously Azure AD) Plugin Jenkins Microsoft Entra ID=
(previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra g= roup permissions using both the group's unique object ID and its display na= me, allowing attackers who can create an Entra group with a colliding displ=
ay name to gain the permissions configured for a privileged group. 2026-09-=
02 8.8 CVE-2026-84672 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84672 ]=
Jenkins Project--Jenkins Performance Plugin Jenkins Performance Plugin 101= 5.v09ca_52b_3370e and earlier does not restrict the classes that can be ins= tantiated when deserializing cached performance reports stored in the build=
directory on the Jenkins controller, allowing attackers with Item/Configur=
e permission to execute arbitrary code on the Jenkins controller. 2026-09-0=
2 8.8 CVE-2026-84670 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84670 ] = Jenkins Project--Jenkins SAML Plugin Jenkins SAML Plugin 4.618.v441a_27fa_4= 6d2 and earlier allows overwriting the SAML identity provider metadata file=
through Stapler data binding, allowing attackers to replace it with attack= er-controlled content and authenticate as any user. 2026-09-02 8.8 CVE-2026= -84668 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84668 ] Jenkins Projec= t--Jenkins SonarQube Scanner Plugin Jenkins SonarQube Scanner Plugin 2.18.3=
and earlier does not limit URL schemes for the dashboard links it creates = based on SonarQube scanner results, allowing the `javascript:` scheme, resu= lting in a stored cross-site scripting (XSS) vulnerability exploitable by a= ttackers with Item/Configure permission. 2026-09-02 8 CVE-2026-84665 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-84665 ] Jenkins Project--Jenkins Th= inBackup Plugin Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwrit= ing the plugin's backup configuration through Stapler data binding, allowin=
g attackers to redirect backup writes to an attacker-specified directory an=
d to include arbitrary files from the Jenkins controller file system in bac= kups. 2026-09-02 7.1 CVE-2026-84667 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-84667 ] Jenkins Project--Jenkins TICS Plugin OS command injection vu= lnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers ab=
le to control build environment variable values to execute arbitrary comman=
ds on the agent running the build. 2026-09-02 7.4 CVE-2026-84675 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84675 ] JetBackup--JetBackup The JetBac= kup WordPress plugin before 3.1.23.5 does not verify the role or capabiliti=
es of the account it preserves across a restore or migration before grantin=
g it administrator privileges, allowing a subscriber-level user to gain adm= inistrator access after the site owner restores or migrates the site. 2026-= 09-02 7.1 CVE-2026-19453 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1945=
3 ] jina-ai--reader jina-ai reader contains a server-side request forgery v= ulnerability where URL validation is performed only on the initial request = but not re-applied to subsequent redirect hops. Attackers can craft a publi=
c URL that redirects to internal network addresses or cloud metadata endpoi= nts, allowing the server to fetch and return the target's response body to = the attacker. 2026-09-04 7.5 CVE-2026-85699 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-85699 ] jofpin trape--jofpin trape 2.0
=C2=A0 A weakness has been identified in jofpin trape 2.0. This affects an = unknown part of the file core/user.py. This manipulation of the argument vI= d/id causes authorization bypass. Remote exploitation of the attack is poss= ible. The exploit has been made available to the public and could be used f=
or attacks. The project was informed of the problem early through an issue = report but has not responded yet. 2026-09-04 7.3 CVE-2026-85638 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-85638 ] John Havlik--Breadcrumb NavXT Un= authenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <=3D 7.5.1 ver= sions. 2026-09-03 7.1 CVE-2026-84765 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-84765 ] JoomUnited--WP File Download The WP File Download plugin fo=
r WordPress is vulnerable to arbitrary file deletion due to insufficient fi=
le path validation in the delete function in all versions. This makes it po= ssible for authenticated attackers, with subscriber-level access and above,=
to delete arbitrary files on the server, which can easily lead to remote c= ode execution when the right file is deleted (such as wp-config.php). The t= wo-stage exploit requires a first request to the file.save task to persist = the path-traversal string into file metadata, followed by a second request =
to the file.delete task to trigger the unlink call - both endpoints lack ca= pability checks and nonce enforcement. 2026-09-02 8.1 CVE-2026-14982 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-14982 ] kamailio -- kamailio An iss=
ue in kamailio v.6.1.1 and before allows a remote attacker to cause a denia=
l of service via the IMS P-CSCF registration handling components 2026-09-01=
7.5 CVE-2026-52022 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52022 ] K= amailio--Kamailio A vulnerability was determined in Kamailio up to 5.5.0/6.= 0.7. This affects the function get_4bytes of the file src/modules/ims_regis= trar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulatio=
n can lead to out-of-bounds read. The attack may be performed from remote. = The exploit has been publicly disclosed and may be utilized. This patch is = called abb5d60af6eefbd367bf6588c5589566b090e272. It is advisable to impleme=
nt a patch to correct this issue. The vendor points out, that "[v]ersion 5.= 5.0 is old and not maintained anymore." 2026-08-31 7.4 CVE-2026-82608 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-82608 ] kerberosmansour--hulumi hu= lumi versions before v1.3.2 contain a privilege escalation vulnerability in=
the weekly integration IAM policy that allows role lifecycle operations on=
af-e2e-* roles without sufficient boundary restrictions. Attackers with th=
e documented principal can create persistent higher-privilege roles in the = sandbox account. 2026-08-31 9.8 CVE-2026-82857 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-82857 ] kerberosmansour--hulumi hulumi versions before v1= .3.2 contain a deployment SCP template that allows tag-on-create bypasses f=
or hulumi:iac-role protections. Attackers can bypass intended IAM boundary = restrictions by exploiting the weakened SCP template in downstream deployme= nts. 2026-08-31 9.8 CVE-2026-82859 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-82859 ] kerberosmansour--hulumi Hulumi versions before v1.3.2 resolve=
the threat-model helper script from an unsafe root, allowing workspace fil=
es to shadow the intended helper script. Attackers can place malicious file=
s in the workspace to execute arbitrary code during local skill execution. = 2026-08-31 8.4 CVE-2026-82862 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -82862 ] killbill--killbill Kill Bill through 0.24.21 fails to enforce perm= ission annotations on several AdminResource endpoints including getQueueEnt= ries, invalidatesCache, and putOutOfRotation. Authenticated users with mini= mal account:read permissions can read internal queues, flush server caches,=
and disable the server by putting the host out of rotation. 2026-09-03 7.6=
CVE-2026-85213 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85213 ] kiril= lbdev--WC Ukraine Shipping Subscriber Insecure Direct Object References (ID= OR) in WC Ukraine Shipping <=3D 1.22.3 versions. 2026-09-03 7.1 CVE-2026-84= 836 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84836 ] kishan0725--Hospi= tal-Management-System A security flaw has been discovered in kishan0725 Hos= pital-Management-System 1.0. This vulnerability affects unknown code of the=
file /search.php. The manipulation of the argument Contact results in sql = injection. It is possible to launch the attack remotely. The exploit has be=
en released to the public and may be used for attacks. The vendor was conta= cted early about this disclosure but did not respond in any way. 2026-08-31=
7.3 CVE-2026-82914 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82914 ] K= itae Park--Mang Board WP Unauthenticated Cross Site Request Forgery (CSRF) =
in Mang Board WP <=3D 2.3.8 versions. 2026-09-02 8.8 CVE-2026-84770 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84770 ] klaussilveira--GitList A sec= urity vulnerability has been detected in klaussilveira GitList 2.0.0. Affec= ted by this vulnerability is the function getDefaultBranch of the file src/= SCM/System/Git/CommandLine.php of the component Git Command Line. Such mani= pulation leads to os command injection. The attack can be executed remotely=
. The exploit has been disclosed publicly and may be used. Upgrading to ver= sion 3.0.0-beta addresses this issue. The name of the patch is 88cf2866083d= 5f7c20d9d565c45f828a7ad1516b. Upgrading the affected component is advised. = 2026-08-31 7.3 CVE-2026-82668 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -82668 ] Klemsan Electrical Electronics Inc.--KIO (Klemsan Internet Objects=
) Improper Control of Generation of Code ('Code Injection') vulnerability i=
n Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows=
Code Injection. This issue affects KIO (Klemsan Internet Objects): before = v1.9. 2026-09-01 9.8 CVE-2026-18808 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-18808 ] kyverno--kyverno Kyverno versions v1.9.0 through v1.12.7 con= tain a policy exception handling flaw. When a policy in enforce mode is com= bined with two PolicyExceptions, the less restrictive exception takes prece= dence, allowing an attacker to bypass the policy by crafting a resource nam=
e that matches the second exception's name pattern (e.g., '*ingress*'). Thi=
s can be used to circumvent policies such as one blocking hostPath volumes.=
Fixed in v1.13.0. 2026-09-01 9 CVE-2026-84200 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-84200 ] kyverno--kyverno Kyverno before 1.16.4 automatica= lly attaches the admission controller's ServiceAccount token to outbound HT=
TP requests in apiCall service mode without explicit authorization headers.=
Attackers can exfiltrate the token by directing apiCall requests to extern=
al or attacker-controlled endpoints, gaining full control over Kyverno poli= cies and cluster resources. 2026-09-01 7.7 CVE-2026-84195 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84195 ] kyverno--kyverno Kyverno before 1.18.0=
contains a server-side request forgery vulnerability in apiCall.service.ur=
l that allows authenticated users to send arbitrary HTTP requests by inject= ing user-controlled input through variable substitution. Attackers can targ=
et internal services, cloud metadata endpoints, and loopback addresses, wit=
h response data reflected in admission error messages enabling non-blind da=
ta exfiltration. 2026-09-01 7.7 CVE-2026-84196 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-84196 ] kyverno--kyverno Kyverno before 1.16.2 contains a=
server-side request forgery (SSRF) vulnerability in the APICall feature. T=
he URL field in a Policy's ServiceCall configuration is not validated, so a=
user with namespace-level Policy creation permissions can direct Kyverno t=
o make HTTP requests to arbitrary internal resources (e.g., cloud metadata = endpoints such as 169.254.169.254 or other tenants' resources). Because Kyv= erno executes these requests using its cluster-wide high-privilege ServiceA= ccount (a Confused Deputy problem), the responses-potentially including oth=
er tenants' secrets and cloud IAM credentials-are returned in the PolicyRep= ort and can be read by the attacker, breaking multi-tenant isolation. 2026-= 09-01 7.7 CVE-2026-84199 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8419=
9 ] Lara Dashboard--Lara Dashboard
=C2=A0 Lara Dashboard before 1.3.0 contains an authentication bypass vulner= ability in the screenshot-login route that allows unauthenticated attackers=
to authenticate as any user by email when APP_ENV is not production. Attac= kers can request the GET /screenshot-login/{email} endpoint with a register=
ed email address to receive a fully authenticated session, enabling access =
to user administration, settings, database contents, and arbitrary code exe= cution through the module installer. 2026-09-05 9.8 CVE-2026-86184 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-86184 ] Laravel--Laravel=C2=A0
=C2=A0 Laravel is a web application framework. Prior to versions 12.60.0 an=
d 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in=
combination with how Symfony Mailer and Symfony Mime handle certain charac= ter sequences, may allow an unauthenticated attacker to interfere with outb= ound email processing in applications that send mail to user-supplied addre= sses. This issue has been patched in versions 12.60.0 and 13.10.0. 2026-09-=
04 8.9 CVE-2026-48019 [
https://www.cve.org/CVERecord?id=3DCVE-2026-48019 ]=
laravel-backup-restore --laravel-backup-restore=C2=A0
=C2=A0 laravel-backup-restore restores database backups made with spatie/la= ravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger =
OS command injection during database restore. This issue has been patched i=
n version 1.9.4. 2026-09-04 8 CVE-2026-53932 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-53932 ] lavague-ai--LaVague LaVague 0.2.35 contains a remot=
e code execution vulnerability in PythonFromMarkdownExtractor.extract_as_ob= ject that evaluates untrusted language model output derived from web page c= ontent. Attackers can inject malicious Python code through web pages using = indirect prompt injection to execute arbitrary code on the operator's host = without review. 2026-09-04 8.1 CVE-2026-85694 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85694 ] lenve--vhr vhr fails to validate user authorizatio=
n in the PUT /hr/info endpoint, allowing authenticated users to modify arbi= trary HR profiles by supplying any profile ID in the request body. Attacker=
s can overwrite other users' names, addresses, and disable accounts includi=
ng administrators to cause denial of service. 2026-09-03 8.1 CVE-2026-85214=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85214 ] lenve--vhr vhr throu=
gh commit 03abbd3 fails to verify that the account ID in PUT /hr/pass reque= sts belongs to the authenticated caller. Authenticated attackers can change=
arbitrary account passwords by supplying a target account ID and that acco= unt's current password in the request body. 2026-09-03 7.5 CVE-2026-85182 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85182 ] librenms--librenms Lib= reNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit m= essage) returned by the admin-configurable Oxidized integration URL (oxidiz= ed.url) into the device showconfig page without applying htmlspecialchars()=
. An administrator who points the Oxidized URL at an attacker-controlled se= rver (SSRF) can cause it to return malicious JSON, resulting in stored/pers= istent cross-site scripting affecting all users who view any device's showc= onfig tab. Fixed in 26.7.0. 2026-09-01 8.1 CVE-2026-84189 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84189 ] librenms--librenms LibreNMS versions b= efore 26.5.0 contain a remote code execution vulnerability in the AboutCont= roller where the snmpget configuration parameter is passed to shell_exec() = without proper validation. An authenticated administrator can modify the sn= mpget configuration to point to a malicious executable file and trigger cod=
e execution by accessing the /about endpoint. 2026-09-01 7.2 CVE-2026-84190=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84190 ] librenms--librenms L= ibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability =
in legacy PHP templates that output SNMP-sourced and syslog-sourced data wi= thout escaping. An attacker who controls a monitored network device can inj= ect arbitrary JavaScript through SNMP interface descriptions or syslog prog= ram fields that executes when authenticated users view affected pages. 2026= -09-01 7.1 CVE-2026-84192 [
https://www.cve.org/CVERecord?id=3DCVE-2026-841=
92 ] libxml2--libxml2
=C2=A0 In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strca=
t stack-based buffer overflow. 2026-09-05 8 CVE-2026-86140 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-86140 ] light0011--cms A vulnerability was id= entified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f= 601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Au= thController::_initialize of the file App/Admin/Controller/ChapterControlle= r.class.php of the component Chapter Controller. The manipulation leads to = authorization bypass. The attack can be initiated remotely. The exploit is = publicly available and might be used. Continious delivery with rolling rele= ases is used by this product. Therefore, no version details of affected nor=
updated releases are available. The project was informed of the problem ea= rly through an issue report but has not responded yet. 2026-09-03 7.3 CVE-2= 026-85378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85378 ] light0011--= cms A security flaw has been discovered in light0011 cms c774dce31c6df00555= 68a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affec=
ts the function ChapterModel::searchChapter of the file App/Home/Controller= /ChapterController.class.php of the component Query Builder. The manipulati=
on of the argument content results in sql injection. The attack can be laun= ched remotely. The exploit has been released to the public and may be used = for attacks. This product does not use versioning. This is why information = about affected and unaffected releases are unavailable. The project was inf= ormed of the problem early through an issue report but has not responded ye=
t. 2026-09-04 7.3 CVE-2026-85379 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-85379 ] light0011--cms A weakness has been identified in light0011 cms = c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380= b38930. This vulnerability affects the function catchimage of the file Publ= ic/ueditor/php/controller.php of the component UEditor. This manipulation o=
f the argument source[] causes server-side request forgery. The attack may =
be initiated remotely. The exploit has been made available to the public an=
d could be used for attacks. This product uses a rolling release model to d= eliver continuous updates. As a result, specific version information for af= fected or updated releases is not available. The project was informed of th=
e problem early through an issue report but has not responded yet. 2026-09-=
04 7.3 CVE-2026-85380 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85380 ]=
Lightstar--SmartIT Desktop Manager SmartIT Desktop Manager developed by Li= ghtstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated = remote attackers can obtain the SSH service account credentials and passwor=
ds for the SmartIT Agent directly from the application source code. 2026-09= -04 9.8 CVE-2026-85146 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85146 =
] Lightstar--SmartIT Desktop Manager SmartIT Desktop Manager developed by L= ightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated=
remote attackers can exploit a fixed password to remotely access user host=
s. 2026-09-04 9.8 CVE-2026-85148 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-85148 ] Lightstar--SmartIT Desktop Manager SmartIT Desktop Manager deve= loped by Lightstar has a Use of Hard-coded Credentials vulnerability. Unaut= henticated remote attackers can obtain a specific password from the source = code, which can be used to retrieve the AES encryption key used for communi= cation. 2026-09-04 7.5 CVE-2026-85147 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-85147 ] Linux--Linux In the Linux kernel, the following vulnerabil= ity has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creat= ing a child shadow page Explicitly clear role.invalid when deriving a child=
shadow page's role from its parent to harden against bugs elsewhere in KVM=
, as violating KVM's invariant that invalid pages are NOT on the list of ac= tive MMU pages leads to use-after-free due to __kvm_mmu_prepare_zap_page() = using list_add() instead of list_move() when processing an invalid shadow p= age, i.e. makes a bad situation far worse. Yell loudly if the parent is inv= alid, as it means KVM has missed a validity check, i.e. KVM is attempting t=
o map memory using an invalid/obsolete root, but continue on as the child i=
s otherwise still a valid shadow page. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D BUG: KASAN: slab-use-after-free in __kvm_mmu_get_shadow_page+0= x1817/0x1860 [kvm] Write of size 8 at addr ff11000153dd1368 by task repro/8=
53 CPU: 1 UID: 1000 PID: 853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf= -next-vm #5 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIO=
S 0.0.0 02/06/2015 Call Trace: <TASK> dump_stack_lvl+0x4b/0x70 print_report= +0x153/0x49c kasan_report+0xbc/0xf0 __kvm_mmu_get_shadow_page+0x1817/0x1860=
[kvm] mmu_alloc_root+0x141/0x320 [kvm] kvm_mmu_load+0x612/0x20f0 [kvm] kvm= _arch_vcpu_ioctl_run+0x3dd5/0x6150 [kvm] kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm] = __x64_sys_ioctl+0x131/0x1b0 do_syscall_64+0x67/0x5f0 entry_SYSCALL_64_after= _hwframe+0x4b/0x53 </TASK> Allocated by task 853: kasan_save_stack+0x20/0x4=
0 kasan_save_track+0x14/0x30 __kasan_slab_alloc+0x5f/0x70 kmem_cache_alloc_= noprof+0xfe/0x2e0 __kvm_mmu_topup_memory_cache+0x135/0x530 [kvm] paging64_p= age_fault+0x318/0x1e30 [kvm] kvm_mmu_do_page_fault+0x21d/0x630 [kvm] kvm_mm= u_page_fault+0x18c/0x17b0 [kvm] kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm]=
kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm] __x64_sys_ioctl+0x131/0x1b0 do_syscall_6= 4+0x67/0x5f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Freed by task 853: ka= san_save_stack+0x20/0x40 kasan_save_track+0x14/0x30 kasan_save_free_info+0x= 3b/0x60 __kasan_slab_free+0x43/0x70 kmem_cache_free+0xe2/0x400 kvm_mmu_comm= it_zap_page.part.0+0x1e2/0x310 [kvm] kvm_mmu_free_roots+0x283/0x560 [kvm] k= vm_arch_vcpu_ioctl_run+0x33c8/0x6150 [kvm] kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm=
] __x64_sys_ioctl+0x131/0x1b0 do_syscall_64+0x67/0x5f0 entry_SYSCALL_64_aft= er_hwframe+0x4b/0x53 2026-09-03 9.3 CVE-2026-80726 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-80726 ] Linux--Linux In the Linux kernel, the followi=
ng vulnerability has been resolved: btrfs: initialize inode mapping flags f=
or cached inodes [BUG] When running generic/795 with 8K block size, 4K page=
size, the test always fails, triggering some ASSERT()s related to folio si= ze: 795 (241074): drop_caches: 3 assertion failed: IS_ALIGNED(start, blocks= ize) && IS_ALIGNED(end + 1, blocksize), in extent_io.c:1404 (blocksize=3D81=
92 root=3D262 ino=3D258 start=3D16826368 end=3D16830463 mapping min order= =3D0) ------------[ cut here ]------------ kernel BUG at extent_io.c:1404! = Oops: invalid opcode: 0000 [#1] SMP CPU: 8 UID: 0 PID: 241105 Comm: fsstres=
s Tainted: G OE 7.2.0-rc5-custom+ #442 PREEMPT(full) f4bfb352566f3949f29c23= 3ce6f735050a03b245 Tainted: [O]=3DOOT_MODULE, [E]=3DUNSIGNED_MODULE Hardwar=
e name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0= 010:assert_folio_range.cold+0x3d/0x3f [btrfs] Call Trace: <TASK> btrfs_read= _folio+0x9e/0x170 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3] prepare_= one_folio.constprop.0+0x104/0x2a0 [btrfs 4cd1dd93b341b8ef766643f9512f4a8625= 9567a3] btrfs_buffered_write+0x285/0xa50 [btrfs 4cd1dd93b341b8ef766643f9512= f4a86259567a3] btrfs_do_write_iter+0x1aa/0x210 [btrfs 4cd1dd93b341b8ef76664= 3f9512f4a86259567a3] iter_file_splice_write+0x31a/0x540 direct_splice_actor= +0x53/0x170 splice_direct_to_actor+0xe9/0x240 do_splice_direct+0x76/0xb0 vf= s_copy_file_range+0x1fd/0x630 __x64_sys_copy_file_range+0xf9/0x220 do_sysca= ll_64+0xe1/0x790 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> ---[ end = trace 0000000000000000 ]--- The ASSERT() itself is added by a later patch. = The crash is triggered with that new debug patch, and without this fix. [CA= USE] In the above case, the start 16826368 is properly 8K aligned, but the = end (16830463 + 1) is not 8K aligned. Furthermore the mapping's minimal fol=
io order is 0, not the expected 1 for 8K block size with 4K page size. So t= his means some inodes do not have btrfs_set_inode_mapping_order() called on=
it. The missing btrfs_set_inode_mapping_order() call happens for cached in= odes, through the following events: - btrfs_create_new_inode() called for i= node X Which properly sets minimal folio order for the VFS inode. - btrfs_u= pdate_inode() called for inode X Which calls btrfs_delayed_update_inode() t=
o create a delayed_node into root->delayed_nodes xarray. - Drop cache/memor=
y pressure, evicting in-memory inode X Which evicted the inode X, but delay= ed_node is still in root->delayed_nodes for future reuse. - btrfs_iget() fo=
r inode X called again btrfs_iget() |- btrfs_iget_locked() | |- iget5_locke= d_rcu() | Which creates a new vfs_inode for btrfs, whose mapping still | ha=
s the minimal order as 0. | |- btrfs_read_locked_inode() |- btrfs_fill_inod= e() | |- btrfs_get_delayed_node() | Which found out the previous node, and = use that delayed | node to initialize the new inode. | |- filled =3D true; =
|- if (filled) goto cache_index; Which skips the btrfs_update_inode_mapping= _flags() and btrfs_set_inode_mapping_order() calls. So the inode still has = minimal folio order set as 0, not the required 1. Thus later page cache rea=
d will get a folio whose size is smaller than block size, as the mapping ha=
s its minimal folio order set as 0 not 1, then trigger the ASSERT(). [FIX] = Move the btrfs_update_inode_mapping_flags() and btrfs_set_inode_mapping_ord= er() calls under cache_index label, so that the mapping flags and minimal f= olio order is always set no matter if we have a cached inode. 2026-09-03 8.=
8 CVE-2026-80734 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80734 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: regulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table=
[] mapping does not match the FP9931 datasheet. The datasheet defines the V= POS/VNEG voltage mapping as: 00h-04h -> 7.04V (-7.04V) 05h -> 7.26V (-7.26V=
) 06h -> 7.49V (-7.49V) ... 28h-3Fh -> 15.06V (-15.06V) However, VPOSNEG_ta= ble[] has two issues: 1. Selector 0x00~0x04 should all map to 7.04V (5 entr= ies), but the table has 6 entries of 7.04V, causing all subsequent entries =
to be shifted by one position. 2. Selectors 0x29~0x3F should all clamp to 1= 5.06V (23 entries), but the table has only 41 entries. Any selector value a= bove 0x28 would result in an out-of-bounds table access. Fix both issues by=
removing the duplicate 7.04V entry and appending the missing 23 clamped 15= .06V entries, bringing the table to the correct size of 64 entries (0x00~0x= 3F). 2026-09-03 8.4 CVE-2026-80745 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-80745 ] Linux--Linux In the Linux kernel, the following vulnerability=
has been resolved: drm/amdkfd: Add bounds check for CRAT subtype length Th=
e CRAT parser validates that the subtype header fits within the image, but = does not verify that the advertised subtype length fits. A malformed CRAT t= able with an oversized length field causes out-of-bounds reads when kfd_par= se_subtype() casts the header to specific subtype structures. Add validatio=
n that sub_type_hdr + length does not exceed the image boundary before pars= ing the subtype contents. (cherry picked from commit 48e1d1e6e8798aef0312e6= 8d8e586021b5b3cf4d) 2026-09-03 8 CVE-2026-80747 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-80747 ] Linux--Linux In the Linux kernel, the following = vulnerability has been resolved: pmdomain: mediatek: fix remaining %pOF aft=
er of_node_put() scpsys_get_bus_protection_legacy() looks up several legacy=
bus protection regmaps from device-tree nodes. Two error paths put the dev= ice node before checking whether the regmap lookup failed, but still pass t= hat node to dev_err_probe() with %pOF on failure. If of_node_put() drops th=
e last reference, the later %pOF formatting can dereference a freed device = node. Keep the node reference until after the error message has been emitte=
d in the infracfg and SMI lookup paths. Also drop the SMI node before retur= ning when the SMI phandle is missing. 2026-09-03 8.4 CVE-2026-80750 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-80750 ] Linux--Linux In the Linux ke= rnel, the following vulnerability has been resolved: Input: psxpad-spi - se=
t driver data before use psxpad_spi_suspend() retrieves the controller stat=
e with spi_get_drvdata(), but probe never stores it, so suspend dereference=
s a NULL pointer. Store it during probe. 2026-09-03 8.4 CVE-2026-80752 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-80752 ] Linux--Linux In the Linux=
kernel, the following vulnerability has been resolved: ovpn: run deferred = work on a module-owned workqueue ovpn queues several work items whose callb= acks execute module text. These works currently run on the global system wo= rkqueues, so module exit has no driver-owned drain point that guarantees th=
e callbacks have fully returned before the module text can be freed. Object=
references protect the objects used by the callbacks, but they do not prov=
e that a workqueue function has returned. In particular, a worker can drop = the final reference that unblocks device teardown while it is still executi=
ng ovpn code. Add a module-owned workqueue and queue all ovpn work items on=
it. During module exit, unregister rtnl and netlink first, flush the workq= ueue so ordinary ovpn workers finish, run the final RCU barrier, and destro=
y the workqueue last. This keeps the workqueue available for cleanup work q= ueued from RCU callbacks, while ensuring no ovpn work item can outlive the = module text. The per-device delayed keepalive work remains explicitly disab= led during netdev teardown (disable_delayed_work_sync in ndo_uninit), since=
flush_workqueue does not flush delayed work that is still only pending on = its timer. 2026-09-03 8.4 CVE-2026-80753 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80753 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: net: remove CAP_SYS_RAWIO zero-padding in dev_val= idate_header dev_validate_header() reads dev->hard_header_len directly when=
zero-padding short link layer headers for CAP_SYS_RAWIO holders: if (capab= le(CAP_SYS_RAWIO)) { memset(ll_header + len, 0, dev->hard_header_len - len)=
; return true; } Packet send paths call dev_validate_header() on skbs whose=
headroom was allocated from an earlier hard_header_len read. If the device=
is reconfigured so that dev->hard_header_len increases before validation, = the memset writes past the reserved buffer, an out-of-bounds write. This ou= t-of-bounds write is masked in some SOCK_RAW paths today because the same c= oncurrent increase can first make skb_push() exceed the reserved headroom a=
nd trigger skb_under_panic(). Remove the zero-padding branch before making = those hard_header_len reads consistent, so the snapshot fixes do not turn a=
loud panic into a silent overwrite. This path is only reached for variable=
length L2 protocols, where len < hard_header_len but len >=3D min_header_l= en. No remaining in-tree variable length L2 protocol implements header_ops-= >validate, and the CAP_SYS_RAWIO bypass that zero-pads and accepts short he= aders has no real value beyond allowing testing of intentionally malformed = input. Drop the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_head= er_len in dev_validate_header() are comparisons only and have no memory saf= ety impact. 2026-09-03 7.8 CVE-2026-80731 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-80731 ] Linux--Linux In the Linux kernel, the following vulner= ability has been resolved: ata: pata_sl82c105: fix bridge revision use-afte= r-free pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b = ("PCI: Change all drivers to use pci_device->revision") replaced a configur= ation-space read with direct access to the cached revision field, but left = that access after pci_dev_put(). The bridge may therefore be freed before i=
ts revision is read. Read the revision before dropping the reference. 2026-= 09-03 7.8 CVE-2026-80732 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8073=
2 ] Linux--Linux In the Linux kernel, the following vulnerability has been = resolved: ovpn: ensure socket is owned by ovpn before deref sk_user_data So=
me subsystems, like BPF SOCKMAP, set sk_user_data without actually setting = the encap_type. For this reason, we must make sure that the type is the one=
ovpn expects before dereferencing sk_user_data. Failing to do so may lead =
to out-of-bounds reads. 2026-09-03 7.3 CVE-2026-80735 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80735 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: thunderbolt: Fix bandwidth group res= ervation indexing Valid bandwidth group IDs range from 1 through MAX_GROUPS=
, while Group ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group I=
D directly to index its local group_reserved[] array. The array currently h=
as MAX_GROUPS entries, so its valid indices are 0 through MAX_GROUPS - 1. G= roup ID MAX_GROUPS therefore accesses one element past the end, and the fin=
al group's reserved bandwidth is not included when the array is summed. Giv=
e group_reserved[] MAX_GROUPS + 1 entries so direct Group ID indexing cover=
s the reserved ID 0 and valid IDs 1 through MAX_GROUPS. 2026-09-03 7.8 CVE-= 2026-80736 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80736 ] Linux--Lin=
ux In the Linux kernel, the following vulnerability has been resolved: seri= al: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not=
wait for a running callback, so the TX callback can still touch the TX buf= fer after it is freed. The RX poll timer reads the RX buffers without the p= ort lock. Switch to dmaengine_terminate_sync() and delete the RX timer befo=
re freeing the buffers. 2026-09-03 7.8 CVE-2026-80737 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80737 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: bpf: Check sk_state before sk_protoc=
ol in bpf_tcp_*_syncookie bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie=
accept a socket pointer 'sk' with argument type ARG_PTR_TO_BTF_ID_SOCK_COM= MON. However, they access sk->sk_protocol without validating whether 'sk' r= epresents a full socket. Fix this issue by checking sk->sk_state !=3D TCP_L= ISTEN before inspecting sk->sk_protocol in both bpf_tcp_gen_syncookie and b= pf_tcp_check_syncookie. Since mini-sockets are never in the TCP_LISTEN stat=
e, the condition short-circuits and prevents dereferencing fullsock-specifi=
c fields. 2026-09-03 7.3 CVE-2026-80738 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80738 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: drm/log: Fix out-of-bounds read on empty message = length drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing=
newline, but len is unsigned int. If len is 0, the subtraction wraps to UI= NT_MAX, causing an out-of-bounds read. Add an early return when len is 0. 2= 026-09-03 7.1 CVE-2026-80741 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 80741 ] Linux--Linux In the Linux kernel, the following vulnerability has b= een resolved: mmc: loongson2: Fix sg iteration in data reorder functions In=
ls2k0500_mmc_reorder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(), the f= or_each_sg() macro already iterates over the scatterlist entries, with 'sg'=
pointing to the current entry. However, the code incorrectly uses '&sg[i]'=
and 'sg_dma_len(&sg[i])' inside the loop, which treats 'sg' as an array ba=
se and indexes it again, leading to access of wrong sg entries (or out-of-b= ounds if the list is not an array). 2026-09-03 7.8 CVE-2026-80748 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-80748 ] Linux--Linux In the Linux kern= el, the following vulnerability has been resolved: drm/connector/hdmi: Fix = out of bounds memory read A helper function was copying a given audio infof= rame into the connector's copy but using the size of the destination (a gen= eric target, sized to accept many different data blocks) not the source (a = very specific type of data block). Thus, it was copying 60 bytes of data fr=
om a 28 byte allocation. Fix that by using the source size instead, togethe=
r with a build bug on the source size actually being smaller than the desti= nation. I hit this running KUnit tests under KASAN (while debugging somethi=
ng else entirely). In the real world, it seems unlikely to cause an actual = problem. It is a read not a write so it can't corrupt any memory. However, =
it could potentially fall off the end of a page and cause an accvio bug. 20= 26-09-03 7.1 CVE-2026-80749 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 0749 ] Linux--Linux In the Linux kernel, the following vulnerability has be=
en resolved: pmdomain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_d= ev() mtk_mfg_attach_dev() reads prev_o on the first iteration of its loop, =
in "if (prev_o && prev_o->freq =3D=3D o->freq)", before prev_o is assigned =
at the end of the loop body. On that first iteration, evaluating prev_o rea=
ds an indeterminate value. If it is non-NULL, the condition dereferences a = stale or invalid pointer, potentially faulting or incorrectly skipping the = first OPP. Initialize prev_o to NULL. This matches the intent as well: ther=
e is no previous OPP to compare against on the first iteration. Found with = Clang's -Wconditional-uninitialized. 2026-09-03 7.8 CVE-2026-80751 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-80751 ] Linux--Linux In the Linux ker= nel, the following vulnerability has been resolved: Input: synaptics-rmi4 -=
fix F55 transmitter electrode count typo During F55 sensor detection, the = transmitter (TX) electrode count was incorrectly assigned the value of the = receiver (RX) electrode count due to copy-paste typos. This incorrect value=
was then propagated to the driver data and used by F54 to determine the di= agnostics report size. On devices with more RX than TX electrodes, this inf= lated the perceived TX count, leading to incorrect report size calculations=
and potential out-of-bounds buffer accesses. Fix the typos by correctly as= signing the TX electrode counts. 2026-09-03 7.8 CVE-2026-80754 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-80754 ] LiquidThemes--Booking Hub Incorre=
ct Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Pr= ivilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.=
2026-09-02 8.8 CVE-2026-81769 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-81769 ] LiteSpeed Technologies--LiteSpeed Cache Unauthenticated Server Si=
de Request Forgery (SSRF) in LiteSpeed Cache <=3D 7.9 versions. 2026-09-03 = 7.2 CVE-2026-84761 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84761 ] ll= lyasviel Fooocus--lllyasviel Fooocus An eval() injection vulnerability in t=
he get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.85=
4 through 2.5.5 allows remote attackers to execute arbitrary Python code vi=
a a crafted styles payload in the EXIF metadata of an uploaded image file. = 2026-09-01 8.8 CVE-2026-51974 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -51974 ] lm-sys--FastChat FastChat contains an authentication bypass vulner= ability in the /register_worker endpoint that allows unauthenticated attack= ers to register arbitrary worker addresses and perform server-side request = forgery. Attackers can register malicious workers under victim model names =
to intercept user prompts, images, and responses, or probe internal network=
ports across the worker mesh. 2026-09-04 9.4 CVE-2026-85695 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-85695 ] malcare--MalCare Security Unauthent= icated Denial of Service Attack in MalCare Security <=3D 6.69 versions. 202= 6-09-03 7.5 CVE-2026-84776 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84= 776 ] MapGeo--Interactive Geo Maps Unauthenticated Cross Site Scripting (XS=
S) in Interactive Geo Maps <=3D 1.6.30 versions. 2026-09-02 7.1 CVE-2026-81= 770 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81770 ] maplibre--maplibr= e-gl-js MapLibre GL JS is an interactive vector tile map library for web br= owsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.att= ributes as a live NamedNodeMap while removeAttributes() removes attributes = from the same collection, shifting indexes and skipping an adjacent dangero=
us attribute. An attacker who controls untrusted third-party style attribut= ion strings or user-supplied custom attributions can supply consecutive dan= gerous attributes, causing an attribute such as onload or ontoggle to survi=
ve sanitization and execute when the attribution control inserts the conten=
t into innerHTML. A victim must render the affected map content for the scr= ipt to execute. This issue is fixed in version 6.4.1. 2026-09-03 10 CVE-202= 6-85061 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85061 ] Marcus--Login=
With Ajax Improper Neutralization of Input During Web Page Generation ('Cr= oss-site Scripting') vulnerability in Marcus Login With Ajax allows Reflect=
ed XSS. This issue affects Login With Ajax: from n/a through 4.5.1. 2026-09= -02 7.1 CVE-2026-82883 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82883 =
] Mauro Cassani--ACPT (Premium) The ACPT (Premium) plugin for WordPress is = vulnerable to Privilege Escalation in all versions up to, and including, 2.= 0.66. This is due to missing authorization in the `submit()` function, whic=
h allows unauthenticated form submissions to control the target user ID bef= ore calling `wp_update_user()`. This makes it possible for unauthenticated = attackers to overwrite any WordPress user's email address and password, inc= luding an administrator's, and take over the account. Successful exploitati=
on requires a public ACPT user form that permits anonymous submissions. 202= 6-09-04 9.8 CVE-2026-15354 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15= 354 ] measX--DASYLab There is an out-of-bounds write vulnerability in DASYL=
ab due to lack of proper validation of user-supplied data. Successful explo= itation requires an attacker to get a user to open a specially crafted .DSB=
file.=C2=A0 This issue affects all versions before 2026.0.0. 2026-09-03 7.=
8 CVE-2026-64195 [
https://www.cve.org/CVERecord?id=3DCVE-2026-64195 ] meas= X--DASYLab There is an out-of-bounds write vulnerability in DASYLab=C2=A0du=
e to improper validation of user-supplied data, resulting in a write past t=
he end of an allocated heap.=C2=A0Successful exploitation requires an attac= ker to get a user to open a specially crafted .DSB file.=C2=A0 This issue a= ffects all versions before 2026.0.0. 2026-09-03 7.8 CVE-2026-64196 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-64196 ] measX--DASYLab There is an ou= t-of-bounds write vulnerability in DASYLab=C2=A0due to improper validation =
of user-supplied data, resulting in a write past the end of an allocated da=
ta structure. Successful exploitation requires an attacker to get a user to=
open a specially crafted .DSB file.=C2=A0 This issue affects all versions = before 2026.0.0. 2026-09-03 7.8 CVE-2026-64197 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-64197 ] measX--DASYLab There is an out-of-bounds read vul= nerability in DASYLab due to improper validation of user-supplied data. =C2= =A0 This results in a read a few bytes past the end of an allocated heap bu= ffer during file handling.=C2=A0 Successful exploitation requires an attack=
er to get a user to open a specially crafted .DSB file.=C2=A0 This issue af= fects all versions before 2026.0.0. 2026-09-03 7.8 CVE-2026-64198 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-64198 ] measX--DASYLab There is an out= -of-bounds read vulnerability in DASYLab due to improper validation of user= -supplied data. =C2=A0 This results in a read outside the bounds of an allo= cated data structure.=C2=A0 Successful exploitation requires an attacker to=
get a user to open a specially crafted .DSB file.=C2=A0 This issue affects=
all versions before 2026.0.0. 2026-09-03 7.8 CVE-2026-64199 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-64199 ] measX--DASYLab There is an out-of-b= ounds read vulnerability in DASYLab due to improper validation of user-supp= lied data. =C2=A0 This results in a read a past the end of an allocated hea=
p buffer during string conversion.=C2=A0 Successful exploitation requires a=
n attacker to get a user to open a specially crafted .DSB file.=C2=A0 This = issue affects all versions before 2026.0.0. 2026-09-03 7.8 CVE-2026-64200 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-64200 ] medplum--medplum Medpl=
um is a developer platform that enables development of healthcare apps. In = Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could = return the client_secret of preconfigured OAuth clients defined via the def= aultOAuthClients server configuration when a matching redirect_uri was prov= ided. This issue has been patched in version 5.1.7. 2026-09-03 8.2 CVE-2026= -44506 [
https://www.cve.org/CVERecord?id=3DCVE-2026-44506 ] medplum--medpl=
um Medplum is a developer platform that enables development of healthcare a= pps. Prior to version 5.1.6, the external identity provider callback at GET=
/auth/external accepts attacker-controlled redirect URIs that only need to=
start with a registered client redirect URI, rather than matching exactly.=
After a successful external IdP login, the server appends Medplum login an=
d code values to that attacker-supplied URL and issues a redirect. Because = the external login request state is serialized as raw JSON and later truste=
d by the callback, an attacker who can tamper with state.redirectUri can ca= use Medplum to redirect authorization artifacts to an attacker-controlled e= ndpoint. When the registered redirect URI is a bare origin or another prefi=
x that can be extended into a different hostname, this becomes a cross-orig=
in authorization code leak. This issue has been patched in version 5.1.6. 2= 026-09-03 7.1 CVE-2026-53728 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 53728 ] MegaEase--EaseProbe A flaw has been found in MegaEase EaseProbe up =
to 2.3.0. Affected is the function realIP of the file web/server.go of the = component Middleware. This manipulation of the argument X-Forwarded-For/X-R= eal-IP/True-Client-IP causes improper access controls. The attack can be in= itiated remotely. The exploit has been published and may be used. The vendo=
r was contacted early about this disclosure but did not respond in any way.=
2026-08-31 7.3 CVE-2026-82815 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-82815 ] melograno--Booking for Appointments and Events Calendar Amelia Th=
e Booking for Appointments and Events Calendar - Amelia (Premium) plugin fo=
r WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. = This is due to insufficient validation of the attacker-controlled 'type' pa= rameter in the customer update endpoint, which allows customers to set thei=
r role to 'manager' and trigger creation of a WordPress user with the wpame= lia-manager role when the 'externalId' parameter is set to 0. This makes it=
possible for unauthenticated attackers to escalate their privileges to adm= inistrator by first elevating to the manager role, then creating a provider=
entity linked to an administrator user ID and overwriting that administrat= or's password. 2026-09-02 9.8 CVE-2026-9055 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-9055 ] Menulux Software Inc.--Menulux Portal Plaintext stora=
ge of a password vulnerability in Menulux Software Inc. Menulux Portal allo=
ws Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: bef= ore 20260903211448. 2026-09-04 7.1 CVE-2026-19051 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-19051 ] Menulux Software Inc.--Menulux Portal Observab=
le response discrepancy vulnerability in Menulux Software Inc. Menulux Port=
al allows Account Footprinting. This issue affects Menulux Portal: before 2= 0260903211448. 2026-09-04 7.5 CVE-2026-19080 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-19080 ] Metagauss--RegistrationMagic Unauthenticated Cross = Site Scripting (XSS) in RegistrationMagic <=3D 6.0.9.8 versions. 2026-08-31=
7.1 CVE-2026-82221 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82221 ] M= etagauss--RegistrationMagic Unauthenticated Broken Authentication in Regist= rationMagic <=3D 6.0.9.8 versions. 2026-08-31 7.4 CVE-2026-82225 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-82225 ] MetaGPT--MetaGPT 0.8.1 An OS co= mmand injection vulnerability in MetaGPT 0.8.1 allows an attacker to execut=
e arbitrary commands via the path argument of RepoParser.rebuild_class_view= s() in metagpt/repo_parser.py. 2026-08-31 9.8 CVE-2026-79408 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-79408 ] MetaGPT--MetaGPT 0.8.1 A path trave= rsal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker=
to read arbitrary files via the FILE_NAME value used by set_file_name() an=
d load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code jo= ins the attacker-controlled FILE_NAME value with the settings directory and=
opens the resulting path without validating that the resolved path remains=
within the intended directory. 2026-08-31 7.5 CVE-2026-79407 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-79407 ] Microsoft--Azure AI Language Autho= ring Missing authentication for critical function in Azure AI Language allo=
ws an unauthorized attacker to elevate privileges over a network. 2026-09-0=
3 10 CVE-2026-70352 [
https://www.cve.org/CVERecord?id=3DCVE-2026-70352 ] M= icrosoft--Azure Cosmos DB Authorization bypass through user-controlled key =
in Azure Cosmos DB allows an authorized attacker to perform spoofing over a=
network. 2026-09-03 8.5 CVE-2026-69857 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-69857 ] Microsoft--Entra Authorization bypass through user-cont= rolled key in Microsoft Azure Active Directory B2C allows an unauthorized a= ttacker to elevate privileges over a network. 2026-09-03 10 CVE-2026-83711 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-83711 ] Microsoft--Microsoft = Copilot Studio Improper verification of cryptographic signature in Copilot = Studio allows an unauthorized attacker to elevate privileges over a network=
. 2026-09-03 9.3 CVE-2026-80098 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-80098 ] Microsoft--Microsoft Discovery Studio Improper neutralization of=
special elements in data query logic in Microsoft Discovery Studio allows =
an unauthorized attacker to disclose information over a network. 2026-09-03=
7.4 CVE-2026-62906 [
https://www.cve.org/CVERecord?id=3DCVE-2026-62906 ] M= icrosoft--Microsoft Entra Authentication bypass using an alternate path or = channel in Microsoft Entra ID allows an unauthorized attacker to elevate pr= ivileges over a network. 2026-09-03 9.1 CVE-2026-62916 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-62916 ] Microsoft--Microsoft Fabric Missing autho= rization in Microsoft Fabric allows an authorized attacker to elevate privi= leges over a network. 2026-09-03 8.5 CVE-2026-70178 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-70178 ] Microsoft--Microsoft Power Platform Server-s= ide request forgery (ssrf) in Power Automate allows an authorized attacker =
to elevate privileges over a network. 2026-09-03 8.5 CVE-2026-65818 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-65818 ] migrateguru--Migrate Guru Si=
te Migration & Cloning Unauthenticated Denial of Service Attack in Migrate = Guru - Site Migration & Cloning <=3D 6.65 versions. 2026-09-03 7.5 CVE-= 2026-84778 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84778 ] MindsDB --=
MindsDB=C2=A0
=C2=A0 MindsDB through 26.1.0 contains a server-side request forgery vulner= ability in the web crawler handler that allows unauthenticated attackers to=
fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.l= ist. Attackers can bypass the allowlist control by exploiting the default e= mpty configuration and access internal services and cloud metadata endpoint=
s without authentication. 2026-09-05 7.5 CVE-2026-86173 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-86173 ] miniOrange--WordPress Social Login and R= egister Unauthenticated Cross Site Scripting (XSS) in WordPress Social Logi=
n and Register <=3D 7.8.2 versions. 2026-08-31 7.1 CVE-2026-82229 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82229 ] Ministry of the Interior (MVR)= --eObanka-Identifikace Improper neutralization of special elements used in =
an OS command ('OS command injection') vulnerability in Digit=C3=83=C2=A1ln= =C3=83=C2=AD a informa=C3=84=C2=8Dn=C3=83=C2=AD agentura (DIA) eOb=C3=84=C2= =8Danka-Identifikace on MacOS enables an attacker to=C2=A0register a custom=
URL scheme (czeeopauth://) for parameterized application execution. Prior =
to version 3.6.0, incoming URL parameters were passed to the compiled Apple= Script wrapper using concatenation without sufficient sanitization. 2026-08= -31 9.3 CVE-2026-59111 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59111 =
] MladenSU--cli-mcp-server cli-mcp-server 0.2.5 contains a command allowlis=
t bypass vulnerability in the _validate_command_with_operators function whe=
n ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substit= ution syntax like $(...) or backticks to execute non-allowlisted commands t= hat bypass the ALLOWED_COMMANDS validation check. 2026-09-04 8.1 CVE-2026-8= 5660 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85660 ] modelscope--mode= lscope ModelScope uses PyYAML's unsafe yaml.Loader to parse model configura= tion files, allowing arbitrary code execution through Python object constru= ction tags. Attackers can craft malicious model repositories with poisoned = configuration files that execute code when loaded by users. 2026-09-01 8.8 = CVE-2026-84202 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84202 ] models= cope--ms-swift ms-swift 4.5.2 contains a server-side request forgery vulner= ability in the swift deploy OpenAI-compatible API that fetches multimodal m= edia URLs without validation or redirect filtering. Unauthenticated attacke=
rs can supply arbitrary image_url, audio_url, or video_url parameters to ma=
ke the server issue requests to internal services and cloud metadata endpoi= nts. 2026-09-04 7.5 CVE-2026-85686 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85686 ] moos-ivp--moos-ivp MOOS-IvP iSay through 24.8.1 contains a re= mote code execution vulnerability in the SAY_MOOS variable handler that pas= ses unsanitized text to a shell command. Attackers can publish SAY_MOOS mes= sages containing backticks or command substitution syntax to execute arbitr= ary commands as the iSay process user. 2026-09-03 9.8 CVE-2026-85425 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85425 ] moos-ivp--moos-ivp MOOS-IvP=
uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MO=
OS client names without sanitization. Attackers can inject shell metacharac= ters into client names to execute arbitrary commands as the uMemWatch proce=
ss user through unquoted redirection targets in system calls. 2026-09-03 9.=
8 CVE-2026-85426 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85426 ] moos= -ivp--moos-ivp MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node=
ping authenticity before creating outbound bridge routes. Attackers can pu= blish NODE_BROKER_PING messages with crafted HostRecord data to redirect br= idged variables to attacker-controlled addresses. 2026-09-03 9.1 CVE-2026-8= 5434 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85434 ] moos-ivp--moos-i=
vp MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of T= RY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll=
attacker-controlled shore routes. Attackers can publish malicious shore ro= ute messages to receive bridged vehicle traffic including sensor data and c= ontrol information. 2026-09-03 9.1 CVE-2026-85435 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-85435 ] moos-ivp--moos-ivp MOOS-IvP through 24.8.1 con= tains multiple buffer overflow vulnerabilities in IvP function string decod= ers that trust attacker-controlled length fields without validation. Attack= ers can craft malicious encoded strings with mismatched declared and actual=
field lengths to overflow heap and stack buffers, potentially achieving re= mote code execution through MOOS variables or alog files. 2026-09-03 9.8 CV= E-2026-85437 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85437 ] moos-ivp= --moos-ivp MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability=
in StringToIvPFunction() where dimension, piece, and degree counts from en= coded BHV_IPF payloads are used as allocation sizes and loop bounds without=
validation. Attackers can supply crafted payloads with mismatched dimensio=
n values to write attacker-controlled doubles past the end of the IvPBox we= ight array, causing memory corruption and potential code execution. 2026-09= -03 9.8 CVE-2026-85438 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85438 =
] moos-ivp--moos-ivp MOOS-IvP uFldNodeComms through 24.8.1 trusts the sourc=
e node identity from the message body rather than validating it from the co= nnection source. Attackers can craft NODE_MESSAGE packets with spoofed sour=
ce identities to impersonate other nodes and post arbitrary variable notifi= cations without validation. 2026-09-03 7.5 CVE-2026-85429 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-85429 ] moos-ivp--moos-ivp MOOS-IvP through 24= .8.1 contains a remote code execution vulnerability in alogsplit's SplitHan= dler::handlePreCheckSplitDir() function that fails to sanitize shell metach= aracters in log file pathnames. Attackers can embed shell syntax in log fil=
e names or the --dir parameter to execute arbitrary commands with the privi= leges of the operator running alogsplit. 2026-09-03 7.8 CVE-2026-85439 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85439 ] moos-ivp--moos-ivp MOOS-I=
vP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), = isBraced(), and isChevroned() functions that strip whitespace but index usi=
ng the original string length. Attackers can send NODE_REPORT messages with=
leading or trailing whitespace to read past buffer bounds and access adjac= ent memory. 2026-09-03 7.5 CVE-2026-85444 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85444 ] moos-ivp--moos-ivp MOOS-IvP through 24.8.1 contains a = denial of service vulnerability in the Demuxer::addMuxPacket() function tha=
t trusts the packet count declared in mux headers without validation. Attac= kers can declare arbitrarily large packet counts to trigger unbounded memor=
y allocation, exhausting system resources and causing service unavailabilit=
y. 2026-09-03 7.5 CVE-2026-85445 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-85445 ] moos-ivp--moos-ivp MOOS-IvP versions through 24.8.1 contain a q= uadratic processing vulnerability in uFldNodeComms where each new node iden= tity creates a ledger entry and triggers all-pairs distribution work. Attac= kers can supply unbounded distinct node names in reports to drive the shore= side broker into quadratic processing, delaying or preventing distribution =
of legitimate node reports. 2026-09-03 7.5 CVE-2026-85446 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-85446 ] moos-ivp--moos-ivp MOOS-IvP pRealm thr= ough version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without v= alidating duration or variable list limits. Attackers can register long-liv=
ed pipeways with many variables to cause pRealm to generate excessive outpu=
t indefinitely, exhausting system resources. 2026-09-03 7.5 CVE-2026-85447 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85447 ] moos-ivp--moos-ivp MO= OS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed = communities stored in parallel vectors within ShoreBroker::handleMailNodePi= ng(). A single publisher can supply unbounded distinct community names to g= row retained state and per-pass work without limit, causing memory exhausti=
on and performance degradation. 2026-09-03 7.5 CVE-2026-85448 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85448 ] moos-ivp--moos-ivp MOOS-IvP pMarin= eViewer through 24.8.1 fails to limit the number of tracked node identities=
from NODE_REPORT messages, allowing attackers to exhaust memory by supplyi=
ng unbounded distinct node names. Attackers can publish crafted NODE_REPORT=
data to cause memory exhaustion and stall the operator display without aut= hentication. 2026-09-03 7.5 CVE-2026-85449 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-85449 ] Motorola--Smart Connect Application The mobile Smart = Connect dashboard UI was subject to manipulation by 3rd party apps. When pa= ired with a phishing attack, this manipulation could result in escalated pr= ivileges of an attacker within the system. 2026-09-02 7.5 CVE-2026-18058 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-18058 ] mozilla -- firefox Sand= box escape due to use-after-free in the DOM: Navigation component. This vul= nerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15=
, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 1= 53.2. 2026-09-01 9.6 CVE-2026-84119 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-84119 ] mozilla -- firefox Sandbox escape due to use-after-free in t=
he DOM: Security component. This vulnerability was fixed in Firefox 155, Fi= refox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, T= hunderbird 140.15, and Thunderbird 153.2. 2026-09-01 9.6 CVE-2026-84121 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84121 ] mozilla -- firefox Site = isolation issue in the DOM: Navigation component. This vulnerability was fi= xed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153= .2. 2026-09-01 9.8 CVE-2026-84129 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84129 ] mozilla -- firefox Site isolation issue in the DOM: Push Subsc= riptions component. This vulnerability was fixed in Firefox 155, Firefox ES=
R 153.2, Thunderbird 155, and Thunderbird 153.2. 2026-09-01 9.8 CVE-2026-84= 133 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84133 ] mozilla -- firefo=
x Other issue in the Profile Backup component. This vulnerability was fixed=
in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.=
2026-09-01 9.8 CVE-2026-84134 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-84134 ] mozilla -- firefox Site isolation issue in the DOM: Navigation co= mponent. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Th= underbird 155, and Thunderbird 153.2. 2026-09-01 9.8 CVE-2026-84140 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84140 ] mozilla -- firefox Integer o= verflow in the Graphics: ImageLib component. This vulnerability was fixed i=
n Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. 2= 026-09-01 9.8 CVE-2026-84141 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84141 ] mozilla -- firefox Internally found bugs present in Thunderbird 154=
. Some of these bugs showed evidence of memory corruption or another securi= ty-relevant defect and we presume that with enough effort some of these cou=
ld have been exploited. This vulnerability was fixed in Firefox 155 and Thu= nderbird 155. 2026-09-01 9.8 CVE-2026-84142 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-84142 ] mozilla -- firefox Internally found bugs present in = Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of = these bugs showed evidence of memory corruption or another security-relevan=
t defect and we presume that with enough effort some of these could have be=
en exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.= 15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird=
153.2. 2026-09-01 9.8 CVE-2026-84143 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84143 ] mozilla -- firefox Privilege escalation due to use-after-f= ree in the Graphics: WebGPU component. This vulnerability was fixed in Fire= fox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. 2026-09= -01 8.8 CVE-2026-84123 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84123 =
] mozilla -- firefox Privilege escalation in the WebDriver BiDi component. = This vulnerability was fixed in Firefox 155 and Thunderbird 155. 2026-09-01=
8.8 CVE-2026-84128 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84128 ] m= ozilla -- firefox Privilege escalation due to invalid pointer in the Graphi=
cs component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.= 40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140= .15, and Thunderbird 153.2. 2026-09-01 8.8 CVE-2026-84131 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84131 ] mozilla -- firefox Information disclos= ure in the Graphics: WebGPU component. This vulnerability was fixed in Fire= fox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. 2026-09= -01 7.5 CVE-2026-84130 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84130 =
] mozilla -- firefox Information disclosure in the Networking: HTTP compone= nt. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunder= bird 155, and Thunderbird 153.2. 2026-09-01 7.5 CVE-2026-84132 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84132 ] mozilla -- firefox Internally fou=
nd bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these=
bugs showed evidence of memory corruption or another security-relevant def= ect and we presume that with enough effort some of these could have been ex= ploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Th= underbird 155, and Thunderbird 153.2. 2026-09-01 7.5 CVE-2026-84144 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84144 ] mozilla -- firefox Internall=
y found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderb= ird ESR 140.14. Some of these bugs showed evidence of memory corruption or = another security-relevant defect and we presume that with enough effort som=
e of these could have been exploited. This vulnerability was fixed in Firef=
ox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderb= ird 155, Thunderbird 140.15, and Thunderbird 153.2. 2026-09-01 7.5 CVE-2026= -84145 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84145 ] mozilla -- fir= efox_mobile Other issue in Firefox Focus for Android. This vulnerability wa=
s fixed in Firefox 155. 2026-09-01 9.8 CVE-2026-84135 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-84135 ] mozilla -- firefox_mobile Privilege escala= tion in Firefox for Android. This vulnerability was fixed in Firefox 155. 2= 026-09-01 8.8 CVE-2026-84117 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84117 ] mozilla -- thunderbird Malicious calendar invitations could use fil=
e URI attachments to launch local or network-hosted executables on Windows,=
bypassing Thunderbird's normal executable attachment protections. With the=
new invitation display enabled, the attachment could also appear under a m= isleading filename. This vulnerability was fixed in Thunderbird 154 and Thu= nderbird 153.2. 2026-09-01 9.8 CVE-2026-84637 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-84637 ] mozilla -- thunderbird Triggering an error conditi=
on in certain MIME bodies would cause uninitialized memory to be used. This=
vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunde= rbird 153.2. 2026-09-01 9.1 CVE-2026-84639 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-84639 ] mozilla -- thunderbird A maliciously constructed mail=
header could lead to a one byte read past the end of a buffer. This vulner= ability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 1= 53.2. 2026-09-01 7.5 CVE-2026-84640 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-84640 ] mozilla -- thunderbird A malicious IMAP server can trigger u= se-after-free and heap-memory disclosure by sending a crafted ID response. = Heap contents can ultimately be persisted to prefs.js. This vulnerability w=
as fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. 202= 6-09-01 7.5 CVE-2026-84641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84= 641 ] mozilla -- thunderbird The values of the mail.allowed_attachment_host= names advanced config setting were used in a regular expression without esc= aping. For some possible valid hostnames, this could allow certain unintend=
ed hostnames to also match and serve remote attachments. This vulnerability=
was fixed in Thunderbird 155 and Thunderbird 153.2. 2026-09-01 7.5 CVE-202= 6-84642 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84642 ] mpdavis--pyth= on-jose python-jose through 3.5.0 fails to properly validate asymmetric key=
s in HMAC initialization, accepting DER-encoded public keys that lack PEM a= rmor or SSH prefixes. Attackers holding the service's public key can forge = HS256 tokens that pass verification when algorithms are not explicitly rest= ricted. This is an incomplete fix for CVE-2024-33663. 2026-09-03 9.1 CVE-20= 26-85394 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85394 ] MSI--Dragon = Center A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affe= cted by this vulnerability is the function MmioWritePath in the library NTI= OLib_X64.sys of the component MMIO Write Path Handler. Performing a manipul= ation of the argument count/elementSize results in integer overflow. The at= tack requires a local approach. The exploit has been made public and could =
be used. The vendor was contacted early about this disclosure but did not r= espond in any way. 2026-08-31 8.8 CVE-2026-82908 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-82908 ] Mstfakts-- College-Management-System
=C2=A0 A vulnerability was found in Mstfakts College-Management-System. Thi=
s issue affects the function mysqli_query of the file Front-end/university.= php of the component Search Handler. The manipulation of the argument book_= name/book_author results in sql injection. The attack may be performed from=
remote. The exploit has been made public and could be used. This product u= tilizes a rolling release system for continuous delivery, and as such, vers= ion information for affected or updated releases is not disclosed. The proj= ect was informed of the problem early through an issue report but has not r= esponded yet. 2026-09-06 7.3 CVE-2026-86213 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-86213 ] Mstfakts-- College-Management-System
=C2=A0 A vulnerability was determined in Mstfakts College-Management-System=
. Impacted is an unknown function of the file Front-end/login.php. This man= ipulation of the argument email causes improper authentication. It is possi= ble to initiate the attack remotely. The exploit has been publicly disclose=
d and may be utilized. This product is using a rolling release to provide c= ontinious delivery. Therefore, no version details for affected nor updated = releases are available. The project was informed of the problem early throu=
gh an issue report but has not responded yet. 2026-09-06 7.3 CVE-2026-86214=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-86214 ] MythicalLTD--Feather= Panel FeatherPanel versions before 1.3.7.10 fail to validate permissions in=
the SubuserController updateSubuser handler, allowing authenticated subuse=
rs to modify their own permission records. A subuser with minimal permissio=
ns can send a crafted request to grant themselves full server control, enab= ling unauthorized access to sensitive data, backups, and server configurati= on. 2026-09-02 8.8 CVE-2026-84715 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84715 ] NangoHQ--nango Nango before 0.71.6 contains a missing authenti= cation vulnerability in the runner tRPC server that allows unauthenticated = attackers to execute arbitrary JavaScript code by invoking the exposed star=
t procedure without credentials. Attackers with network access to the runne=
r port can send requests to the unauthenticated start procedure, bypassing = the unenforced RUNNER_SECRET_KEY environment variable, to achieve remote co=
de execution within the runner process. 2026-09-04 8.1 CVE-2026-9317 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-9317 ] NASA--earthdata-search A vul= nerability was detected in NASA earthdata-search 1.0.0. Affected by this vu= lnerability is the function scaleImage of the file serverless/src/scaleImag= e/handler.js of the component scale Endpoint. Performing a manipulation res= ults in server-side request forgery. The attack can be initiated remotely. = The exploit is now public and may be used. The vendor was contacted early a= bout this disclosure but did not respond in any way. 2026-08-31 7.3 CVE-202= 6-82801 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82801 ] nasa-jpl--ION= -DTN ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerabil= ity in the decodeSdnv function that allows unauthenticated remote attackers=
to read memory by sending truncated SDNV values. Attackers can send a UDP = datagram to the LTP link service input port with a truncated SDNV to trigge=
r reads up to nine bytes past buffer boundaries and underflow byte counters=
. 2026-09-02 7.5 CVE-2026-84484 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-84484 ] Net::DNS--Net::DNS Net::DNS versions before 1.57 for Perl allow = memory exhaustion via unbounded recursion in sig_data when re-encoding a me= ssage with a misplaced TSIG record. sig_data signs a message by re-encoding=
it, and removes TSIG records only from the additional section. A TSIG deco= ded into the answer or authority section survives that step and is signed a= gain, so encoding re-enters sig_data with no termination condition. Decodin=
g does not reject such a message: a TSIG that is not the last record on the=
wire raises "misplaced or corrupt TSIG", but the error is caught, reported=
as a warning, and the record is left in the packet. RFC 8945 section 5.2 r= equires the message to be dropped. The recursion is reached only when the d= ecoded TSIG carries an empty MAC, since a MAC recovered from the wire short= -circuits the signing step. It is reached only from code that re-encodes a = message it decoded, such as a forwarder or a proxy. A decoded message that =
is never re-encoded is unaffected. Message direction does not matter: a que=
ry reaches the same path as a response. Each cycle re-encodes the whole mes= sage, so fewer than 100 bytes on the wire exhaust available memory and term= inate the process. 2026-09-02 7.5 CVE-2026-81928 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-81928 ] netease-youdao--QAnything QAnything 2.0.0 conta= ins an authentication bypass vulnerability in the /api/local_doc_qa/get_fil= e_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticate=
d attackers to access any uploaded file or document. Attackers can enumerat=
e file identifiers through unauthenticated endpoints and retrieve base64-en= coded files or parsed document chunks without ownership verification to dis= close cross-tenant knowledge base content. 2026-09-04 7.5 CVE-2026-85671 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85671 ] nodeca--js-yaml js-yaml=
is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2,=
maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not coun=
t empty mapping sources while processing the merge key <<. An attacker can = alias a large sequence of empty mappings into many merge targets, causing O=
(N * K) processing while totalMergeKeys remains unchanged and the configure=
d resource limit is never reached. A relatively small YAML document can the= refore cause prolonged CPU consumption in applications that parse untrusted=
YAML, and merge processing is enabled by default on these release lines. T= his issue is fixed in versions 3.15.2 and 4.3.2. 2026-09-01 7.5 CVE-2026-84= 375 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84375 ] nodemailer--nodem= ailer Nodemailer before 8.0.4 is vulnerable to SMTP command injection throu=
gh the unsanitized envelope.size parameter. When an application passes a cu= stom envelope object with a size property containing CRLF characters to sen= dMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE= =3D...) without sanitization, allowing injection of arbitrary SMTP commands=
such as RCPT TO to silently add attacker-controlled recipients. Exploitati=
on requires the application to expose the envelope size to attacker-control= led input, as Nodemailer does not include size in the default auto-construc= ted envelope. 2026-08-31 9.8 CVE-2026-82854 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-82854 ] nodemailer--nodemailer nodemailer before 9.0.1 fails=
to apply disableFileAccess and disableUrlAccess flags to message-level raw=
option, allowing authenticated attackers to read arbitrary files or perfor=
m server-side request forgery by supplying path or href properties. Attacke=
rs can exploit this by crafting raw messages with file paths or URLs that b= ypass the intended sandbox, with fetched content delivered in the outgoing = message to attacker-controlled recipients. 2026-08-31 7.1 CVE-2026-82659 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-82659 ] Nokia--WaveSuite WaveSu= ite is affected by an insufficient role-based access control vulnerability =
in the CPB Log Files feature. Successful exploitation allows an authenticat=
ed low-privilege user to load pages restricted to higher-privilege roles by=
requesting the corresponding URL directly in the browser. 2026-08-31 7.6 C= VE-2026-40463 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40463 ] NousRes= earch--hermes-agent Hermes Agent 0.18.2 through 0.21.0, fixed in commit f62= 34d0, contains a remote code execution vulnerability that allows attackers =
to execute arbitrary OS commands by supplying a malicious repository with a=
crafted .git/config that sets core.fsmonitor to an attacker-controlled com= mand. When a user opens the malicious repository and sends any message, the=
agent triggers a git status index refresh which executes the injected comm= and in the user's process context, exposing the full environment including = configured provider API keys. 2026-09-03 8.8 CVE-2026-71963 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-71963 ] NousResearch--hermes-agent A flaw ha=
s been found in NousResearch hermes-agent 0.18.0. Affected by this issue is=
the function _sess_nowait of the file s71.py of the component Session Mana= gement. This manipulation of the argument session_id causes authorization b= ypass. The attack can be initiated remotely. The vendor was contacted early=
about this disclosure but did not respond in any way. 2026-09-03 7.3 CVE-2= 026-85105 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85105 ] NSquared--S= imply Schedule Appointments Unauthenticated Cross Site Request Forgery (CSR=
F) in Simply Schedule Appointments <=3D 1.6.12.23 versions. 2026-09-02 8.8 = CVE-2026-84764 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84764 ] ntop -= -nDPI=C2=A0
=C2=A0 ntop nDPI versions before 6.0 contain a heap buffer overflow vulnera= bility in the ndpi_json_string_escape function that writes beyond caller-su= pplied buffer boundaries. Attackers can trigger the overflow by supplying c= rafted network packet data including TLS SNI, HTTP headers, or DNS names th=
at reach the vulnerable function, causing heap corruption. 2026-09-04 7.4 C= VE-2026-86098 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86098 ] ntop--n= topng ntopng is a web-based network traffic monitoring application. In vers= ions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's t= ag/badge feature - `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/re= st/v2/edit/tag/tag.lua` - perform no authorization check at all. Any authen= ticated user, including a non-administrator ("unprivileged") account, can d= elete or rename any tag in the system, including tags created by an adminis= trator. Version 6.7.260718 contains a fix. 2026-09-03 7.1 CVE-2026-84989 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84989 ] ntopng--ntopng
=C2=A0 ntopng before 6.7.260717 fails to check user privileges in the pools=
bulk-delete endpoint, allowing authenticated non-administrators to delete = all host pools and member bindings. Attackers can issue POST requests to th=
e delete pools endpoint to irreversibly destroy every host pool, removing t= raffic policy bindings and visibility restrictions that may bypass security=
policies. 2026-09-04 7.1 CVE-2026-86091 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-86091 ] ntopng--ntopng=C2=A0
=C2=A0 ntopng before 6.7.260717 fails to perform authorization checks in th=
e delete endpoints and recipients REST v2 handlers. Authenticated non-admin= istrator users can issue POST requests to irreversibly delete all configure=
d notification endpoints and recipients, silencing all alerts. 2026-09-04 7=
.1 CVE-2026-86090 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86090 ] nuc= lio--nuclio Nuclio is a "Serverless" framework for Real-Time Events and Dat=
a Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio D= ashboard's project management API, allowing any authenticated user (without=
membership in the target project) to bypass OPA authorization checks on wr= ite paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or dele=
te any project along with all its associated resources (functions, API gate= ways, etc.). This issue has been patched in version 1.16.0. 2026-09-02 8.3 = CVE-2026-45730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-45730 ] nuclio= --nuclio Nuclio is a "Serverless" framework for Real-Time Events and Data P= rocessing. Prior to version 1.16.4, the Nuclio controller builds a curl inv= ocation string for each cron trigger and stores it as the args of a Kuberne= tes CronJob container (/bin/sh, -c, <command>). Two fields in the trigger s= pecification flow into this string without adequate sanitization: event.hea= ders keys and event.body. This issue has been patched in version 1.16.4. 20= 26-09-02 8 CVE-2026-52831 [
https://www.cve.org/CVERecord?id=3DCVE-2026-528=
31 ] nuclio--nuclio Nuclio is a "Serverless" framework for Real-Time Events=
and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime genera= tes a build.gradle file during function builds using Go's text/template pac= kage. The template renders runtimeAttributes.repositories[] values with the=
{{ . }} action, which performs no escaping. An attacker can embed a closin=
g brace (}) to break out of the repositories {} block and append arbitrary = Groovy statements that execute unconditionally during the Gradle configurat= ion phase. This issue has been patched in version 1.16.5. 2026-09-02 8 CVE-= 2026-52833 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52833 ] nuclio--nu= clio Nuclio is a "Serverless" framework for Real-Time Events and Data Proce= ssing. Prior to version 1.17.4, on the Nuclio local Docker platform, the fu= nction namespace is interpolated-unvalidated-into a double-quoted docker ps=
--filter "label=3Dnuclio.io/namespace=3D<value>" command that is executed = via the host shell (/bin/sh -c). Because the default auth kind is nop (unau= thenticated), a remote attacker can inject arbitrary OS commands that run a=
s root inside the dashboard container, which holds the Docker socket =C3=A2= =E2=80=A0=E2=80=99 host compromise. This issue has been patched in version = 1.17.4. 2026-09-02 8 CVE-2026-79755 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-79755 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contai=
ns a vulnerability where an attacker could cause a deserialization of untru= sted data. A successful exploit of this vulnerability might lead to code ex= ecution, data tampering, and information disclosure. 2026-09-01 7.8 CVE-202= 6-61750 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61750 ] nvidia -- nem= o_megatron_bridge NVIDIA Megatron Bridge contains a vulnerability where an = attacker could cause a deserialization of untrusted data. A successful expl= oit of this vulnerability might lead to code execution, data tampering, and=
information disclosure. 2026-09-01 7.8 CVE-2026-61751 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-61751 ] nvidia -- nemo_megatron_bridge NVIDIA Meg= atron Bridge contains a vulnerability where an attacker could cause a deser= ialization of untrusted data. A successful exploit of this vulnerability mi= ght lead to code execution, data tampering, and information disclosure. 202= 6-09-01 7.8 CVE-2026-61752 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61= 752 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vuln= erability where an attacker could cause a deserialization of untrusted data=
. A successful exploit of this vulnerability might lead to code execution, = data tampering, and information disclosure. 2026-09-01 7.8 CVE-2026-61753 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-61753 ] nvidia -- nemo_megatro= n_bridge NVIDIA Megatron Bridge contains a vulnerability where an attacker = could cause a deserialization of untrusted data. A successful exploit of th=
is vulnerability might lead to code execution, data tampering, and informat= ion disclosure. 2026-09-01 7.8 CVE-2026-61754 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-61754 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bri= dge contains a vulnerability where an attacker could cause a deserializatio=
n of untrusted data. A successful exploit of this vulnerability might lead =
to code execution, data tampering, and information disclosure. 2026-09-01 7=
.8 CVE-2026-61755 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61755 ] nvi= dia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerability=
where an attacker could cause a deserialization of untrusted data. A succe= ssful exploit of this vulnerability might lead to code execution, data tamp= ering, and information disclosure. 2026-09-01 7.8 CVE-2026-61756 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-61756 ] nvidia -- nemo_megatron_bridge = NVIDIA Megatron Bridge contains a vulnerability where an attacker could cau=
se a deserialization of untrusted data. A successful exploit of this vulner= ability might lead to code execution, data tampering, and information discl= osure. 2026-09-01 7.8 CVE-2026-61757 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-61757 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge conta= ins a vulnerability where an attacker could cause a deserialization of untr= usted data. A successful exploit of this vulnerability might lead to code e= xecution, data tampering, and information disclosure. 2026-09-01 7.8 CVE-20= 26-61758 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61758 ] nvidia -- ne= mo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerability where an=
attacker could cause a deserialization of untrusted data. A successful exp= loit of this vulnerability might lead to code execution, data tampering, an=
d information disclosure. 2026-09-01 7.8 CVE-2026-61759 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-61759 ] nvidia -- nemo_megatron_bridge NVIDIA Me= gatron Bridge contains a vulnerability where an attacker could cause a dese= rialization of untrusted data. A successful exploit of this vulnerability m= ight lead to code execution, data tampering, and information disclosure. 20= 26-09-01 7.8 CVE-2026-61760 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6= 1760 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vul= nerability where an attacker could cause a deserialization of untrusted dat=
a. A successful exploit of this vulnerability might lead to code execution,=
data tampering, and information disclosure. 2026-09-01 7.8 CVE-2026-61761 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-61761 ] nvidia -- nemo_megatr= on_bridge NVIDIA Megatron Bridge contains a vulnerability where an attacker=
could cause a deserialization of untrusted data. A successful exploit of t= his vulnerability might lead to code execution, data tampering, and informa= tion disclosure. 2026-09-01 7.8 CVE-2026-61762 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-61762 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Br= idge contains a vulnerability where an attacker could cause a deserializati=
on of untrusted data. A successful exploit of this vulnerability might lead=
to code execution, data tampering, and information disclosure. 2026-09-01 = 7.8 CVE-2026-61763 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61763 ] nv= idia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerabilit=
y where an attacker could cause a deserialization of untrusted data. A succ= essful exploit of this vulnerability might lead to code execution, data tam= pering, and information disclosure. 2026-09-01 7.8 CVE-2026-61764 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-61764 ] nvidia -- nemo_megatron_bridge=
NVIDIA Megatron Bridge contains a vulnerability where an attacker could ca= use a deserialization of untrusted data. A successful exploit of this vulne= rability might lead to code execution, data tampering, and information disc= losure. 2026-09-01 7.8 CVE-2026-61765 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-61765 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge cont= ains a vulnerability where an attacker could cause a deserialization of unt= rusted data. A successful exploit of this vulnerability might lead to code = execution, data tampering, and information disclosure. 2026-09-01 7.8 CVE-2= 026-61766 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61766 ] nvidia -- n= emo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerability where a=
n attacker could cause a deserialization of untrusted data. A successful ex= ploit of this vulnerability might lead to code execution, data tampering, a=
nd information disclosure. 2026-09-01 7.8 CVE-2026-61767 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-61767 ] nvidia -- nemo_megatron_bridge NVIDIA M= egatron Bridge contains a vulnerability where an attacker could cause a des= erialization of untrusted data. A successful exploit of this vulnerability = might lead to code execution, data tampering, and information disclosure. 2= 026-09-01 7.8 CVE-2026-61768 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 61768 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vu= lnerability where an attacker could cause a deserialization of untrusted da= ta. A successful exploit of this vulnerability might lead to code execution=
, data tampering, and information disclosure. 2026-09-01 7.8 CVE-2026-61769=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-61769 ] nvidia -- nemo_megat= ron_bridge NVIDIA Megatron Bridge contains a vulnerability where an attacke=
r could cause a deserialization of untrusted data. A successful exploit of = this vulnerability might lead to code execution, data tampering, and inform= ation disclosure. 2026-09-01 7.8 CVE-2026-61770 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-61770 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron B= ridge contains a vulnerability where an attacker could cause a deserializat= ion of untrusted data. A successful exploit of this vulnerability might lea=
d to code execution, data tampering, and information disclosure. 2026-09-01=
7.8 CVE-2026-61771 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61771 ] n= vidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerabili=
ty where an attacker could cause a deserialization of untrusted data. A suc= cessful exploit of this vulnerability might lead to code execution, data ta= mpering, and information disclosure. 2026-09-01 7.8 CVE-2026-61772 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-61772 ] nvidia -- nemo_megatron_bridg=
e NVIDIA Megatron Bridge contains a vulnerability where an attacker could c= ause a deserialization of untrusted data. A successful exploit of this vuln= erability might lead to code execution, data tampering, and information dis= closure. 2026-09-01 7.8 CVE-2026-61773 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-61773 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge c= ontains a vulnerability where an attacker could cause a deserialization of = untrusted data. A successful exploit of this vulnerability might lead to co=
de execution, data tampering, and information disclosure. 2026-09-01 7.8 CV= E-2026-61774 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61774 ] nvidia -=
- nemo_megatron_bridge NVIDIA Megatron Bridge contains a vulnerability wher=
e an attacker could cause a deserialization of untrusted data. A successful=
exploit of this vulnerability might lead to code execution, data tampering=
, and information disclosure. 2026-09-01 7.8 CVE-2026-61775 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-61775 ] nvidia -- nemo_megatron_bridge NVIDI=
A Megatron Bridge contains a vulnerability where an attacker could cause a = deserialization of untrusted data. A successful exploit of this vulnerabili=
ty might lead to code execution, data tampering, and information disclosure=
. 2026-09-01 7.8 CVE-2026-61776 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-61776 ] nvidia -- nemo_megatron_bridge NVIDIA Megatron Bridge contains a=
vulnerability where an attacker could cause a deserialization of untrusted=
data. A successful exploit of this vulnerability might lead to code execut= ion, data tampering, and information disclosure. 2026-09-01 7.8 CVE-2026-61= 777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61777 ] nvidia -- nemo_me= gatron_bridge NVIDIA Megatron Bridge contains a vulnerability where an atta= cker could cause a deserialization of untrusted data. A successful exploit =
of this vulnerability might lead to code execution, data tampering, and inf= ormation disclosure. 2026-09-01 7.8 CVE-2026-61778 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-61778 ] nvidia -- nemo_megatron_bridge NVIDIA Megatro=
n Bridge contains a vulnerability where an attacker could cause a deseriali= zation of untrusted data. A successful exploit of this vulnerability might = lead to code execution, data tampering, and information disclosure. 2026-09= -01 7.8 CVE-2026-61779 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61779 =
] OAuth Single Sign On--OAuth Single Sign On The OAuth Single Sign On WordP= ress plugin before 7.0.1 does not verify the identity assertion returned by=
its Steam single sign-on flow, allowing unauthenticated attackers to log i=
n as an arbitrary non-administrator user, and to create new accounts. 2026-= 09-02 8.1 CVE-2026-82183 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8218=
3 ] ogx-ai--ogx OGX (formerly Llama Stack, affected at commit fbe8e0f) cont= ains an unauthenticated server-side request forgery vulnerability in the Op= enAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a = server_url parameter (along with headers and authorization values) that is = fetched server-side without destination validation; the existing validate_u= rl_not_private() guard used for other URL inputs is not applied to server_u= rl. On the default starter configuration, which runs without authentication=
, a remote unauthenticated attacker can cause the server to open connection=
s to arbitrary internal addresses (including cloud metadata endpoints such =
as
http://169.254.169.254/) and forward attacker-supplied headers and beare=
r tokens to those destinations. 2026-09-04 7.5 CVE-2026-85666 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85666 ] OHF-Voice--wyoming Wyoming before = 1.10.2 contains a server-side request forgery vulnerability that allows una= uthenticated attackers with network access to force outbound connections to=
arbitrary targets by supplying a malicious `uri` query parameter to the HT=
TP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected=
endpoints including /api/info, /api/speech-to-text, and /api/text-to-speec=
h to override the server-configured backend and redirect connections to att= acker-chosen hosts. 2026-09-01 8.3 CVE-2026-8712 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-8712 ] ollama--ollama Ollama fails to validate redirect=
destinations when pulling tensor-layer models, allowing unauthenticated at= tackers to redirect blob downloads to arbitrary hosts. An attacker can cont= rol a registry, serve a malicious tensor-layer manifest, and cause the serv=
er to issue GET requests to internal hosts including cloud metadata endpoin= ts. 2026-09-03 7.5 CVE-2026-85180 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-85180 ] OpenAI--Codex CLI OpenAI Codex CLI for Windows, macOS, and Lin=
ux and Codex Desktop for Windows and macOS misclassified certain PowerShell=
commands as safe because their command-safety parser interpreted PowerShel= l's stop-parsing token (--%) differently than PowerShell itself. If a user = opens an attacker-prepared repository and Codex follows its instructions, C= odex can run a file-writing Git command without requesting user approval. O=
n macOS and Linux, exploitation additionally requires separately installed = PowerShell Core (pwsh) to be invoked. If filesystem protections permit the = write, the command can modify Codex's configuration. If Codex later loads t=
he modified configuration, it can launch an attacker-controlled MCP server = and execute code with the user's privileges, allowing it to read, change, o=
r delete files accessible to that account. The approval bypass does not dis= able filesystem sandboxing; the default filesystem sandbox on macOS and Lin=
ux can prevent writes outside permitted locations. 2026-09-01 8.8 CVE-2026-= 19591 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19591 ] OpenAI--Codex C=
LI OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Win= dows and macOS automatically collected Git repository metadata without disa= bling the repository-local core.fsmonitor setting. If a user opens or uses =
an attacker-prepared repository whose preserved .git/config sets core.fsmon= itor to an attacker-controlled filesystem-monitor helper, Git can execute t= hat helper while Codex collects repository metadata. The helper runs outsid=
e Codex's command sandbox and without a user-approval prompt, allowing atta= cker-controlled code to run with the user's privileges. The code can read, = change, or delete the user's files and access other resources available to = the user's account. An ordinary Git clone does not preserve the source repo= sitory's local .git/config; exploitation requires a repository delivered or=
copied with that configuration intact. 2026-09-01 7.3 CVE-2026-19592 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-19592 ] OpenAI--Codex Desktop Open=
AI Codex Desktop for Windows and macOS automatically inspected Git metadata=
and working-tree status when a user opened a workspace. If the workspace c= ontains a repository with preserved attacker-controlled .git/config, the at= tr.tree setting and a configured clean or process filter can cause Git to r=
un an attacker-controlled program. The program runs outside Codex's command=
sandbox with the signed-in user's privileges, without a workspace-trust pr= ompt, command approval, or interaction with a model. The attacker can read,=
modify, or delete files and access credentials available to that user. Exp= loitation requires Git to be available on PATH and the user to open the att= acker-prepared repository with its local Git configuration intact. An ordin= ary Git clone does not copy the source repository's .git/config and is not = sufficient by itself. 2026-09-01 9.8 CVE-2026-19593 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-19593 ] OpenAI--Codex Desktop OpenAI Codex Desktop f=
or Windows and macOS could execute attacker-controlled Git hooks because au= tomated Git operations trusted the repository's local core.hooksPath settin=
g. If a user opens an attacker-prepared repository whose preserved .git/con= fig points core.hooksPath to an attacker-controlled directory, Codex can ru=
n a malicious hook while processing the repository. The hook executes outsi=
de Codex's command sandbox, without user approval, and with the user's priv= ileges, allowing it to read, change, or delete the user's files and access = other resources available to the user's account. An ordinary Git clone does=
not preserve the attacker-controlled repository-local configuration requir=
ed for exploitation. 2026-09-01 7.3 CVE-2026-19590 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-19590 ] OpenAtomFoundation--pikiwidb PikiwiDB (Pika) = v3.5.7 exposes an internal protobuf replication server on a port derived fr=
om the client port plus 2000 (e.g. 11221 when the default client port 9221 =
is used) that does not authenticate incoming requests. Although requirepass=
is intended to gate replication - a slave presents it as masterauth inside=
its MetaSync request - only the MetaSync handler (HandleMetaSyncRequest) v= alidates it; the frame dispatcher (DealMessage) does not require a complete=
d or attempted MetaSync before routing other message types to their handler=
s. As a result, an unauthenticated remote attacker can connect directly to = the replication port and issue TrySync, DBSync, BinlogSync, and RemoveSlave= Node requests, obtaining the full-sync snapshot and live write stream and r= emoving replica nodes, even when requirepass is configured. 2026-09-02 8.6 = CVE-2026-84700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84700 ] opened= x--openedx-platform Open edX Platform enables the authoring and delivery of=
online learning at any scale. Prior to commit 59bb6d6, the view function s= et_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashbo= ard.py:430 is decorated only with @login_required and performs no course-le= vel permission check. Any authenticated user - including a learner account = with zero course roles - can issue a single POST request to overwrite the h= onor mode price and currency of any course on the platform. The companion f= rontend modal was removed in a prior cleanup, but the URL route and view re= main live, making this an unguarded orphan endpoint. This issue has been pa= tched via commit 59bb6d6. 2026-09-02 7.6 CVE-2026-53635 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-53635 ] openjsf -- fast-uri fast-uri serializes = the port component of a URI without validating it. When recomposing the aut= hority, the userinfo and host components are escaped but the port is concat= enated verbatim, so a port value that is not a sequence of digits can injec=
t authority delimiters, demoting the intended host to userinfo and pointing=
the authority at an attacker-controlled host. Both fast-uri and Node's URL=
read the result back as the attacker's host with no error, so re-validatin=
g the built URI does not catch it. This affects applications that build URI=
s from parts and assign untrusted data to the port component through the se= rialize, normalize, or equal functions in their object forms. The issue aff= ects fast-uri versions before 2.4.6, from 3.0.0 before 3.1.7, and from 4.0.=
0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.1.4, where recomposeAuth= ority rejects any port that is not a digit sequence per RFC 3986. 2026-09-0=
2 7.5 CVE-2026-84292 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84292 ] = openjsf -- fast-uri fast-uri accepts a host that contains an unbalanced or = misplaced authority bracket without reporting an error. A host that starts = with an opening bracket but does not end with a closing bracket is neither = validated as an IP literal nor canonicalized as a domain name, so parse() r= eturns it as the host with error undefined, while Node's URL and the HTTP c= lients built on it resolve the same string to a different host. An applicat= ion that reads the parsed host to make a host decision, such as an SSRF den= ylist, a redirect allowlist, or proxy routing, and then passes the original=
URL to an HTTP client evaluates its policy against a string that is not th=
e host the request reaches. The same host is carried through normalize, equ= al, and resolve. This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, an=
d is fixed in 2.4.6, 3.1.7, and 4.1.4, where parse() reports a malformed ho=
st for any host that contains a bracket but is not a valid IPv6 literal. 20= 26-09-03 7.5 CVE-2026-84394 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 4394 ] OpenMAIC --OpenMAIC=C2=A0
=C2=A0 OpenMAIC before 1.0.1 skips server-side request forgery validation i=
n non-production builds, allowing unauthenticated attackers to reach cloud = instance metadata services. Attackers can supply arbitrary provider URLs vi=
a the x-base-url header or baseUrl parameter to access sensitive cloud cred= entials and metadata. 2026-09-06 7.5 CVE-2026-86259 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-86259 ] Openpanel-dev--openpanel OpenPanel before 2.= 3.0 fails to properly validate chart formula expressions, allowing authenti= cated project members with read access to execute arbitrary code by recover= ing the native JavaScript Function constructor through mathjs matrix object=
s. Attackers can use the recovered constructor to load Node.js built-ins an=
d execute operating system commands with the privileges of the API process,=
bypassing organization authorization boundaries. 2026-09-04 8.8 CVE-2026-8= 5610 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85610 ] Openpanel-dev--o= penpanel OpenPanel before 2.3.0 contains a cross-site scripting vulnerabili=
ty in the unauthenticated favicon proxy endpoint GET /misc/favicon that all= ows remote attackers to execute scripts by supplying an SVG file URL. Attac= kers can host malicious SVG files with embedded scripts that execute in the=
victim's browser on the API origin, enabling same-origin credentialed requ= ests to authenticated endpoints. 2026-09-04 8.2 CVE-2026-85613 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85613 ] Openpanel-dev--openpanel OpenPane=
l before 2.3.0 contains an unauthenticated server-side request forgery vuln= erability in the GET /tools/site-checker endpoint that accepts a fully clie= nt-controlled URL parameter with no private IP filtering or DNS-rebinding p= rotection. Attackers can make the OpenPanel server issue requests to intern=
al services, localhost, and cloud metadata endpoints, reading internal HTTP=
response titles, headers, status codes, and SSL certificate information. 2= 026-09-04 8.6 CVE-2026-85614 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 85614 ] Openpanel-dev--openpanel Openpanel before 2.3.0 contains an unauthe= nticated full-read server-side request forgery (SSRF) vulnerability in the = GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller= .ts). The endpoint passes a user-supplied url query parameter to fetchWithR= edirects() and performs server-side HTTP requests to arbitrary URLs without=
any SSRF/IP validation. An unauthenticated remote attacker can access clou=
d instance metadata endpoints, probe internal services, scan internal netwo=
rk ports, and read returned content (status code, page size, timing, and pa= rsed HTML metadata), and leak internal IP addresses (via getIPInfo() to a t= hird party). 2026-09-04 7.5 CVE-2026-85609 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-85609 ] Openpanel-dev--openpanel OpenPanel before 2.3.0 conta= ins an unauthenticated server-side request forgery vulnerability in the /mi= sc/favicon and /misc/og endpoints that accept an attacker-supplied url para= meter with insufficient validation. Attackers can force the API to fetch ar= bitrary internal hosts and cloud metadata endpoints, with small responses r= eturned verbatim enabling credential theft and internal service enumeration=
. 2026-09-04 7.5 CVE-2026-85612 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-85612 ] OpenSearch--OpenSearch Unrestricted deserialization of untrusted=
data in the cursor pagination component in the OpenSearch SQL plugin allow=
s a remote authenticated user with basic read/search permissions to execute=
arbitrary code on the server by sending a crafted cursor parameter to the = plugins/sql endpoint. 2026-08-31 8.8 CVE-2026-83497 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-83497 ] OpenTalker--SadTalker SadTalker contains an =
OS command injection vulnerability in the video muxing process where upload=
ed audio filenames are interpolated into ffmpeg commands without proper esc= aping. Attackers can upload audio files with shell metacharacters in the fi= lename to break out of quoted arguments and execute arbitrary system comman=
ds when video generation occurs. 2026-09-04 9.8 CVE-2026-85696 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85696 ] Oxford Nanopore--MinKNOW Oxford N= anopore MinKNOW before 24.06 relies on a client's source IP address for aut= hentication. 2026-09-02 8.6 CVE-2024-35585 [
https://www.cve.org/CVERecord?= id=3DCVE-2024-35585 ] Pangolin--Pangolin Pangolin before 1.22.0 contains an=
authentication bypass vulnerability that allows unauthenticated attackers =
to access any protected resource by supplying an attacker-controlled URL pa= rameter to the share-link authentication endpoint that omits the expected r= esource identifier from the token verification call. Attackers holding a si= ngle valid share link for any resource can authenticate against arbitrary r= esources across different organizations, bypassing all configured authentic= ation methods including SSO, resource passwords, PIN codes, email allowlist=
s, and header authentication. 2026-08-31 8.1 CVE-2026-72001 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-72001 ] Paolo--GeoDirectory Unauthenticated = SQL Injection in GeoDirectory <=3D 2.8.174 versions. 2026-09-03 9.3 CVE-202= 6-84813 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84813 ] Parrot--AR.Dr= one
=C2=A0 Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism=
to prevent denial-of-service (DoS) attacks. An attacker can harm the devic=
e availability (i.e., video streaming and control) by using tool to perform=
an IPv4 flood attack. Verified attacks includes SYN flooding and UDP flood= ing. 2026-09-04 7.5 CVE-2021-44320 [
https://www.cve.org/CVERecord?id=3DCVE= -2021-44320 ] Passionate Programmer Peter--WP Data Access Unauthenticated S=
QL Injection in WP Data Access <=3D 5.5.81 versions. 2026-08-31 9.3 CVE-202= 6-81293 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81293 ] PassMark --Pe= rformanceTest PassMark PerformanceTest before 11.1 build 1012, BurnInTest b= efore 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a pri= vilege escalation vulnerability in DirectIo64.sys that allows local users t=
o clear arbitrary bits at any physical memory address due to missing valida= tion of the physical address parameter in an exposed IOCTL handler. Attacke=
rs can obtain a device handle and supply an arbitrary 64-bit physical addre=
ss with a bit index to invoke MmMapIoSpace and clear bits in kernel code pa= ges or page table entries, enabling local privilege escalation or system co= mpromise. 2026-09-04 7.1 CVE-2026-80113 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80113 ] PassMark --PerformanceTest
=C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper = access control vulnerability in the DirectIo64.sys kernel driver that allow=
s unprivileged local users to perform privileged hardware operations by ope= ning a handle to the device object created without a security descriptor. A= ttackers can issue IOCTLs through the permissive default Windows ACL applie=
d to the device to access restricted hardware operations regardless of priv= ilege or integrity level. 2026-09-04 7.8 CVE-2026-80112 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-80112 ] PassMark --PerformanceTest
=C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded=
credentials vulnerability in DirectIo64.sys that allows local attackers to=
perform arbitrary physical memory writes by extracting an 8-byte key embed= ded as a hardcoded literal in the distributed binary and computing valid MD=
5 authentication tags for arbitrary IOCTL write requests. Attackers can add= itionally bypass a secondary validation gate by using the driver's own bit-= clear IOCTL to clear a single bit in the gating instruction's displacement = byte, causing all subsequent write requests to skip MAC verification, size = checks, and Vendor ID checks entirely. 2026-09-04 7.8 CVE-2026-80114 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-80114 ] PassMark --PerformanceTest =C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege = escalation vulnerability in DirectIo64.sys that allows local users to modif=
y hardware configuration by exploiting exposed IOCTLs with no validation on=
device selection, register offset, or value. Attackers can obtain a device=
handle and issue arbitrary PCI configuration space read/write operations t=
o enable Bus Master DMA on any PCI device, halt storage controller I/O by c= learing command registers, or remap Base Address Registers to redirect DMA =
to an attacker-chosen physical address. 2026-09-04 7.8 CVE-2026-80116 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-80116 ] PassMark --PerformanceTest =C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege = escalation vulnerability in DirectIo64.sys that allows local users to issue=
arbitrary IN and OUT instructions to any x86 I/O port due to missing allow= list or port validation on exposed IOCTLs. Attackers can obtain a device ha= ndle and write to sensitive ports including the PS/2 controller port, CPU r= eset ports, CMOS configuration ports, and interrupt controller ports to cau=
se an immediate system reset or other hardware-level manipulation from a st= andard user account. 2026-09-04 7.1 CVE-2026-80117 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-80117 ] PassMark --PerformanceTest
=C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthent= icated physical memory disclosure in DirectIo64.sys, reachable by unprivile= ged local users through a single IOCTL with no caller-identity check. The h= andler writes a crash-dump-format (PAGEDU64) image of all physical memory t=
o a caller-supplied file path in the SYSTEM context, allowing a standard us=
er to create files in locations they cannot otherwise write and to recover = memory belonging to processes of other users. The image is preceded by a he= ader that exposes the kernel loaded-module list, active-process list and PF=
N database pointers, defeating KASLR. The same handler also dereferences th=
e return value of an internal kernel-structure locator without a NULL check=
; that locator returns NULL on three distinct failure paths, and a kernel c= rash results on builds where any of those paths is taken. 2026-09-04 7.1 CV= E-2026-80118 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80118 ] PassMark=
--PerformanceTest
=C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain an informati=
on disclosure vulnerability in DirectIo64.sys that allows unauthenticated l= ocal attackers to dump complete physical memory contents by supplying a cal= ler-controlled file path to an exposed IOCTL. Attackers can issue a single = IOCTL call to trigger the driver to iterate all physical memory ranges via = MmGetPhysicalMemoryRanges and map each page through ZwMapViewOfSection on t=
he PhysicalMemory section object, writing a full RAM image to an attacker-s= pecified path in the SYSTEM context, bypassing user-mode ACLs and exposing = LSASS working set, process memory, and cryptographic material from all runn= ing processes. 2026-09-04 7.8 CVE-2026-80119 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-80119 ] Paul Ryan--Authorizer Unauthenticated Privilege Esc= alation in Authorizer <=3D 3.15.1 versions. 2026-09-02 9.8 CVE-2026-81294 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-81294 ] PCRE2 --PCRE2=C2=A0
=C2=A0 PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write beca= use reuse of a cached workspace block, in a recursive DFA matching workspac=
e, lacks a size check (even though a newly allocated block, for the same pu= rpose, does have a size check). This outcome requires an attacker-controlle=
d regular expression, or a recursive pattern in conjunction with a small he=
ap limit (this can be set through the API). 2026-09-05 8.2 CVE-2026-86145 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-86145 ] Peppermint-Lab--pepper= mint Peppermint through 0.5.5 contains a hardcoded JWT signing secret in do= cker-compose.yml that allows unauthenticated attackers to forge session tok= ens for any account. Attackers can use the published secret to mint valid t= okens for arbitrary user IDs and access protected endpoints without credent= ials. 2026-09-03 9.8 CVE-2026-85391 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-85391 ] Phison Electronics Corporation--PS3111-S11 Controller Firmwa=
re Phison PS3111-S11 controller firmware verifies RSA signatures using a pu= blic modulus embedded within the firmware image itself rather than anchored=
in immutable storage. Attackers can generate arbitrary RSA key pairs, sign=
modified firmware with the private key, embed the matching modulus in the = signature segment, and the controller accepts the tampered firmware as vali=
d. 2026-08-31 8.2 CVE-2026-82876 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-82876 ] Phison Electronics Corporation--PS3111-S11 Controller Firmware = Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose priv= ileged vendor unique commands over the ATA interface with absent or defeata= ble authentication mechanisms. Attackers can bypass the weak CRC-16 based u= nlock handshake or exploit builds with no VUC lock to read and write contro= ller memory and raw flash, persisting implants across power cycles. 2026-09= -02 8.2 CVE-2026-84696 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84696 =
] Photo Gallery by 10Web--Photo Gallery by 10Web The Photo Gallery by 10Web=
WordPress plugin before 1.8.44 does not escape two request parameters befo=
re reflecting them into input-attribute values on its admin pages (one on t=
he Shortcode page, one on the Galleries/Albums list page), so an unauthenti= cated attacker can craft a link that, when opened by a logged-in administra= tor (or, for the first sink, a contributor), executes arbitrary JavaScript =
in the victim's authenticated session via an auto-firing onfocus handler. T=
he Galleries/Albums sink renders only when the site has more than 20 galler= ies/albums (the normal state of a populated install). 2026-09-02 7.1 CVE-20= 26-12865 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12865 ] Piwigo--Piwi=
go A security vulnerability has been detected in Piwigo up to 16.3.0. Affec= ted by this issue is some unknown functionality of the file i.php of the co= mponent Image Derivative Handler. The manipulation leads to path traversal.=
Remote exploitation of the attack is possible. The exploit has been disclo= sed publicly and may be used. 2026-09-02 7.3 CVE-2026-84441 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-84441 ] pixarlabs--Master Addons for Element=
or Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Buil= der & Template Kits The Master Addons for Elementor - Elementor Addons, Wid= gets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plug=
in for WordPress is vulnerable to Arbitrary File Upload in all versions up = to, and including, 3.1.9 via the upload_template_kit function. This is due =
to incorrect authorization on the upload_template_kit() AJAX handler, which=
requires only upload_files capability instead of the manage_options requir=
ed by all sibling handlers, combined with missing per-entry file type filte= ring after ZIP extraction. This makes it possible for authenticated attacke= rs, with editor-level access and above, to upload files that may be executa= ble, which makes remote code execution possible. Editors can satisfy the no= nce requirement because the required nonces are localized on the standard P= ages list screen, which is accessible to any user with the edit_pages capab= ility. 2026-09-01 7.2 CVE-2026-75921 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-75921 ] plandex-ai--plandex Plandex 2.2.1 contains a path traversal=
vulnerability in the ApplyFiles function that allows attackers to write fi= les outside the project directory. Attackers can influence model output thr= ough poisoned repository files or attacker-controlled context to write to a= rbitrary locations like shell rc or cron files, achieving code execution. 2= 026-09-04 7.8 CVE-2026-85690 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 85690 ] pnpm--pnpm pnpm is a package manager. Prior to 10.34.5 and from 11.= 0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pn= pm-lock.yaml packages keys with dp.parse(depPath).name and uses it without = validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/= graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules=
, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/i= ndex.ts, allowing package contents to be written outside node_modules when =
a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allo= wBuilds entry permits lifecycle scripts, the escaped package can execute co=
de with the user's privileges. This issue is fixed in versions 10.34.5 and = 11.11.0. 2026-08-31 7.1 CVE-2026-82392 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82392 ] pnpm--pnpm pnpm is a package manager. Prior to 10.34.5 = and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's=
package.json manifest name because pnpm11/resolving/npm-resolver/src/pickP= ackage.ts rejects slash characters only for unscoped names. During pnpm ins= tall, the unvalidated name reaches raw path joins in pnpm11/installing/deps= -resolver/src/resolvePeers.ts, pnpm11/installing/deps-resolver/src/index.ts=
, and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts, causing package = extraction outside node_modules and allowing attacker-controlled files to o= verwrite arbitrary filesystem paths even when --ignore-scripts is used. The=
overwrite can replace shell startup files, Git hooks, or installed package=
code and lead to code execution. This issue is fixed in versions 10.34.5, = and 11.11.0. 2026-08-31 7.5 CVE-2026-82393 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-82393 ] PocketMine-MP--PocketMine-MP
=C2=A0 PocketMine-MP before 4.7.2 fails to properly handle exceptions from = the adhocore/json-comment library when parsing skin geometry data. Attacker=
s can send login or skin packets with invalid geometry JSON to trigger an u= nhandled RuntimeException, causing server crash. 2026-09-06 7.5 CVE-2022-51= 009 [
https://www.cve.org/CVERecord?id=3DCVE-2022-51009 ] PostgreSQL-- Anon= ymizer
=C2=A0 PostgreSQL Anonymizer contains a vulnerability that allows unprivile= ged masked users to execute arbitrary code by abusing operators, domain cas= ts, or view subqueries that carry untrusted expressions. When these objects=
are evaluated in the context of the extension's masking mechanisms, the ma= licious code can run with elevated privileges. The issue is fixed in Postgr= eSQL Anonymizer 3.1.4 and later versions 2026-09-06 8.8 CVE-2026-19633 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-19633 ] PowerJob--PowerJob A vuln= erability was identified in PowerJob up to 5.1.2. Impacted is the function = MuConnectionManager.getOrCreateConnection of the file powerjob-server/power= job-server-starter/src/main/java/tech/powerjob/server/web/controller/TestCo= ntroller.java of the component Transport Endpoint. The manipulation leads t=
o server-side request forgery. The attack is possible to be carried out rem= otely. The exploit is publicly available and might be used. The project was=
informed of the problem early through an issue report but has not responde=
d yet. 2026-08-31 7.3 CVE-2026-82630 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-82630 ] PowerJob--Worker v5.1.2 PowerJob Worker version 5.1.2 (and = likely earlier versions) exposes the /worker/deployContainer HTTP endpoint = without authentication on the default transport port. This allows a remote = attacker to execute arbitrary code. 2026-09-04 9.8 CVE-2026-75430 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-75430 ] PowerJob--Worker v5.1.2 PowerJ=
ob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing=
key for HS256-based authentication. This allows a remote attacker to execu=
te arbitrary code. 2026-09-04 9.1 CVE-2026-75431 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-75431 ] predis--predis Predis is a flexible and feature= -complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until ver= sion 3.3.0, pipeline handling on aggregate cluster and replication connecti= ons reparses an already serialized RESP buffer in AbstractAggregateConnecti= on::write() by splitting it with explode("\r\n") instead of honoring RESP l= ength prefixes. Attacker-controlled keys or values containing CRLF sequence=
s can therefore be interpreted by Command::deserializeCommand() as addition=
al commands. On cluster connections, ClusterStrategy::getFakeKey() can rout=
e injected keyless commands using the literal fake key value "key", permitt= ing operations such as shard-wide cache deletion, targeted data modificatio=
n, data reads, or node disruption. On replication connections, malformed re= parsing can throw an uncaught exception and repeatedly terminate affected r= equests. Only pipeline() reaches this vulnerable path; transaction() and MU= LTI are not affected. This issue is fixed in version 3.3.0. 2026-09-01 9.8 = CVE-2026-84372 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84372 ] Progre=
ss Software--Telerik UI for ASP.NET AJAX In Progress=C3=82=C2=AE Telerik=C3= =82=C2=AE UI for AJAX prior to v2026.3.812, insufficient integrity protecti=
on of dialog request parameters used by the RadEditor file browser may allo=
w an attacker who has obtained certain application encryption key material =
to alter the folders the file browser reads from, writes to, and uploads in= to, potentially resulting in remote code execution. 2026-09-02 8.1 CVE-2026= -19219 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19219 ] Progress Softw= are--Telerik UI for ASP.NET AJAX In Progress=C3=82=C2=AE Telerik=C3=82=C2=
=AE UI for AJAX prior to v2026.3.812, insufficient validation of client-sup= plied state in RadImageEditor may allow an attacker to influence which file=
is returned by the control's image cache, potentially exposing file conten=
ts outside the intended image directories. 2026-09-02 7.5 CVE-2026-18672 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-18672 ] Proper Fraction--Profil= ePress ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contain=
s an unauthenticated remote code execution vulnerability that allows unauth= enticated attackers to install and activate arbitrary plugins by brute-forc= ing a weak 32-bit connect token via the ppress_connect_process AJAX handler=
. Attackers can supply a caller-controlled URL through the file request par= ameter to trigger silent plugin installation and activation, achieving PHP = code execution as the web-server user. 2026-08-31 8.1 CVE-2026-66047 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-66047 ] Proxmox Server Solutions Gm= bH--Proxmox Virtual Environment (VE) Proxmox Virtual Environment (VE) 7.0 t= hrough 8.0 contains an authentication bypass vulnerability in libpve-access= -control before 8.0.4 that allows unauthenticated attackers to authenticate=
as any existing enabled user without a configured second factor by supplyi=
ng an arbitrary tfa-challenge value in the API login endpoint. Attackers ca=
n send a POST request to the access ticket API endpoint with any value in t=
he tfa-challenge parameter to completely skip password verification, gainin=
g unauthorized access including to the root@pam account. All affected relea= ses are end of life. 2026-09-01 9.8 CVE-2023-54391 [
https://www.cve.org/CV= ERecord?id=3DCVE-2023-54391 ] Pterodactyl Panel --Pterodactyl Panel=C2=A0 =C2=A0 Pterodactyl Panel before 1.14.1 fails to validate action-specific pe= rmissions in scheduled task creation, allowing subusers with only schedule.= update permission to execute arbitrary console commands. Attackers can crea=
te and immediately trigger scheduled tasks that run game-server console com= mands, control server power state, or create backups without proper authori= zation checks. 2026-09-05 8.8 CVE-2026-86177 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-86177 ] pydantic--httpx2 HTTPX2 is a next generation HTTP c= lient for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/http= core2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/soc= ks_proxy.py when the remote origin uses wss through a SOCKS5 proxy because = the TLS upgrade condition only recognizes https. HTTPX2 exposes the flaw th= rough Client.websocket() and AsyncClient.websocket() from 2.6.0 through 2.9= .1, so the opening handshake, query parameters, Authorization headers, cook= ies, and subsequent frames can cross the proxy path in plaintext without ce= rtificate verification. An attacker controlling or observing that path can = read or modify traffic and impersonate the WebSocket server. This issue is = fixed in httpcore2 2.10.0 and HTTPX2 2.10.0. 2026-09-02 8.1 CVE-2026-84381 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84381 ] pydantic--httpx2 HTTP=
X2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2=
content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip=
, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() y= ields bounded pieces to the application. A 64 KiB compressed chunk can expa=
nd to approximately 64 MiB in one intermediate allocation, so an attacker-c= ontrolled or compromised server can cause severe memory pressure or out-of-= memory process termination even when the application streams the response. = This issue is fixed in version 2.12.0. 2026-09-02 7.5 CVE-2026-84382 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-84382 ] Pyramid Solutions--EtherNet= /IP Adapter DLL Kit (EIPA) An issue in the NetStaX EtherNet/IP Stack prior =
to v5.6.1 could allow a large Class 3 explicit-message request to exceed th=
e application-side receive buffer without generating an error or warning. T=
he result could be memory corruption, a device crash, or a potential remote=
attack vector without the originating device receiving a CIP error indicat= ing that the request could not be processed. 2026-09-01 9.8 CVE-2026-78012 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-78012 ] QD--QD Server-side re= quest forgery (SSRF) in the /har/test endpoint in QD 20220208 through 20250= 803. Fetcher.build_request() in libs/fetcher.py constructs an httpclient.HT= TPRequest from user-supplied JSON without validating URL scheme, host, or I=
P range. The /har/test handler does not require authentication, enabling un= authenticated remote attackers to force the QD server to send arbitrary HTT=
P requests to internal network resources and cloud metadata endpoints. vali= date_cert is set to False, disabling TLS verification. 2026-08-31 9.1 CVE-2= 026-51152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51152 ] Quarkus--qu= arkus-qute A flaw was found in the Qute template engine, which is used by Q= uarkus to generate dynamic content like HTML pages or emails. The issue exi= sts in the component responsible for looking up data values (ReflectionValu= eResolver), which fails to properly block access to sensitive Java internal=
functions when processing certain data types like Enums. An attacker who c=
an provide or influence the template text can exploit this bypass to take c= ontrol of the server by executing unauthorized commands. 2026-08-31 8.8 CVE= -2026-12894 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12894 ] QVidium--= Opera11 A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-ope= ra11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the c= omponent CGI Script. This manipulation of the argument ipaddr causes comman=
d injection. The attack may be initiated remotely. The exploit has been pub= licly disclosed and may be utilized. The vendor explains: "QVidium has now = closed its doors and no longer will be able to sell products or provide sup= port." This vulnerability only affects products that are no longer supporte=
d by the maintainer. 2026-08-31 10 CVE-2026-82971 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-82971 ] rabindralamsal --inventory-management-system 1= .0.0
=C2=A0 A flaw has been found in rabindralamsal inventory-management-system = 1.0.0. This affects an unknown part of the file index.php of the component = Login. Executing a manipulation of the argument username/password can lead =
to sql injection. The attack can be executed remotely. The exploit has been=
published and may be used. 2026-09-06 7.3 CVE-2026-86211 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-86211 ] ramon-victor--freegpt-webui A security=
vulnerability has been detected in ramon-victor freegpt-webui up to 098db3= dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation =
of the file server/backend.py of the component Backend Conversation API. Su=
ch manipulation of the argument model leads to missing authentication. The = attack may be launched remotely. The exploit has been disclosed publicly an=
d may be used. This product operates on a rolling release basis, ensuring c= ontinuous delivery. Consequently, there are no version details for either a= ffected or updated releases. This vulnerability only affects products that = are no longer supported by the maintainer. 2026-09-04 7.3 CVE-2026-85702 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85702 ] Really Simple Plugins--= Really Simple SSL Unauthenticated Broken Authentication in Really Simple SS=
L <=3D 9.8.0 versions. 2026-09-03 7.4 CVE-2026-84777 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-84777 ] Red Hat--Red Hat Advanced Cluster Managemen=
t for Kubernetes 2.17 A flaw was found in submariner. In cert-auth mode, th=
e connection configuration is built using free-form strings from the Custom=
Resource Definition (CRD) without proper validation. A malicious cluster c=
an exploit this by publishing a CableName that includes newlines and ipsec.= conf directives. This allows an attacker to inject arbitrary configuration = parameters or execute commands through leftupdown hooks, leading to remote = code execution as root on the gateway node. 2026-09-02 9.1 CVE-2026-66786 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-66786 ] Red Hat--Red Hat AMQ B= roker 7 A flaw was found in Jolokia's JSR-160 proxy functionality where ins= ufficient validation of client-controlled JMX service URLs allows a bypass =
of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts =
a `target.url` value from a Jolokia POST request and passes it to `JMXServi= ceURL` and `JMXConnectorFactory` for establishing the remote JMX connection=
. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi= /ldap:.*`, which can be bypassed using alternative valid JMX service URL fo= rms, including `ldaps://` schemes or LDAP URLs with a non-empty JMX host co= mponent. These URLs are accepted as valid `JMXServiceURL` objects and can c= ause the Jolokia agent JVM to perform a JNDI lookup against an attacker-con= trolled LDAP endpoint. This can result in server-side request forgery (SSRF=
), forwarding of supplied JMX credentials to the remote endpoint, and poten= tially remote code execution depending on the classes and configuration ava= ilable in the target JVM. 2026-09-01 8.1 CVE-2026-84218 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-84218 ] Red Hat--Red Hat Build of Apache Camel 3= .33 for Quarkus 3.33.3.SP1 A flaw was found in RESTEasy's SourceProvider. T= his vulnerability allows an unauthenticated attacker to perform an unauthen= ticated remote file read. By sending a specially crafted XML body with a DO= CTYPE declaration referencing external entities to an endpoint that accepts=
application/xml and returns Source or StreamSource, the server can be tric= ked into resolving the entity and including sensitive file contents in the = HTTP response. This is due to the SourceProvider.writeTo() method creating =
a SAXParser without disabling external entity resolution, leading to an XML=
External Entity (XXE) vulnerability. 2026-08-31 7.5 CVE-2026-17615 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-17615 ] Red Hat--Red Hat build of Ap= ache Camel for Spring Boot 4 Undertow is a flexible performant web server u= sed in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebS= ocket connections. Specifically, certain configuration limits like message = buffer sizes and session timeouts cannot be adjusted and default to being u= nlimited. This allows a remote attacker to send large amounts of data or ma= intain connections indefinitely, potentially crashing the server by exhaust= ing its memory or other resources. 2026-08-31 7.5 CVE-2026-81624 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-81624 ] Red Hat--Red Hat build of Quark=
us A flaw was found in SmallRye GraphQL. The number scalar coercion for Big= Integer does not properly validate the magnitude of float or string inputs.=
An unauthenticated remote attacker can exploit this by sending a GraphQL q= uery containing a large exponent float literal. This can lead to the alloca= tion of extremely large BigInteger objects, causing CPU exhaustion or an Ou= tOfMemoryError, resulting in a denial of service. 2026-08-31 7.5 CVE-2026-7= 6763 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76763 ] Red Hat--Red Hat=
Enterprise Linux 10 A flaw was found in GDB's STABS debug format parser. T=
he read_member_functions() function in gdb/stabsread.c contains a linked li=
st removal bug in the code that separates destructor and non-destructor mem= ber functions of C++ classes. The bug causes the destructor entries to rema=
in in the main function list while the list length counter is decremented, = resulting in an out-of-bounds write when the function list is copied to its=
final allocated array. An attacker can craft an ELF binary with malicious = .stab and .stabstr sections that triggers this out-of-bounds write when a u= ser opens the file in GDB and performs any symbol-inspection operation such=
as setting a breakpoint. The inferior process does not need to be executed=
. Under controlled conditions, this was demonstrated to achieve execution o=
f arbitrary commands within the GDB process. 2026-08-31 7 CVE-2026-13732 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-13732 ] Red Hat--Red Hat Enterp= rise Linux 10 A heap-based buffer overflow was found in Corosync's Totem Pr= ocess Group (totempg) message reassembly. When processing fragmented multic= ast messages, the buffer used to reassemble fragments lacks a runtime bound=
s check in release builds. A network-adjacent attacker able to send crafted=
multicast protocol messages to the cluster could cause a heap buffer overf= low with attacker-controlled data. This can crash the Corosync daemon, caus= ing a denial of service to the entire cluster, and may potentially allow fu= rther exploitation given sufficient heap-corruption control. 2026-09-04 7.5=
CVE-2026-81665 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81665 ] Red H= at--Red Hat Enterprise Linux 10 A flaw was found in rpm. A local attacker c= ould supply a specially crafted `.gem` filename containing RPM macro syntax=
. When a user or automated workflow invokes `rpmuncompress -x` on this file=
, the macro expansion occurs during command construction. This allows the a= ttacker to execute arbitrary commands with the privileges of the invoking a= ccount, leading to a compromise of confidentiality, integrity, and availabi= lity. 2026-09-01 7 CVE-2026-84233 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84233 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found in rpm. =
An attacker can exploit a command injection vulnerability by influencing th=
e path or filename of a tarball processed by `rpmbuild -t*` to include shel=
l metacharacters. This is particularly relevant in automated build or conti= nuous integration (CI) workflows that ingest externally supplied artifact n= ames. Successful exploitation allows for arbitrary command execution with t=
he privileges of the build user, which could lead to information disclosure=
or disruption of the build environment. 2026-09-02 7.8 CVE-2026-84837 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-84837 ] Red Hat--Red Hat Enterpri=
se Linux 10 A flaw was found in rpmuncompress. This command injection vulne= rability allows a local attacker to execute arbitrary commands. This occurs=
when rpmuncompress processes a specially crafted archive filename containi=
ng shell metacharacters, which are not properly escaped before being passed=
to shell command strings. Successful exploitation requires user interactio=
n, where a user or automated workflow invokes rpmuncompress on the maliciou=
s file, leading to high impact on the confidentiality, integrity, and avail= ability of data accessible to the invoking user. 2026-09-02 7.8 CVE-2026-84= 838 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84838 ] Red Hat--Red Hat = Enterprise Linux 10 A NULL pointer dereference flaw was found in GStreamer'=
s RTSP support library. The vulnerability occurs while parsing an Authoriza= tion or WWW-Authenticate header that uses Digest authentication. Specially = crafted whitespace placement around a parameter's terminator can cause an i= nternal length calculation to underflow, leading to a crash of the process = parsing the header. On an RTSP server this can be triggered by a remote, un= authenticated attacker sending a single malformed request when the server h=
as authentication enabled; the same flaw can also be triggered against an R= TSP client by a malicious or compromised RTSP server. Successful exploitati=
on results in a denial of service (application crash) and has no confirmed = impact on confidentiality or integrity. 2026-09-03 7.5 CVE-2026-85150 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-85150 ] Red Hat--Red Hat Enterpris=
e Linux 10 A flaw was found in libsoup. A malicious HTTP/2 server or a Man-= in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerabili=
ty in the HTTP/2 client implementation. This occurs when a GNOME applicatio=
n uploads a file using HTTP/2, and the server sends a GOAWAY frame while th=
e file body is being read asynchronously. This can lead to memory corruptio=
n, potentially resulting in information disclosure or arbitrary code execut= ion. 2026-09-04 7.6 CVE-2026-85197 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85197 ] Red Hat--Red Hat Enterprise Linux 7 A stack out-of-bounds wri=
te vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field=
from on-disk inode metadata is used as an array index without bounds check= ing, causing a stack buffer overflow that may lead to arbitrary code execut= ion when processing crafted GFS2 filesystem images. 2026-09-03 7 CVE-2026-7= 1220 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71220 ] Red Hat--Red Hat=
Enterprise Linux 7 A stack out-of-bounds write vulnerability was found in = gfs2-utils. In savemeta, the height value from on-disk inode metadata is us=
ed as a loop bound without bounds checking, causing a stack buffer overflow=
that may lead to arbitrary code execution when processing crafted GFS2 fil= esystem images. 2026-09-03 7 CVE-2026-71221 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-71221 ] Red Hat--Red Hat Hardened Images The nsenter --join-= cgroup option opens the target cgroup.procs file as root and leaves that fi=
le descriptor open across later namespace and credential changes and across=
execve(). Because the kernel checks later cgroup migrations using the cred= entials from the original open, a program run in an attacker-controlled tar= get can inherit root's ability to move host processes between cgroups. Afte=
r a privileged operator uses --join-cgroup against that target, an unprivil= eged user can migrate and terminate unrelated root processes. 2026-09-02 7.=
9 CVE-2026-78408 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78408 ] Red = Hat--Red Hat Hardened Images The X-mount.subdir option uses a detached-tree=
fast path on Linux 6.15 and later and passes the configured subdirectory t=
o open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediat=
e symlink traversal or keep resolution inside the newly mounted filesystem.=
A local unprivileged user with an fstab-authorized X-mount.subdir entry ca=
n attach a host path at the intended mountpoint. 2026-09-02 7 CVE-2026-7840=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78409 ] Red Hat--Red Hat Ha= rdened Images A flaw was found in util-linux. Restricted bind mounts take t=
he source path from fstab but do not pin that source before the privileged = mount. A local unprivileged user who can replace the authorized source or a=
writable ancestor can redirect SUID mount(8) to bind another host director=
y. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mo= de, root then changes ownership or mode on that redirected inode. 2026-09-0=
2 7.8 CVE-2026-78410 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78410 ] = Red Hat--Red Hat OpenShift Container Platform 4 A flaw was found in openshi= ft/oauth-server. The OAuth login and error page endpoints pass the unauthen= ticated Accept-Language header to golang.org/x/text/language.ParseAcceptLan= guage() without input validation. A bypass of the CVE-2022-32149 mitigation=
exists: the upstream guard counts only '-' characters but the internal BCP=
47 scanner aliases '_' to '-' after the guard check. An unauthenticated at= tacker can send a crafted Accept-Language header using '_' separators to tr= igger quadratic-time parsing, consuming excessive CPU and denying authentic= ation to all cluster users. 2026-09-01 7.5 CVE-2026-49329 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-49329 ] RedPort--Optimizer wXa-203 A security = vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa= -213 and Optimizer wXa-223 up to 20260704. This impacts the function exec o=
f the file /xgatev1/system/datetime.php of the component System Clock. The = manipulation leads to command injection. The attack may be initiated remote= ly. The exploit has been disclosed publicly and may be used. The vendor was=
contacted early about this disclosure but did not respond in any way. 2026= -08-31 9.9 CVE-2026-83524 [
https://www.cve.org/CVERecord?id=3DCVE-2026-835=
24 ] RegistrationMagic--RegistrationMagic The RegistrationMagic WordPress p= lugin before 6.0.9.9 does not escape a registration form field value before=
outputting it in an HTML attribute on an administrative page, allowing una= uthenticated users to perform Stored Cross-Site Scripting attacks against h= igh privilege users such as admin. 2026-09-02 7.5 CVE-2026-77792 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-77792 ] rometheme--RTMKit Contributor P=
HP Object Injection in RTMKit <=3D 2.1.5 versions. 2026-09-03 8.8 CVE-2026-= 84752 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84752 ] rometheme--RTMK=
it Unauthenticated Cross Site Scripting (XSS) in RTMKit <=3D 2.1.5 versions=
. 2026-09-03 7.1 CVE-2026-84763 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-84763 ] rubyzip--rubyzip rubyzip versions before 3.4.0 contain a path tr= aversal vulnerability in Zip::Entry#extract that fails to properly validate=
extraction paths using prefix comparison without trailing separators. Atta= ckers can craft archive entries with names like ../upload_backup/owned.sh t=
o write files outside the intended extraction directory into sibling paths = sharing the destination prefix. 2026-09-03 7.5 CVE-2026-85396 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85396 ] samanhappy--mcphub MCPHub is a uni= fied hub for centrally managing and dynamically orchestrating multiple MCP = servers/APIs into separate endpoints with flexible routing strategies. Prio=
r to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endp= oints in MCPHub create/update MCP server configurations and then immediatel=
y spawn the configured stdio process via child_process.spawn. Authenticatio=
n is required, but there is no authorization check restricting these endpoi= nts to admins, and there is no allowlist/sanitization on the command and ar=
gs fields. As a result, any authenticated non-admin user can submit a serve=
r configuration with command:"/bin/sh" (or any other binary) and arbitrary = args, causing MCPHub to execute the attacker-controlled process as the MCPH=
ub server's OS user (commonly root in the published Docker image and in npx= /systemd deployments). This issue has been patched in version 0.12.15. 2026= -08-31 9.9 CVE-2026-79748 [
https://www.cve.org/CVERecord?id=3DCVE-2026-797=
48 ] samanhappy--mcphub MCPHub is a unified hub for centrally managing and = dynamically orchestrating multiple MCP servers/APIs into separate endpoints=
with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /a= pi/system-config endpoint (handler updateSystemConfig) performs no authoriz= ation check. It is protected only by the app-wide authentication middleware=
and a rate limiter - it never inspects req.user.isAdmin. This issue has be=
en patched in version 1.0.29. 2026-08-31 8.8 CVE-2026-79744 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-79744 ] samanhappy--mcphub MCPHub is a unifi=
ed hub for centrally managing and dynamically orchestrating multiple MCP se= rvers/APIs into separate endpoints with flexible routing strategies. Prior =
to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom=
') is used against a group route, isBearerKeyAllowedForRequest grants acces=
s to the entire group as long as any single server in that group appears in=
the key's allowedServers list - not only when every server the key is scop=
ed to matches, and critically, without ever re-checking allowedServers agai=
n once the group-level connection is authorized. A key explicitly scoped to=
one specific server therefore also grants full access to every other serve=
r that happens to share a group with it, including servers the key was neve=
r authorized for. This issue has been patched in version 1.0.31. 2026-08-31=
8.1 CVE-2026-79746 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79746 ] s= amanhappy--mcphub MCPHub is a unified hub for centrally managing and dynami= cally orchestrating multiple MCP servers/APIs into separate endpoints with = flexible routing strategies. Prior to version 1.0.32, the built-in prompt a=
nd resource controllers perform no role checking. The mutating POST/PUT /ap= i/prompts* and POST/PUT /api/resources* routes are attached to the authenti= cated router with no admin gate, and the handlers never read req.user. The = DAO singletons they write are consulted first - ahead of any connected MCP = server - for every session in handleGetPromptRequest / handleReadResourceRe= quest. A non-admin can therefore create, overwrite, and shadow global promp=
t templates and resources that all other users are served. The scored impac=
t is the unauthorized integrity violation (creation/tampering/shadowing of = globally-served records); stored prompt injection into other users' LLM ses= sions is a downstream consequence of that tampering. This issue has been pa= tched in version 1.0.32. 2026-08-31 7.1 CVE-2026-79745 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-79745 ] samanhappy--mcphub MCPHub is a unified hu=
b for centrally managing and dynamically orchestrating multiple MCP servers= /APIs into separate endpoints with flexible routing strategies. Prior to ve= rsion 1.0.32, an authenticated non-admin user can register a server pointin=
g at an arbitrary URL and make the hub issue server-side requests to it, wi=
th no egress filtering (no block of loopback / RFC1918 / link-local 169.254= .0.0/16). Via the OpenAPI proxy path the response body is returned to the c= aller (full, reflected SSRF); via the SSE/streamable-http transport the req= uest is sent blind. This issue has been patched in version 1.0.32. 2026-08-=
31 7.1 CVE-2026-79747 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79747 ]=
samanhappy--mcphub MCPHub is a unified hub for centrally managing and dyna= mically orchestrating multiple MCP servers/APIs into separate endpoints wit=
h flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-a= dmin users to servers they own (list views and config edits enforce ownersh= ip), but the tool-execution API does not. Any authenticated non-admin user = can invoke tools on MCP servers owned by other users - servers they cannot = even see in GET /api/servers. Because connected MCP servers carry real capa= bility (filesystem, HTTP fetch, cloud APIs with the owner's keys), this is = cross-tenant compromise: demonstrated arbitrary host file read (/etc/passwd=
, another user's secrets) and SSRF. This issue has been patched in version = 1.0.30. 2026-08-31 7.7 CVE-2026-79750 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-79750 ] Saturday Drive--Ninja Forms - Layout & Styles Unauthentica= ted PHP Object Injection in Ninja Forms - Layout & Styles <=3D 3.0.31 versi= ons. 2026-09-02 8.8 CVE-2026-81772 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-81772 ] Saturday Drive--Ninja Forms File Uploads Extension Unauthenti= cated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <=3D=
3.3.26 versions. 2026-09-03 7.1 CVE-2026-81773 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-81773 ] SciPhi-AI--R2R R2R through 3.6.6 contains a stac= ked SQL injection vulnerability that allows unauthenticated attackers to ex= ecute arbitrary SQL statements by manipulating the index name parameter in = the vector index creation endpoint. The index name is interpolated directly=
into a CREATE INDEX statement via string formatting without identifier quo= ting or allowlist validation, enabling arbitrary DDL and DML execution thro= ugh semicolon-separated statements under the PostgreSQL superuser account. = 2026-09-03 9.8 CVE-2026-82526 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -82526 ] SciPhi-AI--R2R R2R through 3.6.6 contains a SQL injection vulnerab= ility that allows unauthenticated attackers to inject SQL predicates into t=
he chunks search query by manipulating the filter key parameter in the retr= ieval search endpoint. Attackers can exploit the direct interpolation of fi= lter keys into the SQL WHERE clause without parameterization or escaping to=
perform time-based and boolean-based data exfiltration from the applicatio=
n database. 2026-09-03 7.5 CVE-2026-82527 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-82527 ] scrapy--scrapy Scrapy is a high-level web crawling and=
scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/= handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and=
key request into a plaintext HTTP request to the corresponding S3 endpoint=
unless request.meta["is_secure"] is explicitly enabled, then signs and sen=
ds the plaintext request with configured AWS credentials. A network attacke=
r who can observe traffic between Scrapy and S3 can read the bucket and key=
path, AWS Authorization header, X-Amz-Security-Token when temporary creden= tials are used, S3 object contents, and S3 response headers. An active man-= in-the-middle attacker can also modify the plaintext S3 response body, stat=
us code, and headers before Scrapy processes them, causing scraped-data poi= soning, poisoned exports, HTTP cache poisoning when caching is enabled, or = influence over later crawl targets through forged redirects or attacker-con= trolled links. Users making S3-scheme requests with AWS credentials are aff= ected. This issue is fixed in version 2.17.0. 2026-09-01 7.4 CVE-2026-84366=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84366 ] scriptsbundle--Nokri=
Job Board WordPress Theme The Nokri - Job Board WordPress Theme for WordPr= ess is vulnerable to Privilege Escalation via Account Takeover in all versi= ons up to, and including, 1.6.6. This is due to insufficient reset token va= lidation in the `nokri_reset_password()` function, which allows empty attac= ker-supplied reset tokens to match empty or unset `sb_password_forget_token=
` user meta values. This makes it possible for unauthenticated attackers to=
reset the password of any user, including administrators, and gain access =
to their account. 2026-09-01 9.8 CVE-2026-18550 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-18550 ] SeaCMS--SeaCMS A vulnerability was determined in=
SeaCMS up to 13.6. Affected is the function parseIf of the file search.php=
of the component Template Engine. This manipulation of the argument search= type causes code injection. It is possible to initiate the attack remotely.=
The exploit has been publicly disclosed and may be utilized. 2026-08-31 7.=
3 CVE-2026-82598 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82598 ] SeaC= MS--SeaCMS A security flaw has been discovered in SeaCMS up to 13.6. Affect=
ed by this issue is some unknown functionality of the file /zyapi.php?ac=3D= videolist. Performing a manipulation of the argument ids results in sql inj= ection. The attack can be initiated remotely. The exploit has been released=
to the public and may be used for attacks. 2026-08-31 7.3 CVE-2026-82600 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82600 ] SeaCMS--SeaCMS A secur= ity vulnerability has been detected in SeaCMS up to 13.6. This impacts the = function parseIf of the file seacms_locoy_news.php of the component Locoy C= ollector. The manipulation of the argument pwd leads to code injection. The=
attack may be initiated remotely. The exploit has been disclosed publicly = and may be used. 2026-09-03 7.3 CVE-2026-85137 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-85137 ] SeaCMS--SeaCMS A vulnerability was detected in Se= aCMS up to 13.6. Affected is the function addslashes of the file weixin/ind= ex.php of the component WeChat Module. The manipulation of the argument Con= tent results in sql injection. The attack may be launched remotely. The exp= loit is now public and may be used. 2026-09-03 7.3 CVE-2026-85138 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-85138 ] shabti--Frontend Admin by Dyna= miApps The Frontend Admin by DynamiApps plugin for WordPress is vulnerable =
to arbitrary file deletion due to insufficient file path validation in the = move_folders function in all versions up to, and including, 3.29.12. This m= akes it possible for unauthenticated attackers to delete arbitrary files on=
the server, which can easily lead to remote code execution when the right = file is deleted (such as wp-config.php). This is exploitable without authen= tication when a form is configured with public visibility (who_can_see=3D'a= ll'), as the required nonce is publicly obtainable from the rendered form. = 2026-09-01 7.5 CVE-2026-19952 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -19952 ] Sheikh Heera--Agentimus AI SEO, llms.txt & MCP for AI Agents Subsc= riber Broken Access Control in Agentimus - AI SEO, llms.txt & MCP for A=
I Agents <=3D 1.51.0 versions. 2026-09-03 8.1 CVE-2026-84779 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84779 ] Shenzhen Jixiang Tengda Technology = Co., Ltd--Tenda A18 Buffer Overflow vulnerability in Shenzhen Jixiang Tengd=
a Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to = execute arbitrary code via the fromSetCmdlineRun function 2026-09-01 9.8 CV= E-2026-51934 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51934 ] ShopEx--= ECShop A weakness has been identified in ShopEx ECShop up to 2.5.1. This af= fects the function check_img_type of the file admin/pack.php. Executing a m= anipulation of the argument pack_img can lead to unrestricted upload. It is=
possible to launch the attack remotely. The exploit has been made availabl=
e to the public and could be used for attacks. The vendor was contacted ear=
ly about this disclosure but did not respond in any way. 2026-08-31 7.3 CVE= -2026-82921 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82921 ] ShopEx--E= CShop A security vulnerability has been detected in ShopEx ECShop up to 2.5= .1. This vulnerability affects the function flow_update_cart of the file /f= low.php?step=3Dupdate_cart. The manipulation of the argument rec_id leads t=
o sql injection. The attack can be initiated remotely. The exploit has been=
disclosed publicly and may be used. The vendor was contacted early about t= his disclosure but did not respond in any way. 2026-08-31 7.3 CVE-2026-8292=
2 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82922 ] Siemens--Mendix SAM=
L (Mendix 10 compatible) A vulnerability has been identified in Mendix SAML=
(Mendix 10 compatible) (All versions < V4.2.3), Mendix SAML (Mendix 11 com= patible) (All versions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All=
versions < V3.6.27). Affected versions of the module do not properly valid= ate the SAML response signature. This could allow unauthenticated remote at= tackers to hijack an account (session) in specific SSO configurations. 2026= -09-03 8.7 CVE-2026-80465 [
https://www.cve.org/CVERecord?id=3DCVE-2026-804=
65 ] signum-network--signum-node Signum Node is a HDD-mined cryptocurrency = using an energy efficient and fair Proof-of-Commitment (PoC+) consensus alg= orithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.app= lyBlock() allowed a miner to receive an arbitrarily inflated block reward b=
y crafting a block with a negative totalFeeCashBackNqt value. The vulnerabi= lity was introduced when the SMART_FEES hardfork (block ~1,029,000) enabled=
fee cash-back and burn accounting without overflow protection. This issue = has been patched in version 3.9.9. 2026-09-03 7.5 CVE-2026-48486 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-48486 ] Silk Themes--Newspapers X Impro= per Validation of Specified Quantity in Input vulnerability in Silk Themes = Newspapers X allows Malicious Software Implanted. This issue affects Newspa= pers X: from 1.0.46 through 1.0.48. 2026-08-31 10 CVE-2026-81779 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-81779 ] silverplugins217--Calculation F=
or Contact Form 7 Unauthenticated Cross Site Scripting (XSS) in Calculation=
For Contact Form 7 <=3D 1.0 versions. 2026-09-03 7.1 CVE-2026-81300 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-81300 ] Simple Ajax Chat--Simple Aj=
ax Chat The Simple Ajax Chat WordPress plugin before 20260827 does not esca=
pe chat message content before rendering it, allowing unauthenticated users=
to inject arbitrary HTML attributes into the page and run scripts in the b= rowser of anyone viewing the chat, including administrators. 2026-09-02 8.8=
CVE-2026-81807 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81807 ] SiteG= round--SiteGround Security Unauthenticated Bypass Vulnerability in SiteGrou=
nd Security <=3D 1.6.6 versions. 2026-08-31 8.1 CVE-2026-82228 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-82228 ] siyuan-note--siyuan SiYuan before=
v3.8.2 contains a stored cross-site scripting vulnerability in asset servi=
ng due to an incomplete extension blocklist that misses script-capable file=
types. Attackers can upload files with extensions like .xht, .ehtml, .xsl,=
.xbl, or .rdf that resolve to executable media types and execute JavaScrip=
t to steal API tokens and compromise workspaces. 2026-09-02 9 CVE-2026-8480=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84803 ] siyuan-note--siyuan=
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to=
an accessible log file when full-text search requests exceed timing thresh= olds. Authenticated attackers can read the log file via the getFile endpoin=
t to recover admin API tokens and gain permanent administrative access. 202= 6-09-03 8.8 CVE-2026-85174 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85= 174 ] siyuan-note--siyuan SiYuan versions <=3D 3.8.1 (fixed in v3.8.2) cont= ain an incomplete blocklist in the IsForbiddenAbsPath() function (kernel/ut= il/path_guard.go), which only blocks conf/conf.json by exact match and does=
not restrict the TLS private key (conf/key.pem) or CA private key (conf/ca= .key) stored in the same conf/ directory. Because the getFile handler skips=
the blocklist for RoleAdministrator and all authenticated users receive Ro= leAdministrator in v3.8.1, any user (or any client on a default no-auth-cod=
e instance) can retrieve these private keys via POST /api/file/getFile. On = deployments with TLS enabled, this allows decryption of captured HTTPS traf= fic (key.pem) and forging of certificates trusted by clients that imported = SiYuan's CA (ca.key). 2026-09-03 8.8 CVE-2026-85175 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-85175 ] siyuan-note--siyuan SiYuan before v3.8.2 con= tains a denial of service vulnerability in the unauthenticated /api/system/= uiproc endpoint that accepts and retains attacker-controlled process identi= fiers without size limits or authentication. Attackers can send repeated re= quests with unique identifiers to exhaust process memory and degrade servic=
e availability. 2026-09-04 7.5 CVE-2026-85581 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85581 ] siyuan-note--siyuan SiYuan versions before v3.8.2 = contain a denial of service vulnerability in the publish-service Basic Auth=
throttle that stores failed-attempt state using attacker-controlled userna= mes without enforcing capacity limits or eviction policies. Unauthenticated=
attackers can submit repeated authentication requests with unique invalid = usernames to exhaust memory and increase synchronization overhead, degradin=
g service availability. 2026-09-04 7.5 CVE-2026-85584 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-85584 ] siyuan-note--siyuan SiYuan before v3.8.2 c= ontains an unbounded resource consumption vulnerability in the request-conc= urrency middleware that retains mutex entries for every unique request path=
without eviction. Unauthenticated attackers can send numerous unique reque=
st paths to permanently increase process memory and synchronization overhea=
d, degrading availability. 2026-09-04 7.5 CVE-2026-85585 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-85585 ] Slack Nebula mesh VPN--Slack Nebula mes=
h VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. Prior to version 0.7.1, revocation is the only in-band mechanism that iso= lates a compromised/offboarded host from a Nebula mesh. Because the blockli=
st never reaches any peer's config.yml, a Blocked host retains full overlay=
reachability to every peer under its CA (and internal services on the mesh=
) for up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.k= ey+host.crt can run stock slackhq/nebula directly, ignore the agent's 403/4=
10 poll responses, and stay connected after the operator revokes the host. = Operator-visible state (UI shows blocked, audit log records it) is misleadi= ng. This issue has been patched in version 0.7.1. 2026-09-04 8.1 CVE-2026-6= 1699 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61699 ] Slack--Nebula me=
sh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. From version 0.6.0 to before version 0.7.2, non-admin operators (role use=
r) can set allow_private: true on their own managed webhook subscription (P= OST/PATCH /api/v1/webhook-subscriptions). No admin check exists on this fie= ld. At delivery time, allow_private switches the dispatcher to an unguarded=
HTTP client, bypassing the private/loopback/link-local SSRF guard - lettin=
g a low-privilege operator make the server request internal addresses. This=
issue has been patched in version 0.7.2. 2026-09-04 7.7 CVE-2026-63464 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-63464 ] Snowflake--Snowflake Con= nector for Python Improper OCSP response validation in the Snowflake Python=
, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be acc= epted as valid, because OCSP responses were not reliably bound to the certi= ficate being validated and definitive verification failures were treated as=
transient. A man-in-the-middle attacker holding a revoked certificate and = its private key for a Snowflake or stage hostname could cause the driver to=
establish a TLS session to the attacker-controlled endpoint anyway, allowi=
ng the attacker to read and modify data transmitted within that connection.=
Successful exploitation requires that on-path position and the correspondi=
ng private key, and impact is limited to data carried within the intercepte=
d connection. The fix is available in the patched versions listed above. Us= ers must manually upgrade. 2026-09-04 7.4 CVE-2026-85525 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-85525 ] Soarkey--StudentManagement A weakness h=
as been identified in Soarkey StudentManagement and =C3=A5=C2=AD=C2=A6=C3= =A7=E2=80=9D=C5=B8=C3=A4=C2=BF=C2=A1=C3=A6=C2=81=C2=AF=C3=A7=C2=AE=C2=A1=C3= =A7=C2=90=E2=80=A0=C3=A7=C2=B3=C2=BB=C3=A7=C2=BB=C5=B8 up to e08f7f1d5015af= 407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the=
file code/src/service/AdminDao.java of the component Administrative Servle=
t. Executing a manipulation of the argument action can lead to authorizatio=
n bypass. It is possible to launch the attack remotely. The exploit has bee=
n made available to the public and could be used for attacks. The project w=
as informed of the problem early through an issue report but has not respon= ded yet. 2026-08-31 7.3 CVE-2026-82621 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82621 ] Social Media Share Buttons & Social Sharing Icons--Soci=
al Media Share Buttons & Social Sharing Icons The Social Media Share Button=
s & Social Sharing Icons WordPress plugin before 3.0.1 does not properly es= cape a value taken from the incoming request before outputting it in an inl= ine JavaScript event handler, leading to Reflected Cross-Site Scripting whi=
ch is triggered when a user interacts with the affected button. Exploitatio=
n requires the Social Media Share Buttons & Social Sharing Icons WordPress = plugin before 3.0.1 to be running a non-default icon display configuration.=
2026-09-02 7.1 CVE-2026-19723 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-19723 ] SolidInvoice--SolidInvoice SolidInvoice is an open-source invoici=
ng platform. Prior to version 3.0.1, the `DataGrid` LiveComponent deseriali= zes a `context` prop value using PHP's `unserialize()` after receiving it f= rom the client. Because the prop is marked `writable: true`, an authenticat=
ed attacker can supply an arbitrary PHP serialized payload. Version 3.0.1 f= ixes the issue. 2026-09-04 7.5 CVE-2026-61686 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-61686 ] sonaar--MP3 Audio Player for Music, Radio & Podcas=
t by Sonaar Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player = for Music, Radio & Podcast by Sonaar <=3D 5.13.1 versions. 2026-09-02 7.1 C= VE-2026-81289 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81289 ] sonicwa=
ll -- sma8200v A Pre-authentication SSRF vulnerability exists in the SMA100=
0 Appliance Work Place interface due to an unintended alternate access path=
. A remote unauthenticated attacker could potentially exploit this vulnerab= ility to gain unauthorized access to sensitive functionality and perform un= authorized operations. 2026-09-01 10 CVE-2026-83548 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-83548 ] sonicwall -- sma8200v Post-authentication Im= proper Neutralization of Special Elements used in an OS Command ('OS Comman=
d Injection') vulnerability has been identified in the SMA1000 Appliance Ma= nagement Console (AMC) which in specific conditions could potentially enabl=
e a remote authenticated attacker as administrator to execute arbitrary OS = commands, resulting in remote code execution. 2026-09-01 7.8 CVE-2026-83549=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-83549 ] SonicWall--Network S= ecurity Manager
=C2=A0 An Improper Neutralization of Special Elements used in an OS Command=
('OS Command Injection') vulnerability in the SonicWall Network Security M= anager (NSM) On-Prem Management interface allows an authenticated attacker = with SuperAdmin privileges to inject arbitrary commands that are executed o=
n the underlying host, resulting in remote code execution. 2026-09-04 9.1 C= VE-2026-78327 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78327 ] SonicWa= ll--Network Security Manager
=C2=A0 A missing authorization vulnerability in the SonicWall Network Secur= ity Manager (NSM) On-Prem Management interface allows a lower-privileged Ad= min user to escalate privileges to SuperAdmin. 2026-09-04 9.1 CVE-2026-7832=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78328 ] SonicWall--Network = Security Manager
=C2=A0 A Zip Slip vulnerability in the SonicWall Network Security Manager (= NSM) On-Prem file upload and archive processing functionality allows an att= acker to extract files outside the intended destination directory using a s= pecially crafted archive. 2026-09-04 9.1 CVE-2026-81939 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-81939 ] SourceCodester--Class and Exam Timetabli=
ng System A security flaw has been discovered in SourceCodester Class and E= xam Timetabling System 1.0. This vulnerability affects unknown code of the = file /admin/session.php. The manipulation of the argument ID results in mis= sing authorization. The attack can be executed remotely. The exploit has be=
en released to the public and may be used for attacks. 2026-09-04 7.3 CVE-2= 026-85512 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85512 ] SourceCodes= ter--Class and Exam Timetabling System 1.0 A vulnerability was determined i=
n SourceCodester Class and Exam Timetabling System 1.0. Affected is the fun= ction mysqli_query of the file /admin/modal_add_product.php. Executing a ma= nipulation of the argument fname can lead to sql injection. The attack can =
be executed remotely. The exploit has been publicly disclosed and may be ut= ilized. 2026-09-06 7.3 CVE-2026-86224 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-86224 ] SourceCodester--Class and Exam Timetabling System 1.0 A vu= lnerability was identified in SourceCodester Class and Exam Timetabling Sys= tem 1.0. Affected by this vulnerability is the function mysqli_query of the=
file /admin/modal_add_room.php. The manipulation of the argument room_name=
leads to sql injection. The attack is possible to be carried out remotely.=
The exploit is publicly available and might be used. 2026-09-06 7.3 CVE-20= 26-86225 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86225 ] SourceCodest= er--Class and Exam Timetabling System 1.0
=C2=A0 A vulnerability was detected in SourceCodester Class and Exam Timeta= bling System 1.0. The affected element is the function mysqli_query of the = file /admin/modal_add_course.php. The manipulation of the argument course r= esults in sql injection. The attack can be launched remotely. The exploit i=
s now public and may be used. 2026-09-06 7.3 CVE-2026-86220 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-86220 ] SourceCodester--Class and Exam Timet= abling System 1.0
=C2=A0 A flaw has been found in SourceCodester Class and Exam Timetabling S= ystem 1.0. The impacted element is the function mysqli_query of the file /a= dmin/modal_add_course1.php. This manipulation of the argument course causes=
sql injection. The attack may be initiated remotely. The exploit has been = published and may be used. 2026-09-06 7.3 CVE-2026-86221 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-86221 ] SourceCodester--Class and Exam Timetabl= ing System 1.0
=C2=A0 A vulnerability has been found in SourceCodester Class and Exam Time= tabling System 1.0. This affects the function mysqli_query of the file /adm= in/modal_add_course2.php. Such manipulation of the argument course leads to=
sql injection. The attack may be launched remotely. The exploit has been d= isclosed to the public and may be used. 2026-09-06 7.3 CVE-2026-86222 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-86222 ] SourceCodester--Class and = Exam Timetabling System 1.0
=C2=A0 A vulnerability was found in SourceCodester Class and Exam Timetabli=
ng System 1.0. This impacts the function mysqli_query of the file /admin/mo= dal_add_coursea.php. Performing a manipulation of the argument course resul=
ts in sql injection. Remote exploitation of the attack is possible. The exp= loit has been made public and could be used. 2026-09-06 7.3 CVE-2026-86223 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-86223 ] SourceCodester--Exam = Timetabling System 1.0 A weakness has been identified in SourceCodester Cla=
ss and Exam Timetabling System 1.0. Affected is an unknown function of the = file /delete_user.php. This manipulation of the argument ID causes sql inje= ction. The attack may be initiated remotely. The exploit has been made avai= lable to the public and could be used for attacks. 2026-09-06 7.3 CVE-2026-= 86209 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86209 ] SourceCodester-= -Exam Timetabling System 1.0
=C2=A0 A security flaw has been discovered in SourceCodester Class and Exam=
Timetabling System 1.0. This impacts an unknown function of the file /dele= te_teacher.php. The manipulation of the argument ID results in sql injectio=
n. The attack can be launched remotely. The exploit has been released to th=
e public and may be used for attacks. 2026-09-06 7.3 CVE-2026-86208 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-86208 ] SourceCodester--Exam Timetab= ling System 1.0
=C2=A0 A security vulnerability has been detected in SourceCodester Class a=
nd Exam Timetabling System 1.0. Affected by this vulnerability is an unknow=
n functionality of the file /delete_user_account.php. Such manipulation of = the argument ID leads to sql injection. The attack may be launched remotely=
. The exploit has been disclosed publicly and may be used. 2026-09-06 7.3 C= VE-2026-86210 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86210 ] SourceC= odester--Online Voting System 1.0 A vulnerability was found in SourceCodest=
er Online Voting System 1.0. The impacted element is an unknown function of=
the file /ajax.php?action=3Ddelete_category. Performing a manipulation of = the argument ID results in sql injection. Remote exploitation of the attack=
is possible. The exploit has been made public and could be used. 2026-09-0=
6 7.3 CVE-2026-86161 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86161 ] = SourceCodester--Online Voting System 1.0 A vulnerability was determined in = SourceCodester Online Voting System 1.0. This affects an unknown function o=
f the file /ajax.php?action=3Dlogin. Executing a manipulation of the argume=
nt Username can lead to sql injection. The attack can be executed remotely.=
The exploit has been publicly disclosed and may be utilized. 2026-09-06 7.=
3 CVE-2026-86162 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86162 ] Sour= ceCodester--Online Voting System 1.0
=C2=A0 A flaw has been found in SourceCodester Online Voting System 1.0. Im= pacted is an unknown function of the file /ajax.php?action=3Dsave_user. Thi=
s manipulation of the argument ID causes sql injection. The attack may be i= nitiated remotely. The exploit has been published and may be used. 2026-09-=
06 7.3 CVE-2026-86159 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86159 ]=
SourceCodester--Online Voting System 1.0
=C2=A0 A vulnerability has been found in SourceCodester Online Voting Syste=
m 1.0. The affected element is an unknown function of the file /ajax.php?ac= tion=3Ddelete_voting. Such manipulation of the argument ID leads to sql inj= ection. The attack may be launched remotely. The exploit has been disclosed=
to the public and may be used. 2026-09-06 7.3 CVE-2026-86160 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-86160 ] SpartnerNL--Laravel-Excel Laravel = Excel provides supercharged Excel exports and imports in Laravel. From 3.1.=
8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::cop= y() method resolves the caller-controlled $destination supplied through Exc= el::store(), $export->store(), or storeExcel() against the process working = directory with realpath() instead of the configured filesystem disk. If the=
path names an existing writable file, Disk::copy() opens it with fopen() i=
n rb+ mode and uses stream_copy_to_stream(), bypassing Flysystem path confi= nement and allowing an attacker whose application input controls the export=
path to overwrite arbitrary existing files with export content. The rb+ be= havior creates a non-truncating overwrite and trailing bytes when the new e= xport is shorter, and overwriting an executable PHP file can lead to remote=
code execution. This issue is fixed in version 3.1.70. 2026-09-01 7.5 CVE-= 2026-84374 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84374 ] SQL Chat--= SQL Chat
=C2=A0 SQL Chat contains four unauthenticated API endpoints that accept cli= ent-supplied database connection parameters and execute arbitrary SQL queri=
es against attacker-specified hosts. Attackers can connect to internal data= bases, execute SQL commands, enumerate schemas, and pivot into the server's=
network without authentication. 2026-09-05 8.7 CVE-2026-86123 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-86123 ] StellarWP--LearnDash LMS The Lear= nDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Uplo=
ad in versions up to and including 5.1.5. This is due to insufficient input=
validation in the 'learndash_fileupload_process' function, which iterates = through an entire array and validates only the first file. This makes it po= ssible for authenticated attackers, with subscriber-level access and above = who are enrolled in a course with assignment uploads enabled, to upload arb= itrary disallowed files, including PHP files, to the server's wp-content/up= loads/learndash/assignments/ directory. The uploaded files can only be used=
for Remote Code Execution if default server configurations have been chang=
ed to allow for execution. 2026-09-04 7.5 CVE-2026-12483 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-12483 ] Studio-42--elFinder elFinder is an open= -source file manager for web, written in JavaScript using jQuery UI. Prior =
to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server= -side request forgery protections when PHP cURL is unavailable because vali= date_address() validates $info['ip'], but get_remote_contents() selects fso= ck_get_contents(), which connects to $arr['host'] and performs a second DNS=
resolution. An attacker able to submit a URL upload can use DNS rebinding =
to have the first resolution return a public address and the connection res= olution return a loopback or private address, causing the internal HTTP res= ponse body to be stored as an uploaded file and made readable through elFin= der. After a successful fetch, get_headers($url, true) separately requests = the original hostname without reusing the validated and pinned connection, = creating an additional blind server-side request forgery path even when cur= l_get_contents() is selected. This issue is fixed in version 2.1.70. 2026-0= 8-31 8.6 CVE-2026-81889 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81889=
] Studio-42--elFinder elFinder is an open-source file manager for web, wri= tten in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in=
php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without = passing the result through mimeTypeNormalize(). Because the .phtml, .phar, = .php5, and .php3 extensions are absent from mime.types, the staticMimeMap e= ntries that map them to text/x-php are not applied, and allowPutMime() perm= its extraction even when uploadDeny blocks text/x-php. An attacker with ZIP=
upload permission can extract PHP-executable files into a web-accessible f= iles/ directory and achieve remote code execution when the server executes = those extensions. This issue is fixed in version 2.1.70. 2026-08-31 8.1 CVE= -2026-81891 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81891 ] SUSE--Ran= cher A flaw was found in Rancher Manager. The GlobalRole controller derived=
the target ClusterRole name from the user-settable `authz.management.cattl= e.io/cr-name` annotation and overwrote that object's rules without verifyin=
g ownership. A user with delegated GlobalRole create or update permission c= ould point the annotation at any existing ClusterRole, such as `cluster-adm= in`, and revoke the permissions of every principal bound to it. The change = persists after the malicious GlobalRole is deleted. This issue affects Ranc= her: before 2.15.1. 2026-09-03 8.7 CVE-2026-71404 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-71404 ] SUSE--Rancher A flaw was found in Rancher Mana= ger. Project Secrets were propagated into a namespace based only on its `fi= eld.cattle.io/projectId` annotation, without verifying that the referenced = project belonged to the same downstream cluster. A user able to create name= spaces on one cluster could set the annotation to a project ID from another=
cluster and have that project's secrets copied into a namespace under thei=
r control. This issue affects Rancher: before 2.15.1. 2026-09-03 7.7 CVE-20= 26-75033 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75033 ] SUSE--Ranche=
r A flaw was found in Rancher Manager. The SAML assertion replay protection=
introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs i=
n a per-process cache, so each replica only detected replays that reached t=
he same pod. In a high-availability deployment, an attacker holding a captu= red assertion could replay it once against every other replica to obtain ad= ditional authenticated sessions as the victim. This issue affects Rancher: = before 2.15.1. 2026-09-03 7.4 CVE-2026-75034 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-75034 ] SUSE--Rancher A flaw was found in Rancher Manager. = When a non-administrative caller supplied a label selector naming a differe=
nt user, the ext.cattle.io/v1 Token store dropped its internal owner filter=
instead of returning an empty result. Any authenticated user could therefo=
re list and watch every other user's tokens, disclosing token metadata and = the stored salted hash of the bearer token. This issue affects Rancher: bef= ore 2.15.1. 2026-09-03 7.7 CVE-2026-75035 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-75035 ] SUSE--yast2-auth-client A OS command injection vulnera= bility in yast2-auth-client allows an attacker who controls Active Director=
y configuration values to execute arbitrary commands as root on the configu= red host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba ne=
t ads join, net ads lookup -S and net ads testjoin invocations by interpola= ting configuration values into a single command string and passing that str= ing to Open3.popen2 / Open3.capture2, which causes Ruby to run it through /= bin/sh. The Organizational Unit (ou), dnshostname, AD user name and AD doma=
in name values are neither validated nor shell-quoted. 2026-09-01 8.8 CVE-2= 026-59681 [
https://www.cve.org/CVERecord?id=3DCVE-2026-59681 ] SUSE--yast2= -samba-client Improper neutralization of special elements used in an OS com= mand in yast2-samba-client allows an attacker who controls the content of a=
n Active Directory directory tree - a rogue domain controller, or a directo=
ry user delegated the right to create objects - to execute arbitrary comman=
ds as root on a machine being joined to that domain. This issue affects yas= t2-samba-client through 5.0.4. 2026-09-01 7.5 CVE-2026-25706 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-25706 ] SUSE--yast2-users An OS command inj= ection vulnerability was found in yast2-users. When displaying the "Passwor=
d Settings" tab of a user, get_password_term() in src/include/users/dialogs= .rb read the shadowLastChange and shadowExpire fields with GetString(), whi=
ch performs no numeric validation, and passed the resulting string to forma= t_days_after_epoch(). That helper interpolated the value into a shell comma=
nd executed via Ruby backticks without quoting or escaping. Impact: an admi= nistrator who manages users against an external/federated LDAP directory vi=
a `yast2 users` triggers root command execution the moment they view or edi=
t that particular user's "Password Settings" tab. No "join domain" or trust=
setup is required, just browsing/editing one user entry. This issue affect=
s yast2-users through 5.0.8. 2026-09-01 8 CVE-2026-59680 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-59680 ] svg--svgo SVGO, short for SVG Optimizer=
, is a Node.js library and command-line application for optimizing SVG file=
s. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in re= moveScripts plugin, named removeScriptElement in versions 2 and 3, incomple= tely filters executable links in plugins/removeScripts.js and lib/svgo/tool= s.js. The plugin does not recognize namespace-prefixed SVG anchor elements = such as svg:a with href or namespaced *:href values, and it does not remove=
ASCII tab, line-feed, or carriage-return characters before checking URL sc= hemes. Browsers remove those characters before parsing a scheme, allowing a=
n executable link to pass the plugin's check. When an application processes=
attacker-controlled SVG input and serves the result in an active browser c= ontext, a victim who activates the surviving link can execute script in the=
SVG's origin, expose data, modify content, or perform actions as the victi=
m. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0. 2026-09-01 8.2 = CVE-2026-84370 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84370 ] Syed B= alkhi--Charitable Subscriber SQL Injection in Charitable <=3D 1.8.12.1 vers= ions. 2026-08-31 8.5 CVE-2026-81287 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-81287 ] TAC Information Services Internal and External Trade Inc.--G= OLDENHORN ONEIT Improper neutralization of special elements used in an SQL = command ('SQL injection') vulnerability in TAC Information Services Interna=
l and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This=
issue affects GOLDENHORN ONEIT: before G=C3=83=C2=B6beklitepe. 2026-09-04 = 8.8 CVE-2026-18198 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18198 ] Ta= ilored Media--Tailored Tools Unauthenticated Cross Site Scripting (XSS) in = Tailored Tools <=3D 3.0.2 versions. 2026-08-31 7.1 CVE-2026-81765 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-81765 ] TBC Technology Inc.--KitLogist=
ic Missing Authorization vulnerability in TBC Technology Inc. KitLogistic a= llows Accessing Functionality Not Properly Constrained by ACLs. This issue = affects KitLogistic: before v2.2.2. 2026-08-31 7.5 CVE-2026-19616 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-19616 ] TBTAK BLGEM Software Technolog= ies Research Institute--Pardus Boot Repair Improper neutralization of speci=
al elements used in an OS command ('OS command injection') vulnerability in=
T=C3=83=C5=93B=C3=84=C2=B0TAK B=C3=84=C2=B0LGEM Software Technologies Rese= arch Institute Pardus Boot Repair allows OS Command Injection. This issue a= ffects Pardus Boot Repair: from 1.0.7 before 1.0.8. 2026-08-31 7.8 CVE-2026= -19702 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19702 ] Team Password = Manager--Team Password Manager Team Password Manager before 14.184.308 fail=
s to enforce authentication requirements in the local account password rese=
t flow. Unauthenticated attackers can reset local account passwords and aut= henticate as those users to gain unauthorized access. 2026-09-02 9.1 CVE-20= 26-84699 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84699 ] TeamWiseFlow= --xiaobei xiaobei through 5.5.2 fails to implement authentication or signat= ure validation on webhook endpoints, allowing unauthenticated attackers to = inject arbitrary messages into the agent pipeline. Attackers can publish ma= licious messages via the /webhook_worktool handler and exploit unvalidated = media URL fetching to perform server-side request forgery against internal = services. 2026-09-04 9.1 CVE-2026-85667 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85667 ] TEN-framework--ten-framework TEN Framework 0.11.71 cont= ains unauthenticated arbitrary file read and write vulnerabilities in the T= MAN Designer file-content API endpoints. Attackers can submit POST and PUT = requests to the /api/designer/v1/file-content endpoints to read arbitrary f= iles or write malicious content to system paths, enabling code execution th= rough authorized_keys, cron files, or executable graph files. 2026-09-04 9.=
8 CVE-2026-85688 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85688 ] Tend=
a --HG10
=C2=A0 A vulnerability was determined in Tenda HG10 300001138. This issue a= ffects the function formWanRedirect of the file /boaform/formWanRedirect of=
the component Boa Web Server. Executing a manipulation of the argument if = can lead to buffer overflow. The attack may be launched remotely. The explo=
it has been publicly disclosed and may be utilized. 2026-09-06 8.8 CVE-2026= -86166 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86166 ] Tenda-- CP3 A = vulnerability was detected in Tenda CP3 27.5.57.101. The affected element i=
s the function sub_2F77E8 of the file Apis/system.c of the component Networ=
k Configuration Management. Performing a manipulation results in os command=
injection. The attack may be initiated remotely. 2026-09-06 9.1 CVE-2026-8= 6151 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86151 ] Tenda-- CP3
=C2=A0 A security flaw has been discovered in Tenda CP3 27.5.57.101. This v= ulnerability affects the function SystemAsh of the file Apis/system.c of th=
e component Kylin. The manipulation of the argument AlarmVoiceURL results i=
n os command injection. It is possible to launch the attack remotely. 2026-= 09-05 9.1 CVE-2026-86148 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8614=
8 ] Tenda-- CP3
=C2=A0 A weakness has been identified in Tenda CP3 27.5.57.101. This issue = affects some unknown processing of the file Net/NetCheckPing.cpp. This mani= pulation of the argument interface_name/host causes os command injection. T=
he attack can be initiated remotely. 2026-09-05 9.1 CVE-2026-86149 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-86149 ] Tenda-- CP3
=C2=A0 A vulnerability has been found in Tenda CP3 27.5.57.101. This affect=
s the function CRedirServer::SetRedirectEnable of the file Functions/Redire= ct.cpp. The manipulation leads to improper privilege management. Remote exp= loitation of the attack is possible. 2026-09-06 9.1 CVE-2026-86153 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-86153 ] Tenda--AC1206 A vulnerability=
was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the=
function TendaTelnet of the file /goform/telnet of the component Web UI. E= xecuting a manipulation can lead to missing authentication. It is possible =
to launch the attack remotely. The exploit has been publicly disclosed and = may be utilized. 2026-08-31 10 CVE-2026-82693 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-82693 ] Tenda--AC1206 A vulnerability was identified in Te= nda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandl=
er of the file /goform/ate of the component Web UI. The manipulation leads =
to missing authentication. The attack can be initiated remotely. The exploi=
t is publicly available and might be used. 2026-08-31 10 CVE-2026-82694 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-82694 ] Tenda--AC18 A security f= law has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown f= unction of the file /goform/telnet of the component Telnet Handler. The man= ipulation results in missing authentication. The attack can be launched rem= otely. The exploit has been released to the public and may be used for atta= cks. 2026-08-31 10 CVE-2026-82695 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-82695 ] Tenda--CP3 =C2=A027.5.57.101
=C2=A0 A flaw has been found in Tenda CP3 27.5.57.101. The impacted element=
is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi= .cpp of the component Kylin. Executing a manipulation can lead to os comman=
d injection. The attack may be launched remotely. 2026-09-06 10 CVE-2026-86= 152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86152 ] Tenda--HG10 A vul= nerability was determined in Tenda HG10 300001138. This issue affects the f= unction formLogin of the file /boaform/formLogin of the component Boa Web S= erver. Executing a manipulation of the argument Username can lead to buffer=
overflow. The attack may be launched remotely. The exploit has been public=
ly disclosed and may be utilized. 2026-09-03 9.8 CVE-2026-85109 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-85109 ] Tenda--HG10 A vulnerability was = identified in Tenda HG10 300001138. Impacted is the function formWlanSetup =
of the file /boaform/formWlanSetup of the component Boa Web Server. The man= ipulation of the argument ssid leads to buffer overflow. Remote exploitatio=
n of the attack is possible. The exploit is publicly available and might be=
used. 2026-09-03 8.8 CVE-2026-85110 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-85110 ] Tenda--HG10
=C2=A0 A vulnerability was found in Tenda HG10 300001138. This vulnerabilit=
y affects the function formURL of the file /boaform/admin/formURL. Performi=
ng a manipulation of the argument Keywd/urlFQDN results in buffer overflow.=
The attack may be initiated remotely. The exploit has been made public and=
could be used. 2026-09-06 9.8 CVE-2026-86165 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-86165 ] Tenda--HG10
=C2=A0 A vulnerability was identified in Tenda HG10 300001138. Impacted is = the function formgponConf of the file /boaform/admin/formgponConf of the co= mponent Boa. The manipulation of the argument fmgpon_loid leads to os comma=
nd injection. Remote exploitation of the attack is possible. The exploit is=
publicly available and might be used. 2026-09-06 9.9 CVE-2026-86167 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-86167 ] Tenda--HG21 Insecure hardco= ded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows att= ackers to gain root access. 2026-08-31 9.8 CVE-2026-38577 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-38577 ] Teracity Software Technologies Inc.--E= -OSB Improper neutralization of special elements used in an SQL command ('S=
QL injection') vulnerability in Teracity Software Technologies Inc. E-OSB a= llows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. 2026= -09-01 9.8 CVE-2026-18765 [
https://www.cve.org/CVERecord?id=3DCVE-2026-187=
65 ] The Libreswan Project--libreswan In FIPS mode, Libreswan's add_decoded= _cert() function calls CERT_ExtractPublicKey() and asserts that the result =
is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key = extraction fails, for example if the RSA exponent is set to 0. A remote att= acker can send a malformed X.509 certificate in a CERT payload to trigger t=
he assertion, causing the pluto daemon to abort and restart. Continued expl= oitation causes a denial of service. No remote code execution is possible. = Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable wh=
en both the OS and libreswan are running in FIPS mode and at least one CA c= ertificate is loaded. The CERT payload is processed before peer authenticat= ion, so no credentials are needed to exploit this. Configurations using onl=
y PreSharedKey (PSK) authentication with no CA certificates loaded in the N=
SS database are not vulnerable. 2026-09-02 7.5 CVE-2026-14957 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-14957 ] The-Vibe-Company--megaparse MegaPa= rse 0.0.55 contains an unauthenticated server-side request forgery vulnerab= ility in the POST /v1/url endpoint that fetches caller-supplied URLs server= -side. Attackers can supply internal service URLs or metadata endpoints wit= hout authentication to read their responses directly from the JSON response=
. 2026-09-04 7.5 CVE-2026-85691 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-85691 ] themoos--core-moos MOOS core-moos through 10.4.0 lacks authentic= ation in the wire protocol, allowing unauthenticated clients to connect wit=
h full publish, subscribe, and database clear privileges. Attackers can byp= ass the compile-time protocol string check and connect with arbitrary clien=
t names to execute privileged operations including DB_CLEAR which resets al=
l variables and clears client mail queues. 2026-09-03 9.8 CVE-2026-85424 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85424 ] themoos--core-moos MOOS=
core-moos through 10.4.0 contains an authentication bypass vulnerability i=
n the optional MOOSDB HTTP server that allows unauthenticated clients to wr= ite variables. Attackers can send HTTP requests with variable names and val= ues to the MOOSDB HTTP server port to modify MOOS variables including actua= tor and override commands without authentication. 2026-09-03 9.8 CVE-2026-8= 5428 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85428 ] themoos--core-mo=
os MOOS core-moos through 10.4.0 contains a pre-authentication heap overflo=
w vulnerability in MOOSCommPkt packet handling that allows remote attackers=
to write arbitrary data by declaring a negative packet length. Attackers c=
an exploit the signed integer check in InflateTo() and negative size conver= sion in recv() to overflow a four-byte heap buffer during the HandShake pha=
se before authentication. 2026-09-03 9.8 CVE-2026-85440 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-85440 ] themoos--core-moos MOOS core-moos throug=
h 10.4.0 fails to validate client identity in MOOSDB message processing, al= lowing authenticated attackers to attribute writes to other clients by supp= lying arbitrary source identifiers in serialized messages. Attackers can fo= rge message origins and cancel third-party subscriptions by exploiting the = disconnect between authenticated connection identity and wire-supplied sour=
ce attribution. 2026-09-03 8.2 CVE-2026-85432 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85432 ] themoos--core-moos MOOS core-moos through 10.4.0 c= ontains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte = packet triggers out-of-bounds memory access during deserialization. Attacke=
rs can open a TCP connection to the MOOSDB port and send a crafted short pa= cket to read memory before authentication. 2026-09-03 8.2 CVE-2026-85455 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85455 ] themoos--core-moos MOOS=
core-moos through 10.4.0 fails to validate that serialized string lengths = are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can sen=
d a crafted message with a negative length value to the MOOSDB port, causin=
g an unhandled exception that terminates the database process. 2026-09-03 7=
.5 CVE-2026-85441 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85441 ] the= moos--core-moos MOOS core-moos through 10.4.0 fails to validate packet leng=
th declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated=
attackers to trigger unbounded buffer allocation by sending crafted wire p= ackets. Attackers can send packets with large declared lengths to exhaust s= erver memory and cause denial of service before client authentication compl= etes. 2026-09-03 7.5 CVE-2026-85442 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-85442 ] themoos--core-moos MOOS core-moos through 10.4.0 contains a = denial of service vulnerability in MOOSCommServer::ListenLoop() where the a= ccept thread performs a blocking receive without timeout during the wire-pr= otocol handshake. An attacker can open a TCP connection to the MOOSDB port = and send no data, causing the accept thread to block indefinitely while hol= ding the socket-list lock, preventing all subsequent client connections. 20= 26-09-03 7.5 CVE-2026-85443 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 5443 ] themoos--core-moos MOOS core-moos through 10.4.0 contains a denial o=
f service vulnerability in the MOOSDB HTTP server that creates unbounded co= nnections and threads without limits. Attackers can open many connections a=
nd send endless header data to exhaust server threads and memory, causing s= ervice unavailability. 2026-09-03 7.5 CVE-2026-85450 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-85450 ] themoos--core-moos MOOS core-moos through 1= 0.4.0 contains a remote process termination vulnerability in the SuicidalSl= eeper component that uses a hard-coded passphrase for multicast command aut= horization. Any multicast-reachable peer can enumerate MOOS processes and s= end termination commands to trigger process shutdown by exploiting the defa= ult multicast group and port with the known passphrase. 2026-09-03 7.1 CVE-= 2026-85451 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85451 ] themoos--e= ssential-moos MOOS essential-moos through 10.0.1 contains an authentication=
bypass vulnerability in pShare that accepts UDP datagrams from any source = and republishes them with the attacker-claimed identity intact. Attackers c=
an send crafted UDP datagrams to pShare input routes to inject messages int=
o the local MOOS community under spoofed identities, or send malformed data= grams to crash the pShare process. 2026-09-03 9.1 CVE-2026-85430 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-85430 ] themoos--essential-moos MOOS es= sential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD m= essages, allowing any publisher to reconfigure network routes and listeners=
at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=3Doutp=
ut or cmd=3Dinput parameters to open new listeners on arbitrary addresses a=
nd redirect or duplicate bus traffic to attacker-controlled destinations. 2= 026-09-03 9.8 CVE-2026-85433 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 85433 ] themoos--essential-moos MOOS essential-moos pAntler through 10.0.1 = contains a remote code execution vulnerability that allows unauthenticated = attackers to execute arbitrary programs by publishing a crafted MISSION_FIL=
E message to the MOOSDB. Attackers can publish a mission file containing ma= licious Run entries that pAntler parses and executes via execvp() without a= uthentication validation. 2026-09-03 8.1 CVE-2026-85427 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-85427 ] themoos--essential-moos MOOS essential-m= oos through version 10.0.1 contains an unauthenticated UDP packet injection=
vulnerability in pMOOSBridge when configured with UDPListen. Attackers can=
send crafted UDP packets to the configured port to inject arbitrary variab= les into the local MOOS community with spoofed source and community identif= iers. 2026-09-03 7.5 CVE-2026-85431 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-85431 ] themoos--essential-moos MOOS essential-moos through 10.0.1 c= ontains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray()=
that allows remote attackers to corrupt heap memory by sending UDP datagra=
ms with negative declared lengths. Attackers can send crafted UDP packets t=
o the configured UDPListen port to trigger an oversized memcpy operation th=
at writes past the destination buffer, causing heap corruption and denial o=
f service. 2026-09-03 7.5 CVE-2026-85436 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85436 ] themoos--ui-moos MOOS ui-moos through 50b9c6c contains =
a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where=
client and variable names are formatted into fixed 1024-byte buffers using=
sprintf without length validation. Attackers can supply arbitrarily long M= OOS identifiers that overflow the buffers when an operator selects process = list entries or pokes variables, enabling code execution. 2026-09-03 8.8 CV= E-2026-85452 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85452 ] Throws S= PAM Away--Throws SPAM Away Unauthenticated SQL Injection in Throws SPAM Awa=
y <=3D 3.8.2 versions. 2026-08-31 9.3 CVE-2026-81763 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-81763 ] Tickera--Tickera Unauthenticated PHP Object=
Injection in Tickera <=3D 3.6.0.2 versions. 2026-08-31 9.8 CVE-2026-82226 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82226 ] TMT Machine Industry = and Trade Ltd. Co.--Talassoft Industrial Management Software Use of Hard-co= ded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Ta= lassoft Industrial Management Software allows Retrieve Embedded Sensitive D= ata. This issue affects Talassoft Industrial Management Software: from V.4 = before V.16. 2026-09-01 9.1 CVE-2026-18931 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-18931 ] TMT Machine Industry and Trade Ltd. Co.--Talassoft In= dustrial Management Software Improper neutralization of special elements us=
ed in an SQL command ('SQL injection') vulnerability in TMT Machine Industr=
y and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL In= jection. This issue affects Talassoft Industrial Management Software: from = V.4 before V.16. 2026-09-01 8.8 CVE-2026-18630 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-18630 ] TMT Machine Industry and Trade Ltd. Co.--Talassof=
t Industrial Management Software Missing authentication for critical functi=
on vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Indus= trial Management Software allows Authentication Bypass. This issue affects = Talassoft Industrial Management Software: from V4 before V.16. 2026-09-01 7=
.5 CVE-2026-18771 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18771 ] TMT=
Machine Industry and Trade Ltd. Co.--Talassoft Industrial Management Softw= are Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry=
and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross S= ite Request Forgery. This issue affects Talassoft Industrial Management Sof= tware: from V.4 before V.16. 2026-09-01 7.1 CVE-2026-18780 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-18780 ] ToolJet--ToolJet ToolJet before v3.16= .208 fails to validate organizationId ownership in database write and destr=
oy routes, allowing any builder-role user to create, alter, or drop tables =
in other organizations' databases. Attackers can exploit missing organizati= on-resolving guards to permanently delete tables, insert arbitrary data, an=
d modify schemas across tenant boundaries on shared instances. 2026-08-31 9=
.6 CVE-2026-82870 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82870 ] Too= lJet--ToolJet ToolJet before v3.16.208 fails to validate that the path orga= nizationId matches the authenticated user's workspace before performing Too= lJet DB table operations. A workspace admin can create, view, and delete da= tabase tables in another workspace by replacing the organizationId paramete=
r in table-management API requests. 2026-08-31 9.1 CVE-2026-82872 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82872 ] ToolJet--ToolJet ToolJet befor=
e v3.16.208 fails to validate that authenticated users belong to the organi= zation specified in the organizationId path parameter of tooljet-db endpoin= ts, allowing any Builder user to read, modify, and delete tables across ten= ant boundaries. Attackers can extract victim organization IDs from public a=
pp endpoints, then exploit schema operation endpoints to disclose table sch= emas, plant malicious tables, corrupt existing schemas, or permanently dest= roy victim data without any relationship to the target organization. 2026-0= 8-31 9.9 CVE-2026-82874 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82874=
] ToolJet--ToolJet ToolJet Database versions before v3.16.44 contain a pri= vilege escalation vulnerability in the join_tables endpoint that grants JOI= N_TABLES ability to all authenticated users without role or workspace membe= rship validation. Attackers can read arbitrary ToolJet Database tables from=
any workspace by supplying victim workspace identifiers in the request pat=
h while authenticating with their own workspace credentials. 2026-08-31 7.7=
CVE-2026-82869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82869 ] ToolJ= et--ToolJet ToolJet before v3.16.208 fails to validate organization members= hip in database read routes, allowing any authenticated user to access othe=
r organizations' table schemas and row data. Attackers can supply arbitrary=
organization IDs in URL parameters to list tables, retrieve column definit= ions, and execute join queries to read actual stored data from victim organ= izations. 2026-08-31 7.7 CVE-2026-82871 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82871 ] toon-format--toon TOON is a compact, human-readable ser= ialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-= controlled TOON with a __proto__, constructor, or prototype key wrote throu=
gh the object prototype chain instead of creating an own property, pollutin=
g Object.prototype for the runtime. In packages/toon/src/decode/expand.ts, = the expandPaths: 'safe' path and insertPathSafe function made dotted keys s= uch as a.__proto__.x the strongest vector, while plain nested objects, tabu= lar rows, quoted keys, and streaming decode were also affected. The encoder=
also dropped own __proto__ properties and could invoke an inherited setter=
during normalization. Services that decode untrusted TOON could experience=
denial of service or, when a suitable downstream gadget is present, remote=
code execution. This issue is fixed in version 2.3.1. 2026-09-02 8.3 CVE-2= 026-82404 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82404 ] tornadoweb-= -tornado Tornado is a Python web framework and asynchronous networking libr= ary. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded reque=
st bodies with urllib.parse.parse_qs in tornado/escape.py without passing m= ax_num_fields. RequestHandler._execute in tornado/web.py parses the body be= fore handler dispatch through HTTPServerRequest._parse_body and parse_body_= arguments in tornado/httputil.py, so an unauthenticated request body contai= ning millions of separator-delimited fields can synchronously stall the sin= gle-threaded event loop and delay every connection. The body is bounded onl=
y by max_buffer_size, which defaults to 104857600 bytes. This issue is fixe=
d in version 6.5.8. 2026-08-31 7.5 CVE-2026-82397 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-82397 ] TOTOLINK--CP450 A vulnerability was found in T= OTOLINK CP450 4.1.0. The impacted element is an unknown function of the fil=
e /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl = results in buffer overflow. Remote exploitation of the attack is possible. = 2026-09-03 9.9 CVE-2026-85031 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -85031 ] TOTOLINK--NR1800X A vulnerability was found in TOTOLINK NR1800X 9.= 1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file = /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in = stack-based buffer overflow. The attack can be executed remotely. The explo=
it has been made public and could be used. 2026-08-31 9.9 CVE-2026-82616 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-82616 ] TOTOLINK--NR1800X A vul= nerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This a= ffects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulat= ion of the argument ussd leads to command injection. The attack can be init= iated remotely. The exploit is publicly available and might be used. 2026-0= 8-31 7.4 CVE-2026-82597 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82597=
] TOTOLINK--TOTOLINK T6 Incorrect access control in the getPairCfg functio=
n of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to = obtain pairing and mesh-slave configuration via sending a crafted POST requ= est to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51669 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-51669 ] TOTOLINK--TOTOLINK T6 Incorrect acces=
s control in the getSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B202110=
15 allows unauthenticated attackers to query slave upgrade status and affec=
t upgrade bookkeeping via sending a crafted POST request to /cgi-bin/cstecg= i.cgi. 2026-08-31 9.8 CVE-2026-51670 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-51670 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the getRo= amingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticat=
ed attackers to obtain the roaming enablement flag via sending a crafted PO=
ST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51672 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-51672 ] TOTOLINK--TOTOLINK T6 Incorrec=
t access control in the setScheduleCfg function of TOTOLINK T6 4.1.5cu.748_= B20211015 allows unauthenticated attackers to configure forced reboot tasks=
via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8=
CVE-2026-51674 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51674 ] TOTOL= INK--TOTOLINK T6 Incorrect access control in the setWanIeCfg function of TO= TOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfi= gure uplink settings via sending a crafted POST request to /cgi-bin/cstecgi= .cgi. 2026-08-31 9.1 CVE-2026-51675 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-51675 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setAcc= essDeviceCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent= icated attackers to alter access-device policies via sending a crafted POST=
request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51676 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-51676 ] TOTOLINK--TOTOLINK T6 Incorrect = access control in the setUPnPCfg function of TOTOLINK T6 4.1.5cu.748_B20211= 015 allows unauthenticated attackers to change UPnP service state via sendi=
ng a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-= 51677 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51677 ] TOTOLINK--TOTOL= INK T6 Incorrect access control in the setPasswordCfg function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the adm= inistrator account via sending a crafted POST request to /cgi-bin/cstecgi.c= gi. 2026-08-31 9.1 CVE-2026-51679 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-51679 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setLedCf=
g function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta= ckers to modify LED behavior via sending a crafted POST request to /cgi-bin= /cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51680 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-51680 ] TOTOLINK--TOTOLINK T6 Incorrect access control in th=
e setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe= nticated attackers to expose WAN-side administration via sending a crafted = POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51681 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-51681 ] TOTOLINK--TOTOLINK T6 Incorr= ect access control in the setStorageCfg function of TOTOLINK T6 4.1.5cu.748= _B20211015 allows unauthenticated attackers to alter the storage-related se= rvice state via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 202= 6-08-31 9.8 CVE-2026-51684 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51= 684 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setWiFiEasyCfg = function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack= ers to reconfigure or disable wireless networks via sending a crafted POST = request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51686 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-51686 ] TOTOLINK--TOTOLINK T6 Incorrect a= ccess control in the setWiFiEasyGuestCf function of TOTOLINK T6 4.1.5cu.748= _B20211015 allows unauthenticated attackers to create or weaken guest wirel= ess access via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026= -08-31 9.1 CVE-2026-51687 [
https://www.cve.org/CVERecord?id=3DCVE-2026-516=
87 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setUpgradeFW fun= ction of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers=
to trigger firmware-upgrade workflow changes via sending a crafted POST re= quest to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51689 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-51689 ] TOTOLINK--TOTOLINK T6 Incorrect acc= ess control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 = allows unauthenticated attackers to alter upstream provisioning and connect= ivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-3=
1 9.1 CVE-2026-51690 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51690 ] = TOTOLINK--TOTOLINK T6 Incorrect access control in the setUploadSetting func= tion of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers =
to manipulate the upload or flash workflow via sending a crafted POST reque=
st to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51691 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-51691 ] TOTOLINK--TOTOLINK T6 Incorrect access=
control in the setWiFiGuestCfg function of TOTOLINK T6 4.1.5cu.748_B202110=
15 allows unauthenticated attackers to establish or weaken guest wireless a= ccess via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-3=
1 9.1 CVE-2026-51692 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51692 ] = TOTOLINK--TOTOLINK T6 Incorrect access control in the setVpnPassCfg functio=
n of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to = weaken edge filtering via sending a crafted POST request to /cgi-bin/cstecg= i.cgi. 2026-08-31 9.8 CVE-2026-51693 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-51693 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setPo= rtForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe= nticated attackers to expose internal services via sending a crafted POST r= equest to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51696 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51696 ] TOTOLINK--TOTOLINK T6 Incorrect ac= cess control in the setIptvCfg function of TOTOLINK T6 4.1.5cu.748_B2021101=
5 allows unauthenticated attackers to alter IPTV service configuration via = sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-= 2026-51697 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51697 ] TOTOLINK--= TOTOLINK T6 Incorrect access control in the setUrlFilterRules function of T= OTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter = browsing policies via sending a crafted POST request to /cgi-bin/cstecgi.cg=
i. 2026-08-31 9.1 CVE-2026-51698 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-51698 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setDmzCfg=
function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac= kers to expose an internal host via sending a crafted POST request to /cgi-= bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51699 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-51699 ] TOTOLINK--TOTOLINK T6 Incorrect access control in=
the setWiFiAdvancedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allow=
s unauthenticated attackers to degrade wireless behavior via sending a craf= ted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51700 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-51700 ] TOTOLINK--TOTOLINK T6 In= correct access control in the setMacFilterRules function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to change device access=
control via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-0= 8-31 9.1 CVE-2026-51701 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51701=
] TOTOLINK--TOTOLINK T6 Incorrect access control in the setWiFiMeshName fu= nction of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker=
s to rename mesh entries via sending a crafted POST request to /cgi-bin/cst= ecgi.cgi. 2026-08-31 9.8 CVE-2026-51705 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-51705 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the s= etWiFiWpsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent= icated attackers to change WPS availability via sending a crafted POST requ= est to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51708 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-51708 ] TOTOLINK--TOTOLINK T6 Incorrect acces=
s control in the setWiFiBasicCfg function of TOTOLINK T6 4.1.5cu.748_B20211= 015 allows unauthenticated attackers to reconfigure primary Wi-Fi settings = via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 = CVE-2026-51709 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51709 ] TOTOLI= NK--TOTOLINK T6 Incorrect access control in the setParentalRules function o=
f TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alt=
er parental-control behavior via sending a crafted POST request to /cgi-bin= /cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51710 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-51710 ] TOTOLINK--TOTOLINK T6 Incorrect access control in th=
e setWiFiWpsStart function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau= thenticated attackers to open a wireless pairing window via sending a craft=
ed POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51711 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-51711 ] TOTOLINK--TOTOLINK T6 Inc= orrect access control in the setManualDialCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to manipulate WAN dial st= ate via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 = 9.1 CVE-2026-51713 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51713 ] TO= TOLINK--TOTOLINK T6 Incorrect access control in the delMacFilterRules funct= ion of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers t=
o remove MAC filter rules via sending a crafted POST request to /cgi-bin/cs= tecgi.cgi. 2026-08-31 9.8 CVE-2026-51715 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-51715 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the s= etOpModeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti= cated attackers to change the device operating mode via sending a crafted P= OST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51717 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-51717 ] TOTOLINK--TOTOLINK T6 Incorre=
ct access control in the delStaticDhcpRules function of TOTOLINK T6 4.1.5cu= .748_B20211015 allows unauthenticated attackers to remove static DHCP reser= vations via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08= -31 9.8 CVE-2026-51718 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51718 =
] TOTOLINK--TOTOLINK T6 Incorrect access control in the delIpPortFilterRule=
s function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated atta= ckers to remove firewall filter rules via sending a crafted POST request to=
/cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51720 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-51720 ] TOTOLINK--TOTOLINK T6 Incorrect access cont= rol in the setPairCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows = unauthenticated attackers to alter the mesh pairing state via sending a cra= fted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51721 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-51721 ] TOTOLINK--TOTOLINK T6 I= ncorrect access control in the setWiFiRepeaterCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to repoint the device=
to an attacker-controlled upstream Wi-Fi via sending a crafted POST reques=
t to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51722 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-51722 ] TOTOLINK--TOTOLINK T6 Incorrect access = control in the UploadCustomModule function of TOTOLINK T6 4.1.5cu.748_B2021= 1015 allows unauthenticated attackers to install a custom CGI module via se= nding a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-20= 26-51723 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51723 ] TOTOLINK--TO= TOLINK T6 Incorrect access control in the delSmartQosCfg function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smar=
t QoS rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 202= 6-08-31 9.8 CVE-2026-51724 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51= 724 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the NTPSyncWithHost=
function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attac= kers to change the device clock via sending a crafted POST request to /cgi-= bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51725 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-51725 ] TOTOLINK--TOTOLINK T6 Incorrect access control in=
the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows = unauthenticated attackers to remove parental-control rules via sending a cr= afted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51726 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-51726 ] TOTOLINK--TOTOLINK T6 = Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted = firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi. = 2026-08-31 9.8 CVE-2026-51728 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -51728 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the delDevice fu= nction of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attacker=
s to request deletion of a managed slave device via sending a crafted POST = request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026-51729 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-51729 ] TOTOLINK--TOTOLINK T6 Incorrect a= ccess control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B2= 0211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via send= ing a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1 CVE-2026= -51730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51730 ] TOTOLINK--TOTO= LINK T6 Incorrect access control in the delVlanCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entri=
es via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9=
.1 CVE-2026-51731 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51731 ] TOT= OLINK--TOTOLINK T6 Incorrect access control in the FirmwareUpgrade function=
of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to r= emove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin= /cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51733 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-51733 ] TOTOLINK--TOTOLINK T6 Incorrect access control in th=
e informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un= authenticated attackers to trigger mesh slave update coordination via sendi=
ng a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-= 51734 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51734 ] TOTOLINK--TOTOL= INK T6 Incorrect access control in the clearSyslog function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs=
via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.1=
CVE-2026-51736 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51736 ] TOTOL= INK--TOTOLINK T6 Incorrect access control in the LoadDefSettings function o=
f TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to res=
et the device configuration and reboot the device via sending a crafted POS=
T request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2026-51738 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-51738 ] TOTOLINK--TOTOLINK T6 Incorrect=
access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B202= 11015 allows unauthenticated attackers to terminate critical services via s= ending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 9.8 CVE-2= 026-51740 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51740 ] TOTOLINK--T= OTOLINK T6 Incorrect access control in the clearDiagnosisLog function of TO= TOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase d= iagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2= 026-09-01 9.8 CVE-2026-51741 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 51741 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the guest_wifi_sy=
nc function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att= ackers to disable guest virtual AP interfaces via sending a crafted MQTT me= ssage to the cs_broker component. 2026-09-01 9.1 CVE-2026-51743 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-51743 ] TOTOLINK--TOTOLINK T6 Incorrect = access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.7= 48_B20211015 allows unauthenticated attackers to force mesh configuration s= ynchronization from an attacker-controlled host via sending a crafted MQTT = message to the cs_broker component. 2026-09-01 9.8 CVE-2026-51744 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-51744 ] TOTOLINK--TOTOLINK T6 Incorrec=
t access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B2021= 1015 allows unauthenticated attackers to emit indirect mesh heartbeat infor= mation toward the master via sending a crafted MQTT message to the cs_broke=
r component. 2026-09-01 9.8 CVE-2026-51747 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-51747 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the=
updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unau= thenticated attackers to rescan and switch the primary mesh channel via sen= ding a crafted MQTT message to the cs_broker component. 2026-09-01 9.8 CVE-= 2026-51750 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51750 ] TOTOLINK--= TOTOLINK T6 Incorrect access control in the delSlaveDevice function of TOTO= LINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a = specified slave device from local mesh management data and reboot the syste=
m via sending a crafted MQTT message to the cs_broker component. 2026-09-01=
9.8 CVE-2026-51751 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51751 ] T= OTOLINK--TOTOLINK T6 Incorrect access control in the updateSlaveIpList func= tion of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers =
to overwrite the slave IP inventory state via sending a crafted MQTT messag=
e to the cs_broker component. 2026-09-01 9.8 CVE-2026-51754 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-51754 ] TOTOLINK--TOTOLINK T6 Incorrect acce=
ss control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B2021= 1015 allows unauthenticated attackers to start a firmware download or flash=
workflow on the slave device via sending a crafted MQTT message to the cs_= broker component. 2026-09-01 9.8 CVE-2026-51757 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-51757 ] TOTOLINK--TOTOLINK T6 Incorrect access control i=
n the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows = unauthenticated attackers to mass-trigger firmware update activity across m= esh slaves via sending a crafted MQTT message to the cs_broker component. 2= 026-09-01 9.8 CVE-2026-51760 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 51760 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the meshInfoKick = function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attack= ers to kick or clean stale mesh information/state and trigger regeneration =
of mesh metadata via sending a crafted MQTT message to the cs_broker compon= ent. 2026-09-01 9.8 CVE-2026-51762 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-51762 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the freeSta= Client function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated=
attackers to forcibly disconnect wireless clients via sending a crafted MQ=
TT message to the cs_broker component. 2026-09-01 9.8 CVE-2026-51763 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-51763 ] TOTOLINK--TOTOLINK T6 Incor= rect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud= -result tracking files via sending a crafted MQTT message to the cs_broker = component. 2026-09-01 9.8 CVE-2026-51764 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-51764 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the r= ecvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows un= authenticated attackers to insert or replace mesh neighbor records via send= ing a crafted MQTT message to the cs_broker component. 2026-09-01 9.8 CVE-2= 026-51765 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51765 ] TOTOLINK--T= OTOLINK T6 Incorrect access control in the recvClearPairCfg function of TOT= OLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pa= iring state and reboot the device via sending a crafted MQTT message to the=
cs_broker component. 2026-09-01 9.8 CVE-2026-51767 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-51767 ] TOTOLINK--TOTOLINK T6 Incorrect access contr=
ol in the remoteCloudUpdateCheck function of TOTOLINK T6 4.1.5cu.748_B20211= 015 allows unauthenticated attackers to restart the cloud update check work= flow via sending a crafted MQTT message to the cs_broker component. 2026-09= -01 9.8 CVE-2026-51769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51769 =
] TOTOLINK--TOTOLINK T6 Incorrect access control in the sendToMasterQosConf=
ig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated att= ackers to forward attacker-controlled QoS settings to the master via sendin=
g a crafted MQTT message to the cs_broker component.. 2026-09-01 9.8 CVE-20= 26-51770 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51770 ] TOTOLINK--TO= TOLINK T6 Incorrect access control in the setLanguageCfg function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify lang= uage configuration via sending a crafted POST request to /cgi-bin/cstecgi.c= gi. 2026-08-31 7.5 CVE-2026-51668 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-51668 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the getCloud= DownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthe= nticated attackers to obtain cloud firmware download state information via = sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 7.5 CVE-= 2026-51671 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51671 ] TOTOLINK--= TOTOLINK T6 Incorrect access control in the setNtpCfg function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time syn= chronization settings via sending a crafted POST request to /cgi-bin/cstecg= i.cgi. 2026-08-31 7.5 CVE-2026-51673 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-51673 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setWi= FiSignalCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenti= cated attackers to reduce wireless power or cause a Denial of Service (DoS)=
via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 7.5=
CVE-2026-51688 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51688 ] TOTOL= INK--TOTOLINK T6 Incorrect access control in the setStaticDhcpRules functio=
n of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to = add or change static DHCP rules via sending a crafted POST request to /cgi-= bin/cstecgi.cgi. 2026-08-31 7.5 CVE-2026-51694 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-51694 ] TOTOLINK--TOTOLINK T6 Incorrect access control in=
the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth= enticated attackers to alter dynamic DNS state via sending a crafted POST r= equest to /cgi-bin/cstecgi.cgi. 2026-08-31 7.5 CVE-2026-51695 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51695 ] TOTOLINK--TOTOLINK T6 Incorrect ac= cess control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748= _B20211015 allows unauthenticated attackers to delete port-forwarding rules=
via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 7.5=
CVE-2026-51716 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51716 ] TOTOL= INK--TOTOLINK T6 Incorrect access control in the delUrlFilterRules function=
of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to r= emove URL filtering rules via sending a crafted POST request to /cgi-bin/cs= tecgi.cgi. 2026-08-31 7.5 CVE-2026-51719 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-51719 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the s= howSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthentica= ted attackers to retrieve recent system logs via sending a crafted POST req= uest to /cgi-bin/cstecgi.cgi. 2026-08-31 7.5 CVE-2026-51735 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-51735 ] TOTOLINK--TOTOLINK T6 Incorrect acce=
ss control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B2021101=
5 allows unauthenticated attackers to reboot the local device and, on a mas= ter, fan out reboot commands to mesh slaves via sending a crafted MQTT mess= age to the cs_broker component. 2026-09-01 7.5 CVE-2026-51766 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51766 ] TOTOLINK--TOTOLINK T6 Incorrect ac= cess control in the setElinkQosConfig function of TOTOLINK T6 4.1.5cu.748_B= 20211015 allows unauthenticated attackers to modify privileged QoS policy o=
n the master device via sending a crafted MQTT message to the cs_broker com= ponent. 2026-09-01 7.5 CVE-2026-51768 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-51768 ] triggerdotdev--trigger.dev Trigger.dev versions before 4.5=
.2 fail to validate environment membership during run replay operations, al= lowing authenticated attackers to inject task runs into arbitrary environme= nts. Attackers can replay their own runs into other organizations' or proje= cts' environments to consume victim resources and pollute run history. 2026= -09-04 8.5 CVE-2026-85651 [
https://www.cve.org/CVERecord?id=3DCVE-2026-856=
51 ] Trimble --TM4WEB 21.4.0.4 In Trimble TM4WEB 21.4.0.4, the external bil=
l viewer endpoint is vulnerable to reflected cross-site scripting via injec= tion in a arbitrary parameter appended to the URL. 2026-09-04 7.1 CVE-2022-= 35499 [
https://www.cve.org/CVERecord?id=3DCVE-2022-35499 ] TRtek Technolog= ical Products Computer Software Hardware Industry and Trade Limited Company= --Products's Store Improper neutralization of special elements used in an S=
QL command ('SQL injection') vulnerability in TRtek Technological Products = Computer Software Hardware Industry and Trade Limited Company Products's St= ore allows SQL Injection. This issue affects Products's Store: before 03063= 1b2. 2026-09-01 9.8 CVE-2026-18210 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-18210 ] TrustedSite--TrustedSite Unauthenticated Cross Site Scripting=
(XSS) in TrustedSite <=3D 1.2.5 versions. 2026-09-02 7.1 CVE-2026-81771 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-81771 ] tsi-coop--tsi-dpdp-cms =
A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. T= his vulnerability affects unknown code. The manipulation results in client-= side enforcement of server-side security. The attack can be launched remote= ly. The exploit has been released to the public and may be used for attacks=
. Upgrading to version 0.5.1 is able to resolve this issue. It is recommend=
ed to upgrade the affected component. 2026-09-02 7.3 CVE-2026-84841 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84841 ] Tycon Systems--TPDIN-Monitor= -WEB3=C2=A0
=C2=A0 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulner= able to a Missing Authorization vulnerability. This could allow an attacker=
to extract system credentials, configurations, or flash contents. 2026-09-=
04 8.1 CVE-2026-82684 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82684 ]=
Tycon Systems--TPDIN-Monitor-WEB3=C2=A0
=C2=A0 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulner= able to a cross-site request forgery vulnerability. This could allow an att= acker to perform state changing operations on the device. 2026-09-04 8.8 CV= E-2026-82712 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82712 ] Uncode--= Uncode Unauthenticated Cross Site Scripting (XSS) in Uncode <=3D 2.12.7 ver= sions. 2026-08-31 7.1 CVE-2026-81291 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-81291 ] UnderConstructionPage--Under Construction Unauthenticated C= ross Site Scripting (XSS) in Under Construction <=3D 5.82 versions. 2026-09= -03 7.1 CVE-2026-81295 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81295 =
] undici--undici undici's WebSocket client crashes the whole Node.js proces=
s during the opening handshake when a server responds with a subprotocol th=
at the client never requested. A default WebSocket connection sends no subp= rotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol=
header, undici dereferences a null value while checking it against the req= uested list and throws an uncaught TypeError. Because that code runs inside=
a microtask with no surrounding error handling, the exception propagates a=
nd terminates the process under Node's default behavior, instead of gracefu= lly failing the connection as required by the WebSocket protocol. Any appli= cation that opens a WebSocket to an attacker-controlled or compromised serv= er, or over a plaintext connection subject to a machine-in-the-middle, can =
be crashed remotely without authentication in the default configuration. Th=
is affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1=
, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.=
1, or 8.10.2. 2026-09-04 7.5 CVE-2026-19534 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-19534 ] undici--undici undici's BalancedPool constructor pas= ses its entire options object through an internal deep-clone that serialize=
s and reparses the value as JSON. Because JSON cannot represent functions, = any function-valued TLS option, such as a caller-supplied checkServerIdenti=
ty callback or a custom connector inside the connect option, is silently di= scarded before it reaches the TLS layer. As a result a peer whose certifica=
te the application's custom checkServerIdentity was written to reject, but = which still passes Node's default hostname and chain checks, is accepted wh=
en reached through BalancedPool. The Client, Pool, and Agent dispatchers ar=
e not affected because they extract the connect and tls options before clon= ing. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 u=
p to 8.10.2, and only when the application supplies a function-valued conne=
ct or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or = 8.10.2. 2026-09-04 7.4 CVE-2026-84961 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84961 ] undici--undici undici 8.10.0 omits the destination origin = from the cache and request-deduplication keys when the cache or deduplicate=
interceptor is composed directly onto a Client or Pool. Because the intern=
al cache key falls back to an empty origin string, a cacheable or in-flight=
response from one upstream origin is returned for a request to a different=
, trusted origin whenever the method, path, and relevant headers match, whi=
ch permits cross-origin information disclosure and persistent cache poisoni= ng. The reporter demonstrated a full authentication bypass in which a JWT s= igned with an attacker-controlled key was accepted as belonging to a truste=
d issuer, and the trusted origin was never contacted. This is a regression = introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. = Applications using an Agent, which carries the origin in its dispatch optio= ns, are not affected. Users should upgrade to undici 8.10.2. 2026-09-04 7.4=
CVE-2026-85152 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85152 ] Unida= ta--netcdf-c
=C2=A0 Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vuln= erability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a=
fixed 256-byte buffer without length validation. Attackers can craft HDF5 = files with oversized attribute names to overflow the destination buffer, ca= using memory corruption and crashes when applications enumerate attribute n= ames. 2026-09-04 7.8 CVE-2026-86095 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-86095 ] unopim--unopim UnoPim before 2.1.5 contains an authenticated=
file upload vulnerability that allows authenticated administrators to uplo=
ad arbitrary PHP files through the TinyMCE image upload endpoint due to mis= sing file extension and MIME type validation. Attackers can upload a PHP we=
b shell to the public storage disk and execute arbitrary operating system c= ommands on the server by accessing the uploaded file at the URL returned in=
the server response. 2026-09-02 7.2 CVE-2026-82524 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-82524 ] unopim--unopim UnoPim before 2.1.3 fails to = include integration store, update, and key-generation routes in its ACL map=
, allowing any admin user to bypass permission checks. Attackers with minim=
al admin privileges can create OAuth API integrations, mint client credenti= als, and escalate permissions by exploiting missing authorization validatio=
n in the Bouncer middleware. 2026-09-03 7.1 CVE-2026-85395 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-85395 ] uscnanbu--Welcart e-Commerce The Welc= art e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scri= pting via the 'custom_order' parameter in all versions up to, and including=
, 2.12.1 due to insufficient input sanitization and output escaping. This m= akes it possible for unauthenticated attackers to inject arbitrary web scri= pts in pages that will execute whenever a user accesses an injected page. T=
he injected payload is delivered via the guest checkout form, requiring no = authentication, and executes when an administrator views the affected order=
in the WordPress admin panel. 2026-09-01 7.2 CVE-2026-19914 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-19914 ] usememos--memos Memos versions 0.26=
.0 through 0.30.0 fail to revoke refresh tokens when a user changes their p= assword, allowing attackers to maintain account access. An attacker with a = stolen refresh token can call the RefreshToken RPC to obtain new access tok= ens and rotate the refresh token indefinitely, bypassing the password chang=
e security measure. 2026-09-01 8.1 CVE-2026-84203 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84203 ] User Frontend--User Frontend The User Frontend=
WordPress plugin before 4.3.11 does not prevent user-supplied field values=
from being deserialized when a submitted post is reopened in its frontend = editing form, allowing authenticated users with subscriber-level access and=
above to perform PHP Object Injection, which may lead to remote code execu= tion when a suitable gadget chain is present on the site. 2026-09-02 8.8 CV= E-2026-19116 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19116 ] util-lin= ux--util-linux util-linux versions through 2.41.5 and 2.42.2 fail to check = mount helper exit status before running post-mount hooks, allowing unprivil= eged users to execute privileged operations on pre-existing filesystems. At= tackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesyste=
ms with inherited suid bits or modify target inode permissions after a help=
er fails, achieving privilege escalation. 2026-09-03 7.8 CVE-2026-76642 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-76642 ] varunvairavanlc--LeadCon= nector Unauthenticated Cross Site Scripting (XSS) in LeadConnector <=3D 4.0=
.5 versions. 2026-08-31 7.1 CVE-2026-81298 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-81298 ] vercel--next.js Next.js is a React framework for buil= ding full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Nex= t.js applications using Pages Router or App Router without Cache Components=
on Windows-hosted servers do not consistently escape backslashes in route = segments before constructing incremental-cache paths. In packages/next/src/= shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/ser= ver/lib/incremental-cache/file-system-cache.ts, a remote request can supply=
encoded Windows path separators that traverse outside the intended cache r= oot and expose private build data, including the server-reference-manifest = encryption key. Disclosure of that key can enable remote code execution in = the affected application. This issue is fixed in versions 15.5.24 and 16.3.=
3. 2026-09-01 9 CVE-2026-75604 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-75604 ] Voltronic Power--SNMP Web Pro Voltronic Power SNMP Web Pro 1.1 co= ntains an unauthenticated remote code execution vulnerability in the upload= .cgi firmware update endpoint that allows remote attackers to execute arbit= rary commands as root by uploading a crafted tar archive without valid cred= entials. Attackers can supply a malicious tar archive containing arbitrary = executable files that are extracted to a privileged directory and executed =
as root, achieving full system compromise. 2026-09-04 9.8 CVE-2026-44402 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-44402 ] WatchMan-Site7--WatchMa= n-Site7 The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict=
access to its debugging console, which executes user-supplied PHP code, al= lowing any authenticated user, such as a subscriber, to run arbitrary code =
on the server. 2026-09-02 9.9 CVE-2026-77009 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-77009 ] WC Lovers--WCFM Marketplace Unauthenticated SQL Inj= ection in WCFM Marketplace <=3D 3.8.1 versions. 2026-09-02 9.3 CVE-2026-812=
86 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81286 ] WC Lovers--WCFM Me= mbership Subscriber Privilege Escalation in WCFM Membership <=3D 2.11.11 ve= rsions. 2026-09-03 7.1 CVE-2026-84756 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84756 ] webilia--Listdom: AI-powered Business Directory with Class= ifieds Ads Listings The Listdom: AI-powered Business Directory with Classif= ieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site S= cripting via 'lsd[displ][style]' Parameter in all versions up to, and inclu= ding, 5.8.1 due to insufficient input sanitization and output escaping. Thi=
s makes it possible for unauthenticated attackers to inject arbitrary web s= cripts in pages that will execute whenever a user accesses an injected page=
. Exploitation requires the Listdom Pro add-on to be active and the 'Displa=
y Options Per Listing' displ setting to be enabled, both of which are non-d= efault configurations. 2026-09-01 7.2 CVE-2026-19796 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-19796 ] WebKit--WebKit A flaw was found in WebKitGT=
K. Processing malicious web content can cause memory corruption due to impr= oper memory handling. 2026-08-31 8.8 CVE-2026-83596 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-83596 ] Webstudio --Webstudio=C2=A0
=C2=A0 Webstudio through 0.296.0 contains an unauthenticated server-side re= quest forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset p= roxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can=
supply arbitrary URLs to these endpoints to read cloud instance metadata, = access internal services, and perform network reconnaissance on the instanc=
e infrastructure. 2026-09-05 8.6 CVE-2026-86119 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-86119 ] weDevs--WP User Frontend Subscriber PHP Object I= njection in WP User Frontend <=3D 4.3.10 versions. 2026-09-02 8.8 CVE-2026-= 81283 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81283 ] Westermo--WeOS = Westermo WeOS 5.x starting from 5.24 allows OS command injection via a medi=
a definition. 2026-09-02 7.6 CVE-2025-46418 [
https://www.cve.org/CVERecord= ?id=3DCVE-2025-46418 ] wordplus--BP Better Messages Unauthenticated Cross S= ite Scripting (XSS) in BP Better Messages <=3D 2.15.27 versions. 2026-09-03=
7.1 CVE-2026-84812 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84812 ] W= ordPress Plugin --Ninja Forms
=C2=A0 The Ninja Forms - The Contact Form Builder That Grows With You plugi=
n for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater C= hild 'type' Confusion via Unmatched Array Key in all versions up to, and in= cluding, 3.15.1 due to insufficient input sanitization and output escaping.=
This makes it possible for unauthenticated attackers to inject arbitrary w=
eb scripts in pages that will execute whenever a user accesses an injected = page. Exploitation requires the Ninja Forms File Uploads add-on to be activ=
e, as the attack routes the unwhitelisted child entry through the File Uplo= ads handler to write an attacker-supplied HTML file containing arbitrary Ja= vaScript into any web-server-writable directory, including the site root, w= here it is served from the site's own origin. 2026-09-05 7.2 CVE-2026-19769=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-19769 ] WordPress Plugin--Dy= namiApps
=C2=A0 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable =
to Authentication Bypass to Account Takeover in all versions up to, and inc= luding, 3.29.12. This is due to the pre_update_value function lacking any c= apability or ownership check, and ActionPost::conditions_logic() short-circ= uiting its current_user_can('edit_post') authorization gate whenever the po=
st ID is non-numeric - such as the string user_1 - allowing unauthenticated=
form submissions to be routed to arbitrary user records without restrictio=
n. This makes it possible for unauthenticated attackers to overwrite any us= er's registered email address, including an administrator's, and then lever= age WordPress's native password-reset flow to fully take over the targeted = account. 2026-09-06 9.8 CVE-2026-75816 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-75816 ] WordPress Plugin--Gravity Forms
=C2=A0 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross= -Site Scripting via Post Body Field Value in all versions up to, and includ= ing, 2.10.5 due to insufficient input sanitization and output escaping. Thi=
s makes it possible for unauthenticated attackers to inject arbitrary web s= cripts in pages that will execute whenever a user accesses an injected page=
. The exploit survives save-time sanitization because wp_kses_post allows t=
he required HTML tags and attributes, and the client-side tooltip script re= -parses the browser-decoded aria-label value as innerHTML while only stripp= ing script elements, leaving onerror and other event-handler attributes ful=
ly intact and executable. 2026-09-05 7.2 CVE-2026-16649 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-16649 ] WordPress Plugin--HivePress=C2=A0
=C2=A0 The HivePress Authentication plugin for WordPress is vulnerable to A= uthentication Bypass via the access_token parameter in all versions up to, = and including, 1.1.4. This is due to the authenticate_user function's Faceb= ook authenticator resolving third-party identity by forwarding the attacker= -supplied access_token to the Facebook Graph API and trusting the returned = email and ID verbatim, without performing any application ID or audience va= lidation - specifically, no /debug_token verification and no comparison of = the token's app_id against the configured hp_facebook_app_id. This makes it=
possible for unauthenticated attackers to authenticate as any existing Wor= dPress user, including administrators, whose email address is associated wi=
th a Facebook account for which the attacker can obtain any valid access to= ken. Important Note: To exploit the vulnerability, the attacker must obtain=
the victim's access token. 2026-09-06 7.5 CVE-2026-18056 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-18056 ] WordPress Plugin--Hummingbird - Speed = Optimization, Caching, Minify, Compress & CDN=C2=A0
=C2=A0 The Hummingbird - Speed Optimization, Caching, Minify, Compress & CD=
N plugin for WordPress is vulnerable to Remote Code Execution in all versio=
ns up to, and including, 3.21.0 via the log_msg() function in core/modules/= class-page-cache.php. The page-cache debug log is written to wp-content/wph= b-logs/page-caching-log.php, a directly web-accessible PHP file that is sup= posed to be protected by a leading '<?php die(); ?>' header. That header is=
guarded by class_exists( 'Filesystem' ), which can never match because cla= ss_exists() resolves string arguments in the global namespace while the cla=
ss is Hummingbird\Core\Filesystem; when the log is created during a front-e=
nd request the header is therefore omitted entirely. get_cookies() then wri= tes the raw name of any cookie matching the wphb_cache_ prefix into that fi=
le without sanitization. This makes it possible for unauthenticated attacke=
rs to write arbitrary PHP into the log file with a single anonymous request=
and execute it by requesting the file directly, resulting in full remote c= ode execution. Exploitation requires the site administrator to have enabled=
Page Caching with the Debug Log option (non-default), and the log file to =
be created during a front-end request - a state reached by the plugin's own=
'Clear logs' action, any cache flush, or unattended via the plugin's daily=
log-rotation cron, which can strip the protective header from an existing = log file. 2026-09-05 9.8 CVE-2026-83627 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-83627 ] WordPress Plugin--IPGP Visitors Origin
=C2=A0 The IPGP Visitors Origin WordPress plugin before 1.6 does not saniti=
se or escape user input before reflecting it back in the HTTP response, all= owing unauthenticated attackers to perform Reflected Cross-Site Scripting a= ttacks against users who are tricked into submitting a crafted request. 202= 6-09-05 7.1 CVE-2026-81404 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81= 404 ] WordPress Plugin--iubenda=C2=A0 The iubenda | All-in-one Compliance f=
or GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via Comment Content in all versions up to, and = including, 3.13.4 due to insufficient input sanitization and output escapin=
g. This makes it possible for unauthenticated attackers to inject arbitrary=
web scripts in pages that will execute whenever a user accesses an injecte=
d page. The exploit works by embedding KSES-allowed markup such as abbr tit=
le attributes and HTML comments in a submitted comment so that the global s= trtr() substitution strips substrings from an inert tag, mutating it into a=
n executable element such as an img onerror handler that runs in the WordPr= ess origin for any visitor, including logged-in administrators. 2026-09-05 = 7.2 CVE-2026-77263 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77263 ] Wo= rdPress Plugin--iubenda=C2=A0
=C2=A0 The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent +=
more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via=
Comment Content via AdSense Regex Rewrite in all versions up to, and inclu= ding, 3.13.4 due to insufficient input sanitization and output escaping. Th=
is makes it possible for unauthenticated attackers to inject arbitrary web = scripts in pages that will execute whenever a user accesses an injected pag=
e. This vulnerability only manifests when the 'Secondary' parser engine is = active (parser_engine=3Ddefault); it does not exist under the default 'new'=
DOM-based parser engine. 2026-09-05 7.2 CVE-2026-77233 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-77233 ] WordPress Plugin--JetFormBuilder - Dynam=
ic Blocks
=C2=A0 The JetFormBuilder - Dynamic Blocks Form Builder WordPress plugin be= fore 3.6.5.2 does not perform authorisation checks when resolving request-d= erived data during page rendering, allowing unauthenticated users to read a= rbitrary user, post and term properties and metadata, including password ha= shes, private and draft content, and secrets other JetFormBuilder - Dynamic=
Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata. 202= 6-09-05 7.5 CVE-2026-19858 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19= 858 ] WordPress Plugin--Kirki
=C2=A0 The Kirki WordPress plugin before 6.3.0 does not hold back every spe= lling of the HTML entities it decodes when rendering, allowing unauthentica= ted users to store JavaScript in a comment which then runs in the session o=
f anyone viewing a page that displays it, including an administrator, and o=
n every page of the site when its header or footer is built to show comment=
s. 2026-09-06 7.5 CVE-2026-84219 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84219 ] WordPress Plugin--Mail Mint - Email Marketing, Newsletter, Emai=
l Automation & WooCommerce Email
=C2=A0 The Mail Mint - Email Marketing, Newsletter, Email Automation & WooC= ommerce Emails plugin for WordPress is vulnerable to PHP Object Injection i=
n all versions up to, and including, 1.31.0 via deserialization of untruste=
d input in the 'handle_form_submission' function. This makes it possible fo=
r unauthenticated attackers to inject a PHP Object. The additional presence=
of a POP chain allows attackers to execute code on the server. The vulnera= bility was partially patched in version 1.23.1. 2026-09-05 9.8 CVE-2026-101=
96 [
https://www.cve.org/CVERecord?id=3DCVE-2026-10196 ] WordPress Plugin--= MemberDash
=C2=A0 The MemberDash plugin for WordPress is vulnerable to Insecure Direct=
Object Reference in all versions up to, and including, 1.8.5 via the 'id' = parameter due to missing validation on a user controlled key. This makes it=
possible for unauthenticated attackers to change the password of any WordP= ress user, including administrators, by supplying an arbitrary user ID duri=
ng registration, and take over their account without any notification sent =
to the victim. 2026-09-06 9.8 CVE-2026-16310 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-16310 ] WordPress Plugin--Mstore Api
=C2=A0 The Mstore Api plugin for WordPress is vulnerable to Authentication = Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due=
to missing cryptographic signature verification in the FirebasePhoneAuthHe= lper::verify_id_token() function, which decodes and validates Firebase ID t= oken claims (alg, kid, aud, iss) but never calls openssl_verify() or any eq= uivalent to validate the JWT signature against Google's actual public key c= ertificates. This makes it possible for unauthenticated attackers to forge =
a Firebase Phone Auth JWT signed with a self-generated RSA key pair and imp= ersonate any phone number, resulting in unauthorized access to existing Wor= dPress accounts or creation of new arbitrary accounts. 2026-09-05 9.8 CVE-2= 026-13447 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13447 ] WordPress P= lugin--Nokri-Job Board
=C2=A0 The Nokri - Job Board WordPress Theme theme for WordPress is vulnera= ble to unauthorized modification of data due to a missing capability check =
on the 'nokri_account_member_permissions' function in all versions up to, a=
nd including, 1.6.4. This makes it possible for authenticated attackers, wi=
th Subscriber-level access and above, to add new Subscriber users with empl= oyer account member permissions, who in turn can escalate privileges by upd= ating the email address of any user, including Administrator users. 2026-09= -05 8.8 CVE-2025-9049 [
https://www.cve.org/CVERecord?id=3DCVE-2025-9049 ] = WordPress Plugin--Post Grid and Gutenberg Blocks - ComboBlocks
=C2=A0 The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPres=
s is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3=
.1 via several functions in the ~/includes/blocks/form-wrap/function.php fi= le. This makes it possible for unauthenticated attackers to execute actions=
with hooks in WordPress, granted no other security controls are present in=
the function. 2026-09-05 9.8 CVE-2024-11080 [
https://www.cve.org/CVERecor= d?id=3DCVE-2024-11080 ] WordPress Plugin--QuickCal=C2=A0
=C2=A0 The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site=
Scripting via Custom Field Parameters in all versions up to, and including=
, 1.0.20 due to insufficient input sanitization and output escaping. This m= akes it possible for unauthenticated attackers to inject arbitrary web scri= pts in pages that will execute whenever a user accesses an injected page. T=
he nonce guarding the unauthenticated booked_add_appt AJAX action is public=
ly embedded on any page rendering the booking calendar shortcode, making it=
trivially obtainable by unauthenticated attackers without any prior accoun=
t or privilege. 2026-09-05 7.2 CVE-2026-15984 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-15984 ] WordPress Plugin--RegistrationMagic=C2=A0
=C2=A0 The RegistrationMagic WordPress plugin before 6.0.9.9 does not verif=
y which application a Facebook access token was issued to before accepting =
it as proof of identity, allowing unauthenticated attackers to log in as an=
existing user whose token they can obtain, or to create and log into a new=
account even when user registration is disabled. 2026-09-05 8.8 CVE-2026-7= 7826 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77826 ] Wordpress Plugin= --SEO Flow
=C2=A0 The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not co= rrectly validate the credential supplied with its API requests, allowing un= authenticated users to be served as the administrator who configured the SE=
O Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. = Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.= 0.3 to have been configured, which is its normal operating state. 2026-09-0=
5 9.8 CVE-2026-78362 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78362 ] = WordPress Plugin--Spam protection, Honeypot, Anti-Spam by CleanTalk
=C2=A0 The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for Wor= dPress is vulnerable to Stored Cross-Site Scripting via Comment Content ari= a-label Placeholder in all versions up to, and including, 6.86 due to insuf= ficient input sanitization and output escaping. This makes it possible for = authenticated attackers, with custom-level access and above, to inject arbi= trary web scripts in pages that will execute whenever a user accesses an in= jected page. The payload is deliverable via unauthenticated comment submiss= ion and executes exclusively for non-logged-in visitors; if comment moderat= ion is enabled, an approving moderator must first publish the comment befor=
e the script reaches other users. 2026-09-05 7.2 CVE-2026-77830 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-77830 ] WordPress Plugin--SureCart
=C2=A0 The SureCart WordPress plugin before 4.6.3 does not ensure that the = account affected by a customer update is the same account its permission ch= eck authorised, allowing users with a subscriber-level account to change an= other user's email address, including an administrator's, and take over tha=
t account via a password reset. It further allows an attacker-controlled cu= stomer record to be associated with an arbitrary user, and discloses custom=
er identifiers and email addresses to any authenticated user, which togethe=
r make the takeover reachable from a subscriber-level account alone. 2026-0= 9-06 8.8 CVE-2026-18480 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18480=
] WordPress Plugin--SureForms
=C2=A0 The SureForms - Contact Form Builder, AI Forms, Payment Form, Survey=
& Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia Text Field Entity-Encoded Payload in all versions up to, and including, = 2.12.2 due to insufficient input sanitization and output escaping. This mak=
es it possible for unauthenticated attackers to inject arbitrary web script=
s in pages that will execute whenever a user accesses an injected page. 202= 6-09-05 7.2 CVE-2026-18406 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18= 406 ] WordPress Plugin--The Contact Form
=C2=A0 The Contact Form by Supsystic plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via IP Address Header in all versions up to, an=
d including, 1.10.2 due to insufficient input sanitization and output escap= ing. This makes it possible for unauthenticated attackers to inject arbitra=
ry web scripts in pages that will execute whenever a user accesses an injec= ted page. An unauthenticated attacker can first call the 'updateNonce' acti=
on - which is accessible without authentication due to its absence from the=
plugin's permission list - to obtain a valid nonce, then submit a contact = form with a malicious payload in a spoofed IP header such as X-Forwarded-Fo=
r. 2026-09-05 7.2 CVE-2026-83625 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-83625 ] WordPress Plugin--The Music Store
=C2=A0 The Music Store WordPress plugin before 1.4.5 does not sanitise and = escape user input before using it in a SQL statement, leading to a SQL inje= ction exploitable by unauthenticated users. 2026-09-05 8.6 CVE-2026-82304 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82304 ] WordPress Plugin--W3 T= otal Cache
=C2=A0 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via Comment Content via LazyLoad Background Mutator in all=
versions up to, and including, 2.10.5 due to insufficient input sanitizati=
on and output escaping. This makes it possible for unauthenticated attacker=
s to inject arbitrary web scripts in pages that will execute whenever a use=
r accesses an injected page. This requires the "Lazy Load Images" feature w= ith "Process background images" to be enabled, and the malicious comment to=
be approved by a moderator before execution is triggered. 2026-09-05 7.2 C= VE-2026-78438 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78438 ] WordPre=
ss Plugin--Welcart e-Commerce
=C2=A0 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Obj= ect Injection in all versions up to, and including, 2.12.1 via deserializat= ion of untrusted input in the Telecom EDY payment callback (usces_action_ac= ting_transaction). Unauthenticated attackers can store arbitrary 'reserve' = key/value pairs as order metadata during a public checkout, then invoke the=
callback with an attacker-chosen 'option' parameter to select and unserial= ize that metadata without any provider signature, source-address, transacti= on-identity or ownership check. A POP chain is present in the TCPDF library=
bundled with the plugin itself, so no additional plugin or theme is requir= ed. This makes it possible for unauthenticated attackers to delete arbitrar=
y files on the server, including wp-config.php, which can lead to remote co=
de execution when an attacker re-runs the WordPress installer against a dat= abase they control. Successful exploitation is contingent on an admin print= ing an invoice to trigger file deletion. 2026-09-05 8.8 CVE-2026-19887 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-19887 ] WordPress Plugin--WooComm= erce=C2=A0
=C2=A0 The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulne= rable to Privilege Escalation in all versions up to, and including, 10.7.1.=
This is due to missing capability checks and nonce verification on multipl=
e AJAX actions including wcap_save_connector_settings, wcap_send_manual_ema= il, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes=
it possible for authenticated attackers, with subscriber-level access and = above, to modify SMTP connector settings to route administrator recovery em= ails through an attacker-controlled server and intercept auto-login links t=
o gain full administrative access. The plugin's auto-login feature must be = enabled, which is the default configuration. 2026-09-05 8.8 CVE-2026-81543 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-81543 ] WordPress Plugins--HT=
Menu
=C2=A0 The HT Menu WordPress plugin before 1.2.7 does not perform any capab= ility or object-ownership check when saving navigation menu-item settings, = and does not escape those stored settings when the menu is rendered, allowi=
ng users with minimal permissions such as Subscribers to store JavaScript t= hat executes in the browser of any visitor, administrators included, who vi= ews the affected menu. 2026-09-05 8 CVE-2026-84935 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-84935 ] WordPress Plugins--JCH Optimize
=C2=A0 The JCH Optimize WordPress plugin before 6.0.1 does not perform a ca= pability check on one of its authenticated AJAX actions and lets the reques=
t choose which internal action runs, allowing any authenticated users such =
as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0=
.1 settings and store a script that executes in the browser of any visitor =
or administrator viewing the site. 2026-09-05 8 CVE-2026-84934 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84934 ] Worklenz--worklenz Worklenz throu=
gh 3.0.0 fails to properly validate the sort-field query parameter in pagin= ation helper functions, allowing authenticated users to inject arbitrary Po= stgreSQL expressions into ORDER BY clauses. Attackers can use time-based an=
d boolean-based blind SQL injection techniques to extract sensitive databas=
e content including password hashes from other tenants. This is an incomple=
te fix for CVE-2026-25947. 2026-09-03 8.1 CVE-2026-85388 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-85388 ] worschtebrot--Affiliate Super Assistent=
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored=
Cross-Site Scripting via the 'doCommentShortcode' function in all versions=
up to, and including, 1.10.2 due to insufficient input sanitization and ou= tput escaping. This makes it possible for unauthenticated attackers to inje=
ct arbitrary web scripts in pages that will execute whenever a user accesse=
s an injected page. 2026-09-01 7.2 CVE-2026-19573 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-19573 ] WP Legal Pages--WP Cookie Notice for GDPR, CCP=
A & ePrivacy Consent Unrestricted Upload of File with Dangerous Type vulner= ability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consen=
t allows Using Malicious Files. This issue affects WP Cookie Notice for GDP=
R, CCPA & ePrivacy Consent: from n/a through 4.4.1. 2026-08-31 10 CVE-2026-= 82970 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82970 ] WP Manage Ninja= --Fluent Forms Pro Add On Pack Unauthenticated Broken Access Control in Flu= ent Forms Pro Add On Pack <=3D 6.2.12 versions. 2026-08-31 7.5 CVE-2026-812=
96 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81296 ] WP Manage Ninja--F= luent Forms Pro Add On Pack Subscriber Privilege Escalation in Fluent Forms=
Pro Add On Pack <=3D 6.2.12 versions. 2026-08-31 7.5 CVE-2026-81297 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-81297 ] WP Swings--Upsell Order Bum=
p Offer for WooCommerce Unauthenticated Cross Site Scripting (XSS) in Upsel=
l Order Bump Offer for WooCommerce <=3D 3.1.5 versions. 2026-09-02 7.1 CVE-= 2026-81288 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81288 ] WPFunnels-= -Mail Mint Unauthenticated PHP Object Injection in Mail Mint <=3D 1.31.0 ve= rsions. 2026-09-03 9.8 CVE-2026-84753 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84753 ] wplegalpages--WPLP Cookie Consent Cookie Banner & Consent = Management for GDPR, CCPA & Google Consent Mode The WPLP Cookie Consent - C= ookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plug=
in for WordPress is vulnerable to arbitrary file upload due to missing file=
type validation in the saas_upload_logo() function combined with an author= ization bypass on the WPLP connector REST endpoints in all versions up to, = and including, 4.4.1. This makes it possible for unauthenticated attackers =
to upload arbitrary files on the affected site's server which may make remo=
te code execution possible. 2026-09-01 9.8 CVE-2026-75865 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-75865 ] wpmudev--Broken Link Checker The Broke=
n Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scri= pting via Comment Author URL / Link Log in all versions up to, and includin=
g, 2.4.13 due to insufficient input sanitization and output escaping. This = makes it possible for unauthenticated attackers to inject arbitrary web scr= ipts in pages that will execute whenever a user accesses an injected page. = Exploitation requires an administrator to perform the plugin's standard dis= miss-and-recheck workflow on a link submitted by the attacker via the WordP= ress comment author URL field, after which the attacker's HTTP server issue=
s a redirect to a URL containing an HTML/JavaScript payload that is stored = verbatim in the link log. 2026-09-02 7.2 CVE-2026-75528 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-75528 ] WSO2--WSO2 Open Banking AM The administr= ative operations within the Carbon Console do not adequately validate speci= fic user-supplied input. This oversight allows a malicious actor with admin= istrative privileges to inject and execute arbitrary code remotely. Success= ful exploitation enables a threat actor with administrative privileges and = Carbon Console access to execute remote arbitrary code through specific adm= inistrative operations, leading to a complete compromise of the affected sy= stem. 2026-09-03 8.4 CVE-2025-12737 [
https://www.cve.org/CVERecord?id=3DCV= E-2025-12737 ] WWBN--AVideo WWBN AVideo (current e01e41ecc and earlier) mak=
es three login-time security controls depend solely on the client-supplied = User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match H= TTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileAp= p") with no IP check or shared secret. An attacker who submits valid creden= tials and sets User-Agent: AVideoEncoder bypasses two-factor authentication=
, skips brute-force captcha escalation, and avoids being recorded in the lo= gin/device audit history. No patch is available at the time of publication.=
2026-09-01 9.1 CVE-2026-84479 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-84479 ] WWBN--AVideo WWBN AVideo fails to validate password recovery toke=
n expiration in userRecoverPassSave.json.php, allowing attackers to use exp= ired tokens to reset account passwords indefinitely. Attackers who obtain a=
recovery token can use it at any time to change the target account's passw= ord and gain full account access. 2026-09-01 9.8 CVE-2026-84480 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-84480 ] WWBN--AVideo WWBN AVideo contain=
s an authentication failure vulnerability where the video_id_hash credentia=
l is a non-expiring, non-revocable bearer token that grants full administra= tor session access to the video owner's account. Attackers who obtain a vid= eo_id_hash can replay it indefinitely to authenticate as the video owner wi=
th full privileges, and the credential remains valid even after the owner c= hanges their password. 2026-09-03 9.8 CVE-2026-85154 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-85154 ] WWBN--AVideo AVideo contains a cross-site r= equest forgery vulnerability in plugin/API/set.json.php that allows attacke=
rs to perform state-changing actions by crafting GET requests that bypass C= SRF protection. Attackers can navigate a victim's browser to a malicious UR=
L with API parameters to delete videos, deactivate accounts, or modify play= lists without user interaction. 2026-09-01 8.1 CVE-2026-83595 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-83595 ] WWBN--AVideo AVideo contains a mis= sing authentication vulnerability in plugin/Live/on_publish.php that allows=
unauthenticated attackers to mark arbitrary scheduled broadcasts as failed=
by sending crafted POST requests with schedule identifiers. Attackers can = exploit the unguarded RTMP callback endpoint to modify scheduled broadcast = status fields by supplying fabricated stream keys matching the pattern -ps-= <N>, silently canceling any scheduled live broadcast without credentials or=
authorization. 2026-09-01 8.2 CVE-2026-84187 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-84187 ] WWBN--AVideo WWBN AVideo through commit 9c39d8c8 c= ontains a cross-site request forgery vulnerability in the get_domain() and = isSameDomain() functions that fail to properly validate referer origins. At= tackers can forge requests from sibling subdomains or unparseable long-gTLD=
origins to perform administrative ObjectYPT writes including live server c= onfiguration changes. 2026-09-01 8.8 CVE-2026-84482 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-84482 ] WWBN--AVideo AVideo through commit c91b5975d=
contains a cross-site request forgery and path traversal vulnerability in = stopLive.php that allows attackers to delete directories by exploiting miss= ing token validation and unsanitized key parameter concatenation. Attackers=
can craft an image tag with a traversal payload like key=3D../../videos to=
trigger recursive deletion of the videos directory when an admin visits a = malicious page. 2026-09-03 8.1 CVE-2026-85160 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85160 ] WWBN--AVideo AVideo through version 29.0 contains =
an unauthenticated SQL injection vulnerability in the User_Location plugin'=
s regions.json.php and cities.json.php endpoints. The country and region GE=
T parameters are passed directly into SQL queries without escaping or prepa= red statement binding, allowing unauthenticated attackers to execute UNION-= based SQL injection to read arbitrary database contents including password = hashes and sensitive data. 2026-09-01 7.5 CVE-2026-84208 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-84208 ] WWBN--AVideo WWBN AVideo fails to valid= ate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers,=
allowing attackers to spoof the client address used by enforceRateLimit().=
Attackers can rotate the header value per request to bypass login rate lim= iting and perform unlimited credential guessing attacks. 2026-09-01 7.5 CVE= -2026-84476 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84476 ] WWBN--AVi= deo WWBN AVideo contains a path traversal vulnerability in the API get_api_= login_code endpoint that allows unauthenticated attackers to delete arbitra=
ry .log files by supplying directory traversal sequences in the code parame= ter. Attackers can exploit this to destroy audit logs and probe for file ex= istence on the server, with the vulnerability enabling both file deletion a=
nd information disclosure about the filesystem. 2026-09-01 7.3 CVE-2026-844=
78 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84478 ] WWBN--AVideo WWBN = AVideo contains a SQL injection vulnerability in the sort column parameter =
of the get.json.php endpoint with APIName=3Dchannels that allows unauthenti= cated attackers to order results by arbitrary database columns including us= ers.password and users.recoverPass. Attackers can exploit this ordering ora= cle to infer password hash values and recovery tokens, and trigger SQL erro=
rs that disclose the full query statement and database schema. 2026-09-03 7=
.5 CVE-2026-85155 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85155 ] WWB= N--AVideo WWBN AVideo through commit c91b5975d contains a server-side reque=
st forgery vulnerability in the set_api_userImages API endpoint that fails =
to validate profileImg and backgroundImg URLs before fetching them. Authent= icated API clients can supply internal URLs to fetch cloud metadata or inte= rnal services, with responses written to publicly accessible web paths for = retrieval. 2026-09-03 7.1 CVE-2026-85164 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85164 ] WWBN--AVideo
=C2=A0 WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg= .json.php that allows unauthenticated attackers to write files to arbitrary=
locations by supplying a caller-chosen path in the avideoRelativePath para= meter. Attackers can replay any previously issued ciphertext as a notifyCod=
e token, which is decrypted but never validated, to bypass authentication a=
nd write files to the application root and subdirectories. 2026-09-05 9.8 C= VE-2026-86189 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86189 ] WWBN--A= Video
=C2=A0 WWBN AVideo contains a broken access control vulnerability in videoV= iewsInfo endpoints that returns complete user records including password ha= shes, recovery tokens, and live session identifiers to unauthenticated call= ers when a hash parameter is provided. Attackers can use the disclosed sess= ion identifier to hijack viewer sessions, including administrator accounts,=
and obtain sensitive personal data for all video viewers. 2026-09-05 9.1 C= VE-2026-86190 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86190 ] X-Serie=
s Gateway--X-Series Gateway Firmware V6 An issue in X-Serie Gateway Firmwar=
e V6_00_05 allows a remote attacker to escalate privileges via the endpoint=
s /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi. 2026-09-04 9.1 CVE-2026= -75160 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75160 ] xorbitsai--inf= erence Xinference (affected commit 4a94832, v3.x) contains an unauthenticat=
ed arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-r= egister endpoint, which accepts a caller-supplied model_path parameter with= out authentication or path confinement. The endpoint reads and parses confi= g.json, tokenizer_config.json, and chat_template.jinja files at the supplie=
d path and reflects the parsed content back to the caller, allowing an unau= thenticated attacker to probe the server filesystem and extract content of = files with those names in any directory. 2026-09-04 7.5 CVE-2026-85668 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85668 ] XueZhiSi--Open Source Exa=
m System The teacher-end interface POST /api/teacher/user/delete/{id} in Xu= eZhiSi Open Source Exam System <=3D 3.9.0 contains a vertical privilege esc= alatio vulnerability. This interface accepts a user ID and then executes ge= tUserById(id), setDeleted(true), updateByIdFilter() in sequence, without an=
y validation of whether the current user has the authority to delete the ta= rget user. An authenticated teacher user (role=3D2) can delete an administr= ator account (role=3D3), constituting a vertical privilege escalation where=
a lower-privileged user performs a high-privileged operation. 2026-08-31 8=
.1 CVE-2026-75458 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75458 ] yac= y--yacy_search_server YaCy Search Server through 1.941 contains an XML exte= rnal entity injection vulnerability in SVG, FreeMind, and OpenSearch parser=
s that fail to disable external entity resolution. Attackers can publish ma= licious documents with DOCTYPE declarations containing SYSTEM entities poin= ting to local files, causing the crawler to exfiltrate file contents into t=
he searchable index. 2026-08-31 7.5 CVE-2026-82880 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-82880 ] YesWiki --YesWiki=C2=A0
=C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Yes= Wiki's public Bazar entry-listing APIs are vulnerable to unauthenticated SQ=
L injection in numeric query / queries filters. For Bazar fields whose valu=
e structure is numeric, YesWiki escapes the attacker-controlled filter valu=
e but inserts it into SQL without quotes or numeric validation. An unauthen= ticated attacker can inject boolean SQL expressions and infer database cont= ents from whether entries are returned. This issue has been patched in vers= ion 4.6.6. 2026-09-05 7.5 CVE-2026-52770 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-52770 ] YesWiki-- YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the=
{{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php=
) accepts a suppr[] array from POST and deletes every wiki page whose tag a= ppears in that array, with no authorization check anywhere in the action bo=
dy or in the page-deletion path it invokes. Combined with YesWiki's allow-b= y-default action ACL model, any user who has page write access, which is th=
e default for everyone (default_write_acl=3D'*') on a fresh install can per= manently delete arbitrary wiki pages, including the front page, admin pages=
, and pages owned by other users. This issue has been patched in version 4.= 6.6. 2026-09-05 9.1 CVE-2026-52766 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-52766 ] YesWiki--YesWiki YesWiki is a wiki system written in PHP. Pri=
or to version 4.6.6, YesWiki through the latest development branch contains=
a SQL injection vulnerability in ReactionManager::deleteUserReaction() tha=
t allows any authenticated user to inject arbitrary SQL via the {idreaction=
} and {id} URL path parameters. The parameters are concatenated directly in=
to a SQL LIKE clause without escaping or parameterization. This issue has b= een patched in version 4.6.6. 2026-09-05 8.8 CVE-2026-52775 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-52775 ] YesWiki--YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. From version 4.6.2 to befor=
e version 4.6.6, HttpSignatureService::verifySignature() checks the result =
of PHP's openssl_verify() with a loose boolean negation - if (!openssl_veri= fy(...)) { throw ... }. PHP's openssl_verify has four possible return value=
s: 1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules = make -1 a truthy value, so !(-1) =3D=3D=3D false, the throw is skipped, and=
the controller proceeds to processActivity(). Any condition that makes Ope= nSSL's EVP_VerifyFinal() return -1 triggers the bypass. The reachable conse= quence is the controller silently treats a failed verification as success a=
nd processes the attacker's payload. This issue has been patched in version=
4.6.6. 2026-09-05 8.2 CVE-2026-52767 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-52767 ] YesWiki--YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. From version 4.6.2 to befor=
e version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed p= ublicly with acl:"public" - accepts an HTTP Signature header whose keyId pa= rameter is a URL. HttpSignatureService::verifySignature() parses the header=
and immediately makes a server-side HTTP GET to that URL, before any crypt= ographic verification or URL validation. An unauthenticated remote attacker=
can therefore make YesWiki issue arbitrary outbound HTTP requests to any h= ost the server can reach - internal services, cloud-metadata endpoints (169= .254.169.254), intranet-only admin panels, etc. - and read enough back via = timing and error-message oracles to scan ports, enumerate services, and (on=
a real cloud instance) reach IAM metadata. The only deployment-side precon= dition is that ActivityPub be enabled on at least one Bazar form. This issu=
e has been patched in version 4.6.6. 2026-09-05 8.3 CVE-2026-52769 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-52769 ] YesWiki--YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. From version 4.2.0 to befor=
e version 4.6.6, ApiController::deletePage() interpolates a page tag retrie= ved from the database into a DELETE FROM =C2=A6_links WHERE to_tag =3D '$ta=
g' query without escaping. The page tag is attacker-controlled - the POST /= api/pages/{tag} API accepts arbitrary URL-encoded values, including single = quotes, and stores them. A low-privilege authenticated user can therefore c= reate a page whose tag is a SQL fragment, make the page non-orphaned via th=
e standard {{include page=3D"=C2=A6"}} link mechanism, and then invoke the = delete endpoint to execute arbitrary SQL inside the wiki database - includi=
ng time-based blind data exfiltration from any table. This issue has been p= atched in version 4.6.6. 2026-09-05 8.3 CVE-2026-52771 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-52771 ] YITH--YITH Request a Quote for WooCommerc=
e Premium Unauthenticated Broken Access Control in YITH Request a Quote for=
WooCommerce Premium < 4.46.0 versions. 2026-09-03 9.8 CVE-2026-84238 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-84238 ] zhenorzz--goploy Goploy is=
an open-source automation deployment system. In versions 1.17.5 and prior,=
Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in=
cmd/server/api/project/handler.go accept a project or project-file row id = from the JSON body and act on it without checking that the project belongs =
to the caller's namespace. The corresponding model.ProjectFile.GetData and = model.Project.GetData queries filter only by row id. A user holding the man= ager role (or any role that includes the FileSync / EditProject permission)=
in their own namespace can read, write, or delete files in any project acr= oss the install, and can rewrite any project's git remote URL by submitting=
the foreign id in the body. The git-URL primitive escalates to RCE on the = next deploy because Edit runs git remote set-url on the project's working t= ree. At time of publication, there are no known publicly available patches.=
2026-08-31 9.6 CVE-2026-53552 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-53552 ] zhenorzz--goploy Goploy is an open-source automation deployment s= ystem. Prior to version 1.18.0, a severe path traversal vulnerability exist=
s in its backend API endpoints, specifically /deploy/fileDiff (File Compare=
), when handling file paths provided by the client. This issue has been pat= ched in version 1.18.0. 2026-08-31 7.7 CVE-2026-53553 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-53553 ] zlib--zlib zlib versions 1.3.1.2 through 1= .3.2 contain a heap buffer overflow vulnerability in the gz_vacate() functi=
on when processing non-blocking gzwrite() operations with stale external bu= ffer pointers. Attackers can trigger the overflow by calling gzprintf() or = gzvprintf() after a write stall, causing an unchecked memmove() to write be= yond the internal input buffer boundary. 2026-09-03 7.4 CVE-2026-85091 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85091 ] Zohocorp--ManageEngine Pa= ssword Manager Pro Zohocorp ManageEngine Password Manager Pro versions befo=
re 13235, PAM360 versions before 8561, and Access Manager Plus versions bef= ore 4405 are vulnerable to an authenticated SQL Injection vulnerability. 20= 26-09-02 8.8 CVE-2026-14828 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 4828 ] ZTE--ZXDU68 S202 V5.0 Attackers can exploit command injection vulner= abilities to delete core system runtime files, causing the monitoring modul=
e to crash and become paralyzed; simultaneously, they can obtain root privi= leges to steal configuration passwords such as SNMP, thereby tampering with=
critical system parameters and triggering abnormal operation of the entire=
power system. 2026-08-31 9.6 CVE-2026-49003 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-49003 ]=20
Back to top [ #top ]
Medium Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info 2FastLabs--a= gent-squad A vulnerability was detected in 2FastLabs agent-squad up to 1.1.=
4. Affected by this vulnerability is the function AgentSquad.routeRequest o=
f the file agent-squad/typescript/src/orchestrator.ts of the component Stre= aming Agent Response Workflow. The manipulation results in resource consump= tion. It is possible to launch the attack remotely. The exploit is now publ=
ic and may be used. The project was informed of the problem early through a=
n issue report but has not responded yet. 2026-09-03 4.3 CVE-2026-85100 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-85100 ] Admidio--admidio Admidio=
is an open-source user management solution. In versions 5.0.11 and prior, = the modules/plugins.php endpoint handles plugin installation, uninstallatio=
n, and update operations via GET requests without CSRF token validation. Be= cause these are top-level navigations, browsers include SameSite=3DLax sess= ion cookies. An attacker crafts a malicious page that, when an authenticate=
d administrator visits it, triggers arbitrary plugin operations. The uninst= all operation executes DROP TABLE SQL scripts and destroys plugin data. Thi=
s issue has been patched via commit 056b1bd. 2026-09-04 5.2 CVE-2026-53760 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-53760 ] agentverus--agentveru= s-scanner agentverus-scanner fails to analyze compiled Python bytecode file=
s in companion code directories, allowing attackers to bypass security scan= ning by shipping malicious __pycache__ entries alongside benign source file=
s. Attackers can execute arbitrary Python bytecode on import while the scan= ner reports a CERTIFIED verdict with high trust scores in both static and s= emantic analysis modes. 2026-09-02 6.5 CVE-2026-84811 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-84811 ] AirAsia--MOVE App A vulnerability was dete= cted in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the f= unction com.airasia.core.utils.RealPathUtil.getRealPath of the component co= m.airasia.mobile. Performing a manipulation of the argument _display_name r= esults in path traversal. The attack requires a local approach. The exploit=
is now public and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-09-02 4.4 CVE-2026-84431 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84431 ] Ajaxify Comments--Ajaxif=
y Comments The Ajaxify Comments WordPress plugin before 3.2 is vulnerable t=
o HTTP Header Injection due to insufficient input sanitization and output e= scaping on user-supplied data. This makes it possible for unauthenticated a= ttackers to inject arbitrary HTTP headers. 2026-09-02 5.4 CVE-2026-2811 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-2811 ] All in One SEO--All in On=
e SEO The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise = and escape some content stored in posts before rendering it back in the pos=
t editor, which could allow users with the contributor role and above to pe= rform Stored Cross-Site Scripting attacks that trigger when a higher privil= eged user edits the post. 2026-09-02 6.8 CVE-2026-82884 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-82884 ] Amazon --awslabs postgres-mcp-server=C2=
=A0
=C2=A0 An incomplete list of disallowed inputs in the SQL validation compon= ent in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow =
an unauthenticated actor to modify data beyond the read-only scope by placi=
ng crafted SQL into the content that is submitted when an authenticated use=
r interacts with the MCP server. To remediate this issue, users should upgr= ade to version 1.1.7 or above. 2026-09-04 6.5 CVE-2026-85787 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-85787 ] andrii-kryvoviaz--slink Slink befor=
e 1.12.3 fails to properly authorize access to image comment endpoints, all= owing unauthenticated attackers to read comment threads via GET /api/image/= {imageId}/comments and server-sent-events subscriptions. Attackers who obta=
in image IDs out of band can retrieve full comment threads on public images=
and subscribe to live comment updates without authentication or authorizat= ion checks. 2026-09-04 5.3 CVE-2026-85605 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85605 ] apache -- shiro When Apache Shiro is used with the Jak= arta EE integration module, a low-privileged user can craft an HTTP request=
that causes the server to initiate a connection to an attacker-controlled = URL and transmit attacker-controlled data. This vulnerability affects Apach=
e Shiro versions 2.x through 3.0.0 only in deployments that use the Jakarta=
EE integration module. Mitigation: Upgrade to version 3.0.1 or later, whic=
h fixes the issue. + Alternatively, you can set the `org.apache.shiro.form-= resubmit-host` (String) and `org.apache.shiro.form-resubmit-port` (Integer)=
system properties to restrict the host and port that Shiro will connect to=
when resubmitting a form. 2026-08-31 6.5 CVE-2026-58301 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-58301 ] apache -- wicket Improper neutralizatio=
n of input during web page generation in Apache Wicket. org.apache.wicket.m= arkup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoic=
e, writes the body of the default option - the entry shown when no choice i=
s selected - into the markup as it is, while every other option body in the=
same select is escaped according to the escape-model-strings setting. The = body comes from getNullValidDisplayValue() or getNullKeyDisplayValue(), bot=
h of which are protected, so what they return is not necessarily the plain = text the default implementation reads from a resource bundle. An applicatio=
n is affected where it overrides one of those methods and returns a value h= olding data an attacker can influence, or where its own nullValid or null b= undle entry holds such a value. The bundles shipped with Wicket contain pla=
in text. RadioChoice overrides getDefaultChoice to emit no default option a=
nd is not affected. As a workaround, escape the value in the override. This=
issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through=
9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.5.=
0 onwards are also affected. Users are recommended to upgrade to version 8.= 19.0, 9.24.0 or 10.11.0, which fix the issue. 2026-08-31 6.1 CVE-2026-76986=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-76986 ] apache -- wicket Imp= roper validation of resource URL attributes in Apache Wicket allows an unau= thenticated remote attacker to read files from the web application, includi=
ng files under WEB-INF that the servlet container would not otherwise serve=
. The locale, style and variation attributes decoded from a package resourc=
e URL are spliced into the resource lookup path without being checked for p= ath separators. The IPackageResourceGuard - whose rejection of .. is one of=
the two intended controls - is applied to the resource name before those a= ttributes are appended, and WebApplicationPath rejects only paths literally=
beginning with WEB-INF/. Neither control ever inspects the attacker-contro= lled portion of the path. On servlet containers that normalize .. in Servle= tContext.getResource(), a crafted request therefore escapes the intended pa= ckage directory. The set of readable files is limited to the file extension=
s permitted by the configured IPackageResourceGuard. The default SecurePack= ageResourceGuard permits only js, css, png, jpg, jpeg, gif, ico, cur, map, = html, txt, swf, bmp, svg, avif, eot, ttf, woff and woff2, which excludes co= nfiguration formats. Applications that have added patterns to the guard, or=
replaced it with the blocklist-based PackageResourceGuard, can additionall=
y disclose configuration files such as web.xml. Independently of the extens= ion, the lookup performed before the guard runs acts as an existence oracle=
for arbitrary paths. This issue affects Apache Wicket 8.18.0 and before, 9= .23.0 and before and 10.10.0 and before. Users are recommended to upgrade t=
o version 8.19.0, 9.24.0 or 10.11.0, which fix the issue. Users of Apache W= icket 7.x or older, which are no longer supported, should upgrade to a supp= orted version. 2026-08-31 5.3 CVE-2026-70449 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-70449 ] apache -- wicket AjaxEditableChoiceLabel in wicket-= extensions, when constructed with a non-null IChoiceRenderer, writes the di= splay value obtained from that renderer into the label's markup without app= lying the HTML escaping Wicket performs by default for component model valu= es. An attacker who can influence the choice or model data rendered by such=
a label can inject HTML or script that executes in the browser of any user=
who views the page. The same value is correctly escaped when the component=
's dropdown editor renders it as an option, so only the label rendering is = affected. AjaxEditableLabel, AjaxEditableChoiceLabel and AjaxEditableMultiL= ineLabel write the value returned by the protected defaultNullLabel() metho=
d into the label's markup the same way when the component's model is empty,=
while the model value they show otherwise is escaped. The default implemen= tation returns a constant, so an application is affected where it overrides=
that method and returns a value an attacker can influence. Neither value c= ould be escaped by configuration, because escapeModelStrings had no effect =
on any of the three components: it is read by the label they render with ra= ther than by the component itself, and nothing carried the setting across. = This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 thr= ough 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases are a= lso affected; the display value from the renderer since 6.22.0 and the null=
label since 1.4.0. Users are recommended to upgrade to version 8.19.0, 9.2= 4.0 or 10.11.0, which fix the issue. 2026-08-31 5.4 CVE-2026-75802 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-75802 ] apache -- wicket Improper neu= tralization of input during web page generation in Apache Wicket. org.apach= e.wicket.markup.html.form.Button clears the escape-model-strings flag in it=
s constructor, so that the value attribute it writes is not encoded twice -=
ComponentTag already encodes attribute values when it writes the tag. That=
reasoning holds only for the attribute. When the component is attached to =
a <button> element rather than an <input>, it writes its model object into = the element body instead, and nothing encodes an element body, so markup in=
the model is rendered as markup. An application is affected where it rende=
rs a Button on a <button> element and that button's model holds data an att= acker can influence. Wicket cannot determine where a model value comes from=
, so whether it reaches the page from a request or from storage is a proper=
ty of the application. The subclasses that inherit this constructor - AjaxB= utton, AjaxFallbackButton and WizardButton - are affected on the same terms=
. As a workaround, calling setEscapeModelStrings(true) on a button that ren= ders as a <button> element escapes the body correctly, and does not cause d= ouble encoding, because the value attribute is written only for <input> ele= ments. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.= 0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported release=
s from 6.25.0 and 7.5.0 onwards are also affected. Users are recommended to=
upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue. 2026-08= -31 5.4 CVE-2026-76982 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76982 =
] apache -- wicket Improper neutralization of input during web page generat= ion in Apache Wicket. The <wicket:label> tag is provided by org.apache.wick= et.markup.html.form.AutoLabelTextResolver, which is registered by default i=
n every WebApplication. The resolver writes the label it finds into the mar= kup as it is, and reads no escaping setting at all, so markup in a label is=
rendered as markup. When the label comes from the labelled component's lab=
el model, set through FormComponent#setLabel(IModel), it is written to the = markup unescaped.=C2=A0An application is affected where the label of a form=
component holds data an attacker can influence. Wicket cannot determine wh= ere a model value comes from, so whether it reaches the page from a request=
or from storage is a property of the application. There is no workaround. = Unlike every other rendering path in Wicket, the resolver never consulted t=
he escape-model-strings setting, so an application had no way to ask for th=
e label to be escaped. The body of a <wicket:label> tag is markup by design=
and is not affected; it remains the supported way to place markup in a lab= el. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0=
through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases f= rom 1.5.0 onwards are also affected. Users are recommended to upgrade to ve= rsion 8.19.0, 9.24.0 or 10.11.0, which fix the issue. 2026-08-31 5.4 CVE-20= 26-76983 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76983 ] apache -- wi= cket Improper neutralization of input during web page generation in Apache = Wicket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta> a=
nd <link> header tags. It escaped the attribute names it wrote, but ran the=
attribute values through a replacement of " with \". A backslash before a = double quote means nothing in HTML, so a value containing a double quote en=
ds its own attribute and what follows is parsed as further attributes of th=
e generated tag. An application is affected where it supplies an attribute = value holding data an attacker can influence, through addTagAttribute or th=
e forMetaTag and forLinkTag factory methods. A value may be given as an IMo= del, so it is not necessarily a literal. There is no setting to change; an = application can only avoid supplying a value that contains a double quote. = Note that these values have never been escaped effectively: before the chan=
ge released in 6.24.0, 7.4.0 and 8.0.0 they were written with no escaping a=
t all. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.= 0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported release=
s from 6.17.0 onwards are also affected. Users are recommended to upgrade t=
o version 8.19.0, 9.24.0 or 10.11.0, which fix the issue. 2026-08-31 5.4 CV= E-2026-76984 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76984 ] apache -=
- wicket Improper neutralization of input during web page generation in Apa= che Wicket. org.apache.wicket.extensions.markup.html.form.palette.component= .AbstractOptions, which renders the two option lists of a Palette, escapes = the id and the display value of each option according to the escape-model-s= trings setting, and wrote the attribute names and values returned by getAdd= itionalAttributes into the <option> tag as they came. An application is aff= ected where it overrides Palette.getAdditionalAttributesForChoices, Palette= .getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttrib= utes and returns a value holding data an attacker can influence. These meth= ods return null by default, so an application that does not override them i=
s not affected. As a workaround, escape the values in the override. This is= sue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.= 23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.4.0 o= nwards are also affected. Users are recommended to upgrade to version 8.19.=
0, 9.24.0 or 10.11.0, which fix the issue. 2026-08-31 5.4 CVE-2026-76985 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-76985 ] apache -- wicket Resour= ceIsolationRequestCycleListener protects a Wicket application against cross= -site=C2=A0request forgery by rejecting requests that a resource isolation = policy judges to come from another origin. Its default policy, FetchMetadat= aResourceIsolationPolicy, was derived from=C2=A0a reference implementation = written to guard static resources, and it inherited two=C2=A0allowances tha=
t are unsafe when the thing being guarded is an action on a page: * Every "= simple top-level navigation" was allowed. Any GET request carrying=C2=A0Sec= -Fetch-Mode: navigate whose Sec-Fetch-Dest was neither object nor embed was= =C2=A0allowed, whatever Sec-Fetch-Site said - including cross-site. Wicket = invokes component=C2=A0listeners (Link.onClick(), form submits, behaviour c= allbacks) through ordinary GET=C2=A0navigations, so a page under an attacke= r's control could navigate the victim's browser to a=C2=A0listener URL and = have that listener run inside the victim's authenticated session. Browsers= =C2=A0send SameSite=3DLax cookies - the effective default when no SameSite = attribute is set - on=C2=A0cross-site top-level GET navigations, so the vic= tim's session cookie accompanied the=C2=A0request. * Sec-Fetch-Site: same-s= ite was allowed unconditionally. That value means the same=C2=A0registrable=
domain and scheme but a different origin - another subdomain or another=C2= =A0port. Any sibling origin could therefore invoke any listener by any meth= od, POST form=C2=A0submits included, and cookies are always sent on same-si=
te requests regardless of=C2=A0SameSite. A hostile sibling origin obtained = through a subdomain takeover, through=C2=A0delegated user content, or throu=
gh an XSS elsewhere on the site could act as the=C2=A0authenticated user. U= sers are recommended to upgrade to version 9.24.0 or 10.11.0, which fix the=
issue. Affected versions * Apache Wicket 9.1.0 through 9.23.0 * Apache Wic= ket 10.0.0 through 10.10.0 Not affected Any release older than 9.1.0: * Apa= che Wicket 8.x (8.0.0 through 8.17.0). The resource isolation classes do no=
t exist in=C2=A0the 8.x line, which offers only the Origin/Referer-based=C2= =A0CsrfPreventionRequestCycleListener. No 8.x release requires a fix. * Apa= che Wicket 9.0.0. ResourceIsolationRequestCycleListener=C2=A0and FetchMetad= ataResourceIsolationPolicy were introduced by WICKET-6786 and first shipped= =C2=A0in 9.1.0 (released 2020-10-07). 2026-08-31 4.6 CVE-2026-71378 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-71378 ] Apache Software Foundation--= Apache Allura Stored XSS via markdown HTML processing=C2=A0in Apache Allura=
. This issue affects Apache Allura: from through 1.20.0. Users are recommen= ded to upgrade to version=C2=A01.21.0, which fixes the issue. 2026-09-04 6.=
1 CVE-2026-80180 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80180 ] Apac=
he Software Foundation--Apache Allura Apache Allura: stored XSS via SVN cod=
e repositories.=C2=A0 Git repositories are not known to be affected.=C2=A0 = The vulnerability is likely mitigated via default CSP headers. This issue a= ffects Apache Allura: through 1.20.0. Users are recommended to upgrade to v= ersion 1.21.0, which fixes the issue. 2026-09-04 6.1 CVE-2026-80190 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-80190 ] Apache Software Foundation--= Apache Spark There is a lack of XSS escaping in the Spark History Server pr= ior to 3.5.8 which allows a malicious Spark job to generate arbitrary unesc= aped frontend code which could lead to a minimal privilege escalation in br= owser. Users are encouraged to upgrade to Spark 3.5.8 or later. This CVE is=
marked as "low" since the path to exploit requires both relatively high pe= rmissions (ability to launch a Spark job) and requires tricking a user with=
higher permissions to log in and visit the Spark history web page. Users a=
re encouraged to upgrade their Spark history servers to Spark 3.5.8 or late=
r. 2026-09-02 6.1 CVE-2026-32773 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-32773 ] apconw--Aix-DB Aix-DB through 1.2.4 renders markdown with raw H= TML enabled into v-html bindings without sanitization, allowing stored cros= s-site scripting attacks. Attackers can inject malicious HTML and JavaScrip=
t through markdown content in chat responses, skill descriptions, or knowle= dge messages that execute in users' browsers when viewed. 2026-08-31 5.4 CV= E-2026-82881 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82881 ] APITable=
--APITable
=C2=A0 APITable through 1.13.0-beta.1 contains an incorrect authorization v= ulnerability in NodePermissionGuard that fails to enforce node-level access=
control when permission lookups throw exceptions. Attackers with valid Fus= ion API tokens can write attachments to private datasheets they have been e= xplicitly denied access to by exploiting the unhandled exception in the per= mission guard. 2026-09-05 4.3 CVE-2026-86120 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-86120 ] apostrophecms--apostrophe ApostropheCMS is an open-= source Node.js content management system, and sanitize-html provides a simp=
le HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7=
, packages/sanitize-html/index.js validates an animation value attribute as=
one flat URL and does not recognize that attributeName selecting href or x= link:href gives the sibling values, from, to, or by attribute SVG SMIL URL = semantics. In configurations that allow the animate, animateColor, animateM= otion, animateTransform, or set elements, a values list can begin with a sa=
fe fragment and contain a later executable destination that survives allowe= dSchemesAppliedToAttributes checking. When the sanitized SVG is rendered, t=
he browser can copy that later destination into the live link, and a victim=
who activates the link can execute script in the application's origin. Thi=
s issue is fixed in version 2.17.7. 2026-09-01 5.4 CVE-2026-84371 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-84371 ] AppFlowy-IO--AppFlowy-Cloud Ap= pFlowy-Cloud through 0.9.64 fails to validate workspace membership when est= ablishing WebSocket connections in the establish_ws_connection_v2 handler, = allowing authenticated users to bind sessions to workspaces they do not bel= ong to. Attackers can send sync Manifest messages with victim object identi= fiers to read full document or database state from collaborations in other = workspaces without victim involvement. 2026-09-04 5.3 CVE-2026-85622 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85622 ] Arcane --Arcane=C2=A0
=C2=A0 Arcane versions before 2.0.0 fail to properly restrict template oper= ations, allowing default user role accounts to create, modify, and delete c= ompose templates including instance-wide defaults. Attackers can inject mal= icious container configurations with privileged settings or host path mount=
s that execute with administrative privileges when deployed by administrato= rs. 2026-09-05 6.5 CVE-2026-86114 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-86114 ] armink--struct2json A vulnerability has been found in armink s= truct2json 1.0. This affects the function S2J_STRUCT_GET_string_ELEMENT in = the library struct2json/inc/s2jdef.h of the component JSON Deserialization.=
The manipulation of the argument valuestring leads to null pointer derefer= ence. The attack may be initiated remotely. The exploit has been disclosed =
to the public and may be used. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-08-31 5.3 CVE-2026-82803 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-82803 ] Arraytics--Timetics Unaut= henticated Broken Access Control in Timetics <=3D 1.0.61 versions. 2026-09-=
03 6.5 CVE-2026-84215 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84215 ]=
Arraytics--WP Event SOlution Unauthenticated Broken Access Control in WP E= vent SOlution <=3D 4.1.22 versions. 2026-09-02 6.5 CVE-2026-82223 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82223 ] arubanetworks -- fabric_compos=
er A vulnerability has been identified in the underlying operating system o=
f HPE Networking Fabric Composer that could potentially allow an unauthenti= cated adjacent actor to circumvent existing authentication controls. Succes= sful exploitation could allow an attacker to gain administrative access, mo= dify system configurations, and access or manipulate sensitive data. 2026-0= 9-01 6.8 CVE-2026-73726 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73726=
] arubanetworks -- fabric_composer Vulnerabilities in the API of HPE Netwo= rking Fabric Composer could allow an authenticated low privilege operator u= ser to access sensitive information. A successful exploit allows an attacke=
r to access data beyond what is authorized by the user's existing privilege=
level, which could be used to potentially gain further access to network s= ervices supported by HPE Networking Fabric Composer. 2026-09-01 6.5 CVE-202= 6-73727 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73727 ] arubanetworks=
-- fabric_composer Denial-of-service vulnerabilities exist in the API of H=
PE Networking Fabric Composer that could allow an authenticated low privile=
ge operator user to cause a denial of service. Successful exploitation coul=
d allow an attacker to interrupt the normal operation of the affected servi= ce. 2026-09-01 6.5 CVE-2026-73728 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-73728 ] arubanetworks -- fabric_composer A vulnerability in the underl= ying operating system of HPE Networking Fabric Composer could allow an auth= enticated low privilege operator user with local access to upstream AFC dep= endencies to view sensitive information. Successful exploitation could allo=
w an attacker to access data beyond what is authorized by the user's existi=
ng privilege level, potentially leading to further unauthorized access. 202= 6-09-01 6.5 CVE-2026-73729 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73= 729 ] arubanetworks -- fabric_composer A privilege escalation vulnerability=
exists in the API of HPE Networking Fabric Composer. Successful exploitati=
on could allow an authenticated low privilege operator user to change the s= tate of certain settings of a vulnerable system. 2026-09-01 6.5 CVE-2026-73= 730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73730 ] arubanetworks -- = fabric_composer A vulnerability in the web-based management interface of HP=
E Networking Fabric Composer could allow an unauthenticated remote attacker=
to conduct a reflected cross-site scripting (XSS) attack against a user of=
the interface. A successful exploit could allow an attacker to execute arb= itrary script code in a victim's browser in the context of the affected int= erface. 2026-09-01 6.1 CVE-2026-73731 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-73731 ] arubanetworks -- fabric_composer A vulnerability in the un= derlying operating system of HPE Networking Fabric Composer could allow an = authenticated low privilege operator user with local access to obtain sensi= tive information. Successful exploitation could allow an attacker to retrie=
ve sensitive data which could be used to gain further unauthorized access t=
o the affected system and to other systems it interacts with. 2026-09-01 5.=
6 CVE-2026-73732 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73732 ] arub= anetworks -- fabric_composer Authentication bypasses in the API of HPE Netw= orking Fabric Composer could allow an authenticated low privilege operator = user to circumvent existing authentication controls. Successful exploitatio=
n could allow an attacker to retain limited access to the affected system a= fter that access should have been revoked. 2026-09-01 5.4 CVE-2026-73733 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-73733 ] arubanetworks -- fabric= _composer A vulnerability in the web-based management interface of HPE Netw= orking Fabric Composer could allow an unauthenticated remote attacker to re= direct users to an arbitrary URL. 2026-09-01 5.4 CVE-2026-73734 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-73734 ] arubanetworks -- fabric_composer=
Vulnerabilities in the API of HPE Networking Fabric Composer could allow a=
n authenticated low privilege operator user to access some information beyo=
nd their privilege level. Successful exploitation could allow an attacker t=
o obtain limited information and/or make limited changes beyond what is aut= horized by the user's existing privilege level. 2026-09-01 5.4 CVE-2026-737=
35 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73735 ] arubanetworks -- f= abric_composer A vulnerability in the web-based management interface of HPE=
Networking Fabric Composer could allow an unauthenticated remote attacker =
to view some system files. Successful exploitation could allow an attacker =
to read files within the affected directory. 2026-09-01 5.3 CVE-2026-73736 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-73736 ] arubanetworks -- fabr= ic_composer An unauthenticated path traversal vulnerability exists in the A=
PI endpoint of HPE Networking Fabric Composer. Successful exploitation coul=
d allow an unauthenticated adjacent attacker to manipulate user generated f= iles, potentially leading to unauthorized changes in critical system config= urations, if certain preconditions outside of the attacker's control are me=
t. 2026-09-01 4.8 CVE-2026-73737 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-73737 ] arubanetworks -- fabric_composer A vulnerability in the underly= ing operating system of HPE Networking Fabric Composer could allow an authe= nticated low privilege operator user with local access to view sensitive in= formation. Successful exploitation could allow an attacker to retrieve info= rmation which could be used to potentially gain further privileges on the a= ffected system. 2026-09-01 4.7 CVE-2026-73738 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-73738 ] arubanetworks -- fabric_composer A vulnerability e= xists in the API of HPE Networking Fabric Composer that allows for an attac= ker with administrative privileges to access sensitive information in a cle= artext format. A successful exploit allows an attacker to retrieve sensitiv=
e information that was expected to remain protected within the affected sys= tem. 2026-09-01 4.4 CVE-2026-73739 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-73739 ] arubanetworks -- fabric_composer A local privilege escalation=
vulnerability in HPE Networking Fabric Composer could allow an authenticat=
ed privileged user on the underlying host to elevate their user privileges =
to those of a higher role. A successful exploit allows the attacker to chan=
ge the state of certain settings of the affected system. 2026-09-01 4.4 CVE= -2026-73740 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73740 ] arubanetw= orks -- fabric_composer A vulnerability in the API of HPE Networking Fabric=
Composer could allow an authenticated low privilege operator user to view = some system files. Successful exploitation could allow an attacker to acces=
s limited data beyond what is authorized by the user's existing privilege l= evel. 2026-09-01 4.3 CVE-2026-73741 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-73741 ] arubanetworks -- fabric_composer A vulnerability in an API e= ndpoint of HPE Networking Fabric Composer could allow an authenticated low = privilege operator user to spoof the source address attributed to their req= uests. Successful exploitation could allow an attacker to cause inaccurate = attribution information to be recorded on the affected system. 2026-09-01 4=
.3 CVE-2026-73742 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73742 ] ata= urr--GutenKit Page Builder Blocks, Patterns, and Templates for Gutenberg Bl= ock Editor The GutenKit - Page Builder Blocks, Patterns, and Templates for = Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting via the 'postBodyCss' parameter in all versions up to, and in= cluding, 2.4.4 due to insufficient input sanitization and output escaping. = This makes it possible for authenticated attackers, with Contributor-level = access and above, to inject arbitrary web scripts in pages that will execut=
e whenever a user accesses an injected page. 2026-09-03 6.4 CVE-2026-2573 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-2573 ] Autodesk--Shared Compon= ents A maliciously crafted IFC file, when parsed through certain Autodesk p= roducts, can trigger an Uncontrolled Recursion vulnerability. A malicious a= ctor may leverage this vulnerability to cause the application to terminate = unexpectedly, resulting in a denial-of-service. Exploitation requires a use=
r to open a specially crafted IFC file. 2026-09-02 5.5 CVE-2026-14255 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-14255 ] AVideo--AVideo
=C2=A0 AVideo API fails to enforce rate limits when clients send a bot User= -Agent header, allowing attackers to bypass all eight protected operations = including login brute-force protection. Attackers can send requests with a = bot User-Agent to disable rate limiting and perform unlimited password gues= sing attempts against any account from a single IP address. 2026-09-05 6.5 = CVE-2026-86186 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86186 ] Avo--A=
vo
=C2=A0 Avo is a framework to create admin panels for Ruby on Rails apps. Fr=
om version 2.28.0 to before version 3.32.0, Avo's direct attachment upload = endpoint lacks server-side upload authorization and bypasses the documented=
field-level upload policy methods such as upload_{FIELD_ID}?. An authentic= ated Avo user who can reach the Avo attachment upload endpoint can replace =
or add attachment content, including binary content, filename, and content-= type metadata, on a resolved record even when both update? and upload_<fiel= d>? policies deny the operation. This primarily affects multi-role Avo Pro/= Advanced-style deployments where non-administrator or restricted operator u= sers can reach Avo and per-record or per-field operations are expected to b=
e enforced by policies. This issue has been patched in version 3.32.0. 2026= -09-04 6.5 CVE-2026-53769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-537=
69 ] axllent--mailpit Mailpit's IsInternalIP deny list function fails to bl= ock the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-t= ranslated IPv6 prefix, allowing server-side request forgery to internal des= tinations. Attackers can supply hostnames resolving to these addresses in m= essage content to reach the link check API and proxy endpoint for accessing=
internal resources. 2026-09-02 5.3 CVE-2026-84697 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-84697 ] ays-pro--Photo Gallery by Ays Responsive Imag=
e Gallery The Photo Gallery by Ays - Responsive Image Gallery plugin for Wo= rdPress is vulnerable to generic SQL Injection via the 's' parameter in all=
versions up to, and including, 6.8.2 due to insufficient escaping on the u= ser supplied parameter and lack of sufficient preparation on the existing S=
QL query. This makes it possible for authenticated attackers, with administ= rator-level access and above, to append additional SQL queries into already=
existing queries that can be used to extract sensitive information from th=
e database. The vulnerability exists across two execution paths - $wpdb->ge= t_var() in record_count() and $wpdb->get_results() in prepare_items()/get_i= mage_categories() - enabling both blind and UNION-based exfiltration techni= ques. 2026-09-01 4.9 CVE-2026-76006 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-76006 ] BareBones--BBEdit A flaw has been found in BareBones BBEdit =
up to 15.5.5. Impacted is an unknown function of the component Java Languag=
e Module. This manipulation causes uncontrolled recursion. Remote exploitat= ion of the attack is possible. Upgrading to version 16.0 is recommended to = address this issue. You should upgrade the affected component. 2026-08-31 4=
.3 CVE-2026-82604 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82604 ] Bar= eBones--BBEdit A vulnerability has been found in BareBones BBEdit up to 15.= 5.5. The affected element is an unknown function of the component Lasso Lan= guage Tokenizer. Such manipulation leads to infinite loop. The attack can b=
e executed remotely. Upgrading to version 16.0 is sufficient to fix this is= sue. The affected component should be upgraded. 2026-08-31 4.3 CVE-2026-826=
05 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82605 ] BEN Group--TubeBud=
dy for YouTube Extension A vulnerability was detected in BEN Group TubeBudd=
y for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TB= Global.GetToken of the file tubebuddymaster1.js. The manipulation of the ar= gument t/c/r results in insufficient verification of data authenticity. It =
is possible to launch the attack remotely. The exploit is now public and ma=
y be used. The vendor was contacted early about this disclosure. 2026-08-31=
5.4 CVE-2026-82813 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82813 ] B= erriAI--litellm LiteLLM is a proxy server (AI Gateway) to call LLM APIs in = OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.2, any authent= icated LiteLLM proxy user could redirect an outbound provider call to a des= tination the user controls and cause the proxy to send its configured provi= der credentials to that destination. Request validation in litellm/proxy/au= th/auth_utils.py, litellm/proxy/common_request_processing.py, litellm/proxy= /health_endpoints/_health_endpoints.py, litellm/proxy/image_endpoints/endpo= ints.py, and litellm/proxy/litellm_pre_call_utils.py used incomplete checks=
that did not cover every sensitive parameter or inspect equivalent values = across nested request fields, path values, and bracket-notation form data. = Routing and credential parameters including api_base, base_url, model_list,=
fallbacks, and litellm_credential_name could therefore be applied without = clearing the operator's stored key, exposing upstream provider credentials = and other configured secrets and permitting server-side requests to interna=
l services reachable by the proxy. This issue is fixed in versions 1.88.6 a=
nd 1.96.2. 2026-09-02 6.5 CVE-2026-84377 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84377 ] blinkospace--blinko Blinko 1.8.7 contains a cross-user = private note disclosure vulnerability in the noteReferenceList procedure th=
at performs no ownership verification on supplied note identifiers. Authent= icated attackers can enumerate sequential note IDs and retrieve complete co= ntent of other users' private notes including attachments and tags. 2026-09= -04 6.5 CVE-2026-85624 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85624 =
] Booking for Appointments and Events Calendar--Booking for Appointments an=
d Events Calendar The Booking for Appointments and Events Calendar WordPres=
s plugin before 2.4.9 does not require authentication or a valid request to= ken before running the post-booking action chain, allowing an unauthenticat=
ed user to trigger booking notifications and integration callbacks for a bo= oking by enumerating its identifier. 2026-09-02 6.5 CVE-2026-14215 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-14215 ] BookWyrm--BookWyrm
=C2=A0 BookWyrm through 0.9.1 fails to validate user visibility permissions=
in the status edit endpoint, allowing authenticated attackers to read foll= owers-only and direct-message reviews by enumerating sequential status IDs.=
Attackers can access the raw content of restricted statuses through the ed=
it view, bypassing the privacy protections documented for these message typ= es. 2026-09-05 6.5 CVE-2026-86111 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-86111 ] BookWyrm--BookWyrm
=C2=A0 BookWyrm through 0.9.1 fails to validate user visibility permissions=
in the Favorite and Unfavorite views, allowing authenticated attackers to = favorite or unfavorite followers-only and direct statuses they cannot acces=
s. Attackers can POST to the favorite endpoint with a status ID to create u= nauthorized interactions, trigger ActivityPub broadcasts, and enumerate pri= vate status IDs through response differentiation. 2026-09-05 5.4 CVE-2026-8= 6112 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86112 ] BookWyrm--BookWy=
rm
=C2=A0
=C2=A0 BookWyrm through 0.9.1 contains an authorization bypass vulnerabilit=
y in the edit_readthrough function that allows authenticated users to modif=
y other users' reading records. Attackers can exploit sequential ReadThroug=
h IDs to overwrite arbitrary users' start dates, finish dates, progress, an=
d progress mode, affecting reading statistics and exported data. 2026-09-05=
6.5 CVE-2026-86113 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86113 ] B= ootstrapped Ventures--WP Recipe Maker Premium The WP Recipe Maker Premium p= lugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl= ugin's 'wprm-call-to-action' shortcode in all versions up to, and including=
, 10.5.0 due to insufficient input sanitization and output escaping on user=
supplied attributes. This makes it possible for authenticated attackers, w= ith contributor-level access and above, to inject arbitrary web scripts in = pages that will execute whenever a user accesses an injected page. 2026-09-=
01 6.4 CVE-2026-7877 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7877 ] B= rainstorm Force--SureForms Authorization Bypass Through User-Controlled Key=
vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly = Configured Access Control Security Levels. This issue affects SureForms: fr=
om n/a through 2.12.5. 2026-09-03 5.3 CVE-2026-85308 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-85308 ] Brave--Brave The Brave WordPress plugin bef= ore 0.8.8 does not prevent a URL parameter used to pre-fill a form field fr=
om being passed to WordPress's shortcode engine, allowing unauthenticated a= ttackers to have arbitrary shortcodes registered on the site executed serve= r-side. 2026-09-02 4.8 CVE-2026-81571 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-81571 ] brightvesseldev--Pre-Orders for WooCommerce Unauthenticate=
d Bypass Vulnerability in Pre-Orders for WooCommerce <=3D 2.3 versions. 202= 6-09-03 6.5 CVE-2026-84849 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84= 849 ] C4illin--ConvertX ConvertX 0.17.0 contains an arbitrary file read vul= nerability in the xelatex converter that allows authenticated users to read=
files by uploading LaTeX files with input directives. Attackers can upload=
.tex files containing \input{path} or \verbatiminput{path} directives to h= ave the TeX engine read arbitrary files accessible to the server process an=
d include them in downloadable PDF output. 2026-09-04 6.5 CVE-2026-85618 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-85618 ] Camaleon--CMS=C2=A0
=C2=A0 Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect = targets when fetching remote files in the Upload from URL media feature. Au= thenticated attackers can supply URLs that pass initial validation but redi= rect to internal network addresses, allowing server-side request forgery to=
internal services. 2026-09-05 6.4 CVE-2026-86100 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-86100 ] caoqianming--django-vue-admin A weakness has b= een identified in caoqianming django-vue-admin 1.0. This vulnerability affe= cts unknown code of the file /api/file/. Executing a manipulation of the ar= gument file_id can lead to improper access controls. The attack can be exec= uted remotely. The exploit has been made available to the public and could =
be used for attacks. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-08-31 5.4 CVE-2026-82835 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82835 ] Cascadia Web Services--MountDev AI = MCP Connector for WordPress Missing Authorization vulnerability in Cascadia=
Web Services MountDev AI MCP Connector for WordPress allows Exploiting Inc= orrectly Configured Access Control Security Levels. This issue affects Moun= tDev AI MCP Connector for WordPress: from n/a through 1.6.5. 2026-09-03 6.5=
CVE-2026-85306 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85306 ] Catal= ogX--CatalogX The CatalogX WordPress plugin before 6.1.3 does not sanitise =
or escape content that an unauthenticated user can store before including i=
t in the product enquiry notification email sent to the site administrator,=
allowing unauthenticated attackers to inject arbitrary content into that e= mail, which is delivered when an unrelated visitor later submits a product = enquiry. 2026-09-02 4.3 CVE-2026-79621 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-79621 ] ccfos--nightingale Nightingale (n9e), as of commit 8362= cbe (main branch, confirmed 2026-08-27), contains a server-side request for= gery vulnerability in the isPublicIP function in aiagent/tools/http.go, the=
SSRF guard for the http_fetch AI-agent tool. The function only unwraps sta= ndard IPv4-mapped (::ffff:a.b.c.d) IPv6 addresses before checking them agai= nst the forbidden-range list, and does not classify 6to4 (2002::/16), NAT64=
(64:ff9b::/96, 64:ff9b:1::/48), or deprecated site-local (fec0::/10) addre= sses. On a dual-stack or NAT64-enabled host, an attacker able to supply a U=
RL to the http_fetch tool can bypass the guard by encoding a forbidden IPv4=
address (such as the cloud instance-metadata endpoint 169.254.169.254) in = one of these IPv6 forms to reach internal or metadata services. 2026-09-04 = 6.5 CVE-2026-85692 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85692 ] CD= T--CDT=C2=A0
=C2=A0 CDT before 1.4.5 contains an out-of-bounds read vulnerability in the=
opposedVertexInd() function when constraint edge intersections are compute=
d in floating point and round outside adjacent triangles. Attackers can sup= ply nearly-degenerate constraint edges through geometry data to trigger an = out-of-bounds array access that crashes the calling process. 2026-09-05 5.5=
CVE-2025-15647 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15647 ] chesh= ire-cat-ai--core Cheshire Cat AI's GET /memory/collections/{collection_id}/= points endpoint fails to apply per-user filtering when retrieving episodic = memory points. Authenticated attackers with MEMORY:READ permission can retr= ieve all users' stored conversation messages and personal data by paginatin=
g through the collection using the offset cursor. 2026-09-03 6.5 CVE-2026-8= 5093 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85093 ] Cisco--Cisco Sec= ure Email Multiple vulnerabilities in the Secure/Multipurpose Internet Mail=
Extensions (S/MIME) decryption functionality of Cisco Secure Email could a= llow an unauthenticated, remote attacker to recover plain text from encrypt=
ed email messages. These vulnerabilities are due to insufficient validation=
of message integrity. An attacker could exploit these vulnerabilities by u= sing a machine-in-the-middle technique to intercept and modify traffic betw= een email gateways. A successful exploit could allow the attacker to obtain=
plaintext content from the encrypted communication. 2026-09-02 5.9 CVE-202= 6-20354 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20354 ] Cisco--Cisco = Secure Email Multiple vulnerabilities in the Secure/Multipurpose Internet M= ail Extensions (S/MIME) decryption functionality of Cisco Secure Email coul=
d allow an unauthenticated, remote attacker to recover plain text from encr= ypted email messages. These vulnerabilities are due to insufficient validat= ion of message integrity. An attacker could exploit these vulnerabilities b=
y using a machine-in-the-middle technique to intercept and modify traffic b= etween email gateways. A successful exploit could allow the attacker to obt= ain plaintext content from the encrypted communication. 2026-09-02 5.9 CVE-= 2026-20355 [
https://www.cve.org/CVERecord?id=3DCVE-2026-20355 ] claude-wor= ld--claude-skill-antivirus claude-skill-antivirus fails to analyze executab=
le files when scanning local skill directories, reading only SKILL.md while=
ignoring Python source, bytecode, and other artifacts in the scripts direc= tory. Attackers can distribute skills with malicious code in non-manifest f= iles that receive a SAFE verdict with 100/100 trust score despite containin=
g unanalyzed executable payloads. 2026-09-02 6.5 CVE-2026-84810 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-84810 ] Cleo--Harmony A vulnerability ha=
s been found in Cleo Harmony up to 5.8.1.10. Impacted is the function Local= UserUtil.getNativeUserByAssertions of the component SAML Authentication. Su=
ch manipulation of the argument Email leads to improper authentication. The=
attack can be executed remotely. The exploit has been disclosed to the pub= lic and may be used. Upgrading to version 5.8.1.11 is recommended to addres=
s this issue. Upgrading the affected component is recommended. 2026-09-01 6=
.3 CVE-2026-84114 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84114 ] cod= e-projects --Daily Expense Manager 1.0
=C2=A0 A flaw has been found in code-projects Daily Expense Manager 1.0. Af= fected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql=
of the component Database Backup Handler. Executing a manipulation can lea=
d to information disclosure. It is possible to launch the attack remotely. = The exploit has been published and may be used. 2026-09-06 5.3 CVE-2026-861=
79 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86179 ] code-projects--Hot=
el and Tourism Reservation
=C2=A0 A vulnerability was detected in code-projects Hotel and Tourism Rese= rvation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_d= b%20(1).sql of the component Database Backup Handler. The manipulation resu= lts in information disclosure. The attack may be launched remotely. The exp= loit is now public and may be used. 2026-09-06 5.3 CVE-2026-86217 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-86217 ] code-projects--Hotel and Touri=
sm Reservation=C2=A0
=C2=A0 A security vulnerability has been detected in code-projects Hotel an=
d Tourism Reservation in PHP 1.0. This impacts an unknown function of the f= ile /ht/details.php. The manipulation of the argument room leads to cross s= ite scripting. The attack may be initiated remotely. The exploit has been d= isclosed publicly and may be used. 2026-09-06 4.3 CVE-2026-86216 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-86216 ] code-projects--Online Shopping = System A vulnerability was found in code-projects Online Shopping System 1.=
0. Affected by this vulnerability is an unknown functionality of the file /= offersmail.php of the component Newsletter Subscription. The manipulation o=
f the argument email results in cross site scripting. The attack may be per= formed from remote. The exploit has been made public and could be used. 202= 6-08-31 4.3 CVE-2026-82700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 700 ] code-projects--Online Shopping System 1.0
=C2=A0 A flaw has been found in code-projects Online Shopping System 1.0. I= mpacted is the function mysqli_query of the file admin/adduser.php. Executi=
ng a manipulation of the argument mobile can lead to sql injection. The att= ack may be performed from remote. The exploit has been published and may be=
used. 2026-09-04 4.7 CVE-2026-85643 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-85643 ] code-projects--Simple Inventory System A flaw has been foun=
d in code-projects Simple Inventory System 1.0. Affected by this issue is s= ome unknown functionality of the file inventorymanagement.sql of the compon= ent Database Backup File Handler. This manipulation causes information disc= losure. The attack may be initiated remotely. The exploit has been publishe=
d and may be used. 2026-08-31 5.3 CVE-2026-82624 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-82624 ] code-projects--Simple Inventory System A vulner= ability has been found in code-projects Simple Inventory System 1.0. This a= ffects an unknown part of the file /register.php of the component User Regi= stration. Such manipulation of the argument last_name leads to cross site s= cripting. The attack may be launched remotely. The exploit has been disclos=
ed to the public and may be used. 2026-08-31 4.3 CVE-2026-82625 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-82625 ] code-projects--Vehicle Managemen=
t System A flaw has been found in code-projects Vehicle Management System 1= .0. The impacted element is an unknown function of the file /vehicle_manage= ment.sql of the component SQL Database Backup File Handler. Executing a man= ipulation can lead to information disclosure. It is possible to launch the = attack remotely. The exploit has been published and may be used. 2026-09-04=
5.3 CVE-2026-85517 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85517 ] C= omments--Comments The Comments WordPress plugin before 7.6.66 does not vali= date a value used to build a database query, allowing unauthenticated users=
to inject SQL and read comments they are not entitled to see, including co= mments awaiting moderation, comments marked as spam or trashed, and comment=
s on private and draft posts. The injected text reaches the query as gramma=
r rather than as data and does not yield extraction of arbitrary data, so t=
he confidentiality impact is the disclosed comment content rather than the = database at large. 2026-09-02 5.3 CVE-2026-19704 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-19704 ] Content Views--Content Views The Content Views = WordPress plugin before 4.5.1.2 does not check whether the user requesting =
a view is allowed to read the posts it returns, allowing unauthenticated at= tackers to obtain the title and content of non-public posts, such as draft,=
pending, private and scheduled posts, when a view has been configured to i= nclude them. 2026-09-04 5.3 CVE-2026-17517 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-17517 ] cozmoslabs--User Profile Builder Beautiful User Regis= tration Forms, User Profiles & User Role Editor The User Profile Builder - = Beautiful User Registration Forms, User Profiles & User Role Editor plugin = for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' = parameter in all versions up to, and including, 4.0.0 due to insufficient i= nput sanitization and output escaping. This makes it possible for unauthent= icated attackers to inject arbitrary web scripts in pages that will execute=
whenever a user accesses an injected page. The payload reaches administrat= ors with the manage_options capability when they visit the Users > Unconfir= med Email Addresses list table and interact with row-action links, as the p= oisoned javascript: href is rendered verbatim into the page HTML by row_act= ions(). 2026-09-01 6.1 CVE-2026-75964 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-75964 ] cozmoslabs--User Profile Builder Beautiful User Registrati=
on Forms, User Profiles & User Role Editor The User Profile Builder - Beaut= iful User Registration Forms, User Profiles & User Role Editor plugin for W= ordPress is vulnerable to Stored Cross-Site Scripting via 'date' Shortcode = Attribute in all versions up to, and including, 4.0.0 due to insufficient i= nput sanitization and output escaping. This makes it possible for authentic= ated attackers, with contributor-level access and above, to inject arbitrar=
y web scripts in pages that will execute whenever a user accesses an inject=
ed page. This requires the wppb_toolbox_shortcodes_settings[format-date] op= tion to be set to 'yes' by an administrator for the shortcode to be active = and the vulnerability to be exploitable. 2026-09-01 6.4 CVE-2026-75965 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-75965 ] cozythemes--Cozy Blocks P= age Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Temp= lates The Cozy Blocks - Page Builder for Gutenberg Editor & FSE with 700+ P= atterns, 58 Blocks & Templates plugin for WordPress is vulnerable to author= ization bypass in all versions up to, and including, 2.2.17. This is due to=
the plugin not properly verifying that a user is authorized to perform an = action. This makes it possible for unauthenticated attackers to retrieve th=
e name, price, short description, image URL, permalink, stock status, and p= roduct type of draft, pending, private, and catalog-hidden WooCommerce prod= ucts not intended to be publicly visible. The sidebarNonce value is emitted=
unconditionally into public page HTML by multiple block renderers with no = login gate, allowing unauthenticated visitors to harvest a valid nonce and = pass the only authentication check in the handler. 2026-09-01 5.3 CVE-2026-= 19948 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19948 ] craftcms--cms C= raft CMS versions before 5.10.11 contain an authorization bypass vulnerabil= ity in ElementsController::actionDuplicate() that allows authenticated user=
s with createEntries permission to delete peer provisional drafts. Attacker=
s can exploit the deleteProvisionalDraft parameter to delete another user's=
unsaved draft without proper authorization checks, gaining access to the v= ictim's in-progress content. 2026-09-02 6.3 CVE-2026-84797 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-84797 ] craftcms--cms Craft CMS versions befo=
re 5.10.11 contain a broken access control vulnerability in the element-ind= exes/save-elements endpoint that allows control panel users to move entries=
into sections they cannot edit. Attackers with limited section permissions=
can relocate or publish entries to unauthorized sections by overwriting th=
e sectionId attribute after initial authorization checks, bypassing the des= tination section permission validation. 2026-09-02 4.3 CVE-2026-84792 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-84792 ] craftcms--cms Craft CMS ve= rsions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting = vulnerability in the site name field that fails to sanitize input. Administ= rators can inject arbitrary JavaScript payloads in the site name that execu=
te when other users view the control panel settings pages. 2026-09-02 4.8 C= VE-2026-84793 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84793 ] craftcm= s--cms Craft CMS before 5.11.0 fails to enforce user-group scope filters on=
native GraphQL user relations including author, authors, uploader, draftCr= eator, and revisionCreator fields. Attackers with a scoped GraphQL token ca=
n query these relations to read usernames, email addresses, and full names =
of any content author or uploader including administrators. 2026-09-02 4.3 = CVE-2026-84799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84799 ] craftc= ms--cms Craft CMS versions from 5.7.0 before 5.10.12 contain an information=
disclosure vulnerability in AssetsController::actionMoveInfo that fails to=
enforce volume permissions. Authenticated control panel users can submit P= OST requests to the assets/move-info endpoint with arbitrary folderIds to r= etrieve asset count and total storage size for volumes they cannot access. = 2026-09-02 4.3 CVE-2026-84802 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84802 ] creativethemeshq--Blocksy Companion The Blocksy Companion plugin f=
or WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Blo=
ck Attribute (blocksy/dynamic-data) in all versions up to, and including, 2= .1.51 due to insufficient input sanitization and output escaping. This make=
s it possible for authenticated attackers, with author-level access and abo= ve, to inject arbitrary web scripts in pages that will execute whenever a u= ser accesses an injected page. 2026-09-01 6.4 CVE-2026-18488 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-18488 ] crmeb--CRMEB CRMEB through 6.0.0 fa= ils to validate message ownership in the edit_message handler of MessageSys= temController.php, allowing authenticated users to modify arbitrary system = inbox messages. Attackers can update any message's columns including is_del=
, look, and uid to delete, mark read, or reassign victim notifications with= out authorization. 2026-09-03 5.4 CVE-2026-85177 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-85177 ] Crocoblock--JetPopup Missing Authorization vuln= erability in Crocoblock JetPopup allows Exploiting Incorrectly Configured A= ccess Control Security Levels. This issue affects JetPopup: from n/a throug=
h 2.0.20.2. 2026-09-04 5.3 CVE-2026-27347 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-27347 ] cypht-org--cypht Cypht before 2.12.2 contains a cross-= site scripting vulnerability in the contacts module that allows remote atta= ckers to execute arbitrary script content by embedding malicious payloads w= ithin angle brackets in the FROM email header. The sanitization logic remov=
es only the first occurrence of each angle bracket character, leaving addit= ional angle brackets intact, which attackers exploit by delivering a crafte=
d email whose FROM header executes script in the victim's browser when the = user opens the message and accesses the Add Local Contacts function. 2026-0= 9-01 6.1 CVE-2026-73524 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73524=
] dataease--dataease DataEase versions before 2.10.26 omit object-level au= thorization checks on geographic information, dashboard linkage, and chart = detail REST endpoints, allowing authenticated users to access resources bel= onging to other users. Attackers can overwrite or delete map geometry, modi=
fy dashboard linkages, and retrieve chart metadata and configuration for re= sources they do not own by supplying arbitrary identifiers in requests. 202= 6-08-31 6.3 CVE-2026-82878 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 878 ] dataease--dataease DataEase before 2.10.26 contains multiple access c= ontrol defects in the sharing link module. Tickets are not bound to the tar= get share UUID, so a valid ticket issued for one share can be reused agains=
t another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo)=
. The POST /de2api/share/validate endpoint issues a LinkToken after passwor=
d verification without requiring a ticket, bypassing the 'ticket mandatory'=
policy. Additionally, the ticket create and delete endpoints (POST /de2api= /ticket/saveTicket, POST /de2api/ticket/delTicket) lack share-ownership che= cks, allowing an authenticated user who knows another user's ticket to modi= fy, rebind, or delete it (denial of service), and GET /de2api/share/queryRe= lationByUserId/{uid} allows authenticated users to enumerate other users' s= hare mappings. 2026-08-31 6.3 CVE-2026-82879 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82879 ] DefaultFuction--CRM 1.0.0 A vulnerability was detec= ted in DefaultFuction CRM 1.0.0. This impacts an unknown function of the fi=
le /modules/customers/delete.php. Performing a manipulation of the argument=
ID results in sql injection. It is possible to initiate the attack remotel=
y. The exploit is now public and may be used. 2026-09-06 6.3 CVE-2026-86172=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-86172 ] DefaultFuction--CRM = 1.0.0
=C2=A0 A weakness has been identified in DefaultFuction CRM 1.0.0. The impa= cted element is an unknown function of the file /modules/orders/edit.php. T= his manipulation of the argument ID causes sql injection. The attack is pos= sible to be carried out remotely. The exploit has been made available to th=
e public and could be used for attacks. 2026-09-06 6.3 CVE-2026-86170 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-86170 ] DefaultFuction--CRM 1.0.0 =C2=A0 A security vulnerability has been detected in DefaultFuction CRM 1.0= .0. This affects an unknown function of the file /modules/orders/delete.php=
. Such manipulation of the argument ID leads to sql injection. The attack m=
ay be performed from remote. The exploit has been disclosed publicly and ma=
y be used. 2026-09-06 6.3 CVE-2026-86171 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-86171 ] Dell--PowerProtect Data Manager Dell PowerProtect Data = Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Lay= out vulnerability. An unauthenticated remote attacker could potentially exp= loit this vulnerability, leading to Launch of phishing attacks. 2026-09-03 = 6.8 CVE-2026-68860 [
https://www.cve.org/CVERecord?id=3DCVE-2026-68860 ] De= ll--PowerProtect Data Manager Dell PowerProtect Data Manager, versions 20.2= .0.0 and below, contain an Incorrect Authorization vulnerability in the RES=
T API. A low privileged remote attacker could potentially exploit this vuln= erability, leading to Protection mechanism bypass. 2026-09-03 6.5 CVE-2026-= 74769 [
https://www.cve.org/CVERecord?id=3DCVE-2026-74769 ] Dell--PowerProt= ect Data Manager Dell PowerProtect Data Manager, versions 20.2.0.0 and belo=
w, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST A= PI. A high privileged remote attacker could potentially exploit this vulner= ability, leading to Information disclosure. 2026-09-03 4.1 CVE-2026-74768 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-74768 ] Dell--PowerStore 500T = Dell PowerStore contains an Argument Injection vulnerability. An authentica= ted user with limited privileges could potentially exploit this vulnerabili=
ty to gain unauthorized access to sensitive sensitive system information. 2= 026-09-01 6.5 CVE-2026-79685 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 79685 ] Dell--SmartFabric OS10 Dell SmartFabric OS10 Software, versions pri=
or to 10.5.6.14, contains an Improper Neutralization of Special Elements us=
ed in a Command ('Command Injection') vulnerability. A high privileged atta= cker with remote access could potentially exploit this vulnerability, leadi=
ng to Command execution. 2026-09-03 5 CVE-2026-63694 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-63694 ] Dell--SmartFabric OS10 Software Dell SmartF= abric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neut= ralization of Special Elements used in an OS Command ('OS Command Injection=
') vulnerability. A high privileged attacker with remote access could poten= tially exploit this vulnerability, leading to Command execution. 2026-09-03=
5 CVE-2026-35160 [
https://www.cve.org/CVERecord?id=3DCVE-2026-35160 ] dib= o-software--diboot A vulnerability has been found in dibo-software diboot 3= .8.0. Affected by this vulnerability is an unknown functionality of the fil=
e /api/ai-session/ of the component AI Session Endpoint. Such manipulation = leads to authorization bypass. The attack can be launched remotely. The exp= loit has been disclosed to the public and may be used. The vendor was conta= cted early about this disclosure but did not respond in any way. 2026-08-31=
6.3 CVE-2026-82816 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82816 ] d= ibo-software--diboot A vulnerability was found in dibo-software diboot 3.8.=
0. Affected by this issue is some unknown functionality of the file /admin/=
of the component Tenant Administrator Management API. Performing a manipul= ation of the argument tenantId results in improper access controls. The att= ack may be initiated remotely. The exploit has been made public and could b=
e used. The vendor was contacted early about this disclosure but did not re= spond in any way. 2026-08-31 6.3 CVE-2026-82817 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-82817 ] dibo-software--diboot A vulnerability was determ= ined in dibo-software diboot 3.8.0. This affects an unknown part of the fil=
e /api/iam/tenant/resource of the component Tenant Resource Assignment Hand= ler. Executing a manipulation of the argument tenantId can lead to improper=
access controls. The attack may be launched remotely. The exploit has been=
publicly disclosed and may be utilized. The vendor was contacted early abo=
ut this disclosure but did not respond in any way. 2026-08-31 6.3 CVE-2026-= 82818 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82818 ] diem-project --= diem=C2=A0
=C2=A0 A vulnerability was determined in diem-project diem up to 5.1.3. Thi=
s affects the function executeCommand of the file dmAdminPlugin/modules/dmC= onsole/actions/actions.class.php of the component dmConsole. This manipulat= ion of the argument dm_command causes cross-site request forgery. The attac=
k may be initiated remotely. The exploit has been publicly disclosed and ma=
y be utilized. The project was informed of the problem early through an iss=
ue report but has not responded yet. 2026-09-06 4.3 CVE-2026-86182 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-86182 ] diem-project--diem A security=
flaw has been discovered in diem-project diem up to 5.1.3. The impacted el= ement is an unknown function of the file dmFrontPlugin/lib/dmWidget/media/d= mWidgetContentBaseMediaForm.php of the component Widget Editor. Performing =
a manipulation results in unrestricted upload. The attack may be initiated = remotely. The exploit has been released to the public and may be used for a= ttacks. The project was informed of the problem early through an issue repo=
rt but has not responded yet. 2026-08-31 6.3 CVE-2026-82679 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-82679 ] diem-project--diem A vulnerability w=
as identified in diem-project diem up to 5.1.3. The affected element is the=
function executeCommand of the file dmAdminPlugin/modules/dmConsole/action= s/actions.class.php of the component Administrative Console. Such manipulat= ion of the argument dm_command leads to os command injection. The attack ca=
n be launched remotely. The exploit is publicly available and might be used=
. The project was informed of the problem early through an issue report but=
has not responded yet. 2026-08-31 4.7 CVE-2026-82678 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-82678 ] diem-project--diem=C2=A0
=C2=A0 A vulnerability was identified in diem-project diem up to 5.1.3. Thi=
s vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWi= dget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such mani= pulation of the argument widget_id leads to authorization bypass. The attac=
k may be launched remotely. The exploit is publicly available and might be = used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A = patch should be applied to remediate this issue. The project was informed o=
f the problem early through an issue report but has not responded yet. 2026= -09-06 5.3 CVE-2026-86183 [
https://www.cve.org/CVERecord?id=3DCVE-2026-861=
83 ] DimaFreund--Rentsyst Missing Authorization vulnerability in DimaFreund=
Rentsyst allows Exploiting Incorrectly Configured Access Control Security = Levels. This issue affects Rentsyst: from n/a through 2.1.2. 2026-09-02 5.3=
CVE-2026-84835 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84835 ] Docca= no--Open Source Annotation Tools for Machine Learning Practitioners A vulne= rability was identified in Doccano Open Source Annotation Tools for Machine=
Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Doc= ument Automatically up to 1.8.5. Affected by this issue is the function Exa= mpleDetail of the file /v1/projects/1/examples/ of the component Project Ex= ample Detail Endpoint. Such manipulation leads to improper access controls.=
The attack may be launched remotely. The exploit is publicly available and=
might be used. The vendor was contacted early about this disclosure but di=
d not respond in any way. 2026-08-31 6.3 CVE-2026-82833 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-82833 ] Doccano--Open Source Annotation Tools fo=
r Machine Learning Practitioners A security flaw has been discovered in Doc= cano Open Source Annotation Tools for Machine Learning Practitioners and Au=
to Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.=
5. This affects the function LabelList of the file /v1/projects/1/category-= types of the component Bulk-Delete Endpoint. Performing a manipulation resu= lts in improper access controls. Remote exploitation of the attack is possi= ble. The exploit has been released to the public and may be used for attack=
s. The vendor was contacted early about this disclosure but did not respond=
in any way. 2026-08-31 5.4 CVE-2026-82834 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-82834 ] documenso--documenso Documenso 2.17.0 contains an acc= ess control vulnerability in the PDF-serving endpoint that fails to validat=
e document visibility settings. Attackers with low privileges can read rest= ricted documents within their team or cross-tenant by leveraging missing ow= nership validation on document data identifiers. 2026-09-04 6.5 CVE-2026-85= 697 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85697 ] Dolibarr--Dolibar=
r A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Af= fected by this issue is some unknown functionality of the file htdocs/core/= filemanagerdol/connectors/php/config.inc.php of the component Legacy File M= anager. Executing a manipulation can lead to improper access controls. The = attack can be launched remotely. The exploit has been made available to the=
public and could be used for attacks. Upgrading to version 23.0.4 can reso= lve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02= ec. It is suggested to upgrade the affected component. 2026-09-04 6.3 CVE-2= 026-85401 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85401 ] domainaware= --parsedmarc parsedmarc 9.0.6 before 11.0.1 writes forensic report sample f= iles using an output path derived from the email subject. When the subject = consists entirely of path traversal sequences, the filename sanitization fu= nction produces an empty string, and a fallback to the raw unsanitized subj= ect causes the resulting file to be written outside the intended samples di= rectory. An attacker who can cause a forensic failure report with a crafted=
Subject to be processed can write a dot-prefixed file with attacker-contro= lled content to an ancestor directory of the configured samples output path=
. Exploitation requires that file output for forensic report samples is ena= bled. 2026-09-03 5.3 CVE-2026-82521 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-82521 ] Drupal--Address Suggestion Improper Neutralization of Input = During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal=
Address Suggestion allows Cross-Site Scripting (XSS). This issue affects A= ddress Suggestion versions: from 0.0.0 to 1.0.25. 2026-09-02 4.8 CVE-2026-8= 1167 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81167 ] Drupal--Blazy In= correct Authorization vulnerability in Drupal Blazy allows Forceful Browsin=
g. This issue affects Blazy versions: from 0.0.0 to 3.0.18. 2026-09-02 5.3 = CVE-2026-81165 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81165 ] Drupal= --Data field Missing Authorization vulnerability in Drupal Data field allow=
s Forceful Browsing. This issue affects Data field versions: from 0.0.0 to = 2.0.13. 2026-09-02 5.3 CVE-2026-81269 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-81269 ] Drupal--Diff Incorrect Authorization vulnerability in Drup=
al Diff allows Forceful Browsing. This issue affects Diff versions: from 0.= 0.0 to 2.0.1, from 2.1.0 to 2.1.1. 2026-09-02 5.3 CVE-2026-73478 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-73478 ] Drupal--Digital Signage Framewo=
rk Missing Authorization vulnerability in Drupal Digital Signage Framework = allows Forceful Browsing. This issue affects Digital Signage Framework vers= ions: from 0.0.0 to 2.6.1. 2026-09-02 5.3 CVE-2026-81166 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-81166 ] Drupal--Disable Login Page Authenticati=
on Bypass Using an Alternate Path or Channel vulnerability in Drupal Disabl=
e Login Page allows Functionality Bypass. This issue affects Disable Login = Page versions: from 0.0.0 to 1.1.4. 2026-09-02 4.1 CVE-2026-16647 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-16647 ] Drupal--DXPR Builder: The Best=
Editing (AI) Experience for Drupal Insertion of Sensitive Information Into=
Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Expe= rience for Drupal allows Forceful Browsing. This issue affects DXPR Builder=
: The Best Editing (AI) Experience for Drupal versions: from 0.0.0 to 2.8.1=
. 2026-09-02 5.3 CVE-2026-81162 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-81162 ] Drupal--Entity API Incorrect Authorization vulnerability in Drup=
al Entity API allows Forceful Browsing. This issue affects Entity API versi= ons: from 0.0.0 to 1.8.0. 2026-09-02 5.3 CVE-2026-81158 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-81158 ] Drupal--Entity Browser Improper Neutrali= zation of Input During Web Page Generation ("Cross-site Scripting") vulnera= bility in Drupal Entity Browser allows Stored XSS. This issue affects Entit=
y Browser versions: from 0.0.0 to 2.16.0. 2026-09-02 4.8 CVE-2026-18986 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-18986 ] Drupal--Entity PDF Missi=
ng Authorization vulnerability in Drupal Entity PDF allows Forceful Browsin=
g. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5. 2026-09-02 = 5.4 CVE-2026-81164 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81164 ] Dr= upal--Entity Share Websub Server-Side Request Forgery (SSRF) vulnerability =
in Drupal Entity Share Websub allows Server Side Request Forgery. This issu=
e affects Entity Share Websub versions: from 0.0.0 to 1.1.2. 2026-09-02 5.3=
CVE-2026-73474 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73474 ] Drupa= l--External Authentication Improper Handling of Case Sensitivity vulnerabil= ity in Drupal External Authentication allows Privilege Escalation. This iss=
ue affects External Authentication versions: from 0.0.0 to 2.0.13. 2026-09-=
02 5.4 CVE-2026-73476 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73476 ]=
Drupal--Gammu SMS Daemon Vulnerability in Drupal Gammu SMS Daemon. This is= sue affects Gammu SMS Daemon versions: *.*. 2026-09-02 5.9 CVE-2026-76755 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-76755 ] Drupal--Gammu SMS Daem=
on Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS D= aemon versions: *.*. 2026-09-02 5.9 CVE-2026-76756 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-76756 ] Drupal--Gammu SMS Daemon Vulnerability in Dru= pal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. 20= 26-09-02 5.9 CVE-2026-76757 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7= 6757 ] Drupal--LDAP / Active Directory Integration Improper Neutralization =
of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability =
in Drupal LDAP / Active Directory Integration allows LDAP Injection. This i= ssue affects LDAP / Active Directory Integration versions: from 0.0.0 to 2.= 2.1. 2026-09-02 5.3 CVE-2026-81205 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-81205 ] Drupal--Link content parser Vulnerability in Drupal Link cont= ent parser. This issue affects Link content parser versions: *.*. 2026-09-0=
2 5.9 CVE-2026-76758 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76758 ] = Drupal--Monster Menus Improper Neutralization of Input During Web Page Gene= ration ("Cross-site Scripting") vulnerability in Drupal Monster Menus allow=
s Stored XSS. This issue affects Monster Menus versions: from 0.0.0 to 9.5.=
3. 2026-09-02 6.1 CVE-2026-81201 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-81201 ] Drupal--Quick Tabs Incorrect Authorization vulnerability in Dru= pal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs vers= ions: from 0.0.0 to 4.3.1. 2026-09-02 5.3 CVE-2026-73477 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-73477 ] Drupal--Slick Carousel Improper Neutral= ization of Input During Web Page Generation ("Cross-site Scripting") vulner= ability in Drupal Slick Carousel allows Stored XSS. This issue affects Slic=
k Carousel versions: from 0.0.0 to 2.1.0. 2026-09-02 6.1 CVE-2026-81160 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-81160 ] DSpace--DSpace DSpace op=
en source software is a repository application which provides durable acces=
s to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Cu= ration Task feature allows an output path to be used by the reporter (-r pa= rameter), typically used to stream results and status of curation task oper= ations. It is not restricted to any particular base path, meaning that any = path writable by the DSpace (often 'tomcat') user is allowed. This constitu= tes a Path Traversal Vulnerability in the curate script. This issue has bee=
n patched in versions 7.6.7, 8.4, 9.3, and 10.0. 2026-09-02 5.5 CVE-2026-49= 831 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49831 ] DSpace--DSpace DS= pace open source software is a repository application which provides durabl=
e access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1=
to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability i=
s possible via the COAR Notify / LDN service in DSpace. The attacker MUST a= lready have DSpace administrator credentials in order to perform the attack=
. When reading a file input stream of an "inbound pattern" / "template", us=
ed to generate an LDN message, the LDN class does not check for path traver= sal or restrict the templates to a known base path. This could allow an unt= rusted file from elsewhere in the file system (e.g. an export log, a bitstr= eam path, a temporary file) to be read and interpreted as an Apache Velocit=
y template. This issue has been patched in versions 8.4, 9.3, and 10.0. 202= 6-09-02 5.5 CVE-2026-49833 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49= 833 ] DSpace--DSpace DSpace open source software is a repository applicatio=
n which provides durable access to digital resources. Prior to versions 7.6= .7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (u= sing the OAI-ORE Harvester), the ORE Ingestion Crosswalk does not validate = the URI scheme. This may allow for local file inclusion via malicious paths=
like file:///etc/passwd. The attacker MUST already have DSpace collection = administrator privileges in order to perform the attack. This issue has bee=
n patched in versions 7.6.7, 8.4, 9.3, and 10.0. 2026-09-02 4.4 CVE-2026-49= 830 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49830 ] dubinc--dub Dub c= ontains an open redirect vulnerability in the redir_url query parameter tha=
t is accepted on every short link without validation or domain allowlist en= forcement. Attackers can append the redir_url parameter to any short link t=
o redirect visitors to arbitrary external URLs through the trusted Dub doma= in, bypassing destination blacklists and potentially enabling phishing atta= cks with link cloaking enabled. 2026-09-04 4.3 CVE-2026-85676 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85676 ] E-cab Taxi Booking Manager for Woo= commerce--E-cab Taxi Booking Manager for Woocommerce The E-cab Taxi Booking=
Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a = client-supplied trip distance and base-price value on the server before pri= cing a booking, allowing unauthenticated attackers to manipulate the order = total down to zero and place real taxi-booking orders at an arbitrary price=
. 2026-09-04 5.3 CVE-2026-84045 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-84045 ] Ebyte--Ebyte NE2-D11 Firmware The affected Ebyte product exports=
administrative credentials and other sensitive configuration information w= ithout adequate protection. An unauthenticated attacker on the adjacent net= work who can obtain an exported configuration file could recover valid cred= entials and use them to access the device or similarly configured systems. = 2026-08-31 6.5 CVE-2026-77975 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -77975 ] Edimax--BR-6214K A vulnerability was identified in Edimax BR-6214K=
1.40. This affects the function system of the file www/wlanMP.asp of the c= omponent asp_WlanMP Endpoint. Such manipulation of the argument ateFunc lea=
ds to os command injection. It is possible to launch the attack remotely. T=
he exploit is publicly available and might be used. The vendor was contacte=
d early about this disclosure but did not respond in any way. 2026-08-31 6.=
6 CVE-2026-82702 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82702 ] Edim= ax--BR-6214K A security flaw has been discovered in Edimax BR-6214K 1.40. T= his vulnerability affects the function system of the file www/ping.asp of t=
he component asp_setPing Endpoint. Performing a manipulation of the argumen=
t pingstr results in os command injection. The attack can be initiated remo= tely. The exploit has been released to the public and may be used for attac= ks. The vendor was contacted early about this disclosure but did not respon=
d in any way. 2026-08-31 6.6 CVE-2026-82703 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-82703 ] elastic -- apm_server Improper Handling of Highly Co= mpressed Data (CWE-409) in APM Server can lead to a persistent denial of se= rvice via Excessive Allocation (CAPEC-130). An authenticated user with writ=
e access to source map content could store specially crafted, highly compre= ssed content that exhausts the memory available to APM Server when it is la= ter processed, terminating the process. The condition recurs on every resta=
rt until the stored content is removed. 2026-09-02 4.9 CVE-2026-78594 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-78594 ] elastic -- elastic_cloud_o= n_kubernetes Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernet=
es (ECK) can lead to unauthorized modification of data via Metadata Spoofin=
g (CAPEC-690). An actor holding limited Kubernetes permissions confined to =
a single namespace could cause attacker-controlled certificate material to =
be included in the Elasticsearch client trust bundle managed by ECK in a se= parate namespace. 2026-09-02 5.4 CVE-2026-78609 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-78609 ] elastic -- elasticsearch Inconsistent Interpreta= tion of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch=
can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). = Under specific proxy deployment configurations, a network attacker could ob= tain confidential responses intended for other authenticated users. 2026-09= -01 5.9 CVE-2026-78605 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78605 =
] elastic -- elasticsearch Missing Authorization (CWE-862) in the Elasticse= arch custom inference service can lead to information disclosure via Privil= ege Abuse (CAPEC-122). A user holding only inference execution privileges c= ould cause outbound inference traffic to be directed to a destination of th= eir choosing and could cause administrator-provisioned credentials to be ex= posed. 2026-09-01 5.4 CVE-2026-78607 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-78607 ] elastic -- elasticsearch Allocation of Resources Without Li= mits or Throttling (CWE-770) in Elasticsearch can lead to a denial of servi=
ce via Excessive Allocation (CAPEC-130). A user with elevated privileges ca=
n submit a specially crafted request that causes excessive memory consumpti= on, which may render the affected node unavailable. 2026-09-01 4.9 CVE-2026= -56143 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56143 ] elastic -- fil= ebeat Allocation of Resources Without Limits or Throttling (CWE-770) in Fil= ebeat can lead to a denial of service via Excessive Allocation (CAPEC-130).=
An attacker able to reach the Filebeat HTTP ingestion endpoint could send = specially crafted compressed requests that exhaust the memory resources of = the Filebeat process. 2026-09-02 6.5 CVE-2026-78588 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-78588 ] elastic -- kibana Allocation of Resources Wi= thout Limits or Throttling (CWE-770) in Kibana can lead to a denial of serv= ice via Excessive Allocation (CAPEC-130). An authenticated user with low-le= vel permissions could submit a specially crafted request that causes excess= ive resource consumption, which may render Kibana unavailable. 2026-09-01 6=
.5 CVE-2026-33465 [
https://www.cve.org/CVERecord?id=3DCVE-2026-33465 ] ela= stic -- kibana Improper Neutralization of Special Elements in Data Query Lo= gic (CWE-943) in Kibana can lead to information disclosure via NoSQL Inject= ion (CAPEC-676). An authenticated user with access to the affected query fu= nctionality could submit specially crafted input that alters the intended q= uery logic, returning data the user is not authorized to read. 2026-09-01 6=
.5 CVE-2026-63138 [
https://www.cve.org/CVERecord?id=3DCVE-2026-63138 ] ela= stic -- kibana Improper Handling of Highly Compressed Data (CWE-409) in Kib= ana can lead to a denial of service via Excessive Allocation (CAPEC-130). A=
n authenticated user holding Streams management privileges could supply spe= cially crafted content that expands to a far larger volume of data during p= rocessing, exhausting the memory available to Kibana. The Kibana process is=
terminated by the host and remains unavailable to all users until the serv= ice is restarted. 2026-09-01 6.5 CVE-2026-72628 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-72628 ] elastic -- kibana Uncaught Exception (CWE-248) i=
n Kibana can lead to a denial of service via Input Data Manipulation (CAPEC= -153). An authenticated user holding only the low-privileged feature access=
required to use the Observability AI Assistant can submit a specially craf= ted request that produces an unhandled error condition, terminating the Kib= ana process and denying service to all users and spaces on that instance un= til it is restarted. 2026-09-01 6.5 CVE-2026-72644 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-72644 ] elastic -- kibana Allocation of Resources Wit= hout Limits or Throttling (CWE-770) in Kibana can lead to a denial of servi=
ce via Excessive Allocation (CAPEC-130). An authenticated user can submit a=
specially crafted request that causes excessive resource consumption, whic=
h may render Kibana unavailable. 2026-09-01 6.5 CVE-2026-72652 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-72652 ] elastic -- kibana Execution with = Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can=
lead to information disclosure via Privilege Abuse (CAPEC-122). An operati=
on available to users holding only read access to the machine learning feat= ure was performed with an internal service identity rather than the identit=
y of the requesting user. Such a user could therefore receive data from Ela= sticsearch indices they are not authorized to read. No Elasticsearch cluste=
r or index privileges are required. 2026-09-01 6.5 CVE-2026-72654 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-72654 ] elastic -- kibana Allocation o=
f Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a = denial of service via Excessive Allocation (CAPEC-130). An authenticated us=
er holding only low, read-level Agent Builder privileges could submit a spe= cially crafted request that causes Kibana to consume an unbounded amount of=
memory, terminating the process and denying service to all users of the in= stance. 2026-09-01 6.5 CVE-2026-72682 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-72682 ] elastic -- kibana Allocation of Resources Without Limits o=
r Throttling (CWE-770) in Kibana can lead to a denial of service via Excess= ive Allocation (CAPEC-130). An authenticated user with low-level privileges=
could submit a specially crafted request that causes Kibana to consume an = unbounded amount of memory, rendering it unavailable to all users. 2026-09-=
02 6.5 CVE-2026-78586 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78586 ]=
elastic -- kibana Improper Limitation of a Pathname to a Restricted Direct= ory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the=
unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-p= rivileged user could cause a subsequent action taken by a higher-privileged=
user in the Fleet administration interface to act on an unintended target,=
resulting in the deletion of resources including accounts with elevated pr= ivileges. 2026-09-02 6.3 CVE-2026-78591 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-78591 ] elastic -- kibana Improper Limitation of a Pathname to =
a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feat= ure can lead to the unauthorized deletion of internal resources via Path Tr= aversal (CAPEC-126). A low-privileged user holding Fleet write access could=
cause a subsequent administrative delete action to act on unintended inter= nal resources. Exploitation requires an administrator to interact with the = affected Fleet interface. 2026-09-02 6.5 CVE-2026-78599 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-78599 ] elastic -- kibana Missing Authorization = (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse = (CAPEC-122). An authorization control was not applied to an internal Kibana=
APM integration function, allowing any authenticated Kibana user to read A=
PM server credentials that should be restricted to users holding APM or Fle=
et administrative privileges. 2026-09-01 6.5 CVE-2026-78608 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-78608 ] elastic -- kibana Incorrect Authoriz= ation (CWE-863) in Kibana can lead to unauthorized modification of data via=
Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An aut= henticated user holding only Security Solution read access in a Kibana spac=
e could enumerate and change the state of Entity Store maintainer tasks, si= lently disabling Entity Analytics maintenance for that space. 2026-09-01 5.=
4 CVE-2026-72641 [
https://www.cve.org/CVERecord?id=3DCVE-2026-72641 ] elas= tic -- kibana Incorrect Authorization (CWE-863) in the Kibana machine learn= ing feature can lead to information disclosure via Exploiting Incorrectly C= onfigured Access Control Security Levels (CAPEC-180). An authenticated user=
holding machine learning job management privileges within a single Kibana = space could cause a job's saved object to become accessible across all spac=
es in the Kibana instance, without holding access rights to those additiona=
l spaces. 2026-09-02 5.4 CVE-2026-78598 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-78598 ] elastic -- kibana Missing Authorization (CWE-862) in Ki= bana can lead to information disclosure via Privilege Abuse (CAPEC-122). An=
authorization control was not applied to a Kibana Entity Store configurati=
on operation, allowing an authenticated user with elevated Kibana privilege=
s to indirectly cause a background task to read from Elasticsearch indices = that user is not authorized to access. Derived entity data from those indic=
es is then exposed through the entity store output. 2026-09-02 5.5 CVE-2026= -78601 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78601 ] elastic -- kib= ana Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead t=
o a loss of security monitoring via Accessing Functionality Not Properly Co= nstrained by ACLs (CAPEC-1). An authenticated user holding only read-level = Security feature access, and no Elasticsearch privileges, could stop the re= curring Privilege Monitoring engine task for a Kibana space. Privileged use=
r monitoring then stops producing data for that space while the engine cont= inues to report a healthy state to operators. 2026-09-01 4.3 CVE-2026-72633=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-72633 ] elastic -- kibana Ob= servable Response Discrepancy (CWE-204) in the Kibana Osquery feature can l= ead to information disclosure via Query System for Information (CAPEC-54). =
An authenticated user holding Osquery live-query privileges could determine=
whether a scheduled query identifier exists in a Kibana space they are not=
authorized to access. 2026-09-02 4.3 CVE-2026-78584 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-78584 ] elastic -- kibana Missing Authorization (CW= E-862) in the Kibana Entity Store feature can lead to unauthorized credenti=
al creation via Accessing Functionality Not Properly Constrained by ACLs (C= APEC-1). An authenticated user holding only low-privilege Security feature = access could invoke an administrative operation that creates and persists E= lasticsearch API keys under the caller's identity, bypassing the elevated c= luster and Kibana privileges that the documented Entity Store setup flow re= quires. 2026-09-01 4.3 CVE-2026-78597 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-78597 ] elastic -- kibana Missing Authorization (CWE-862) in Kiban=
a can lead to information disclosure via Exploiting Incorrectly Configured = Access Control Security Levels (CAPEC-180). An authenticated user holding m= inimal Elasticsearch privileges could bypass Kibana feature authorization a=
nd space access controls, resulting in the unauthorized disclosure of Fleet=
deployment metadata from the default Kibana space. 2026-09-01 4.3 CVE-2026= -78603 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78603 ] elastic -- kib= ana Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized di= sclosure, modification, and deletion of data via Accessing Functionality No=
t Properly Constrained by ACLs (CAPEC-1). Where two authenticated principal=
s originating from different authentication realms share the same username = value, one could read, modify, and delete the other's private Elastic AI As= sistant Knowledge Base entries. 2026-09-01 4.2 CVE-2026-78606 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-78606 ] Elastic--Elastic Maps Server Impro= per Limitation of a Pathname to a Restricted Directory ('Path Traversal') (= CWE-22) in Elastic Maps Server can lead to information disclosure via Path = Traversal (CAPEC-126). An unauthenticated attacker able to reach the servic=
e over the network could cause it to return the contents of files outside i=
ts intended content directory that are readable by the server process. 2026= -09-02 5.3 CVE-2026-78602 [
https://www.cve.org/CVERecord?id=3DCVE-2026-786=
02 ] Elastic--Kibana Incorrect Authorization (CWE-863) in Kibana can lead t=
o information disclosure via Exploiting Incorrectly Configured Access Contr=
ol Security Levels (CAPEC-180). 2026-09-03 6.5 CVE-2026-82299 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-82299 ] Elastic--Kibana An insufficiently = validated configuration field in Kibana's Cribl integration allows an authe= nticated user holding Kibana Fleet management privileges to inject attacker= -controlled expressions into a server-side script template, resulting in an=
Elasticsearch ingest pipeline being written beyond the caller's authorized=
Elasticsearch permissions. 2026-09-03 4.3 CVE-2026-78593 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-78593 ] Elastic--Kibana Missing Authorization =
in Kibana Leading to Information Disclosure / Missing Authorization (CWE-86=
2) in the Kibana Fleet feature can lead to information disclosure via Privi= lege Abuse (CAPEC-122). An authenticated user holding read-level Fleet agen=
t privileges in one Kibana space could enumerate agent metadata and access = diagnostic content belonging to agents enrolled in other Kibana spaces. 202= 6-09-03 4.3 CVE-2026-78595 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78= 595 ] Elastic--Kibana Missing Authorization in Kibana Leading to Unauthoriz=
ed Modification of Data / Missing Authorization (CWE-862) in Kibana can lea=
d to unauthorized modification of data via Privilege Abuse (CAPEC-122). An = authenticated user holding Security read-level access in a single Kibana sp= ace could trigger Entity Analytics migration operations that perform privil= eged writes across all Kibana spaces, regardless of that user's actual acce=
ss scope. 2026-09-03 4.3 CVE-2026-78596 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-78596 ] Elastic--Kibana Incorrect Authorization (CWE-863) in th=
e Kibana machine learning feature can lead to unauthorized resource consump= tion via Exploiting Incorrectly Configured Access Control Security Levels (= CAPEC-180). An authenticated user could invoke machine learning functionali=
ty beyond their authorization scope, consuming cluster resources they shoul=
d not be able to reach. 2026-09-02 4.3 CVE-2026-82293 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-82293 ] Elastic--Kibana Incorrect Authorization (C= WE-863) in Kibana can lead to denial of service via Exploiting Incorrectly = Configured Access Control Security Levels (CAPEC-180). 2026-09-03 4.3 CVE-2= 026-82298 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82298 ] Elegant The= mes--Divi The Divi theme for WordPress is vulnerable to Stored Cross-Site S= cripting via the `redirect_url` parameter of the `et_pb_contact_form` short= code in all versions up to, and including, 4.27.6. This is due to the `redi= rect_url` attribute being sanitized with `esc_attr()` instead of `esc_url()=
` before being rendered into the `data-redirect_url` HTML data attribute. A= dditionally, `redirect_url` is absent from the hardcoded `$url_options` arr=
ay in `class-et-builder-element.php`, so it does not receive `esc_url_raw()=
` sanitization during shortcode parsing. After a successful form submission=
, client-side JavaScript reads this data attribute and passes it directly t=
o `window.location.href`, executing arbitrary JavaScript from a `javascript=
:` URI. This makes it possible for authenticated attackers, with Contributo= r-level access and above, to inject arbitrary web scripts in pages that exe= cute whenever a user submits the contact form. 2026-09-02 6.4 CVE-2026-3850=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-3850 ] Elegant Themes--Divi = The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting v=
ia the Dynamic Content feature's legacy JSON format in all versions up to, = and including, 4.27.6. This is due to two compounding flaws: (1) the save-t= ime sanitization filter `et_builder_sanitize_dynamic_content_fields()` only=
searches for dynamic content markers in the `@ET-DC@...@` format, but the = rendering engine also supports a legacy JSON format that is silently conver= ted at render time, completely bypassing the save-time filter, and (2) the = `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_cont= ent()` does not apply `wp_kses_post()` to the resolved meta value when `ena= ble_html` is set to `on`, passing raw `get_post_meta()` output directly to = the page. This makes it possible for authenticated attackers, with Contribu= tor-level access and above, to inject arbitrary web scripts in pages that w= ill execute whenever a user accesses an injected page. 2026-09-02 6.4 CVE-2= 026-3851 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3851 ] Elegant Theme= s--Divi The Divi theme for WordPress is vulnerable to Stored Cross-Site Scr= ipting via the `skype_url` shortcode attribute of the Social Media Follow m= odule in all versions up to, and including, 4.27.6. This is due to a three-= part sanitization failure: (1) the `skype_url` field is not included in the=
`$url_options` whitelist in `class-et-builder-element.php`, so it never in= vokes `esc_url_raw()` during shortcode processing, (2) the render code in `= SocialMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! = $is_skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_fie= ld()` is applied, which preserves single and double quote characters allowi=
ng attribute breakout. The unsanitized value is interpolated directly into =
a single-quoted `href` attribute (`href=3D'{$social_network_link_url}'`). T= his makes it possible for authenticated attackers, with Contributor-level a= ccess and above, to inject arbitrary web scripts in pages that will execute=
whenever a user interacts with the injected element. 2026-09-03 6.4 CVE-20= 26-3852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3852 ] Eleveo--Qualit=
y Management A vulnerability was identified in Eleveo Quality Management 9.= 7.0. The affected element is the function QuestionnaireService.runDataExpor= tNow of the component Questionnaire Service. Such manipulation of the argum= ent file_name leads to path traversal. The attack may be performed from rem= ote. The exploit is publicly available and might be used. The vendor was co= ntacted early about this disclosure but did not respond in any way. 2026-09= -04 6.3 CVE-2026-85409 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85409 =
] Eleveo--Quality Management A vulnerability was found in Eleveo Quality Ma= nagement 9.7.0. This issue affects some unknown processing of the file /enc= -fwk-data/api/v3/conversations/<ID>/events of the component Conversation Ha= ndler. The manipulation of the argument labels results in denial of service=
. The attack can be executed remotely. The exploit has been made public and=
could be used. The vendor was contacted early about this disclosure but di=
d not respond in any way. 2026-09-04 4.3 CVE-2026-85407 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-85407 ] Eleveo--Quality Management A vulnerabili=
ty was determined in Eleveo Quality Management 9.7.0. Impacted is an unknow=
n function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of th=
e component Conversation Handler. This manipulation of the argument created=
By causes dynamically-determined object attributes. The attack is possible =
to be carried out remotely. The exploit has been publicly disclosed and may=
be utilized. The vendor was contacted early about this disclosure but did = not respond in any way. 2026-09-04 4.3 CVE-2026-85408 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-85408 ] ellite--Wallos Wallos is an open-source, s= elf-hostable personal subscription tracker. Prior to version 4.9.1, an auth= enticated user can edit their own inactive subscription and set replacement= _subscription_id to a subscription ID belonging to another user. The write =
is accepted, and later the stats logic dereferences that foreign subscripti=
on ID without user_id scoping. This lets the attacker infer the victim subs= cription's monthly-normalized cost by observing changes in their own stats = output. This does not expose the full victim subscription object, but it do=
es expose derived financial metadata. This issue has been patched in versio=
n 4.9.1. 2026-08-31 4.3 CVE-2026-50198 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-50198 ] ellite--Wallos Wallos is an open-source, self-hostable = personal subscription tracker. Prior to version 4.9.1, endpoints/currency/u= pdate_exchange.php loads the first Fixer/API Layer credential globally inst= ead of loading the credential for the authenticated user. As a result, a no= rmal authenticated user without their own provider key can trigger exchange= -rate refreshes using another user's stored provider credential. This issue=
has been patched in version 4.9.1. 2026-08-31 4.3 CVE-2026-50199 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-50199 ] ellite--Wallos Wallos is an op= en-source, self-hostable personal subscription tracker. From version 2.0.0 =
to before version 5.0.0, any authenticated Wallos user (no admin rights req= uired) can make the server open arbitrary outbound SMTP connections to inte= rnal/link-local addresses, by setting the SMTP host of their personal email=
notifications to an internal IP. The per-user notification settings endpoi=
nt (endpoints/notifications/saveemailnotifications.php) performs no SSRF va= lidation, and the notification cron (endpoints/cronjobs/sendnotifications.p= hp) feeds that user-controlled host straight into PHPMailer ($mail->Host =
=3D $email['smtpAddress']). When the user's subscription notification fires=
, the server connects to the chosen host:port. This issue has been patched =
in version 5.0.0. 2026-08-31 4.3 CVE-2026-77352 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-77352 ] ellite--Wallos Wallos is an open-source, self-ho= stable personal subscription tracker. Prior to version 5.0.0, Wallos allows=
authenticated users to inject arbitrary iCalendar properties and events in=
to their exported .ics feed by embedding raw CRLF sequences in subscription=
names or notes. Because the input validation layer only encodes HTML metac= haracters but never strips newlines, and the export layer decodes those ent= ities back before writing iCal output, an attacker with any valid account c=
an craft a subscription whose name breaks out of the current VEVENT block a=
nd inserts fully attacker-controlled calendar events - including spoofed or= ganizers, arbitrary email addresses in ATTENDEE properties, and misleading = event content - into any calendar application subscribed to that feed. This=
issue has been patched in version 5.0.0. 2026-08-31 4.6 CVE-2026-77353 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-77353 ] emlog--emlog Emlog is an=
open source website building system. Prior to version 2.6.16, Emlog CMS Pr=
o contains a blind SQL injection in User_Model::getUserDataByLogin(). The $= account parameter is directly interpolated into SQL queries without any fil= tering. The vulnerability is reachable through the auth cookie validation p= ath, where $username is extracted from the cookie and passed unfiltered int=
o SQL - guarded only by an HMAC signature that requires AUTH_KEY to forge. = This issue has been patched in version 2.6.16. 2026-09-04 4.9 CVE-2026-5375=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53756 ] enchant97--note-mar=
k Note Mark is an open-source note-taking application. Prior to version 0.1= 9.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that acce= pts a "deleted" query parameter. When the request is ?deleted=3Dtrue, the s= ervice runs the query with Unscoped() (bypassing GORM's soft-delete scope) = but keeps the read-authorization clause as "owner_id =3D ? OR is_public =3D=
?". As a result, any unauthenticated caller can enumerate the metadata of = soft-deleted ("trashed") notes belonging to any public book - notes the own=
er explicitly deleted and expected to be removed from public view. This iss=
ue has been patched in version 0.19.5. 2026-09-03 5.3 CVE-2026-50554 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-50554 ] ePayco Payment Gateway for = WooCommerce--ePayco Payment Gateway for WooCommerce The ePayco Payment Gate= way for WooCommerce WordPress plugin before 8.4.7 does not properly verify = the authenticity of payment confirmation requests, allowing unauthenticated=
attackers to mark orders as paid without a valid gateway signature. 2026-0= 9-04 5.3 CVE-2026-84043 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84043=
] Exterro--FTK Imager Exterro FTK Imager before 8.3 contains an XML extern=
al entity (XXE) injection vulnerability that allows attackers to read arbit= rary files from the host filesystem by embedding malicious external entity = references and attacker-controlled XSLT stylesheets within a Report.xml fil=
e inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR arc= hive that, when previewed by an examiner, causes the XML parser to resolve = file:// external entity references and execute msxsl:script within the exte= rnal stylesheet to exfiltrate the resolved file contents to an attacker-con= trolled endpoint via a generated image URL. 2026-09-03 5.5 CVE-2026-82525 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82525 ] FasterXML--jackson-dat= abind jackson-databind's deserializer for java.nio.file.Path resolves an at= tacker-supplied URI without restricting the URI scheme. In JDKFromStringDes= erializer.NioPathHelper.deserialize, a string bound from untrusted JSON is = passed to new URI(value) and then to Path.of(uri). When that throws FileSys= temNotFoundException, the code enumerates ServiceLoader<FileSystemProvider>=
and calls provider.getPath(uri) on the first provider whose scheme matches=
the attacker-chosen scheme. Untrusted JSON can therefore select and drive =
an arbitrary registered FileSystemProvider during readValue under a default=
JsonMapper, and forces provider class loading at the same time. With only = the JDK built-in providers (file, jar/zipfs) present, the resolved path is = inert and no mount or network I/O occurs; further impact requires a side-ef= fecting third-party FileSystemProvider on the classpath. This affects com.f= asterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from 2.19=
.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jac= kson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users sh= ould upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.nio.= file.Path from untrusted JSON should be avoided regardless of version. 2026= -09-01 5.3 CVE-2026-19032 [
https://www.cve.org/CVERecord?id=3DCVE-2026-190=
32 ] FasterXML--jackson-databind DefaultBaseTypeLimitingValidator is the Po= lymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used=
without an explicitly configured custom validator. It denies polymorphic r= esolution only for a fixed set of "unsafe base types", and its isSafeSubTyp=
e method returns true unconditionally for every base type outside that set.=
java.lang.Comparable was absent from the list despite being implemented by=
a very large fraction of JDK and application classes, comparable in breadt=
h to java.io.Serializable, which is on the list for that reason. An applica= tion declaring an @JsonTypeInfo-annotated property or class with Comparable=
as its base type, and no custom PolymorphicTypeValidator, will accept a ty=
pe identifier for essentially any class implementing Comparable. This yield=
s an attacker-controlled object instantiation primitive; a demonstrated cas=
e constructs a java.io.File for an arbitrary attacker-chosen path, which be= comes path-traversal-adjacent if the application subsequently calls path-se= nsitive methods on the value. No class implementing Comparable has been ide= ntified that yields code execution through deserialization alone. Global De= fault Typing via activateDefaultTyping is not affected, because that method=
structurally requires an explicit PolymorphicTypeValidator argument. This = affects com.fasterxml.jackson.core:jackson-databind from 2.11.0 before 2.18= .10, from 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.ja= ckson.core:jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3= .2.2. Users should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. 202= 6-09-01 5.6 CVE-2026-83557 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83= 557 ] FastGPT--FastGPT FastGPT Community Edition 4.10.0 through 4.14.0 are = vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories end= point. An unauthenticated attacker can inject malicious NoSQL operators via=
crafted JSON payloads to bypass authorization checks, resulting in unautho= rized access to chat history titles of all users across the platform. 2026-= 08-31 5.3 CVE-2026-79483 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7948=
3 ] Ffmpeg--Ffmpeg v.7.0 Buffer Overflow vulnerability in Ffmpeg v.7.0 and = after allows an attacker to cause a denial of service via the libavformat/i= amf_writer.c component 2026-09-01 6.2 CVE-2026-52295 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-52295 ] filamentphp--filament Filament is a collect= ion of full-stack components for accelerated Laravel development. From 4.0.=
0 until 4.12.6 and 5.7.6, packages/panels/src/Auth/MultiFactor/App/AppAuthe= ntication.php uses AppAuthentication::verifyCode() with a used-code cache k=
ey derived from both the app authentication secret and the submitted TOTP c= ode. This isolates the newest accepted timestep by code instead of by secre=
t, allowing a previously issued app-based MFA code to be accepted after a n= ewer code has already been used. Reuse of the exact same code was already p= revented, but another code inside the accepted time window remained usable.=
An attacker who obtains the target account's password and one app-based MF=
A code can use that code for the remainder of the configured window, which =
is approximately four minutes with the default settings, even after the leg= itimate account holder logs in with a newer code. Email-based MFA is not af= fected. This issue is fixed in versions 4.12.6 and 5.7.6. 2026-09-01 6.5 CV= E-2026-84306 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84306 ] Flatpak-= -Flatpak
=C2=A0 A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU)=
race condition exists in the `org.freedesktop.Flatpak.SystemHelper` compon= ent. This vulnerability occurs because a privileged `chmod` operation execu= tes before the OSTree repository validation within the `Deploy()` function.=
An attacker can exploit this timing window to redirect symlinks to arbitra=
ry files, potentially leading to unauthorized file manipulation or informat= ion disclosure. 2026-09-04 5.8 CVE-2026-76925 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-76925 ] FLVMeta--FLVMeta A vulnerability was found in FLVM= eta up to 1.2.2. Affected is the function amf_string_new of the file src/am= f.c of the component AMF String Processing. The manipulation of the argumen=
t length results in heap-based buffer overflow. The attack can be launched = remotely. The exploit has been made public and could be used. The patch is = identified as f412a33b9a84c2d1a9dee145a868feddbf64879e. A patch should be a= pplied to remediate this issue. The project maintainer doubts the security = impact: "While I acknowledged the bugs and provided fixes, I have yet to se=
e any way to exploit these alleged vulnerabilities." 2026-08-31 4.3 CVE-202= 6-82820 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82820 ] FLVMeta--FLVM= eta A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this=
vulnerability is the function amf_object_get of the file src/amf.c of the = component AMF Object Parsing. This manipulation causes null pointer derefer= ence. The attack may be initiated remotely. The exploit has been publicly d= isclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae= 963d79b. To fix this issue, it is recommended to deploy a patch. The projec=
t maintainer doubts the security impact: "While I acknowledged the bugs and=
provided fixes, I have yet to see any way to exploit these alleged vulnera= bilities." 2026-08-31 4.3 CVE-2026-82821 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82821 ] FormLayer--FormLayer The FormLayer WordPress plugin bef= ore 1.0.9 does not perform any authorization check before returning a form'=
s full stored configuration in the response to its public submission handle=
r, allowing unauthenticated users to disclose notification recipient addres= ses, confirmation redirect targets and integration settings, including thos=
e of unpublished forms. 2026-09-02 5.3 CVE-2026-78151 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-78151 ] FreeRDP--FreeRDP FreeRDP versions 3.0.0 th= rough 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Ses= sion Info PDU reserved padding fields. Three PDU writers in libfreerdp/core= /info.c (rdp_write_logon_info_v2, rdp_write_logon_info_plain, and rdp_write= _logon_info_ex) use Stream_Seek instead of Stream_Zero for reserved pad byt=
es (up to 576 bytes), leaving previously freed heap contents in the outgoin=
g PDU. Because the send buffer is allocated with malloc (not zeroed), stale=
heap data - which may include cleartext credentials from prior sessions - = can be sent to the receiving peer. FreeRDP-based servers using rdpUpdate::S= aveSessionInfo and freerdp-proxy (which forwards these PDUs) are affected, = allowing disclosure of server/proxy process memory to a downstream client. = 2026-09-03 6.5 CVE-2026-85089 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -85089 ] FreeRDP--FreeRDP FreeRDP before 3.31.0 contains a heap out-of-boun=
ds read vulnerability in the general_ChromaV1ToYUV444 function during AVC44=
4 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC44= 4_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds me= mory read past the allocated luma plane. 2026-09-03 5.4 CVE-2026-85090 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85090 ] Frontend Admin by DynamiA= pps--Frontend Admin by DynamiApps The Frontend Admin by DynamiApps WordPres=
s plugin before 3.29.13 does not properly validate a user-controllable dire= ctory path before deleting files within it, allowing unauthenticated attack= ers to delete index.php and .htaccess files outside the intended directory,=
including the WordPress root, which can render the site inoperable. Succes= sful exploitation requires a non-default form configuration. 2026-09-04 5.9=
CVE-2026-81347 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81347 ] GamiP= ress--GamiPress The GamiPress WordPress plugin before 7.9.9.6 does not prop= erly restrict its video watch-tracking functionality, allowing users with a=
role as low as Subscriber to award the configured gamification points, ach= ievements and ranks to arbitrary users including administrators, and to acc= rue them without limit. 2026-09-02 4.3 CVE-2026-77764 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-77764 ] Gastromenum--Gastromenum Ticket and QR Men=
u System Improper neutralization of input during web page generation ('cros= s-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR M= enu System allows Stored XSS. This issue affects Gastromenum Ticket and QR = Menu System: before 2026.08.31. 2026-09-04 5.4 CVE-2026-19057 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-19057 ] Gastromenum--Gastromenum Ticket an=
d QR Menu System Missing Authorization vulnerability in Gastromenum Gastrom= enum Ticket and QR Menu System allows Accessing Functionality Not Properly = Constrained by ACLs. This issue affects Gastromenum Ticket and QR Menu Syst= em: before 2026.08.31. 2026-09-04 4.3 CVE-2026-19081 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-19081 ] getgrav--grav Grav versions 2.0.0 through 2= .0.17 fail to apply save-time XSS detection to modular pages, allowing auth= enticated page editors to store Twig-assembled XSS payloads. Attackers with=
page-edit rights can create modular pages with malicious Twig code that ex= ecutes in visitor browsers when the parent page is rendered, including in a= dministrator sessions. 2026-09-04 6.4 CVE-2026-85598 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-85598 ] getgrav--grav Grav versions before 1.10.55 = contain a path traversal vulnerability in the admin plugin's Save As action=
that fails to validate the language code parameter. An authenticated admin=
user with admin.pages.create permission can supply directory traversal seq= uences in the lang POST field to write arbitrary .md files outside the page=
s directory with attacker-controlled content. 2026-09-04 6.5 CVE-2026-85603=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85603 ] getgrav--grav Grav A= dmin (getgrav/grav-plugin-admin2) versions <=3D 2.0.19 contain a stored cro= ss-site scripting vulnerability in the tHtml() function (src/lib/stores/i18= n.svelte.ts), which substitutes untrusted parameters such as usernames into=
translation templates before parsing the result as markdown. Grav's server= -side username validation (DataUser::isValidUsername) blocks filesystem-dan= gerous characters but not <, >, ", or ', allowing an attacker to register a=
username containing an HTML payload. When an administrator views a UI surf= ace that renders the username through tHtml()-such as the two-factor force-= disable confirmation prompt or the 'page is locked' editor notice-the paylo=
ad executes in their authenticated session. Fixed in 2.0.21. 2026-09-04 5.4=
CVE-2026-85600 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85600 ] getgr= av--grav Grav Admin before 2.0.20 fails to sanitize output from marked.pars= e() before injecting it into the DOM via Svelte's {@html} directive in Mark= downEditor and MarkdownModal components. Attackers can inject javascript: U=
RI schemes in plugin or theme changelogs to execute arbitrary code in authe= nticated admin sessions without requiring site access. 2026-09-04 5.4 CVE-2= 026-85601 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85601 ] getgrav--gr=
av The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9= .1.19 select the reCAPTCHA version to validate based solely on which respon=
se field key is present in the submitted payload. On a site configured for = reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 f= ield name (g-recaptcha-response instead of token), causing validation to us=
e the v2 branch, which never applies the score threshold or verifies the ex= pected action. This results in a complete bypass of reCAPTCHA v3 bot protec= tion. The issue is fixed in version 9.1.20. 2026-09-04 5.3 CVE-2026-85602 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85602 ] GFI Software--GFI Exin=
da AI GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vu= lnerability in the diagnostic file deletion handler. The unlink_or_email_fi= le() function accepts parameters prefixed with v_file_row_ and appends thei=
r values directly to a base directory path without sanitizing for directory=
traversal sequences. An authenticated attacker with Admin privileges can d= elete arbitrary files from the system in the context of root. 2026-09-04 6.=
5 CVE-2026-74236 [
https://www.cve.org/CVERecord?id=3DCVE-2026-74236 ] GFI = Software--GFI Exinda AI GFI Exinda AI and ClearView before 7.6.5 contains a=
n argument injection vulnerability in the Tools Iperf Client functionality.=
The web_tools_cmd() function constructs an iperf command using the server = and options parameters without sanitization, permitting injection of arbitr= ary iperf flags. An authenticated attacker with Unprivileged (lowest-level)=
access can supply the iperf -F flag to read an arbitrary file from the sys= tem and transmit its contents to an attacker-controlled server. 2026-09-04 = 6.5 CVE-2026-74237 [
https://www.cve.org/CVERecord?id=3DCVE-2026-74237 ] GF=
I Software--GFI Exinda AI GFI Exinda AI and ClearView before 7.6.5 contains=
a path traversal vulnerability in the system maintenance configuration dow= nload handler. The wcf_handle_download() function accepts parameters prefix=
ed with v_del_ and appends their values directly to the base configuration = directory path without sanitizing for directory traversal sequences. An aut= henticated attacker with Admin privileges can read arbitrary files from the=
system in the context of root. 2026-09-04 4.9 CVE-2026-74235 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-74235 ] GNOME--gvfs A flaw was found in th=
e AFP backend in gvfs. When mounting a share, a malicious AFP server can ca= use the DSI read path to process a length that exceeds the size requested b=
y the client. The function does not verify the server-provided length again=
st the pre-sized reply buffer, causing the operation to access past the int= ended boundaries. This issue allows a malicious server to overflow a heap b= uffer and crash the gvfsd-afp process, resulting in a denial of service. 20= 26-09-01 6.5 CVE-2026-84269 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 4269 ] GNOME--gvfs A flaw was found in the SFTP backend in gvfs. When mount= ing a share, a malicious SFTP server can cause read_string() to allocate a = buffer with a certain length but the function does not verify that the buff=
er is completely filled, leaving the remainder of the buffer containing uni= nitialized heap contents. If the server sends a short FXP_HANDLE reply, the=
se uninitialized bytes are taken as the file handle. The client will then e= cho these uninitialized bytes back to the server on all subsequent requests=
using that handle. With a length of 128 bytes, this issue allows the malic= ious server to deterministically read uninitialized heap memory from the gv= fsd-sftp process, leaking its heap base and the load address of the libgio = library, resulting in a deterministic defeat of Address Space Layout Random= ization (ASLR). 2026-09-01 4.3 CVE-2026-84267 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-84267 ] GNOME--gvfs A flaw was found in the MTP backend in=
gvfs. When reading a file from a mounted MTP device, do_read() in gvfsback= endmtp.c trusts the data length returned by the device without limiting it =
to the original size requested by the client. If a malicious MTP device res= ponds with more bytes than requested, this unrestricted length is passed di= rectly to memcpy(). This causes the operation to read memory outside the in= tended boundaries. This allows an attacker who plugs in a malicious MTP dev= ice to cause a segmentation fault when a file is read and crash the gvfsd-m=
tp process, resulting in a denial of service. 2026-09-01 4.3 CVE-2026-84270=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84270 ] gonic --gonic=C2=A0 =C2=A0 gonic versions before 0.22.0 fail to validate administrator privileg=
es in the startScan endpoint, allowing any authenticated user to trigger me= dia library rescans. Attackers can repeatedly call the startScan endpoint t=
o force CPU and I/O-intensive filesystem operations, causing denial of serv= ice on multi-user instances. 2026-09-05 4.3 CVE-2026-86118 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-86118 ] google -- chrome Incorrect authorizat= ion in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remot=
e attacker to bypass system access restrictions via a crafted HTML page. (C= hromium security severity: Medium) 2026-09-02 6.5 CVE-2026-84332 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84332 ] google -- chrome Information le=
ak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote=
attacker to potentially leak sensitive information via a crafted HTML page=
. (Chromium security severity: Medium) 2026-09-02 6.5 CVE-2026-84348 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-84348 ] google -- chrome Improper i= nput validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed =
a remote attacker leveraging social engineering to bypass web origin policy=
via crafted network traffic. (Chromium security severity: High) 2026-09-02=
6.5 CVE-2026-84357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84357 ] g= oogle -- chrome Missing authorization in FileSystem in Google Chrome prior =
to 152.0.7977.75 allowed a remote attacker who had compromised the renderer=
process and leveraged social engineering to obtain sensitive information v=
ia a crafted HTML page. (Chromium security severity: Medium) 2026-09-02 5.3=
CVE-2026-84323 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84323 ] googl=
e -- chrome Confused deputy in CredentialProvider in Google Chrome on on Wi= ndows prior to 152.0.7977.75 allowed a remote attacker who had compromised = the renderer process to leak sensitive information via a crafted HTML page.=
(Chromium security severity: Low) 2026-09-02 5.3 CVE-2026-84329 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-84329 ] google -- chrome UI misrepresen= tation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remo=
te attacker to spoof address bar via a crafted HTML page. (Chromium securit=
y severity: Low) 2026-09-02 4.3 CVE-2026-84356 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-84356 ] google -- chrome Improper privilege management in=
Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacke=
r who had compromised the renderer process to spoof address bar via a craft=
ed HTML page. (Chromium security severity: Medium) 2026-09-02 4.2 CVE-2026-= 84358 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84358 ] Google--Chrome = Incorrect authorization in Autofill in Google Chrome on on Android prior to=
152.0.7977.75 allowed a remote attacker leveraging social engineering to o= btain sensitive information via a crafted HTML page. (Chromium security sev= erity: Low) 2026-09-02 6.5 CVE-2026-84327 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-84327 ] Google--Chrome Use of released resource in Mobile in G= oogle Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker=
leveraging social engineering to bypass web origin policy via a crafted HT=
ML page. (Chromium security severity: Medium) 2026-09-03 6.5 CVE-2026-85044=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85044 ] Google--Chrome UI mi= srepresentation in FullScreen in Google Chrome on on Android prior to 152.0= .7977.75 allowed a remote attacker to spoof address bar via a crafted HTML = page. (Chromium security severity: Medium) 2026-09-02 5.4 CVE-2026-84330 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84330 ] gouguoa--gouguoa A secu= rity vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vu= lnerability affects the function update of the file app/home/controller/Ind= ex.php of the component edit_personal Endpoint. Such manipulation of the ar= gument position_id leads to dynamically-determined object attributes. The a= ttack can be executed remotely. The exploit has been disclosed publicly and=
may be used. Upgrading to version 6.0.3 is able to resolve this issue. Upg= rading the affected component is advised. 2026-09-02 6.3 CVE-2026-84430 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84430 ] Grafana--Grafana Enterpr= ise When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAM=
L library skips validation of the InResponseTo field on all SAML responses,=
including SP-initiated logins. This removes anti-replay protection, allowi=
ng an attacker who obtains a valid signed SAML assertion to replay it and g= ain a session as the victim user. Only instances with the allow_idp_initiat=
ed SAML setting enabled are affected; this setting is off by default and Gr= afana OSS is not affected. 2026-09-02 6.8 CVE-2026-12704 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-12704 ] Grafana--PostgreSQL Datasource An authe= nticated user with permission to query a SQL data source can bypass the fix=
for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause=
, which Grafana's regex-based macro parsing does not reject. Evaluating the=
injected macro causes uncontrolled memory consumption that can terminate t=
he Grafana server process, resulting in a denial of service. The Microsoft = SQL Server, PostgreSQL, and MySQL data sources are affected. 2026-09-02 6.5=
CVE-2026-19475 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19475 ] groka= bility--snipe-it Snipe-IT before 8.7.0 gates the bulk asset restore endpoin=
t on the assets.edit permission instead of assets.delete, allowing users wi= thout delete rights to restore soft-deleted assets. Attackers with edit per= missions can post asset identifiers to the bulk restore endpoint to undo ad= ministrator deletions and bypass intended permission separation. 2026-09-01=
4.3 CVE-2026-84206 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84206 ] g= rowilabs--growi GROWI contains an access control vulnerability in the GET /= _api/v3/attachment/:id endpoint that fails to validate page access permissi= ons. Authenticated attackers can retrieve attachment metadata from pages th=
ey cannot view by supplying known attachment identifiers. 2026-09-01 6.5 CV= E-2026-84204 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84204 ] growilab= s--growi GROWI contains an access control vulnerability in the GET /_api/v3= /revisions/:id endpoint that validates access against a query parameter but=
returns the revision identified by the path parameter without confirming t= hey reference the same page. Authenticated attackers can pair a page identi= fier they can access with an arbitrary revision identifier to read revision=
content from pages they lack permission to view. 2026-09-01 6.5 CVE-2026-8= 4205 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84205 ] Gutentor--Gutent=
or The Gutentor WordPress plugin before 4.0.6 does not apply the correct co= ntext restriction to one of its REST endpoints, exposing the plaintext pass= words of password-protected posts to any authenticated user with at least t=
he Subscriber role. 2026-09-02 4.3 CVE-2026-16983 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-16983 ] h3 --h3=C2=A0
=C2=A0 h3 versions before 2.0.1-rc.18 contain an open redirect vulnerabilit=
y in the redirectBack() utility that fails to sanitize protocol-relative pa= ths in the Referer header pathname. Attackers can craft a same-origin URL w= ith a double-slash path segment that passes origin validation but produces =
a Location header interpreted by browsers as a protocol-relative redirect t=
o an external domain. 2026-09-06 5.4 CVE-2026-86205 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-86205 ] h3 --h3=C2=A0
=C2=A0 h3 versions before 1.15.9 contain a path traversal vulnerability in = the serveStatic utility. A double-decoding flaw allows a request path conta= ining double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2=
e, which survives resolveDotSegments() because that function only checks fo=
r literal '.' characters. When the resulting asset ID is resolved by URL-ba= sed backends (CDN, S3, object storage), %2e%2e is interpreted as '..' per R=
FC 3986, enabling path traversal to read arbitrary files from the backend. = 2026-09-06 5.9 CVE-2026-86251 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -86251 ] h3 --h3=C2=A0
=C2=A0 h3 (npm package) versions <=3D 2.0.1-rc.14 contain a path traversal = vulnerability in serveStatic(). On Node.js deployments, event.url.pathname =
is not normalized, so percent-encoded dot segments (%2e%2e) are passed to d= ecodeURI() and decoded to ../ sequences without sanitization. An unauthenti= cated remote attacker can send crafted requests to endpoints served by serv= eStatic() to read arbitrary files outside the intended static directory. Fi= xed in 1.15.6 and 2.0.1-rc.15. 2026-09-06 5.9 CVE-2026-86253 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-86253 ] h3 --h3=C2=A0
=C2=A0
=C2=A0 h3 versions before 1.15.9 fail to sanitize carriage return character=
s in EventStream data and comment fields, allowing attackers to inject arbi= trary SSE events by including unsanitized carriage returns. Attackers can i= nject event type directives, split single push calls into multiple browser-= parsed events, or escape comment fields to inject data, bypassing the prior=
CVE fix that only addressed newline injection. 2026-09-06 5.3 CVE-2026-862=
52 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86252 ] heymrun--heym Heym=
before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebS= ocket Trigger nodes, allowing authenticated users to connect to internal se= rvices. Attackers can craft workflow nodes with arbitrary URLs and headers =
to reach internal services and read responses from the WebSocket Trigger no= de. 2026-09-01 5.4 CVE-2026-84207 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84207 ] HIPAA FORMS--HIPAA FORMS The HIPAA FORMS WordPress plugin befo=
re 3.2.0 contains a hardcoded authentication bypass via a hardcoded paramet=
er alongside all AJAX requests. The server explicitly checks for this value=
to skip nonce validation entirely. This allows unauthenticated attackers t=
o access protected AJAX endpoints. 2026-09-02 6.5 CVE-2026-2688 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-2688 ] Hitachi Energy--RTU500 series CMU=
firmware RTU500 has a vulnerability, where high-load scenarios, such as se= nding GI requests at short intervals, may cause a NULL pointer dereference =
in the last entry of the enhanced message queue. This can cause a BCI_IEC10=
4 fatal write error, resulting in connection interruption and restart, and = ultimately a denial of service for bidirectional IEC 60870-5-104 communicat= ion. 2026-09-03 5.9 CVE-2026-17539 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-17539 ] honojs--@hono/oauth-providers @hono/oauth-providers is Authen= tication middleware for Hono. Prior to version 0.8.6, the built-in social l= ogin providers accept an OAuth callback even when the `state` value is abse=
nt on both sides, so the anti-CSRF check passes for a callback that never c= ame from a genuine login attempt. This defeats the `state`-based CSRF prote= ction under default usage. Version 0.8.6 has a patch. 2026-08-31 5.4 CVE-20= 26-81888 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81888 ] honojs--hono=
Hono is a Web application framework that provides support for any JavaScri=
pt runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 = does not cover every traversal sequence, and toSSG() can still write files = outside the configured output directory when a route parameter contains con= secutive parent-directory segments. Static site generation builds each outp=
ut path from the route path and values supplied through ssgParams, then ver= ifies that the result stays inside the output directory using the same norm= alization routine that built the path. That routine does not fully collapse=
runs of consecutive parent-directory segments, allowing a path that the ch= eck accepts to resolve outside the output directory, and the check also tre= ats output directories that differ in how they are rooted as equivalent. Th=
is arises when an application generates a static site from route parameter = values it does not fully control, such as slugs from a CMS, API, or user su= bmission. An untrusted ssgParams value can create or overwrite files elsewh= ere in the build environment and alter generated artifacts or deployment ou= tput. The vulnerability affects build-time static site generation only; req= uest-time routing and applications with entirely developer-controlled ssgPa= rams values are not affected. This issue is fixed in version 4.13.5. 2026-0= 9-01 6.5 CVE-2026-84365 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84365=
] honojs--hono Hono is a Web application framework that provides support f=
or any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a qu= estion mark after a literal hash fragment as the start of a query string, s=
o the application can read request parameters that browsers, new URL(), rev= erse proxies, filtering rules, parameter allow and deny lists, access loggi= ng, request validation, and other middleware do not observe. The Cache Midd= leware removes the fragment when building its cache key, allowing a respons=
e influenced by parameters inside the fragment to be stored under a key tha=
t omits those parameters and later served to other users. This can bypass f= iltering and auditing, poison cached responses, and enable stored cross-sit=
e scripting when an affected parameter is reflected into cached HTML withou=
t escaping. Exploitation requires a runtime and intermediary path that pass=
es a literal hash character through to the request URL; Cloudflare Workers = and intermediaries that strip fragments are not affected. This issue is fix=
ed in version 4.13.5. 2026-09-01 5.9 CVE-2026-84363 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-84363 ] honojs--hono Hono is a Web application frame= work that provides support for any JavaScript runtime. Prior to 4.13.5, whe=
n parseBody() expands dot-separated form field names into nested objects wi=
th dot-notation parsing enabled, it does not limit the nesting depth or the=
total number of intermediate objects created. Empty segments are preserved=
, so one deeply dotted field name can encode one nesting level per byte, wh= ile a large number of shallowly dotted fields can create the same amplifica= tion across a request. A request body within a normal size limit can theref= ore allocate an object graph far larger than the request after the body has=
already been accepted. An unauthenticated attacker who can reach an affect=
ed endpoint can send concurrent requests that exhaust the JavaScript heap, = terminate the server process, and leave the service unavailable until resta= rt. Dot-notation parsing is not enabled by default, and applications using = the default behavior are not affected. This issue is fixed in version 4.13.=
5. 2026-09-01 5.3 CVE-2026-84364 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84364 ] hpe -- arubaos-cx A vulnerability in the web-based management i= nterface of AOS-CX could allow an authenticated remote attacker to conduct =
a server-side request forgery (SSRF) attack. A successful exploit allows an=
attacker to enumerate information about the internal structure of the AOS-=
CX host, leading to potential disclosure and limited modification of sensit= ive information. 2026-09-01 6.4 CVE-2026-73757 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-73757 ] hpe -- arubaos-cx A privilege escalation vulnerab= ility exists in the API endpoint of AOS-CX. Successful exploitation could a= llow an authenticated low privilege operator user to change the state of ce= rtain settings of a vulnerable system. 2026-09-01 6.5 CVE-2026-73758 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-73758 ] hpe -- arubaos-cx Vulnerabi= lities in AOS-CX could allow an unauthenticated remote malicious actor to t= rigger a denial-of-service condition by sending specially crafted packets. = Successful exploitation of these vulnerabilities results in disruption of n= ormal operation on affected devices. 2026-09-01 6.5 CVE-2026-73759 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-73759 ] hpe -- arubaos-cx An authenti= cated Path Traversal vulnerability exists in AOS-CX. Successful exploitatio=
n of this vulnerability allows an attacker to read arbitrary files from the=
web-based management interface of the underlying operating system, which c= ould lead to remote unauthorized access to files. 2026-09-01 6.5 CVE-2026-7= 3760 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73760 ] hpe -- arubaos-c=
x An out-of-bounds read vulnerability exists in the underlying operating sy= stem of AOS-CX that could lead to unauthenticated information disclosure by=
sending a specially crafted packet. Successful exploitation of this vulner= ability results in the ability to disclose sensitive information from the u= nderlying operating system. 2026-09-01 6.5 CVE-2026-73761 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-73761 ] hpe -- arubaos-cx A vulnerability has = been identified in the API endpoint of AOS-CX that could allow a remote act=
or to circumvent existing access controls. In some cases this could enable = unauthorized access to management functionality that should be restricted b=
y the configured access control policy. 2026-09-01 6.6 CVE-2026-73762 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-73762 ] hpe -- arubaos-cx Buffer o= verflow vulnerabilities exist in an underlying service of AOS-CX that could=
lead to an unauthenticated denial-of-service condition by sending speciall=
y crafted packets to the affected device. Successful exploitation of these = vulnerabilities results in a disruption of normal operation of the underlyi=
ng operating system. 2026-09-01 6.5 CVE-2026-73772 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-73772 ] hpe -- arubaos-cx Denial-of-service vulnerabi= lities exist in the command line interface of AOS-CX. Successful exploitati=
on could allow an authenticated user to disrupt the normal operation of a v= ulnerable system. 2026-09-01 5.3 CVE-2026-73754 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-73754 ] hpe -- arubaos-cx A privilege escalation vulnera= bility exists in the API endpoint of AOS-CX. Successful exploitation could = allow an authenticated low-privilege operator user, after a required user a= ction, to access sensitive information from the vulnerable system. 2026-09-=
01 5.7 CVE-2026-73755 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73755 ]=
hpe -- arubaos-cx A vulnerability in an API endpoint of AOS-CX could allow=
a remote unauthenticated attacker to obtain sensitive information via a ma= n-in-the-middle attack. Successful exploitation allows an attacker to retri= eve data which could be used to further compromise the confidentiality of t=
he affected system. 2026-09-01 5.9 CVE-2026-73756 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-73756 ] hpe -- arubaos-cx Stack overflow vulnerabiliti=
es exist in an API endpoint of AOS-CX. Successful exploitation could allow =
an authenticated malicious actor to cause a denial-of-service condition on = the affected system. 2026-09-01 4.9 CVE-2026-73783 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-73783 ] huggingface--tokenizers tokenizers (Hugging F= ace) is affected by an out-of-bounds buffer access in BpeBuilder::build (to= kenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokeni= zer::from_file/from_str, the builder sizes a scratch buffer to the longest = vocabulary key, then writes each concatenated merge rule into it. A merge w= hose concatenated token exceeds the longest vocabulary key overruns the buf= fer, which Rust turns into a panic that aborts the process in Rust and FFI = embeddings. This occurs at load time with no encoding required, so an attac= ker who supplies a crafted tokenizer.json can cause a denial of service. A = secondary defect at the same location can cause a usize underflow (panic in=
debug, potential memory corruption in release) when continuing_subword_pre= fix is set and a merge token is shorter than the prefix. Observed in versio=
n 0.23.1. 2026-09-04 6.5 CVE-2026-85670 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85670 ] IBM-- App Connect Enterprise
=C2=A0 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 t= hrough 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.=
7 could allow a local attacker to obtain sensitive information due to impro= per logging of credentials. 2026-09-04 6.2 CVE-2026-16689 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-16689 ] IBM-- i
=C2=A0 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated atta= cker to obtain sensitive information due to the use of hardcoded cryptograp= hic constants to obfuscate encryption keys. 2026-09-04 4.4 CVE-2026-16693 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-16693 ] IBM-- i
=C2=A0 IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker =
to modify certain system messages due to improper authorization. 2026-09-04=
4.3 CVE-2026-16941 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16941 ] I= BM--App Connect Enterprise IBM App Connect Enterprise 13.0.1.0 through 13.0= .8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1= .0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive info= rmation due to improper logging of database credentials. 2026-09-04 6.2 CVE= -2026-19649 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19649 ] IBM--App = Connect Enterprise IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, an=
d 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 thr= ough 10.1.0.7 could allow a local attacker to cause a denial of service due=
to uncontrolled recursion. 2026-09-04 5.5 CVE-2026-17440 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-17440 ] IBM--App Connect Enterprise IBM App Co= nnect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28=
and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a l= ocal attacker to obtain sensitive information due to credentials being writ= ten to trace logs in cleartext. 2026-09-04 5.1 CVE-2026-17442 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-17442 ] IBM--App Connect Enterprise IBM Ap=
p Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.1= 2.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow=
a remote authenticated attacker to obtain sensitive information due to an = XML external entity (XXE) injection flaw. 2026-09-04 5.3 CVE-2026-17443 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-17443 ] IBM--App Connect Enterpr= ise IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a remote authenticated attacker to obtain sensitive information = due to an XML external entity (XXE) injection. 2026-09-04 5.3 CVE-2026-1744=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17444 ] IBM--App Connect En= terprise IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0=
through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.= 0.7 could allow a remote attacker to cause a denial of service due to an in= finite loop. 2026-09-04 5.3 CVE-2026-78543 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-78543 ] IBM--App Connect Enterprise
=C2=A0 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 t= hrough 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.=
7 Toolkit could allow an authenticated user to cause a denial-of-service co= ndition due to improper validation of XML entities. 2026-09-04 5.7 CVE-2026= -16180 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16180 ] IBM--Cloud Pak=
for Business Automation CP4BA - IBM Enterprise Records could allow a local=
attacker to obtain sensitive information due to the use of a broken or ris=
ky cryptographic algorithm. 2026-09-04 6.2 CVE-2026-81859 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-81859 ] IBM--Cloud Pak for Data System
=C2=A0 IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could=
allow an unauthorized user to inject data into log messages due to imprope=
r neutralization of special elements when written to log files. 2026-09-04 = 5.3 CVE-2026-14350 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14350 ] IB= M--Db2 Mirror for i IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allo=
w a local attacker to delete historical flight-recorder archives due to imp= roper access control in an SQL procedure. 2026-09-04 4.3 CVE-2026-17483 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-17483 ] IBM--Db2 Mirror for i IB=
M Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain=
information due to a race condition involving a predictable Unix domain so= cket path in a world-writable directory. 2026-09-04 4.4 CVE-2026-18567 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-18567 ] IBM--Db2 Mirror for i
=C2=A0 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker=
to cause a denial of service due to an out-of-bounds read. 2026-09-04 5.3 = CVE-2026-16660 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16660 ] IBM--i=
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a deni=
al of service and compromise integrity due to a buffer overflow. 2026-09-04=
6.5 CVE-2026-17207 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17207 ] I= BM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attac= ker to cause a denial of service due to a NULL pointer dereference. 2026-09= -04 6.5 CVE-2026-17273 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17273 =
] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated at= tacker to corrupt memory due to an integer underflow. 2026-09-04 6.3 CVE-20= 26-18341 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18341 ] IBM--i IBM i=
7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sen= sitive information in PASE. An attacker could exploit this vulnerability to=
access information about process they shouldn't be permitted to access. 20= 26-09-04 6.5 CVE-2026-18887 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 8887 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticat=
ed attacker to bypass security restrictions due to predictable server seeds=
. 2026-09-04 5.4 CVE-2026-17274 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-17274 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenti= cated attacker to cause a denial of service due to an off-by-one write in t=
he LPD queue name parser. 2026-09-04 5.3 CVE-2026-17469 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-17469 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 coul=
d allow a remote attacker to cause a denial of service due to a buffer over= flow. 2026-09-04 5.3 CVE-2026-17470 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-17470 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote att= acker to cause a denial of service due to improper validation of the prefix=
length in ICMPv6 Router Advertisements. 2026-09-04 4.3 CVE-2026-17255 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-17255 ] IBM--i IBM i 7.6, 7.5, 7.=
4, and 7.3 could allow a remote authenticated attacker to cause a denial of=
service due to a stack-based buffer overflow. 2026-09-04 4.3 CVE-2026-1725=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17259 ] IBM--i IBM i 7.6, 7= .5, 7.4, and 7.3 could allow a local attacker to cause a denial of service = due to a stack-based buffer overflow. 2026-09-04 4.3 CVE-2026-17270 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-17270 ] IBM--i IBM i 7.6, 7.5, 7.4, = and 7.3 could allow a local attacker to execute arbitrary commands due to i= mproper neutralization of special elements used in an OS command. 2026-09-0=
4 4.4 CVE-2026-17499 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17499 ] = IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attac= ker to inject parameters into a CL command due to improper neutralization o=
f special elements. 2026-09-04 4.4 CVE-2026-18073 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-18073 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allo=
w a remote authenticated attacker to cause a denial of service due to a mem= ory leak. 2026-09-04 4.3 CVE-2026-18076 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-18076 ] IBM--i IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remot=
e authenticated attacker to cause a denial of service due to an integer ove= rflow. 2026-09-04 4.3 CVE-2026-18078 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-18078 ] IBM--i
=C2=A0 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause =
a denial of service and affect data integrity due to missing authentication=
for critical functions. 2026-09-04 6.5 CVE-2026-17057 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-17057 ] IBM--i
=C2=A0 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute=
arbitrary commands due to improper neutralization of special elements used=
in an OS command. 2026-09-04 5.3 CVE-2026-16826 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-16826 ] IBM--i
=C2=A0
=C2=A0 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated atta= cker to bypass security restrictions due to improper authentication during = service-name matching. 2026-09-04 5.4 CVE-2026-16892 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-16892 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 th= rough 1.10.2 could allow a remote authenticated attacker to obtain sensitiv=
e information due to improper limitation of a pathname to a restricted dire= ctory. 2026-09-04 6.5 CVE-2026-17622 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-17622 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 through 1.11.2 cou=
ld allow a remote authenticated attacker to obtain sensitive information du=
e to path traversal. 2026-09-04 6.5 CVE-2026-19299 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-19299 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 thro= ugh 1.11.2 could allow a remote authenticated attacker to obtain sensitive = information due to improper validation of symbolic links. 2026-09-04 6.5 CV= E-2026-19302 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19302 ] IBM--Lan= gflow OSS IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-= site scripting vulnerability in the Playground chat interface. 2026-09-04 6=
.1 CVE-2026-8447 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8447 ] IBM--= Langflow OSS IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an = authenticated attacker to write arbitrary files to the server due to improp=
er input validation in the SaveToFileComponent. The application constructs = local file paths using attacker-controlled input without sufficient sanitiz= ation when handling requests to the /api/v1/run/{flow_id} endpoint. An atta= cker with low-privileged authenticated access (such as a valid API key or u= ser session) can supply crafted path values, including absolute paths or pa=
th traversal sequences, allowing arbitrary file writes to locations writabl=
e by the Langflow process. Successful exploitation may lead to unauthorized=
file creation or modification, potentially resulting in further compromise=
depending on the deployment environment. 2026-09-04 6.5 CVE-2026-9138 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-9138 ] IBM--Langflow OSS IBM Lang= flow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypa=
ss localhost-only MCP configuration installation by spoofing X-Forwarded-Fo=
r: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.curs= or/mcp.json, etc.). 2026-09-04 6.5 CVE-2026-9186 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-9186 ] IBM--Langflow OSS IBM Langflow OSS 1.0.0 through=
1.10.2 could allow a remote attacker to traverse directories on the system=
. An attacker could send a specially crafted URL request containing "dot do=
t " sequences ( /.. /) to view arbitrary files on the system. 2026-09-04 5.=
4 CVE-2026-17621 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17621 ] IBM-= -Langflow OSS IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote au= thenticated attacker to obtain sensitive information due to a server-side r= equest forgery (SSRF) vulnerability. 2026-09-04 5 CVE-2026-17631 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-17631 ] IBM--Langflow OSS IBM Langflow = OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obt= ain sensitive information due to server-side request forgery. 2026-09-04 5 = CVE-2026-19301 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19301 ] IBM--L= angflow OSS IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote auth= enticated attacker to obtain sensitive information and inject messages into=
workflow history due to improper authorization. 2026-09-04 4.9 CVE-2026-17= 627 [
https://www.cve.org/CVERecord?id=3DCVE-2026-17627 ] IBM--Langflow OSS =C2=A0 IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated a= ttacker to traverse directories on the system. An attacker could send a spe= cially crafted URL request containing "dot dot" sequences (/../) to view ar= bitrary files on the system. 2026-09-04 6.5 CVE-2026-14470 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-14470 ] IBM--MQ Agent IBM MQ Agent CD: v1.0.0=
, v1.0.1, v2.0.0, v2.0.1 An authenticated user with a valid session cookie = can submit arbitrarily large or computationallyexpensive requests that caus=
e the LLM agent workers to be held for extended periods - rangingfrom tens =
of seconds to over ten minutes per request. When multiple such requests are=
sentconcurrently, the agent worker pool becomes exhausted, causing all oth=
er IBM MQ Console users toexperience degraded performance or complete unava= ilability of the AI Agent feature. 2026-09-04 6.5 CVE-2026-19645 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-19645 ] IBM--Netezza Software IBM Netez=
za Software 11.3.0.3 through Interim Fix 002 has operations that are perfor= med without validating bucket ownership using the ExpectedBucketOwner param= eter. This omission may allow a remote attacker to exploit misconfiguration=
s or naming collisions to redirect application requests to an unintended S3=
bucket under their control. 2026-09-03 6.5 CVE-2026-9745 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-9745 ] IBM--Netezza Software IBM Netezza Softw= are 11.3.0.3 through Interim Fix 002 does not validate or improperly valida= tes TLS certificate validation, which could allow an attacker to obtain sen= sitive information using man in the middle techniques. 2026-09-03 5.9 CVE-2= 026-9036 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9036 ] IBM--Netezza = Software IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow =
an unauthorized user to inject data into log messages due to improper neutr= alization of special elements when written to log files. 2026-09-03 5.3 CVE= -2026-9736 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9736 ] IBM--Netezz=
a Software IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not v= alidate or improperly validates TLS certificate validation, which could all=
ow an attacker to obtain sensitive information using man in the middle tech= niques. 2026-09-03 5.3 CVE-2026-9744 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-9744 ] IBM--Qiskit SDK Qiskit could allow a local attacker to cause=
a denial of service due to a stack overflow during deserialization of QPY = payloads. A malicious QPY payload can trigger a segmentation fault, causing=
the application to crash when deserializing untrusted input. 2026-09-03 6.=
2 CVE-2026-19795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19795 ] IBM-= -QRadar IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-c= oded credentials, such as a password or cryptographic key, which it uses fo=
r its own inbound authentication, outbound communication to external compon= ents, or encryption of internal data. 2026-09-04 6.7 CVE-2026-5522 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-5522 ] IBM--UCD - IBM UrbanCode Deplo=
y IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.3.= 2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.1.= 2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UCD)=
is susceptible to an formation disclosure vulnerability when processing re= dacted property values. If a deployment is configured with a secure propert=
y that starts with certain non-ASCII characters, the redaction engine may f= ail to mask subsequent ASCII secure values embedded inside unsecure propert= ies. An authenticated user with permissions to view deployment request deta= ils could exploit this flaw via the UI or API to view sensitive values in p= lain text that should otherwise be redacted. 2026-09-04 6.5 CVE-2026-78658 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-78658 ] ILIAS--ILIAS A securi=
ty flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the=
function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file=
Services/Repository/Service/Resources/ZipAdapter.php of the component Medi= aPool. The manipulation results in unrestricted upload. The attack may be l= aunched remotely. Upgrading to version 9.22, 10.10 and 11.3 is able to miti= gate this issue. The patch is identified as ef5d7f99fe1ea0381db04b333a29065= 48b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recommended to up= grade the affected component. 2026-09-03 6.3 CVE-2026-85135 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85135 ] ILIAS-eLearning e.V.--ILIAS ILIAS be= fore versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnera= bility in the SOAP addFile method that allows authenticated users to read s= erver files by supplying crafted XML with COPY-mode imports. Attackers can = construct absolute file paths through an unsandboxed import directory and r= etrieve sensitive files including configuration files containing database c= redentials and setup passwords. 2026-08-31 6.5 CVE-2026-82877 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-82877 ] Insyde Software--InsydeH2O An issu=
e was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administra= tor password hashes are exposed in runtime UEFI variables, leading to escal= ation of privilege 2026-09-03 6.5 CVE-2021-43613 [
https://www.cve.org/CVER= ecord?id=3DCVE-2021-43613 ] Insyde Software--InsydeH2O Error in handling th=
e PlatformLangCodes UEFI variable could cause a buffer overflow, leading to=
resource exhaustion and failure. 2026-09-03 6.7 CVE-2021-43614 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2021-43614 ] Interinfo--DreamMaker DreamMaker=
developed by Interinfo has a Reflected Cross-site Scripting vulnerability.=
Authenticated remote attackers can execute arbitrary JavaScript codes in u= ser's browser via a malicious website. 2026-09-04 5.4 CVE-2026-85541 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85541 ] invoiceninja--Invoice Ninja=
A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26=
. This affects an unknown part of the file /vedor/profile/ of the component=
Vendor Portal Profile Update. Executing a manipulation of the argument ven= dor_contact can lead to authorization bypass. The attack may be performed f= rom remote. The exploit has been made available to the public and could be = used for attacks. Upgrading to version 5.13.27 is able to mitigate this iss= ue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The affe= cted component should be upgraded. 2026-09-01 6.3 CVE-2026-83743 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-83743 ] invoiceninja--Invoice Ninja A s= ecurity vulnerability has been detected in invoiceninja Invoice Ninja up to=
5.13.26. This vulnerability affects the function Purify::isHostSafe of the=
file app/Services/Pdf/Purify.php of the component invoices Endpoint. The m= anipulation of the argument notes leads to server-side request forgery. It =
is possible to initiate the attack remotely. The exploit has been disclosed=
publicly and may be used. The vendor was contacted early about this disclo= sure but did not respond in any way. 2026-09-01 4.3 CVE-2026-83744 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-83744 ] IObit--Uninstaller A flaw has=
been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_M= J_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Ha= ndler. Executing a manipulation can lead to improper privilege management. = The attack requires local access. The vendor was contacted early about this=
disclosure but did not respond in any way. 2026-08-31 4.4 CVE-2026-82670 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82670 ] itsourcecode --Sales a=
nd Inventory System 1.0
=C2=A0 A vulnerability was identified in itsourcecode Sales and Inventory S= ystem 1.0. This impacts an unknown function of the file /pages/pro_del.php.=
The manipulation of the argument ID leads to sql injection. The attack is = possible to be carried out remotely. The exploit is publicly available and = might be used. 2026-09-06 6.3 CVE-2026-86163 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-86163 ] itsourcecode --Sales and Inventory System 1.0
=C2=A0 A security flaw has been discovered in itsourcecode Sales and Invent= ory System 1.0. Affected is an unknown function of the file /pages/trans_vi= ew.php. The manipulation of the argument ID results in sql injection. The a= ttack may be performed from remote. The exploit has been released to the pu= blic and may be used for attacks. 2026-09-06 6.3 CVE-2026-86164 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-86164 ] itsourcecode--Online Medicine De= livery System A weakness has been identified in itsourcecode Online Medicin=
e Delivery System 1.0. Affected by this vulnerability is the function doupd= ateimage of the file /customer/controller.php?action=3Dphotos of the compon= ent Customer Controller. Executing a manipulation of the argument photo can=
lead to unrestricted upload. The attack may be performed from remote. The = exploit has been made available to the public and could be used for attacks=
. 2026-09-03 6.3 CVE-2026-85186 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-85186 ] itsourcecode--Online Medicine Delivery System A vulnerability wa=
s determined in itsourcecode Online Medicine Delivery System 1.0. This issu=
e affects the function addwishlist of the file /customer/controller.php?act= ion=3Daddwish of the component Wishlist. This manipulation of the argument = proid causes sql injection. The attack may be initiated remotely. 2026-09-0=
3 6.3 CVE-2026-85205 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85205 ] = itsourcecode--Sales and Inventory System A vulnerability was identified in = itsourcecode Sales and Inventory System 1.0. This impacts an unknown functi=
on of the file /pages/inv_edit.php. The manipulation of the argument ID lea=
ds to sql injection. It is possible to initiate the attack remotely. The ex= ploit is publicly available and might be used. 2026-08-31 6.3 CVE-2026-8260=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82609 ] itsourcecode--Sales=
and Inventory System A weakness has been identified in itsourcecode Sales = and Inventory System 1.0. The affected element is an unknown function of th=
e file /pages/inv_searchfrm.php. This manipulation of the argument ID cause=
s sql injection. The attack may be initiated remotely. The exploit has been=
made available to the public and could be used for attacks. 2026-08-31 6.3=
CVE-2026-82696 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82696 ] itsou= rcecode--Sales and Inventory System A flaw has been found in itsourcecode S= ales and Inventory System 1.0. The affected element is an unknown function =
of the file /pages/inv_del.php. Executing a manipulation of the argument ID=
can lead to sql injection. The attack can be executed remotely. The exploi=
t has been published and may be used. 2026-09-04 6.3 CVE-2026-85383 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-85383 ] itsourcecode--Sales and Inve= ntory System 1.0
=C2=A0 A weakness has been identified in itsourcecode Sales and Inventory S= ystem 1.0. Affected by this vulnerability is an unknown functionality of th=
e file /pages/sup_del.php?type=3Dsupplier. Executing a manipulation of the = argument ID can lead to sql injection. The attack may be performed from rem= ote. The exploit has been made available to the public and could be used fo=
r attacks. 2026-09-06 6.3 CVE-2026-86232 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-86232 ] JeecgBoot--JeecgBoot JeecgBoot 3.9.2 and earlier contai=
ns an authorization bypass vulnerability in the SystemApiController compone= nt. An authenticated attacker with any valid JWT token can access multiple = API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById=
, and queryUsersByIds) to retrieve sensitive information of all users, incl= uding real names, phone numbers, email addresses, employee numbers, and rol=
e definitions, due to missing fine-grained permission checks and incomplete=
data desensitization. 2026-09-04 6.5 CVE-2026-78970 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-78970 ] jeecgboot--jeewx-boot A vulnerability was d= etermined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40d= ad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of t=
he file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/M= yJwWebJwid3Controller.java of the component doUpload Endpoint. Executing a = manipulation of the argument File can lead to unrestricted upload. The atta=
ck can be executed remotely. The exploit has been publicly disclosed and ma=
y be utilized. This product implements a rolling release for ongoing delive= ry, which means version information for affected or updated releases is una= vailable. The project was informed of the problem early through an issue re= port but has not responded yet. 2026-08-31 4.7 CVE-2026-82629 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-82629 ] Jenkins Project--Jenkins In Jenkin=
s 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoint=
s for updating agent configuration do not prevent a submitted configuration=
from overwriting a different agent by specifying that agent's name in the = submitted XML document, allowing attackers with Agent/Configure permission =
on one agent to take over a different agent, gaining control of its configu= ration and obtaining access to its inbound agent secret and environment var= iables. 2026-09-02 6.3 CVE-2026-84651 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84651 ] Jenkins Project--Jenkins In Stapler 2107.v8dfcb_e8ed317 an=
d earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and e= arlier, LTS 2.568.2 and earlier, form data binding allows setting public st= atic fields of the bound configuration object, allowing attackers who can s= ubmit configuration forms to modify public static fields of the configurati=
on objects those forms are bound to, resulting in changes that apply global=
ly to the Jenkins instance. 2026-09-02 5.4 CVE-2026-84654 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84654 ] Jenkins Project--Jenkins In Jenkins 2.= 579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested=
field values in other deserialized XML objects, allowing attackers with Ov= erall/Read permission to create user objects by submitting crafted XML. 202= 6-09-02 4.3 CVE-2026-84646 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84= 646 ] Jenkins Project--Jenkins Jenkins 2.579 and earlier, LTS 2.568.2 and e= arlier does not escape map keys when serializing objects as JSON and Python=
through its REST API, allowing attackers able to control map property name=
s to inject arbitrary fields into JSON and Python API responses. 2026-09-02=
4.3 CVE-2026-84655 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84655 ] J= enkins Project--Jenkins A missing permission check in Jenkins 2.579 and ear= lier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on=
at least one job to read build parameter names and values of jobs they hav=
e no access to. 2026-09-02 4.3 CVE-2026-84656 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-84656 ] Jenkins Project--Jenkins In Jenkins 2.579 and earl= ier, LTS 2.568.2 and earlier, the build CLI command does not check the Item= /Cancel permission when using the -s flag to cancel a build triggered to wa=
it for completion, allowing attackers with Item/Build permission to cancel = builds started by other users. 2026-09-02 4.2 CVE-2026-84657 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84657 ] Jenkins Project--Jenkins GitLab Plu= gin Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global = GitLab connection configuration through Stapler data binding, allowing atta= ckers to connect to an attacker-specified URL using GitLab API tokens alrea=
dy configured by administrators. 2026-09-02 5.4 CVE-2026-84664 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84664 ] Jenkins Project--Jenkins Job Conf= iguration History Plugin Jenkins Job Configuration History Plugin 1367.vc8f= a_b_15101dc and earlier allows overwriting the plugin's history recording c= onfiguration through Stapler data binding, allowing attackers to redirect h= istory storage to an attacker-specified directory and modify history record= ing settings. 2026-09-02 5.4 CVE-2026-84666 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-84666 ] Jenkins Project--Jenkins LDAP Plugin Jenkins LDAP Pl= ugin 807.809.vd3a_4e5e4ec98 and earlier allows connecting to a specified UR=
L through Stapler data binding, allowing attackers to connect to an attacke= r-specified URL. 2026-09-02 4.3 CVE-2026-84662 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-84662 ] Jenkins Project--Jenkins Parameterized Remote Tri= gger Plugin Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier s= tores tokens unencrypted in job config.xml files on the Jenkins controller = where they can be viewed by users with Item/Extended Read permission or acc= ess to the Jenkins controller file system. 2026-09-02 4.3 CVE-2026-84676 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84676 ] Jenkins Project--Jenkin=
s Pipeline: Build Step Plugin A missing permission check in Jenkins Pipelin=
e: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream bui= lds triggered by the `build` step to be canceled even when the build's auth= entication lacks Item/Cancel permission on the downstream job. 2026-09-02 5=
.4 CVE-2026-84660 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84660 ] Jen= kins Project--Jenkins Pipeline: Build Step Plugin A missing permission chec=
k in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier c= auses downstream builds awaited by the `waitForBuild` step when the `propag= ateAbort` parameter is used to be canceled even when the build's authentica= tion lacks Item/Cancel permission on the downstream job. 2026-09-02 5.4 CVE= -2026-84661 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84661 ] Jenkins P= roject--Jenkins Pipeline: Groovy Libraries Plugin A cross-site request forg= ery (CSRF) vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 798.v= 5cc688825312 and earlier allows attackers to delete shared library caches. = 2026-09-02 5.4 CVE-2026-84663 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84663 ] Jenkins Project--Jenkins Script Security Plugin Jenkins Script Sec= urity Plugin 1412.v7737b_3405f86 and earlier uses the `@DataBoundConstructo=
r` annotation on a constructor that loads script approval configuration, al= lowing attackers able to submit certain forms to read that configuration. 2= 026-09-02 4.3 CVE-2026-84658 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84658 ] Jenkins Project--Jenkins Script Security Plugin Jenkins Script Secu= rity Plugin 1412.v7737b_3405f86 and earlier does not enforce a permission c= heck in the method that controls the "Force the use of the sandbox globally=
in the system" setting, allowing attackers to disable it through Stapler d= ata binding. 2026-09-02 4.3 CVE-2026-84659 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-84659 ] Jenkins Project--Jenkins update-center2 Jenkins updat= e-center2 3.18.3 and earlier does not escape plugin-provided values (plugin=
names, descriptions, and version metadata) on plugin download index pages,=
resulting in a stored cross-site scripting (XSS) vulnerability exploitable=
by attackers able to provide a plugin for hosting. 2026-09-02 5.4 CVE-2026= -84677 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84677 ] Jenkins Projec= t--Jenkins XebiaLabs XL Deploy Plugin Missing permission checks in Jenkins = XebiaLabs XL Deploy Plugin 26.1.0 and earlier allow attackers with Overall/= Read permission to enumerate credentials IDs of credentials stored in Jenki= ns. 2026-09-02 5.4 CVE-2026-84674 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84674 ] JetStyleManager for Gutenber--JetStyleManager for Gutenberg Th=
e JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have=
CSRF protection on some of its AJAX actions, allowing attackers to make a = logged-in user with the edit_posts capability (Contributor and above) delet=
e or modify custom widget skins via a crafted request, provided they can tr= ick the user into performing an action such as clicking a link. 2026-09-02 = 4.3 CVE-2026-81432 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81432 ] jo= fpin--trape A vulnerability was identified in jofpin trape 1.0.0. Affected =
by this vulnerability is an unknown functionality of the file core/stats.py=
of the component Login Endpoint. The manipulation leads to missing authent= ication. The attack may be initiated remotely. The exploit is publicly avai= lable and might be used. The project was informed of the problem early thro= ugh an issue report but has not responded yet. 2026-09-04 5.3 CVE-2026-8563=
6 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85636 ] John James Jacoby--= bbPress Missing Authorization vulnerability in John James Jacoby bbPress al= lows Exploiting Incorrectly Configured Access Control Security Levels. This=
issue affects bbPress: from n/a through 2.6.14. 2026-08-31 5.3 CVE-2026-74= 010 [
https://www.cve.org/CVERecord?id=3DCVE-2026-74010 ] jtsylve--LiME LiM=
E through 1.12.0 fails to validate the disk acquisition output path and doe=
s not use O_NOFOLLOW when opening the operator-supplied path parameter, all= owing unprivileged local users to overwrite arbitrary root-owned files. An = attacker who controls the output directory can create a symbolic link with = the expected filename pointing to any root-owned file, and when the acquisi= tion runs in kernel context, LiME follows the link and truncates the target=
file with the memory acquisition stream. 2026-09-03 6.6 CVE-2026-85092 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-85092 ] Kevin Pirnie--KP Agent R= eady Insertion of Sensitive Information Into Sent Data vulnerability in Kev=
in Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issu=
e affects KP Agent Ready: from n/a before 1.2.08. 2026-09-03 5.3 CVE-2026-8= 5307 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85307 ] Keyence Corporat= ion--XG-X VisionTerminal XG VisionTerminal and XG-X VisionTerminal provided=
by Keyence Corporation improperly restrict XML external entity references.=
If a user opens a specially crafted setting file, the sensitive informatio=
n stored in the system where XG VisionTerminal or XG-X VisionTerminal is in= stalled may be disclosed. 2026-09-03 5.5 CVE-2026-82918 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-82918 ] kimai--kimai Kimai before 2.65.0 fails t=
o properly validate permissions when removing team access to activities, pr= ojects, and customers via API endpoints. Authenticated users with edit_team=
permission can revoke team access without the required permissions_activit=
y check, bypassing authorization controls. 2026-09-02 5.4 CVE-2026-84804 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84804 ] kimai--kimai Kimai befo=
re 2.63.0 contains an improper authorization vulnerability in team access e= ndpoints that allows authenticated users with team edit permissions and rea= d-only access to grant team access to customers, projects, or activities. A= ttackers can exploit insufficient permission checks by sending POST request=
s to team access endpoints to modify access control lists for entities they=
should not be able to modify. 2026-09-02 5.4 CVE-2026-84806 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84806 ] kimai--kimai Kimai (kimai/kimai) th= rough 2.65.0 contains a business logic / improper authorization vulnerabili=
ty in the default team creation endpoints. An authenticated user with proje=
ct permission-management privileges can create or use a customer, project, =
or activity whose name matches an existing team; because the endpoints POST=
/api/customers/{id}/team, POST /api/projects/{id}/team, and POST /api/acti= vities/{id}/team reuse an existing team of the same name and add the curren=
t user as teamlead without verifying that the user is authorized to manage = that team, the attacker gains unauthorized team-lead (administration) right=
s over the existing team. Fixed in 2.65.0. 2026-09-02 5.4 CVE-2026-84807 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84807 ] kimai--kimai Kimai vers= ions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract pre= ferences for low-privilege users in the PATCH /api/users/{id}/preferences e= ndpoint. Although the web interface gates these employment-contract fields = behind the contract_other_profile admin permission, the WorkContractPrefere= nceSubscriber (introduced in 2.61.0) registers the preferences as enabled w= ithout a permission check, so an authenticated regular user can use the API=
to modify their own admin-only work-contract data. The issue is fixed in 2= .63.0 by applying the same permission check to the API endpoint. 2026-09-02=
4.3 CVE-2026-84805 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84805 ] k= imai--kimai Kimai versions before 2.65.0 contain an authorization bypass vu= lnerability in the REST API timesheet collection endpoint that fails to enf= orce activity-team access controls. Users with view_other_timesheet permiss= ion can list timesheets using activities restricted to teams they do not be= long to, bypassing intended data isolation. 2026-09-02 4.3 CVE-2026-84808 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-84808 ] Kings Plugins--MarketK= ing Missing Authorization vulnerability in Kings Plugins MarketKing allows = Exploiting Incorrectly Configured Access Control Security Levels. This issu=
e affects MarketKing: from n/a through 2.1.60. 2026-09-04 5.3 CVE-2026-8531=
1 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85311 ] KiviCare--KiviCare = The KiviCare WordPress plugin before 4.5.5 does not perform authorization c= hecks on some of its REST endpoints, allowing unauthenticated attackers to = disclose the patient roster and, when a payment gateway is configured, the = payment gateway secret key. 2026-09-01 5.3 CVE-2026-13611 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-13611 ] klaussilveira--GitList A vulnerability=
was detected in klaussilveira GitList 2.0.0. Affected by this issue is the=
function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php o=
f the component XML Parsing. Performing a manipulation results in denial of=
service. The attack is possible to be carried out remotely. The exploit is=
now public and may be used. Upgrading to version 3.0.0-beta can resolve th=
is issue. The patch is named f67609d52c1812fa8a7ed80eae5e795cfd72115f. It i=
s advisable to upgrade the affected component. 2026-08-31 5.3 CVE-2026-8266=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82669 ] Kriesi--Enfold Impr= oper Neutralization of Input During Web Page Generation ('Cross-site Script= ing') vulnerability in Kriesi Enfold allows Reflected XSS. This issue affec=
ts Enfold: from n/a through 8.0. 2026-09-03 5.8 CVE-2026-84815 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84815 ] kyverno--kyverno Kyverno before v= 1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service = Call functionality. An attacker with permission to create Kyverno (Cluster)= Policies can specify an external URL in a policy's apiCall/service configur= ation; although Service Call is documented for in-cluster services, it also=
resolves external addresses, allowing requests to an attacker-controlled s= erver. Because policy context data (including contents of Kubernetes resour= ces such as secrets) is sent in these requests, an attacker can exfiltrate = sensitive cluster data. 2026-09-01 6.5 CVE-2025-15613 [
https://www.cve.org= /CVERecord?id=3DCVE-2025-15613 ] langgenius--dify A vulnerability was deter= mined in langgenius dify 1.13.0. Affected is the function router.replace of=
the file web/app/(shareLayout)/components/splash.tsx of the component Spla=
sh Layout. This manipulation of the argument redirect_url causes cross site=
scripting. The attack is possible to be carried out remotely. The exploit = has been publicly disclosed and may be utilized. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-09-03 4.3 C= VE-2026-85021 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85021 ] Laravel= -Backpack--CRUD backpack/crud provides Create, Read, Update & Delete (CRUD)=
functions for Backpack, a collection of Laravel packages that help users b= uild custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the = src/app/Library/Uploaders/SingleBase64Image.php methods SingleBase64Image::= uploadFiles and SingleBase64Image::uploadRepeatableFiles, used by image fie= lds through withFiles(), accept any data URI beginning with data:image with= out validating the declared MIME subtype or decoded bytes, while src/app/Li= brary/Uploaders/Support/FileNameGenerator.php method FileNameGenerator::get= ExtensionFromFile applies mime_content_type() to the data URI instead of th=
e decoded content. An authenticated administrator can therefore store arbit= rary file content under an extensionless filename on the configured disk, w= hich can cause stored cross-site scripting or other unintended behavior whe=
n the file is served and accessed. This issue is fixed in version 7.0.38 an=
d 6.8.14. 2026-08-31 4.4 CVE-2026-54179 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-54179 ] levelfourstorefront--Shopping Cart & eCommerce Store Th=
e Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to gen= eric SQL Injection via the 'product_order' parameter in all versions up to,=
and including, 5.9.2 due to insufficient escaping on the user supplied par= ameter and lack of sufficient preparation on the existing SQL query. This m= akes it possible for authenticated attackers, with administrator-level acce=
ss and above, to append additional SQL queries into already existing querie=
s that can be used to extract sensitive information from the database. This=
is a second-order SQL injection: the payload is written to the ec_pageopti=
on table via the ec_ajax_save_page_options handler - which applies no sanit= ization to raw $_POST values - and is later retrieved with stripslashes() (= bypassing WordPress magic-quotes protection) before being concatenated dire= ctly into SQL on every store page render. 2026-09-01 4.9 CVE-2026-17589 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-17589 ] libjxl--libjxl libjxl be= fore 0.12 contains an integer underflow vulnerability in the container box = parser that allows remote attackers to inject arbitrary metadata by exploit= ing 64-bit box size truncation to size_t on 32-bit platforms. Attackers can=
supply a crafted JPEG XL file causing the decoder to parse attacker-contro= lled codestream bytes as phantom box headers, enabling injection of arbitra=
ry metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-bounds reads. 202= 6-09-02 5.4 CVE-2026-82522 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 522 ] libpcap --BPF interpreter
=C2=A0 libpcap BPF interpreter treats the offset in the 'ja L' BPF instruct= ion as a signed integer to implement looping via backward jumps, but it doe=
s not limit the number of loop iterations. In particular uncommon use cases=
a crafted filter program can cause the interpreter to loop infinitely. 202= 6-09-05 5.5 CVE-2026-6554 [
https://www.cve.org/CVERecord?id=3DCVE-2026-655=
4 ] libpcap--BPF interpreter
=C2=A0 libpcap BPF interpreter calls abort() if it encounters a BPF instruc= tion that has an invalid opcode. In particular uncommon use cases a crafted=
filter program can terminate the OS process. 2026-09-05 5.5 CVE-2026-31911=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-31911 ] libpcap--BPF interpr= eter
=C2=A0 libpcap BPF interpreter detects neither reaching the end of the filt=
er program buffer due to lack of a return instruction nor executing a jump = instruction with an offset that translates to a pointer outside of the buff= er. In particular uncommon use cases a crafted filter program can cause the=
interpreter to try reading the OS process memory in the 32GiB around the b= uffer on 64-bit architectures and in the entire address space on 32-bit arc= hitectures. 2026-09-05 5.5 CVE-2026-31912 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-31912 ] libpcap--BPF interpreter
=C2=A0 libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructio=
ns does not check whether the immediate value is zero. In particular uncomm=
on use cases a crafted filter program can cause a division by zero. 2026-09= -05 5.5 CVE-2026-6244 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6244 ] = librenms--librenms LibreNMS before 26.5.0 contains stored cross-site script= ing vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_n= ame, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered=
without sanitization. Attackers controlling a monitored network device can=
inject arbitrary JavaScript through SNMP responses that executes in the br= owser of any user viewing VRF-related pages. 2026-09-01 6.1 CVE-2026-84191 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84191 ] librenms--librenms Li= breNMS versions <=3D 26.4.0 contain a stored cross-site scripting vulnerabi= lity in the graph_descr.<graphtype> configuration settings, which are echoe=
d verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An = administrator can store a malicious HTML payload that executes in the brows=
er of any authenticated user who views the affected graph type. The issue i=
s fixed in version 26.7.0. 2026-09-01 4.8 CVE-2026-84188 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-84188 ] libxml2 --libxml2=C2=A0
=C2=A0 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer=
overflow and resultant heap-based buffer overflow. 2026-09-05 6.9 CVE-2026= -86138 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86138 ] libxml2 --libx= ml2=C2=A0
=C2=A0 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer ov= erflow. 2026-09-05 6.9 CVE-2026-86139 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-86139 ] libxml2 --libxml2=C2=A0
=C2=A0 In libxml2 before 2.15.4, there is a heap-based buffer overflow in x= mlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. 2026-= 09-05 6.9 CVE-2026-86142 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8614=
2 ] libxml2 --libxml2=C2=A0
=C2=A0 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWrit= eCallback and xmlBufUse causes negative lengths to reach write callbacks, a=
ka a lack of a check for integer overflow before calling writecallback. Thi=
s has security relevance for many types of uses of that length value within=
a callback. 2026-09-05 6.9 CVE-2026-86143 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-86143 ] libxml2 --libxml2=C2=A0
=C2=A0 In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInc= ludeProcessTree do not propagate parseFlags. This has security relevance fo=
r, for example, the XML_PARSE_NONET flag, if (without it) a custom resource=
loader accesses the internet and triggers XML external entity injection, S= SRF, or a denial of service (e.g., for an attacker-controlled internet reso= urce that is intentionally slow). 2026-09-05 5.6 CVE-2026-86144 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-86144 ] light0011--cms A security vulner= ability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d= 99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some = unknown processing of the file App/Home/Controller/ChapterController.class.= php of the component Chapter Controller. Such manipulation of the argument = content leads to authorization bypass. The attack may be launched remotely.=
The exploit has been disclosed publicly and may be used. This product oper= ates on a rolling release basis, ensuring continuous delivery. Consequently=
, there are no version details for either affected or updated releases. The=
project was informed of the problem early through an issue report but has = not responded yet. 2026-09-04 5.3 CVE-2026-85381 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-85381 ] light0011--cms A vulnerability was detected in = light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618= c3814cc2f61380b38930. Impacted is the function htmlspecialchars_decode of t=
he file App/Home/View/Default/Chapter/oneChapter.tpl of the component Chapt=
er Content Output. Performing a manipulation of the argument content result=
s in cross site scripting. Remote exploitation of the attack is possible. T=
he exploit is now public and may be used. This product follows a rolling re= lease approach for continuous delivery, so version details for affected or = updated releases are not provided. The project was informed of the problem = early through an issue report but has not responded yet. 2026-09-04 4.3 CVE= -2026-85382 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85382 ] Lightstar= --SmartIT Desktop Manager SmartIT Desktop Manager developed by Lightstar ha=
s a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att= ackers can obtain the SFTP service credentials of the SmartIT Agent applica= tion from the source code, thereby browsing the file system of the user's h= ost. 2026-09-04 5.3 CVE-2026-85149 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85149 ] livecomposer--Live Composer Free WordPress Website Builder Th=
e Live Composer - Free WordPress Website Builder plugin for WordPress is vu= lnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attri= bute of the dslc_modules_section and dslc_modules_area shortcodes in versio=
ns up to, and including, 2.1.19. This is due to insufficient input sanitiza= tion and output escaping on the user-supplied attribute, which is concatena= ted into the HTML id=3D"" attribute of the rendered <div> element in the ds= lc_modules_section_front() and dslc_modules_area_front() functions without = esc_attr(). This makes it possible for authenticated attackers, with Contri= butor-level access and above, to inject arbitrary web scripts in pages that=
will execute whenever a user accesses an injected page. 2026-09-01 6.4 CVE= -2026-13203 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13203 ] livecompo= ser--Live Composer Free WordPress Website Builder The Live Composer - Free = WordPress Website Builder plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via dslc_module_testimonials_output Shortcode in all versi= ons up to, and including, 2.1.19 due to insufficient input sanitization and=
output escaping. This makes it possible for authenticated attackers, with = contributor-level access and above, to inject arbitrary web scripts in page=
s that will execute whenever a user accesses an injected page. The injected=
payload survives save-time wp_kses_post filtering because KSES treats shor= tcode delimiters as opaque, and the unescaped fields - including main_headi= ng_title, view_all_link, main_heading_link_title, and main_filter_title_all=
- are only rendered when do_shortcode() executes at page-view time. 2026-0= 9-01 6.4 CVE-2026-16786 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16786=
] livecomposer--Live Composer Free WordPress Website Builder The Live Comp= oser - Free WordPress Website Builder plugin for WordPress is vulnerable to=
Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versi= ons up to, and including, 2.1.19 due to insufficient input sanitization and=
output escaping. This makes it possible for authenticated attackers, with = contributor-level access and above, to inject arbitrary web scripts in page=
s that will execute whenever a user accesses an injected page. 2026-09-01 6=
.4 CVE-2026-16787 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16787 ] liv= ecomposer--Live Composer Free WordPress Website Builder The Live Composer -=
Free WordPress Website Builder plugin for WordPress is vulnerable to Store=
d Cross-Site Scripting via dslc_module_projects_output Shortcode in all ver= sions up to, and including, 2.1.19 due to insufficient input sanitization a=
nd output escaping. This makes it possible for authenticated attackers, wit=
h contributor-level access and above, to inject arbitrary web scripts in pa= ges that will execute whenever a user accesses an injected page. WordPress'=
s shortcode-aware kses handling preserves the serialized shortcode body as =
a placeholder before content filtering runs, allowing attacker-controlled v= alues such as view_all_link, main_heading_link_title, main_filter_title_all=
, and button_text to reach render-time sinks entirely unescaped. 2026-09-01=
6.4 CVE-2026-16788 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16788 ] L= iveJournal Shortcode--LiveJournal Shortcode The LiveJournal Shortcode WordP= ress plugin through 1.1.1 does not validate and escape some of its shortcod=
e attributes before outputting them back in a page/post where the shortcode=
is embed, which could allow users with the contributor role and above to p= erform Stored Cross-Site Scripting attacks 2026-09-02 5.9 CVE-2024-3773 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2024-3773 ] llmware-ai--llmware llmwa=
re 0.4.6 contains an SQL injection vulnerability in the collection-database=
layer (llmware/resources.py) where filter and lookup values are directly s= tring-interpolated into SQL WHERE clauses without parameterization or escap= ing, in both the SQLite and PostgreSQL backends. The filter validator only = checks keys against an allow-list and never sanitizes values. Attacker-cont= rolled filter values reaching the public API via Library.block_lookup and Q= uery.text_query_with_custom_filter / text_query_by_author_or_speaker can ne= utralize the intended filter to disclose rows the caller was scoped out of = (cross-document/cross-collection disclosure); on PostgreSQL the flaw permit=
s boolean- and UNION-based SQL injection. 2026-09-04 6.5 CVE-2026-85689 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-85689 ] lobehub--lobehub LobeCha=
t (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook si= gnatures in the QQ and Feishu adapters. The webhook route (/api/agent/webho= oks/:platform) is unauthenticated by design and delegates verification to e= ach adapter; the QQ adapter performs no Ed25519 signature verification on d= ispatched message events, and the Feishu adapter only performs an optional = static-token comparison that is skipped when no token is configured (the de= fault) and is not a body signature. An unauthenticated attacker who knows t=
he public webhook URL can POST forged inbound messages with an attacker-cho= sen sender identity and arbitrary text, causing the bot owner's agent to pr= ocess attacker-controlled input and treat the attacker as a trusted platfor=
m sender. 2026-09-04 6.5 CVE-2026-85621 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85621 ] LogNet--grpc-spring-boot-starter A vulnerability has be=
en found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unk= nown function of the component Annotation Processing. Such manipulation lea=
ds to improper authorization. The attack may be performed from remote. A hi=
gh complexity level is associated with this attack. The exploitability is t= old to be difficult. The exploit has been disclosed to the public and may b=
e used. The project was informed of the problem early through an issue repo=
rt but has not responded yet. 2026-08-31 5 CVE-2026-82594 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-82594 ] lukeseager--Persistent Login The Persi= stent Login plugin for WordPress is vulnerable to generic SQL Injection via=
'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to=
insufficient escaping on the user supplied parameter and lack of sufficien=
t preparation on the existing SQL query. This makes it possible for authent= icated attackers, with subscriber-level access and above, to append additio= nal SQL queries into already existing queries that can be used to extract s= ensitive information from the database. This vulnerability is only exploita= ble when the plugin's Login History feature is enabled. 2026-09-01 6.5 CVE-= 2026-18752 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18752 ] Magepeople=
inc.--Booking and Rental Manager Improper Neutralization of Input During W=
eb Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc=
. Booking and Rental Manager allows Stored XSS. This issue affects Booking = and Rental Manager: from n/a through 2.7.7. 2026-09-03 6.5 CVE-2026-85303 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85303 ] magepeopleteam--Bookin=
g and Rental Manager Subscriber Broken Access Control in Booking and Rental=
Manager <=3D 2.7.6 versions. 2026-08-31 6.5 CVE-2026-81762 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-81762 ] malach-it--boruta-server Boruta is a=
standalone authorization server that aims to implement OAuth 2.0 and Openi=
d Connect up to decentralized identity specifications. Prior to version 0.1= 0.0, Boruta logged sensitive OAuth and OpenID Connect values in business ev= ent logs. Logged values could include access tokens, refresh tokens, author= ization codes, agent tokens, direct-post codes, ID tokens, VP tokens, and t= okens submitted to introspection or revocation endpoints. An attacker with = access to Boruta logs, log aggregation systems, or the administration log v= iewer could recover these credentials and use them until expiration or revo= cation. This issue has been patched in version 0.10.0. 2026-09-02 6.5 CVE-2= 026-55221 [
https://www.cve.org/CVERecord?id=3DCVE-2026-55221 ] Mamunur Ras= hid--Classified Listing Missing Authorization vulnerability in Mamunur Rash=
id Classified Listing allows Accessing Functionality Not Properly Constrain=
ed by ACLs. This issue affects Classified Listing: from n/a through 6.1.1. = 2026-09-02 5.4 CVE-2026-84217 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84217 ] MapQuest--Get Directions App A vulnerability was identified in Map= Quest Get Directions App 10.16.1 on Android. This vulnerability affects the=
function getDataColumn of the file ExpoShareIntentModule.kt of the compone=
nt com.mapquest.android.ace. The manipulation leads to path traversal. An a= ttack has to be approached locally. The exploit is publicly available and m= ight be used. The vendor was contacted early about this disclosure but did = not respond in any way. 2026-09-02 4.4 CVE-2026-84442 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-84442 ] MapSVG--MapSVG Unauthenticated Server Side=
Request Forgery (SSRF) in MapSVG <=3D 8.15.0 versions. 2026-08-31 5.4 CVE-= 2026-82852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82852 ] marqo-ai--= marqo Marqo 2.26.0 contains a server-side request forgery vulnerability in = the add_documents endpoint that allows unauthenticated attackers to trigger=
requests to arbitrary URLs by supplying malicious media field values. Atta= ckers can exploit download_image_from_url and fetch_content_sample function=
s which lack destination filtering and host validation to access internal s= ervices and cloud metadata endpoints. 2026-09-04 5.3 CVE-2026-85662 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-85662 ] MasterStudy LMS WordPress Pl= ugin--MasterStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plugin=
WordPress plugin before 3.7.46 does not perform an authorization check bef= ore returning per-student course enrollment and progress data, allowing una= uthenticated attackers to disclose the enrolled courses and learning progre=
ss of any registered user. 2026-09-02 5.3 CVE-2026-81195 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-81195 ] MasterStudy LMS WordPress Plugin--Maste= rStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plugin WordPress = plugin before 3.7.46 does not restrict access to a REST route that lists an=
author's courses, nor does it filter that listing by publication status, a= llowing unauthenticated users to read the titles and IDs of unpublished (dr= aft, pending and private) courses. 2026-09-02 5.3 CVE-2026-81197 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-81197 ] MasterStudy LMS WordPress Plugi= n--MasterStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plugin Wo= rdPress plugin before 3.7.46 does not perform an authorization check before=
returning a student's learning statistics, allowing unauthenticated attack= ers to disclose the course counts, points, certificates, quiz and assignmen=
t totals of any registered user. 2026-09-02 5.3 CVE-2026-81199 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-81199 ] MasterStudy LMS WordPress Plugin-= -MasterStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plugin Word= Press plugin before 3.7.46 does not properly verify authorization when retr= ieving order line-item data, allowing any authenticated user including Subs= cribers to read other instructors' course sales records by supplying anothe=
r user's identifier. 2026-09-02 4.3 CVE-2026-81194 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-81194 ] MBS-Solutions--X-Series Gateway=C2=A0 An info= rmation disclosure vulnerability in the ugw-deviceinfo method of /cgi-bin/w= wwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 returns detail=
ed system version fields (operatingsystem, gatewayversion) to any authentic= ated user, including users with the low-privileged Standard role. 2026-09-0=
4 6.5 CVE-2026-75163 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75163 ] = MBS-Solutions--X-Series Gateway=C2=A0 An arbitrary file read vulnerability =
in /cgi-bin/ugwdownload.cgi of MBS-Solutions X-Serie Gateway firmware V6_00= _05 allows a remote authenticated user with the low-privileged Standard rol=
e to retrieve arbitrary files from the device filesystem via the file query=
string parameter. 2026-09-04 6.5 CVE-2026-75164 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-75164 ] MBS-Solutions--X-Series Gateway=C2=A0 An issue =
in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie = Gateway firmware V6_00_05 allows a remote authenticated user with the low-p= rivileged Standard role to write arbitrary content to files within /uxx/con= fig/ and /ugw/config/. 2026-09-04 6.3 CVE-2026-75168 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-75168 ] mckaywrigley--chatbot-ui Chatbot UI contain=
s an authorization bypass vulnerability in the retrieval endpoint that allo=
ws authenticated attackers to access private file content belonging to othe=
r users by supplying arbitrary file UUIDs. The endpoint uses a service-role=
Supabase client that bypasses row-level security and fails to validate fil=
e ownership, enabling attackers to retrieve indexed content chunks from vic= tim files through crafted POST requests. 2026-09-04 6.5 CVE-2026-85693 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85693 ] Menulux Software Inc.--Me= nulux Portal Improper neutralization of input during web page generation ('= cross-site scripting') vulnerability in Menulux Software Inc. Menulux Porta=
l allows Stored XSS. This issue affects Menulux Portal: before 202609032114= 48. 2026-09-04 5.4 CVE-2026-18957 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-18957 ] Menulux Software Inc.--Menulux Portal Missing Authorization vu= lnerability in Menulux Software Inc. Menulux Portal allows Accessing Functi= onality Not Properly Constrained by ACLs. This issue affects Menulux Portal=
: before 20260903211448. 2026-09-04 4.3 CVE-2026-19043 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-19043 ] Metabase--Metabase
=C2=A0 Metabase versions before 0.63.1 fail to enforce data analyst permiss= ion checks on glossary API endpoints, allowing any authenticated user to cr= eate, modify, and delete glossary entries. Attackers can submit requests to=
POST, PUT, and DELETE glossary endpoints to tamper with instance-wide busi= ness glossary data without proper authorization. 2026-09-05 6.5 CVE-2026-86= 116 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86116 ] mikel--mail Mail =
is an internet library for Ruby designed to handle email generation, parsin=
g, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and Mail::Ut= ilities.b_value_decode used a single String#match and an overly greedy char= set capture to decode only the first RFC 2047 encoded-word and mishandle su= rrounding or subsequent text. A crafted malformed encoded-word in an addres=
s display name or local part could cross ? delimiters and make decoded From=
, To, or Reply-To header values differ from the raw values inspected by a h= uman reviewer or downstream parser, enabling apparent sender or recipient s= poofing, phishing, or authorization-check bypass. This issue is fixed in ve= rsion 2.9.1. 2026-09-01 5.3 CVE-2026-63435 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-63435 ] MongoDB--C Driver An incorrect numeric conversion in = the JSON parsing component of the MongoDB C Driver's BSON library may cause=
an unusually large text value to be silently shortened, or the correspondi=
ng field to be omitted, while the parsing operation still reports success a=
nd returns no error. An unauthenticated party who can supply the input proc= essed by an application that uses this component may cause that application=
to hold data that does not match what was submitted, which may result in u= nintended alteration of data. 2026-09-03 5.3 CVE-2026-84963 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-84963 ] MongoDB--C Driver A double free in t=
he OpenSSL-based TLS certificate revocation checking path of the MongoDB C = Driver can be reached by a TLS endpoint that the client already trusts. Dur= ing the handshake, specially formed certificate data can cause the same hea=
p object to be released twice. An unauthenticated party acting as the trust=
ed endpoint may cause the connecting client application to terminate unexpe= ctedly. 2026-09-03 5.9 CVE-2026-84964 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-84964 ] MongoDB--C Driver An integer wraparound in an allocation s= ize calculation in the BSON library's JSON parsing code can cause a buffer =
to be released while a following copy operation still writes through the st= ale pointer. On builds where sizes are 32 bits, an unauthenticated party ab=
le to supply a sufficiently large JSON input to an application that links t=
he library may cause that application to terminate unexpectedly, resulting =
in denial of service. 2026-09-03 5.1 CVE-2026-84965 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-84965 ] MongoDB--C++ Driver A numeric truncation wea= kness exists in the JSON parsing component of the MongoDB C++ Driver's BSON=
library. An actor who controls the text that an embedding application hand=
s to the library's public JSON parsing interface, when that text is very la= rge, can cause the library to read memory beyond the supplied buffer and re= turn it to the caller, to silently accept only part of the input as a compl= ete document, or to terminate the process. No MongoDB server, credentials, =
or non-default configuration is required; the effect is confined to the pro= cess that uses the library. 2026-09-03 6.2 CVE-2026-84970 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84970 ] MongoDB--C++ Driver An incorrect numer=
ic type conversion in the BSON document building component of the MongoDB C=
++ Driver may cause a length value to be interpreted incorrectly. When an a= pplication supplies an extremely large, non-terminated field name to the bu= ilder, the library may read memory outside the intended buffer and terminat=
e the calling process. No authentication is required, but the calling appli= cation must pass the oversized name in a specific form. 2026-09-03 5.1 CVE-= 2026-84966 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84966 ] MongoDB--l= ibmongocrypt Improper handling of an unexpected value size in the decryptio=
n path of a client-side encryption library can cause a failed internal chec=
k that terminates the process using the library. A party able to place a su= itably formed encrypted value where an application will decrypt it, or able=
to control the responses the application receives, may cause that applicat= ion to stop running. 2026-09-03 6.5 CVE-2026-84971 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-84971 ] MongoDB--libmongocrypt An unauthorized user w= ith key vault write access may cause an authorized client to issue arbitrar=
y authenticated Google Cloud KMS API calls under the authorized user's iden= tity, escalating database-level access into cloud key control and defeating=
client-side encryption. 2026-09-03 4.2 CVE-2026-84962 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-84962 ] MongoDB--MongoDB for VS Code A component =
of the MongoDB extension for Visual Studio Code does not neutralize special=
characters in a connection string before that value is placed into a comma=
nd line the extension composes for an integrated terminal. An unauthenticat=
ed remote unauthorized-user who persuades a developer to accept a user-supp= lied connection target, and then to open the extension's shell feature, can=
place characters of the unauthorized-user's choosing into that command lin=
e. No privileges on the developer's machine are required, but several user = actions are. The confirmation the developer sees does not display the suppl= ied text. 2026-09-03 4.3 CVE-2026-84967 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84967 ] MongoDB--PHP Driver An out-of-bounds read in the BSON d= ecoding component of the MongoDB PHP driver may allow an unauthenticated pa= rty who supplies specially formed input to have a small amount of adjacent = process memory copied into an error message that is returned to application=
code. This may result in unintended disclosure of limited memory contents.=
2026-09-03 5.3 CVE-2026-84968 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-84968 ] moos-ivp--moos-ivp MOOS-IvP through 24.8.1 fails to properly vali= date variable names extracted from alog files in the SplitHandler, allowing=
attackers to write files outside the split directory. Attackers can supply=
crafted alog files with backslash sequences in variable names to escape th=
e output directory and append to arbitrary files on Windows systems. 2026-0= 9-03 5.5 CVE-2026-85456 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85456=
] MotoPress Appointment Booking--MotoPress Appointment Booking The MotoPre=
ss Appointment Booking WordPress plugin before 2.4.8 does not perform an au= thorization or ownership check when handling a user-supplied booking identi= fier on an unauthenticated endpoint, allowing unauthenticated attackers to = permanently delete other users' reservations. This is an incomplete fix of = CVE-2026-9180: the deletion remains reachable on sites using payment confir= mation, confirmed through version 2.4.7. 2026-09-02 5.3 CVE-2026-15232 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-15232 ] mozilla -- firefox Other = issue in the DOM: Navigation component. This vulnerability was fixed in Fir= efox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. 2026-0= 9-01 6.1 CVE-2026-84136 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84136=
] mozilla -- firefox Denial-of-service in the PDF Viewer component. This v= ulnerability was fixed in Firefox 155 and Thunderbird 155. 2026-09-01 6.5 C= VE-2026-84138 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84138 ] mozilla=
-- firefox Clickjacking issue in the DOM: Events component. This vulnerabi= lity was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thun= derbird 153.2. 2026-09-01 6.1 CVE-2026-84139 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-84139 ] mozilla -- firefox Use-after-free in the JavaScript=
: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 15= 3.2, Thunderbird 155, and Thunderbird 153.2. 2026-09-01 5.4 CVE-2026-84118 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84118 ] mozilla -- firefox Us= e-after-free in the Audio/Video component. This vulnerability was fixed in = Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thu= nderbird 155, Thunderbird 140.15, and Thunderbird 153.2. 2026-09-01 5.4 CVE= -2026-84120 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84120 ] mozilla -=
- firefox Use-after-free in the Audio/Video component. This vulnerability w=
as fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird=
155, Thunderbird 140.15, and Thunderbird 153.2. 2026-09-01 5.4 CVE-2026-84= 122 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84122 ] mozilla -- firefo=
x Use-after-free in the DOM: Core & HTML component. This vulnerability was = fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 15=
5, Thunderbird 140.15, and Thunderbird 153.2. 2026-09-01 5.4 CVE-2026-84124=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84124 ] mozilla -- firefox U= se-after-free in the DOM: Core & HTML component. This vulnerability was fix=
ed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.=
2. 2026-09-01 5.4 CVE-2026-84125 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84125 ] mozilla -- firefox Incorrect boundary conditions in the Layout:=
Grid component. This vulnerability was fixed in Firefox 155 and Thunderbir=
d 155. 2026-09-01 4.3 CVE-2026-84126 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-84126 ] mozilla -- firefox Spoofing issue in the DOM: Core & HTML c= omponent. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, T= hunderbird 155, and Thunderbird 153.2. 2026-09-01 4.3 CVE-2026-84137 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-84137 ] mozilla -- firefox_mobile A=
malicious webpage could stall a popup's cross-origin navigation after comm= it, causing the address bar to display the destination origin while continu= ing to render attacker-controlled content. This vulnerability was fixed in = Firefox for iOS 155.0. 2026-08-31 5.4 CVE-2026-81267 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-81267 ] mozilla -- firefox_mobile Information discl= osure in the WebExtensions component in Firefox for Android. This vulnerabi= lity was fixed in Firefox 155. 2026-09-01 4.3 CVE-2026-84127 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84127 ] Mstfakts --College-Management-System =C2=A0 A vulnerability was identified in Mstfakts College-Management-System=
. The affected element is an unknown function of the file Front-end/server.= php of the component Logout Handler. Such manipulation of the argument log_= out leads to session expiration. It is possible to launch the attack remote= ly. The exploit is publicly available and might be used. This product takes=
the approach of rolling releases to provide continious delivery. Therefore=
, version details for affected and updated releases are not available. The = project was informed of the problem early through an issue report but has n=
ot responded yet. 2026-09-06 4.3 CVE-2026-86215 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-86215 ] MultiVendorX--MultiVendorX The MultiVendorX Word= Press plugin before 5.0.15 does not have proper authorisation controls on o=
ne of its REST API listing routes, allowing unauthenticated users to retrie=
ve vendor contact and payout details, pending payout amounts, and administr= ative notes attached to store applications. 2026-09-02 5.3 CVE-2026-74927 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-74927 ] MW WP Form--MW WP Form=
The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes i=
n user-submitted values from being executed when it merges those values int=
o a message that it later processes for shortcodes, allowing unauthenticate=
d users to run any shortcode registered on the site. Exploitation requires = the site to have been configured to echo a submitted value back to the visi= tor after submission. 2026-09-01 4.8 CVE-2026-78363 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-78363 ] nameprep--nameprep URI versions before 5.36 = for Perl encode non-NFC host names to non-standard punycode labels via miss= ing normalization in nameprep. nameprep lowercases each host label but perf= orms no Unicode normalization. IDNA requires a label to be normalized to Fo=
rm C before it is encoded (RFC 5891), so a label that is not already in NFC=
is encoded to a different A-label than its normalized form. A label built = from the precomposed Devanagari sequence U+0958 U+093E encodes to xn--72b5c=
without normalization but to xn--11b2fg after NFC normalization, and xn--7= 2b5c does not round-trip back to the original label. Any caller that reads = host() from a URI built from untrusted input and uses it for a security dec= ision (an allow or deny list, an SSRF filter, deduplication, a cache key) s= ees the non-standard label, while a client that fetches the same URL resolv=
es the NFC form, so the check and the fetch can disagree about the host. 20= 26-08-31 6.5 CVE-2026-19953 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 9953 ] NASA--earthdata-search A flaw has been found in NASA earthdata-searc=
h 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLamb=
da of the file serverless/src/openSearchGranuleSearch/handler.js of the com= ponent granules Endpoint. Executing a manipulation of the argument openSear= chOsdd can lead to server-side request forgery. The attack can be launched = remotely. The exploit has been published and may be used. The vendor was co= ntacted early about this disclosure but did not respond in any way. 2026-08= -31 5.3 CVE-2026-82802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82802 =
] nbviewer--nbviewer
=C2=A0 nbviewer through 1.0.1 contains a path traversal vulnerability in Lo= calFileHandler.can_show() that uses string-prefix comparison instead of pro= per path validation. Attackers can read files from sibling directories outs= ide the configured root by requesting paths that share the root as a textua=
l prefix, disclosing unintended notebooks and credentials. 2026-09-06 5.9 C= VE-2026-86258 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86258 ] NetBox = --NetBox=C2=A0
=C2=A0 NetBox through 4.7.0 fails to properly scope user-private records in=
REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookm= arks. Authenticated users with view permissions can access all users' priva=
te records through unscoped querysets, disclosing which users watch or book= mark which objects. 2026-09-05 4.3 CVE-2026-86176 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-86176 ] NetBox-- NetBox=C2=A0
=C2=A0 NetBox through 4.7.0 fails to redact sensitive data source backend c= redentials in REST and GraphQL API responses. Authenticated users with only=
view permission can retrieve plaintext passwords and secret keys for Git a=
nd Amazon S3 backends through API endpoints, gaining unauthorized access to=
external repositories and storage buckets. 2026-09-05 6.5 CVE-2026-86175 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-86175 ] Netgate--pfSense Plus = pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users wit=
h the Status: Monitoring privilege to inject arbitrary JavaScript via graph=
configuration parameters in /status_monitoring.php. Multiple POST paramete=
rs including graph-left, graph-right, time-period, resolution, start-date, = end-date, start-time, end-time, graph-type, invert, and refresh-interval ar=
e concatenated and written to the global pfSense XML configuration without = sanitization, then echoed unsanitized into a JavaScript string context on p= age render. Because the setting is stored in the global configuration, the = payload executes in the browser of every user who visits the Status: Monito= ring page. 2026-09-03 5.4 CVE-2026-56126 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-56126 ] Netgate--pfSense Plus pfSense Plus before 26.07 and CE = before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privi= lege to inject arbitrary JavaScript via the descr parameter in /firewall_ru= les_edit.php. The firewall rule description is stored in the pfSense XML co= nfiguration with only backslash-escaping applied and no HTML sanitization, = then rendered without encoding in the firewall log table in /status_logs_fi= lter.php. The payload executes in the browser of any user with the Status: = Logs: Firewall privilege who views the affected log entries. 2026-09-03 5.4=
CVE-2026-56127 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56127 ] Netga= te--pfSense Plus pfSense Plus before 26.07 and CE before 2.9.0 allow authen= ticated users with the Firewall: Schedules: Edit privilege to inject arbitr= ary JavaScript via the descr parameter in /firewall_schedule_edit.php. The = schedule description is stored without HTML sanitization and subsequently i= nserted into an HTML attribute value in /firewall_rules.php with only singl= e-quote escaping applied, permitting double-quote breakout. The payload exe= cutes in the browser of any user with the Firewall: Rules privilege who vie=
ws the rules list with the affected schedule attached. 2026-09-03 5.4 CVE-2= 026-56128 [
https://www.cve.org/CVERecord?id=3DCVE-2026-56128 ] Nexcess--Bo= okIt Unauthenticated Bypass Vulnerability in BookIt <=3D 2.6.0.3 versions. = 2026-09-03 5.3 CVE-2026-84767 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84767 ] Ninja Forms--Ninja Forms The Ninja Forms WordPress plugin before 3= .15.2 does not restrict its REST abilities to administrators, accepting a N= inja Forms WordPress plugin before 3.15.2-specific capability as equivalent=
to full site administration, which allows any user granted that capability=
to read Ninja Forms WordPress plugin before 3.15.2 settings and stored for=
m submissions, overwrite the Ninja Forms WordPress plugin before 3.15.2's c= onfiguration, and create or modify arbitrary posts and pages. The capabilit=
y belongs to no default WordPress role and the Ninja Forms WordPress plugin=
before 3.15.2 never grants it, so an administrator must have assigned it, = typically when delegating access to the form builder. 2026-09-04 5.9 CVE-20= 26-80438 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80438 ] nocobase--no= cobase NocoBase fails to sanitize rich text field values in the read render= er, allowing users with create permissions to store malicious HTML with eve=
nt handlers. Attackers can write arbitrary markup through the collection AP=
I that executes in the browsers of all users viewing the affected record. 2= 026-09-02 5.4 CVE-2026-84701 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84701 ] nodemailer--nodemailer Nodemailer before 8.0.8 disables TLS certifi= cate verification in lib/fetch/index.js through rejectUnauthorized: false, = allowing attackers to intercept OAuth2 token requests. Attackers in a machi= ne-in-the-middle position can capture OAuth client secrets, refresh tokens,=
and access tokens transmitted over compromised HTTPS connections. 2026-08-=
31 6.5 CVE-2026-82662 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82662 ]=
nodemailer--nodemailer nodemailer before 6.9.9 contains a regular expressi=
on denial of service vulnerability in email parsing when attachDataUrls par= ameter is set or processing embedded file attachments. Attackers can send s= pecially crafted emails with malicious data URLs or embedded attachments to=
cause the event loop to hang and deny service. 2026-08-31 5.3 CVE-2024-583=
79 [
https://www.cve.org/CVERecord?id=3DCVE-2024-58379 ] nodemailer--nodema= iler Nodemailer before 8.0.9 fails to enforce disableFileAccess and disable= UrlAccess options during message normalization in jsonTransport. Attackers = can read local files or fetch URLs by supplying path or href values in mess= age content fields, bypassing intended access controls. 2026-08-31 5.4 CVE-= 2026-82660 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82660 ] nodemailer= --nodemailer Nodemailer before 8.0.9 fails to sanitize carriage return and = line feed characters in list comment fields, allowing attackers to inject a= rbitrary message headers. An attacker with control over list.*.comment para= meters can inject CRLF sequences to create additional headers in generated = RFC822 messages, altering mail client behavior and message semantics. 2026-= 08-31 5.4 CVE-2026-82661 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8266=
1 ] nodemailer--nodemailer Nodemailer versions before 8.0.5 contain an SMTP=
command injection vulnerability in the transport name option used in EHLO/= HELO commands. The name parameter is concatenated directly into SMTP comman=
ds without sanitizing carriage return and line feed characters, allowing at= tackers to inject arbitrary SMTP commands for email spoofing and phishing a= ttacks. 2026-08-31 4.9 CVE-2026-82853 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-82853 ] Nokia--NSP NSP is vulnerable to a stored XSS due to insuff= icient validation or encoding of user-controlled input in a workflow applic= ation. An authenticated attacker with access to the workflow application co= uld embed harmful code that runs when another user views the content. 2026-= 08-31 5.4 CVE-2026-40464 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4046=
4 ] Nokia--NSP NSP is vulnerable to an open redirect due to insufficient se= rver-side validation of the URL (or redirect) parameter. 2026-08-31 5.3 CVE= -2026-40465 [
https://www.cve.org/CVERecord?id=3DCVE-2026-40465 ] Notificat= ion Bar for WordPress--Notification Bar for WordPress The Notification Bar = for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export sc= ript that discloses all stored subscriber emails. 2026-09-02 5.3 CVE-2025-1= 5481 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15481 ] NousResearch--he= rmes-agent A vulnerability has been found in NousResearch hermes-agent 0.18= .0. This affects the function fetchLinkTitle of the file apps/desktop/src/a= pp/artifacts/index.tsx of the component Link Title Fetch. Such manipulation=
of the argument url leads to server-side request forgery. The attack can b=
e launched remotely. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-09-03 6.3 CVE-2026-85106 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-85106 ] NousResearch--hermes-agent A flaw h=
as been found in NousResearch hermes-agent 0.18.0. Affected by this issue i=
s some unknown functionality of the file gateway/platforms/api_server.py of=
the component Session Chat Interface. This manipulation causes denial of s= ervice. The attack is possible to be carried out remotely. The exploit has = been published and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way. 2026-09-01 4.3 CVE-2026-84287 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84287 ] NousResearch--hermes-age=
nt A vulnerability has been found in NousResearch hermes-agent up to 0.18.2=
. This affects the function HermesACPAgent.prompt of the file acp_adapter/s= ession.py of the component ACP Prompt Workflow. Such manipulation leads to = denial of service. The attack may be performed from remote. The exploit has=
been disclosed to the public and may be used. The vendor was contacted ear=
ly about this disclosure but did not respond in any way. 2026-09-01 4.3 CVE= -2026-84288 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84288 ] NousResea= rch--hermes-agent A vulnerability was found in NousResearch hermes-agent up=
to 0.18.2. This vulnerability affects the function list_tools of the file = tools/mcp_tool.py of the component MCP Tool. Performing a manipulation resu= lts in uncontrolled memory allocation. It is possible to initiate the attac=
k remotely. The exploit has been made public and could be used. The vendor = was contacted early about this disclosure but did not respond in any way. 2= 026-09-01 4.3 CVE-2026-84289 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 84289 ] NousResearch--hermes-agent A vulnerability was found in NousResearc=
h hermes-agent 0.18.0. This vulnerability affects the function resourceBuff= erFromUrl of the file apps/desktop/electron/main.ts of the component Electr=
on Main Process. Performing a manipulation results in allocation of resourc= es. The attack may be initiated remotely. copyImageFromUrl() entry point no=
longer reachable on current main. That function did exist at v2026.8.3 but=
was removed by v2026.8.19. The modern copy-image path is Electron-native e= vent.sender.copyImageAt(). 2026-09-03 4.3 CVE-2026-85107 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-85107 ] ntegrals--openbrowser A vulnerability w=
as found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c= 75c8. Affected by this vulnerability is an unknown functionality of the fil=
e packages/core/src/agent/agent.ts of the component Browser Agent Message C= onstruction. Performing a manipulation results in resource consumption. It =
is possible to initiate the attack remotely. The exploit has been made publ=
ic and could be used. This product is using a rolling release to provide co= ntinious delivery. Therefore, no version details for affected nor updated r= eleases are available. The vendor was contacted early about this disclosure=
but did not respond in any way. 2026-09-02 4.3 CVE-2026-84833 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84833 ] nuclio--nuclio Nuclio is a "Serve= rless" framework for Real-Time Events and Data Processing. Prior to version=
1.16.5, Nuclio Dashboard exposes POST /api/functions without authenticatio=
n by default (NOP auth mode). The spec.handler field (e.g., mymodule:myfunc= tion) is parsed by functionconfig.ParseHandler() which splits on : only - n=
o path validation is applied to the module portion. This issue has been pat= ched in version 1.16.5. 2026-09-02 4.9 CVE-2026-52832 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-52832 ] onyx-dot-app--onyx Onyx 4.6.6 fails to pro= perly restrict access to custom tool credentials stored in custom_headers, = allowing any authenticated user to read admin-defined API keys. Attackers w= ith basic authentication can call GET /tool/{tool_id} or GET /tool endpoint=
s to retrieve plaintext authorization headers and third-party API credentia= ls, then use them to directly access upstream APIs. 2026-09-04 6.5 CVE-2026= -85700 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85700 ] Open5GS --Open= 5GS=C2=A0
=C2=A0 A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerab= ility affects unknown code of the component AMF/MME. The manipulation leads=
to improper authorization. The attack is possible to be carried out remote= ly. The exploit has been disclosed to the public and may be used. The ident= ifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this=
issue, it is recommended to deploy a patch. 2026-09-06 4.3 CVE-2026-86212 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-86212 ] open62541--open62541 =
A vulnerability was detected in open62541 up to 1.5.5. Affected by this vul= nerability is the function UA_DataValue_backend_copyRange of the file plugi= ns/historydata/ua_history_data_backend_memory.c of the component History Ba= ckend. The manipulation results in use after free. The attack can be launch=
ed remotely. The exploit is now public and may be used. The project closed = the issue report, stating that this is not the official way to report a sec= urity vulnerability. 2026-08-31 5.3 CVE-2026-82623 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-82623 ] openedx--openedx-platform Open edX Platform e= nables the authoring and delivery of online learning at any scale. Prior to=
commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a=
server-side fetch using "requests.get(url, allow_redirects=3DTrue)". The f= etched bytes are then returned inside a ZIP response. This enables SSRF wit=
h response exfiltration. Redirect-following is enabled, and there is no tim= eout in the vulnerable fetch path. This issue has been patched via commit 0= 0b7c3c. 2026-09-02 6.8 CVE-2026-55421 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-55421 ] openedx--openedx-platform Open edX Platform enables the au= thoring and delivery of online learning at any scale. Prior to commit 3a5ac= 85, a security vulnerability has been identified in the Open edX LMS platfo= rm's LTI (Learning Tools Interoperability) Provider implementation. The val= idate_timestamp_and_nonce function in lms/djangoapps/lti_provider/signature= _validator.py does not validate OAuth nonces or timestamps, allowing an att= acker who captures a valid LTI launch request to replay it an unlimited num= ber of times without detection. This issue has been patched via commit 3a5a= c85. 2026-09-02 4.7 CVE-2026-53636 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-53636 ] OpenListTeam--OpenList OpenList a file list program that supp= orts multiple storage. Prior to 4.2.3, OpenList's offline-download feature =
at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an att= acker-supplied URL and saves its bytes under a per-task temporary directory=
before transferring them to the user's destination storage. The temporary = filename comes from the attacker-controlled Content-Disposition header, is = passed from parseFilenameFromContentDisposition in internal/offline_downloa= d/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run i=
n internal/offline_download/http/client.go, and is opened with os.Create wi= thout a containment check. Because filepath.Join cleans .. segments, a non-= admin user with PermAddOfflineDownload on any path can traverse out of task= .TempDir and create, truncate, or overwrite any file writable by the OpenLi=
st process whose parent directory already exists. The server/handles/offlin= e_download.go AddOfflineDownload route uses normal user authentication rath=
er than AuthAdmin, and local-storage destinations fall through tryPutUrl in=
internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run pat=
h. This issue is fixed in version 4.2.3. 2026-09-03 6.5 CVE-2026-75602 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-75602 ] Openpanel-dev--openpanel = OpenPanel before 2.3.0 contains a cross-tenant broken object level authoriz= ation vulnerability in the report.getLayouts and report.resetLayout tRPC pr= ocedures that fail to scope dashboard queries to the caller's project. Auth= enticated attackers can supply their own projectId with a victim organizati= on's guessable dashboardId to read confidential report definitions or perma= nently delete dashboard layouts across tenant boundaries. 2026-09-04 6.4 CV= E-2026-85611 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85611 ] Openpane= l-dev--openpanel Openpanel before 2.3.0 contains an insecure direct object = reference vulnerability in the report.getLayouts and report.resetLayout tRP=
C procedures that fail to bind dashboardId to the authorized projectId. Aut= henticated attackers can supply an arbitrary victim dashboardId with their = own projectId to read report layouts and configurations or delete dashboard=
grid arrangements across tenants. 2026-09-04 6.4 CVE-2026-85615 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-85615 ] oppia--oppia Oppia's AdminRoleH= andler GET endpoint in core/controllers/admin.py is decorated with open_acc= ess, allowing any registered user to enumerate privileged accounts and role=
s. Attackers can query the endpoint with filter_criterion parameters to ret= rieve usernames holding specific roles, banned flags, and managed topic ide= ntifiers without authorization. 2026-09-03 4.3 CVE-2026-85210 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85210 ] OwnerRez--OwnerRez API Subscriber = Broken Access Control in OwnerRez API <=3D 1.2.6 versions. 2026-08-31 6.3 C= VE-2026-81758 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81758 ] PassMar= k--PerformanceTest
=C2=A0 PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 1= 1.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege = escalation and denial-of-service vulnerability in DirectIo64.sys that allow=
s local attackers to read arbitrary Model-Specific Registers or write zero =
to any MSR through exposed IOCTLs with insufficient blocklist enforcement. = Attackers can exploit the unrestricted write IOCTL to zero out the system c= all handler MSR, causing an immediate unrecoverable kernel crash on the nex=
t system call, or read security-sensitive MSRs used to locate kernel data s= tructures. 2026-09-04 6.1 CVE-2026-80115 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80115 ] Passster--Passster The Passster WordPress plugin before=
4.2.24 does not handle input properly in an AJAX action, allowing unauthen= ticated users to retrieve the value of password protected content 2026-09-0=
2 5.3 CVE-2025-15489 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15489 ] = Passster--Passster The Passster WordPress plugin before 4.2.26 has a flaw i=
n its global protection checks, allowing unauthenticated users to bypass th=
e protection offered via crafted URLs 2026-09-02 5.3 CVE-2025-15490 [ https= ://www.cve.org/CVERecord?id=3DCVE-2025-15490 ] pdfme--common @pdfme/common = before 5.5.10 contains a server-side request forgery vulnerability in the g= etB64BasePdf function that fetches arbitrary URLs without validation when b= asePdf is attacker-controlled. Attackers who control the basePdf template f= ield can force servers or clients to make requests to internal endpoints, e= nabling metadata exfiltration, network reconnaissance, and blind request fo= rgery attacks. 2026-08-31 6.8 CVE-2026-82866 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82866 ] pdfme--pdf-lib pdfme pdf-lib versions before 5.5.10=
contain an unbounded buffer growth vulnerability in the DecodeStream.ensur= eBuffer() method that allows attackers to cause denial of service by supply= ing a crafted PDF with a FlateDecode stream containing a decompression bomb=
. Attackers can upload a small compressed PDF that decompresses to hundreds=
of megabytes, exhausting memory and crashing the Node.js process or freezi=
ng browser tabs during PDF parsing. 2026-08-31 6.5 CVE-2026-82864 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82864 ] pdfme--schemas @pdfme/schemas = before 5.5.9 contains a cross-site scripting vulnerability in the Select sc= hema plugin that fails to sanitize option values before interpolating them = into HTML via innerHTML. Attackers can supply malicious templates with craf= ted option values containing HTML and JavaScript to execute arbitrary code =
in users' browsers. 2026-08-31 6.1 CVE-2026-82867 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-82867 ] pdfme--schemas @pdfme/schemas before 5.5.9 con= tains a cross-site scripting vulnerability in the SVG schema plugin that re= nders user-supplied SVG content directly to innerHTML without sanitization.=
Attackers can inject malicious SVG with embedded scripts, event handlers, =
or foreignObject elements to execute arbitrary JavaScript in users' browser=
s when viewing or filling templates. 2026-08-31 6.1 CVE-2026-82868 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-82868 ] pdfme--schemas pdfme schemas = before 5.5.10 contains a cross-site scripting vulnerability in the multiVar= iableText property panel that assigns unsanitized i18n label values to inne= rHTML. Attackers who control label overrides through options.labels can inj= ect arbitrary JavaScript that executes when users open the Designer and sel= ect a multiVariableText field without variable placeholders. 2026-08-31 4.4=
CVE-2026-82865 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82865 ] Peppe= rmint-Lab--peppermint Peppermint through 0.5.5 contains an authorization by= pass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that al= lows authenticated attackers to delete sessions for any user by supplying a= rbitrary user IDs. Attackers can forcibly log out any user including admini= strators by calling the logout handler with another user's ID, since the en= dpoint performs no authorization checks to verify the caller owns the targe=
t account. 2026-09-03 4.3 CVE-2026-85392 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85392 ] phpseclib--phpseclib phpseclib is a PHP secure communic= ations library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplic= ation in phpseclib/Math/PrimeField/Integer.php performs data-dependent cond= itional modular reductions in add() and subtract(). During the Montgomery l= adder in phpseclib/Crypt/EC/BaseCurves/Montgomery.php, the reduction behavi=
or of each step depends on the secret scalar prefix, creating per-step timi=
ng and libgmp call-count observations that can reveal a reused 251-bit clam= ped private scalar. The phpseclib/Crypt/EC/Formats/Keys/MontgomeryPrivate.p=
hp derivation path invokes the pure-PHP multiplication without a native-eng= ine check, while phpseclib/Crypt/EC/Formats/Keys/PKCS8.php reaches it when = ext-sodium is unavailable. Exploitation requires a reused or long-lived X25= 519 private key, knowledge of the corresponding public key, execution of th=
e pure-PHP path, and a local observer capable of resolving individual ladde=
r steps or libgmp entry-point calls. Ephemeral X25519 keys, including phpse= clib's normal SSH exchange path, are not affected. Recovery of the scalar p= ermanently compromises operations that reuse that key. This issue is fixed =
in versions 3.0.57 and 4.0.1. 2026-09-01 6.3 CVE-2026-84308 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-84308 ] Pik Online Software Solutions Inc.--= Pik Online Portal Use of a One-Way hash without a salt vulnerability in Pik=
Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. Thi=
s issue affects Pik Online Portal: through 3.5.1. 2026-09-04 6.3 CVE-2026-6= 217 [
https://www.cve.org/CVERecord?id=3DCVE-2026-6217 ] Pixelfed--Pixelfed =C2=A0 Pixelfed through 0.12.9 fails to validate follower status in StoryCo= mposeController react and comment endpoints, allowing authenticated users t=
o access follower-only stories. Attackers can enumerate sequential story ID=
s and submit reactions or comments to retrieve story media URLs and author = information without following the account. 2026-09-05 5.4 CVE-2026-86178 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-86178 ] Plane --Plane=C2=A0
=C2=A0 Plane through 1.4.2 fails to validate that issues belong to the depl=
oy board's project in the public comment endpoint. Authenticated attackers = can post comments to arbitrary issues across workspaces by supplying an iss= ue_id parameter to the public deploy-board comment endpoint. 2026-09-05 4.3=
CVE-2026-86174 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86174 ] Pocke= tMine-MP--PocketMine-MP
=C2=A0 PocketMine-MP versions before 3.15.4 contain a denial of service vul= nerability in the InventoryTransaction component's findResultItem() method.=
Malicious clients can send specially crafted InventoryTransactionPackets w= ith multiple conflicting pathways to cause exponential processing complexit=
y, freezing the server. 2026-09-06 6.5 CVE-2020-37277 [
https://www.cve.org= /CVERecord?id=3DCVE-2020-37277 ] PocketMine-MP--PocketMine-MP
=C2=A0 PocketMine-MP versions before 3.18.1 fail to validate NaN or INF val= ues in MovePlayerPacket position and rotation fields. Malicious clients can=
send crafted movement packets with invalid floating-point values to crash = servers through unhandled mathematical operations or prevent clients from r= endering other players. 2026-09-06 6.5 CVE-2021-48007 [
https://www.cve.org= /CVERecord?id=3DCVE-2021-48007 ] PocketMine-MP--PocketMine-MP
=C2=A0 PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions,=
allowing attackers to exhaust player slots by creating sessions without se= nding LoginPacket. Attackers can flood the server with unauthenticated conn= ections that occupy max-player slots, preventing legitimate players from jo= ining. 2026-09-06 5.3 CVE-2022-51008 [
https://www.cve.org/CVERecord?id=3DC= VE-2022-51008 ] Pods--Pods The Pods WordPress plugin before 3.3.9.2 does no=
t restrict which functions a display callback may resolve to, allowing user=
s with the author role and above to read arbitrary files from the server, i= ncluding files outside the web root. Only sites using the restricted displa= y-callback mode are affected, which is the automatic default on installatio=
ns whose first Pods version predates 3.1. 2026-09-04 6.8 CVE-2026-74853 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-74853 ] PostgreSQL--Anonymizer= =C2=A0
=C2=A0 PostgreSQL Anonymizer contains a SQL injection vulnerability in two = import functions. A user can create a malicious JSON document containing sp= ecially crafted object names. If a superuser subsequently calls anon.import= _database_rules() or anon.import_roles_rules(), the malicious code is execu= ted with superuser privileges. The issue is fixed in PostgreSQL Anonymizer = 3.1.4 and later 2026-09-06 6.4 CVE-2026-19634 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-19634 ] PostgreSQL--Anonymizer=C2=A0
=C2=A0 PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize= _database_parallel() function that allows the owner of a table to run arbit= rary code with superuser privilege. The issue is fixed in PostgreSQL Anonym= izer 3.2.0 and later versions 2026-09-06 6.4 CVE-2026-83534 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-83534 ] potpie-ai--potpie potpie through 2.0=
.0 fails to verify user ownership on the POST /conversations/{conversation_= id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary=
file changes into other users' conversations by supplying their conversati=
on IDs, allowing unauthorized modification of pending changes. 2026-09-04 6=
.5 CVE-2026-85669 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85669 ] Pub= lishPress--PublishPress Permissions Unauthenticated Insecure Direct Object = References (IDOR) in PublishPress Permissions <=3D 4.8.3 versions. 2026-09-=
02 5.3 CVE-2026-84771 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84771 ]=
PX4 --Autopilot=C2=A0
=C2=A0 PX4 Autopilot through 1.17.0 contains a null pointer dereference vul= nerability in param_set_default_file() and param_set_backup_file() function=
s that allows attackers to crash the autopilot process. Attackers can invok=
e 'param select' or 'param select-backup' commands with no path argument fr=
om any PX4 shell to trigger the crash. 2026-09-04 6.5 CVE-2026-86097 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-86097 ] PX4 --Autopilot=C2=A0
=C2=A0 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability=
in TemperatureCalibration::start() due to a race condition between task sp= awning and object deletion. Attackers can trigger the calibration process v=
ia shell commands to write to freed heap memory, corrupting unrelated objec=
ts or allocator metadata and destabilizing heap operations. 2026-09-04 5.9 = CVE-2026-86096 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86096 ] PX4--P= X4-Autopilot PX4 Autopilot contains a heap buffer overflow vulnerability in=
the sd_bench command that writes a four-byte block number into a user-supp= lied sized allocation. Attackers can invoke sd_bench with a block size belo=
w four bytes to overflow the heap buffer and potentially execute code or cr= ash the system. 2026-09-02 6.5 CVE-2026-84698 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-84698 ] pydantic--httpx2 HTTPX2 is a next generation HTTP = client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events p= arser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered t= ext in _SSELineDecoder.decode() when an attacker-controlled or compromised = SSE endpoint splits one unterminated line across many response chunks. The = behavior affects httpx2.Client.sse() and httpx2.AsyncClient.sse(), and the = total processing work grows quadratically with the line length, allowing a = crafted stream to consume excessive CPU and block a synchronous worker or a= synchronous event loop. This issue is fixed in version 2.10.0. 2026-09-02 5=
.9 CVE-2026-84378 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84378 ] pyd= antic--httpx2 HTTPX2 is a next generation HTTP client for Python. Prior to = 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py direc= tly interpolates attacker-controlled content_type values and custom headers=
from the files=3D three-element (filename, content, content_type) tuple an=
d the files=3D four-element (filename, content, content_type, headers) tupl=
e into multipart/form-data part headers without validating header names or = values. CR or LF characters can terminate a part header, inject additional = part headers, or end the part header block early, allowing a downstream mul= tipart parser to treat attacker-supplied lines as genuine headers and poten= tially alter part semantics or bypass header-based checks. This issue is fi= xed in version 2.11.0. 2026-09-02 5.3 CVE-2026-84379 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-84379 ] pydantic--httpx2 HTTPX2 is a next generatio=
n HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2= /httpx2/_models.py can add a body-derived Content-Length header to a reques=
t that already contains a caller-supplied Transfer-Encoding header because = its setdefault() processing checks each default header independently rather=
than treating the two framing headers as mutually exclusive. Fixed-size by= te, JSON, form, and known-length multipart bodies can therefore be serializ=
ed over HTTP/1.1 with both headers, allowing request smuggling or connectio=
n desynchronization when downstream intermediaries disagree about which fra= ming header takes precedence. This issue is fixed in version 2.11.0. 2026-0= 9-02 5.6 CVE-2026-84380 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84380=
] QD--QD Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web= /handlers/task.py in QD 20220208 through 20250803. When a task is run via /= task/<taskid>/run, the handler renders task log content (logtmp) into the H= TML response using Python % string formatting without HTML encoding. logtmp=
is populated from the exception object or from new_env.variables.__log__, = which is attacker-controlled via the template extract_variables mechanism. =
A low-privileged authenticated attacker can create a crafted HAR template t= hat extracts arbitrary HTML/JavaScript into the __log__ variable via the ap= i://util/unicode endpoint. When a victim triggers the task run, the embedde=
d script executes in the victim browser within the QD application context. = 2026-08-31 5.4 CVE-2026-51153 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -51153 ] QuantumNous--new-api A vulnerability was determined in QuantumNous=
new-api up to 1.0.0-rc.15. Affected by this issue is some unknown function= ality of the file /api/usage/token/ of the component Revoked API Token Hand= ler. Executing a manipulation can lead to session expiration. The attack ma=
y be performed from remote. The exploit has been publicly disclosed and may=
be utilized. Upgrading to version 1.0.0-rc.17 can resolve this issue. This=
patch is called 0d5995eb63f8801d32eb32fbe74b75b68752bfa9. The affected com= ponent should be upgraded. 2026-08-31 4.3 CVE-2026-82909 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-82909 ] ramon-victor--freegpt-webui
=C2=A0 A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb= 41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJ= ailbreak of the file server/backend.py of the component Jailbreak Mode. Exe= cuting a manipulation can lead to allocation of resources. The attack can b=
e executed remotely. The exploit has been published and may be used. This p= roduct implements a rolling release for ongoing delivery, which means versi=
on information for affected or updated releases is unavailable. This vulner= ability only affects products that are no longer supported by the maintaine=
r. 2026-09-04 6.5 CVE-2026-85703 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-85703 ] ramon-victor--freegpt-webui
=C2=A0 A vulnerability has been found in ramon-victor freegpt-webui up to 0= 98db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function Ch= atCompletion.create of the file g4f/__init__.py of the component Authentica= tion Check. Such manipulation leads to missing authentication. The attack m=
ay be performed from remote. The exploit has been disclosed to the public a=
nd may be used. This product utilizes a rolling release system for continuo=
us delivery, and as such, version information for affected or updated relea= ses is not disclosed. This vulnerability only affects products that are no = longer supported by the maintainer. 2026-09-04 5.3 CVE-2026-85701 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-85701 ] Rank Math SEO--Rank Math SEO T=
he Rank Math SEO WordPress plugin before 1.0.277.1 does not check whether a=
post is password protected before using its content to build publicly gene= rated SEO metadata, allowing unauthenticated users to read the content of p= assword-protected posts. 2026-09-02 5.3 CVE-2026-77782 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-77782 ] Rank Math SEO--Rank Math SEO The Rank Mat=
h SEO WordPress plugin before 1.0.277 does not verify that the metadata row=
being updated belongs to the object the user was authorised against, allow= ing users with the Author role and above to overwrite arbitrary post and us=
er metadata, including that belonging to higher-privileged users. 2026-09-0=
2 4.9 CVE-2026-77788 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77788 ] = Reader Tools--PDF Reader App A security vulnerability has been detected in = Reader Tools PDF Reader App 98.8 on Android. The affected element is the fu= nction ActSplashNew.handleDeeplink of the component File Handler. The manip= ulation of the argument _display_name leads to path traversal. An attack ha=
s to be approached locally. The exploit has been disclosed publicly and may=
be used. The vendor was contacted early about this disclosure but did not = respond in any way. 2026-09-02 4.4 CVE-2026-84852 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84852 ] Really Simple Plugins--Really Simple SSL Unaut= henticated Denial of Service Attack in Really Simple SSL <=3D 9.8.0 version=
s. 2026-09-02 5.3 CVE-2026-84775 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84775 ] Red Hat--Red Hat Ansible Automation Platform 2 A flaw was found=
in Ansible Automation Platform's automation-controller (AWX). The Bulk Job=
Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instan= ce_groups with only a read-level permission check, whereas the standard sin= gle-job launch path requires use-level permission on the same field. A prin= cipal that holds read (but not use) permission on an instance group -- for = example the built-in read-only System Auditor role -- together with execute=
permission on a job template can launch bulk jobs onto instance groups the=
y are not authorized to use, bypassing execution-placement isolation. 2026-= 09-01 6.4 CVE-2026-84470 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8447=
0 ] Red Hat--Red Hat Ansible Automation Platform 2 A flaw was found in the = jwcrypto library, which is used for implementing Javascript Object Signing = and Encryption (JOSE) standards. The issue occurs when the library verifies=
a General JSON Serialization JWS using a set of keys. Due to a coding erro=
r, the library fails to correctly identify the specific key ID (kid) and ma=
y instead accept a signature made by any valid key in the set. This can all=
ow an attacker with a valid key to bypass authorization checks in applicati= ons that rely on the key ID to identify specific tenants or users. 2026-09-=
03 5.9 CVE-2026-84185 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84185 ]=
Red Hat--Red Hat Ansible Automation Platform 2 A flaw was found in pulpcor= e's content serving application. Files uploaded to Pulp file-type repositor= ies are served with their original content type (e.g., text/html for .html = files, image/svg+xml for .svg files) and without a Content-Disposition: att= achment header when using local filesystem storage. An authenticated user o=
r attacker with content upload permissions can upload a specially crafted H= TML or SVG file containing JavaScript, which executes in the browser of any=
user who visits the file URL, resulting in stored cross-site scripting (XS=
S) in the context of the host application. 2026-09-01 5.4 CVE-2026-84232 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84232 ] Red Hat--Red Hat Build =
of Keycloak A flaw was found in the first-broker-login flow of the Keycloak=
identity management service. When a user links a social identity provider = account to their local account, the verification proof generated is not str= ictly bound to the specific upstream identity being verified. This allows a=
n attacker with a different account on the same social provider to intercep=
t the process and link their own account to the victim's local profile, gai= ning unauthorized access. 2026-09-02 6.4 CVE-2026-82968 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-82968 ] Red Hat--Red Hat Certificate System 9 An=
Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certr= equests) returns HTTP 500 with internal Java stack traces for unauthenticat=
ed malformed requests. The same unauthenticated error path emits large mult= i-line stack traces into the CA debug log, creating a log-amplification res= ource exhaustion vector (disk growth and I/O contention) without requiring = authentication. 2026-09-01 6.5 CVE-2026-11873 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-11873 ] Red Hat--Red Hat Certificate System 9 An unauthent= icated client can query the Security Domain hosts inventory via GET /ca/res= t/securityDomain/hosts and receive a structured response enumerating intern=
al PKI/CA hosts and roles (security domain topology and participating subsy= stems), without requiring a principal, client certificate, or session. 2026= -09-01 5.3 CVE-2026-53682 [
https://www.cve.org/CVERecord?id=3DCVE-2026-536=
82 ] Red Hat--Red Hat Enterprise Linux 10 An integer overflow was found in = Corosync's handling of membership commit token messages. The length-validat= ion check for these messages can be bypassed on 32-bit systems due to an in= teger overflow in the calculation of the expected message length, allowing =
a crafted network packet to trigger an out-of-bounds memory access that cra= shes the Corosync daemon. This results in a denial of service for the affec= ted cluster node. The overflow does not occur on 64-bit systems, where the = length calculation is correctly performed in 64-bit arithmetic. 2026-09-04 = 6.5 CVE-2026-81666 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81666 ] Re=
d Hat--Red Hat Enterprise Linux 10 A flaw was found in libtpms, a library t= hat provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for = example during a virtual machine's power-on or state/migration restore), a = malformed state blob can supply an oversized skip-block length that is not = validated against the remaining size of the input buffer. This can drive an=
internal size counter negative, which bypasses a subsequent bounds check d=
ue to an unsafe signed-to-unsigned conversion, causing the parser to read m= emory outside the bounds of the heap buffer holding the state data. Success= ful exploitation can crash the process hosting libtpms (such as swtpm), res= ulting in a denial of service of the emulated TPM device and the virtual ma= chine that depends on it. No data corruption or information disclosure was = confirmed. 2026-09-04 6.5 CVE-2026-85769 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85769 ] Red Hat--Red Hat Enterprise Linux 10 A flaw was found i=
n libsoup. When a client sends an HTTP/2 request body from a non-pollable i= nput stream, the library can buffer more data than the current flow-control=
window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL= _WINDOW_SIZE while that buffered read is still in progress. The client then=
copies the full buffer into a smaller DATA callback without a runtime boun=
ds check, which can abort the process or fail the HTTP/2 session. 2026-09-0=
4 5.9 CVE-2026-85534 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85534 ] = Red Hat--Red Hat Enterprise Linux 10 reset_password.html parses query strin=
g parameters and uses the 'url' parameter as a redirection target (window.l= ocation =3D url) after password reset, optionally delayed by a 'delay' para= meter. No validation or allowlisting is performed on url, enabling an attac= ker to redirect users to an arbitrary external site after completion of the=
password-reset workflow. 2026-09-02 4.3 CVE-2026-53683 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-53683 ] Red Hat--Red Hat Enterprise Linux 7 A he=
ap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptr=
s field from on-disk extended attribute metadata is consumed without bounds=
validation, causing a heap buffer over-read that may disclose sensitive me= mory contents or cause a crash when processing crafted GFS2 filesystem imag= es. 2026-09-03 5.3 CVE-2026-71222 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-71222 ] Red Hat--Red Hat Enterprise Linux 7 A stack overflow vulnerabi= lity was found in gfs2-utils. The hash table traversal code in metawalk.c u= ses alloca() with an exponentially-derived size from the untrusted on-disk = di_depth field without bounds validation. A crafted GFS2 filesystem image w= ith a large di_depth value causes stack exhaustion and a denial of service = when processed by fsck.gfs2, gfs2_edit, or savemeta. 2026-09-03 4.7 CVE-202= 6-71219 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71219 ] Red Hat--Red = Hat Enterprise Linux 7 A stack overflow vulnerability was found in gfs2-uti= ls. The metadata walk code in metawalk.c uses alloca() with an untrusted in= ode height value from on-disk metadata without bounds validation, causing s= tack exhaustion and a denial of service when processing crafted GFS2 filesy= stem images. 2026-09-03 4.7 CVE-2026-71224 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-71224 ] RegistrationMagic--RegistrationMagic The Registration= Magic WordPress plugin before 6.0.9.9 does not validate the total price of =
a paid registration server-side, allowing unauthenticated users to complete=
a paid registration without paying and obtain an activated account. 2026-0= 9-02 5.3 CVE-2026-77793 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77793=
] RegistrationMagic--RegistrationMagic The RegistrationMagic WordPress plu= gin before 6.0.9.9 does not validate a client-supplied quantity multiplier = when calculating the total price of a paid registration, allowing unauthent= icated users to register without paying and obtain an activated account hol= ding the role the form grants. 2026-09-02 5.3 CVE-2026-77794 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-77794 ] Releasit--Releasit COD Form & Upsel=
ls A vulnerability was detected in Releasit Releasit COD Form & Upsells v1.=
This vulnerability affects unknown code of the component OTP Validation. T=
he manipulation results in client-side enforcement of server-side security.=
The attack may be launched remotely. The exploit is now public and may be = used. Upgrading to version v2 is able to resolve this issue. The affected c= omponent should be upgraded. 2026-09-01 5.3 CVE-2026-84110 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-84110 ] Restaurant Menu and Food Ordering--Re= staurant Menu and Food Ordering The Restaurant Menu and Food Ordering WordP= ress plugin before 2.4.12 does not verify that a PayPal payment notificatio=
n genuinely originates from PayPal, allowing unauthenticated attackers to f= orge a payment notification and mark their own order as paid and completed = without making any payment. 2026-09-04 5.3 CVE-2026-84044 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84044 ] Restrict User Access--Restrict User Ac= cess The Restrict User Access WordPress plugin before 2.8.1 does not normal= ise the REST API route before checking it against the routes its content pr= otection covers, allowing unauthenticated users to bypass that protection a=
nd read restricted content and enumerate users. 2026-09-02 5.3 CVE-2026-781=
53 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78153 ] RightNow-AI--OpenF= ang A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Thi=
s vulnerability affects the function shell_exec of the file crates/openfang= -runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory a= llocation. The attack is possible to be carried out remotely. The exploit h=
as been made available to the public and could be used for attacks. The ven= dor was contacted early about this disclosure but did not respond in any wa=
y. 2026-09-03 4.3 CVE-2026-84888 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84888 ] Rowboat--Rowboat=C2=A0
=C2=A0 Rowboat through 0.9.1 fails to validate custom MCP server and webhoo=
k URLs, allowing authenticated users to configure arbitrary destinations. A= ttackers can point these URLs at internal services and cloud metadata endpo= ints to perform server-side request forgery and enumerate internal network = topology. 2026-09-05 5 CVE-2026-86122 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-86122 ] rowboatlabs--rowboat A vulnerability was detected in rowbo= atlabs rowboat up to 0.9.1. The impacted element is the function request.te= xt/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of t=
he component Composio Webhook Endpoint. The manipulation results in denial =
of service. It is possible to launch the attack remotely. The exploit is no=
w public and may be used. Upgrading to version 0.9.2 is sufficient to resol=
ve this issue. Upgrading the affected component is recommended. The legacy = Next.js app was deleted at 0.9.2 rather than patched, leaving no security c= ontrol behind. 2026-09-02 5.3 CVE-2026-84856 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-84856 ] rpcap--rpcap
=C2=A0 The rpcap client code that processes a RPCAP_MSG_PACKET message rece= ived from the server incorrectly validates its headers. A malicious server = can send a crafted message and cause the client to treat up to 20 bytes of = the client process memory beyond the end of the buffer as if it was a part =
of the captured packet. 2026-09-05 5 CVE-2026-18238 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-18238 ] rpcapd --rpcapd=C2=A0
=C2=A0 rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTE= R_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it ne= ver frees the memory, so it leaks memory even under normal use. A malicious=
client can cause the server to leak memory substantially faster. 2026-09-0=
5 4.3 CVE-2026-18313 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18313 ] = Saad Iqbal--WP EasyPay Unauthenticated Bypass Vulnerability in WP EasyPay <= =3D 4.5.3 versions. 2026-09-03 5.3 CVE-2026-84762 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84762 ] sambitraj--Student-Management-System A vulnera= bility was detected in sambitraj Student-Management-System up to 56ba287f2e= 9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown function of the fil=
e aca.sql. Performing a manipulation results in use of default password. Re= mote exploitation of the attack is possible. The exploit is now public and = may be used. This product follows a rolling release approach for continuous=
delivery, so version details for affected or updated releases are not prov= ided. The project was informed of the problem early through an issue report=
but has not responded yet. 2026-08-31 5.3 CVE-2026-82698 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-82698 ] Samsung Open Source--mTower Untrusted = pointer dereference vulnerability in Samsung Open Source mTower allows Poin= ter Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea= 54ae3c803992c91be. 2026-09-01 5.5 CVE-2026-10420 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-10420 ] Samsung Open Source--mTower NULL pointer derefe= rence vulnerability in Samsung Open Source mTower allows Pointer Manipulati= on. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c374= 89a. 2026-09-01 5.5 CVE-2026-82926 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-82926 ] Samsung Open Source--mTower Untrusted pointer dereference vul= nerability in Samsung Open Source mTower allows Pointer Manipulation. This = issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. 2026= -09-01 5.5 CVE-2026-82927 [
https://www.cve.org/CVERecord?id=3DCVE-2026-829=
27 ] Samsung Open Source--rlottie Uncontrolled Recursion vulnerability in S= amsung Open Source rlottie allows Serialized Data with Nested Payloads. Thi=
s issue affects rlottie: before 8de0d9e6ca80ffef654965505981727b9fa06a51. 2= 026-08-31 5.5 CVE-2026-82797 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 82797 ] Samsung Open Source--TizenFX Out-of-bounds Write and Improper Valid= ation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/T= izenFX allows Overflow Buffers. 2026-09-03 6.3 CVE-2026-85084 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-85084 ] Samsung Opensource--rLottie Out-of= -bounds read vulnerability in Samsung Opensource rLottie allows Overread Bu= ffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630=
. 2026-09-04 4.4 CVE-2026-49509 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-49509 ] sc Internet Vivoo--WP Rentals Authorization Bypass Through User-= Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploit= ing Incorrectly Configured Access Control Security Levels. This issue affec=
ts WP Rentals: from n/a before 3.16.0. 2026-09-04 5.4 CVE-2026-27432 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-27432 ] sdcb--chats A vulnerability=
was detected in sdcb chats up to 1.12.0. This affects the function McpCont= roller of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of th=
e component fetch-tools Endpoint. The manipulation results in server-side r= equest forgery. The attack may be launched remotely. The exploit is now pub= lic and may be used. The vendor was contacted early about this disclosure b=
ut did not respond in any way. 2026-08-31 6.3 CVE-2026-82905 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82905 ] SeaCMS--SeaCMS A vulnerability was = identified in SeaCMS up to 13.6. Affected by this vulnerability is the func= tion unlink of the file /member.php?action=3Dchgpwdsubmit of the component = Avatar Upload. Such manipulation of the argument oldpic leads to path trave= rsal. It is possible to launch the attack remotely. The exploit is publicly=
available and might be used. 2026-08-31 5.4 CVE-2026-82599 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-82599 ] SeaCMS--SeaCMS A security vulnerabil= ity has been detected in SeaCMS up to 13.6. This vulnerability affects unkn= own code of the file /ass.php. The manipulation leads to authorization bypa= ss. The attack may be initiated remotely. The exploit has been disclosed pu= blicly and may be used. 2026-08-31 5.3 CVE-2026-82602 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-82602 ] SeaCMS--SeaCMS A vulnerability was detecte=
d in SeaCMS up to 13.6. This issue affects some unknown processing of the f= ile /member.php?action=3Ddel_pl of the component Comment Cache. The manipul= ation of the argument itype/vid results in path traversal. The attack may b=
e launched remotely. The exploit is now public and may be used. 2026-08-31 = 5.4 CVE-2026-82603 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82603 ] Se= aCMS--SeaCMS A weakness has been identified in SeaCMS up to 13.6. This affe= cts an unknown part of the file /err.php. Executing a manipulation of the a= rgument errtxt can lead to cross site scripting. The attack can be launched=
remotely. The exploit has been made available to the public and could be u= sed for attacks. 2026-08-31 4.3 CVE-2026-82601 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-82601 ] SEOPress--SEOPress Server-Side Request Forgery (S= SRF) vulnerability in SEOPress allows Server Side Request Forgery. This iss=
ue affects SEOPress: from n/a through 10.1. 2026-09-03 5.4 CVE-2026-85305 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85305 ] SEOWriting--SEOWriting=
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-sit=
e scripting vulnerability that allows authenticated contributors to inject = malicious JavaScript by exploiting an overly permissive KSES allowlist that=
explicitly permits the onload event handler on iframe elements. Attackers = can store crafted JavaScript payloads in post content that execute when the=
affected post is viewed or previewed by higher-privileged users, potential=
ly leading to privilege escalation or account compromise. 2026-09-02 6.4 CV= E-2026-75134 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75134 ] Septeo I=
T Solutions--UpSignOn UpSignOn for Windows before 7.19.0 contains a sensiti=
ve data exposure vulnerability that allows local attackers to recover the m= aster password and decrypt vault contents by reading a retained backup key = from the process memory of UpSignOn.exe, even after the vault has been re-l= ocked. Attackers can extract the backup key from process memory to decrypt = the encrypted master password backup stored in v6-vault1.DATA.txt, then use=
the recovered master password to decrypt the main vault and export all pas= sword manager entries in cleartext. 2026-09-02 6.1 CVE-2026-75135 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-75135 ] Septeo IT Solutions--UpSignOn = UpSignOn for Windows before 7.19.0 contains an insecure credential storage = vulnerability that allows local attackers to retrieve the biometric unlock = key stored in the Windows PasswordVault API without triggering any authenti= cation prompt. Attackers can access the stored biometric key from a standar=
d local process within the same Windows session to decrypt the protected va= ult files and export the entire password manager contents in cleartext. 202= 6-09-02 6.1 CVE-2026-75136 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75= 136 ] Septeo IT Solutions--UpSignOn UpSignOn for Windows before 7.19.0 cont= ains a sensitive data exposure vulnerability that allows local attackers to=
recover cleartext vault data from process memory even after the applicatio=
n has been locked. Attackers can use the PROCESS_VM_READ permission to read=
the memory space of UpSignOn.exe and extract sensitive fields including en= try names, URLs, usernames, passwords, TOTP secrets, and notes. 2026-09-02 = 6.1 CVE-2026-75137 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75137 ] sh= abti--Frontend Admin by DynamiApps The Frontend Admin by DynamiApps plugin = for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortc= ode Attribute in all versions up to, and including, 3.29.11 due to insuffic= ient input sanitization and output escaping. This makes it possible for aut= henticated attackers, with contributor-level access and above, to inject ar= bitrary web scripts in pages that will execute whenever a user accesses an = injected page. 2026-09-01 6.4 CVE-2026-12747 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-12747 ] sigoden--aichat A flaw has been found in sigoden ai= chat up to 0.30.4. This affects an unknown function of the file src/serve.r=
s of the component API Endpoint. This manipulation causes uncontrolled memo=
ry allocation. The attack can be initiated remotely. The exploit has been p= ublished and may be used. The vendor was contacted early about this disclos= ure but did not respond in any way. 2026-09-02 5.3 CVE-2026-84857 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-84857 ] silverks--Graphene Subscriber = Cross Site Scripting (XSS) in Graphene <=3D 2.9.4 versions. 2026-09-03 6.5 = CVE-2026-81281 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81281 ] Sim --= Sim=C2=A0
=C2=A0 Sim before 0.8.14 classifies tool requests as internal based on URL = prefix matching without scheme normalization, skipping SSRF validation and = minting internal authentication tokens. Authenticated workflow authors can = bypass external URL validation by supplying paths starting with /api/ in HT=
TP blocks to reach internal-only endpoints like POST /api/function/execute.=
2026-09-05 5 CVE-2026-86115 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 86115 ] Simple Membership MailChimp Integration--Simple Membership MailChim=
p Integration The Simple Membership MailChimp Integration WordPress plugin = before 1.9.8 does not have CSRF checks in its settings page, allowing attac= kers to trick a logged-in administrator into changing the configured third-= party API key. Once replaced, all subsequent member registration data (name=
, email, membership level) is sent to the attacker-controlled account. 2026= -09-02 5.4 CVE-2026-8151 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8151=
] simular-ai--Agent-S A vulnerability was determined in simular-ai Agent-S=
up to 0.3.2. Affected by this vulnerability is the function ImageData of t=
he file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Ex= ecuting a manipulation of the argument img_bytes can lead to resource consu= mption. The attack may be launched remotely. The exploit has been publicly = disclosed and may be utilized. The vendor was contacted early about this di= sclosure but did not respond in any way. 2026-09-03 5.3 CVE-2026-84886 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-84886 ] simular-ai--Agent-S A vul= nerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts a=
n unknown function of the file code_agent.py of the component CodeAgent. Su=
ch manipulation leads to denial of service. The attack can be launched remo= tely. The exploit has been disclosed to the public and may be used. The ven= dor was contacted early about this disclosure but did not respond in any wa=
y. 2026-09-03 4.3 CVE-2026-84885 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-84885 ] simular-ai--Agent-S A vulnerability was identified in simular-a=
i Agent-S up to 0.3.2. Affected by this issue is some unknown functionality=
of the file grounding.py of the component Model-generated GUI Action Execu= tion Workflow. The manipulation leads to denial of service. Remote exploita= tion of the attack is possible. The exploit is publicly available and might=
be used. The vendor was contacted early about this disclosure but did not = respond in any way. 2026-09-03 4.3 CVE-2026-84887 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84887 ] SiYuan --SiYuan=C2=A0
=C2=A0 SiYuan versions before v3.8.2 fail to properly filter private attrib= ute-view cell values in the getAttributeViewKeys endpoint. Publish readers = can retrieve hidden KeyValues payloads from rows bound to inaccessible docu= ments, exposing private database contents without authorization. 2026-09-05=
6.5 CVE-2026-86192 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86192 ] S= iYuan --SiYuan=C2=A0
=C2=A0 SiYuan versions before v3.8.2 contain an information disclosure vuln= erability in the getAttributeViewKeysByID endpoint that allows publish read= ers to enumerate private attribute view key definitions without verifying p= arent database visibility. Attackers can access the endpoint to retrieve co= mplete key schemas including sensitive field names and relation definitions=
from hidden databases. 2026-09-05 4.3 CVE-2026-86191 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-86191 ] siyuan-note--siyuan SiYuan through 3.8.1 c= ontains an authorization bypass vulnerability in the /api/file/getFile endp= oint that allows readers to retrieve files from notebooks explicitly config= ured as Visible:false. Attackers with reader role can access private worksp= ace files including notebook metadata and internal configuration by knowing=
the hidden notebook identifier and file path. 2026-09-04 6.5 CVE-2026-8557=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85578 ] siyuan-note--siyuan=
SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in=
the MCP file-access handler that uses case-sensitive matching on Linux fil= esystems. Attackers can read the protected publishAccess.json file by reque= sting case-variant paths like PublishAccess.json to disclose sensitive publ= ish-access configuration and metadata. 2026-09-04 6.5 CVE-2026-85580 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-85580 ] siyuan-note--siyuan SiYuan = versions before v3.8.2 contain an unbounded session creation vulnerability =
in the publish-service Basic Auth handler that allows authenticated attacke=
rs to exhaust memory. Attackers can repeatedly authenticate with valid cred= entials to create persistent session entries without expiry or capacity lim= its, causing indefinite process memory growth and denial of service. 2026-0= 9-04 6.5 CVE-2026-85582 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85582=
] siyuan-note--siyuan SiYuan versions before v3.8.2 contain a path travers=
al vulnerability in the reader-accessible file-read endpoint that follows s= ymlinks when opening authorized asset paths. Attackers with reader role can=
request a logical asset under data/assets/ that is a symlink to a file out= side the workspace and receive the target file bytes, bypassing workspace b= oundary restrictions. 2026-09-04 6.5 CVE-2026-85583 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-85583 ] siyuan-note--siyuan SiYuan is affected by an=
information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2=
) in the reader-accessible POST /api/transactions/undoState endpoint. The e= ndpoint returns the peekMutatedRootIDs list from the global undo-log stack = for a caller-supplied root ID without applying publish-access visibility fi= ltering. An authenticated reader who knows the root ID of a visible documen=
t can obtain the internal root IDs of other documents (including private or=
unpublished ones) modified in the same cross-document transaction, disclos= ing internal identifiers and cross-document relationships. Document body co= ntents are not directly exposed. 2026-09-04 4.3 CVE-2026-85579 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-85579 ] Slack --Nebula mesh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui= /oidc/login is reachable without authentication and is registered outside t=
he Web UI rate-limited auth routes. Every request creates a fresh random OI=
DC state value and stores it in an in-memory map for 10m. Expired states ar=
e swept lazily, but there is no rate limit or maximum live-state cap on the=
allocation path. An unauthenticated remote client can therefore grow OIDC.= states for the full state TTL, bounded by request throughput rather than by=
configured auth rate limits. This issue has been patched in version 0.5.0.=
2026-09-04 5.3 CVE-2026-55512 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-55512 ] Slack --Nebula mesh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-c= reation path ignores both the server-wide enrollment_token_ttl security set= ting and per-network network_config.enrollment_token_ttl overrides. API hos=
t creation and token-regeneration paths use the configured TTL resolver, bu=
t POST /ui/hosts hardcodes now.Add(24 * time.Hour) for newly minted agent e= nrollment tokens. In deployments that intentionally reduce enrollment-token=
lifetime, any authenticated operator who can create a host through the Web=
UI can still mint a bearer enrollment token valid for about 24 hours. This=
issue has been patched in version 0.5.0. 2026-09-04 5.4 CVE-2026-55513 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-55513 ] smub--Charitable Donatio=
n & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising=
Campaigns) The Charitable - Donation & Fundraising Platform (Donation Form=
s, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vul= nerable to generic SQL Injection via 'order' Shortcode Attribute in all ver= sions up to, and including, 1.8.12.1 due to insufficient escaping on the us=
er supplied parameter and lack of sufficient preparation on the existing SQ=
L query. This makes it possible for authenticated attackers, with contribut= or-level access and above, to append additional SQL queries into already ex= isting queries that can be used to extract sensitive information from the d= atabase. The [charitable_donors] shortcode is accessible to Contributor-lev=
el users via draft or pending post previews, providing an authenticated but=
low-privileged entry point for exploitation. 2026-09-01 6.5 CVE-2026-77189=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-77189 ] Snowflake--Snowflake=
JDBC Driver Improper input validation of the auto-configuration account id= entifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a cr= edential-bearing login request to be redirected to an attacker-selected HTT=
PS endpoint. An attacker able to control the account value could cause the = driver to transmit a reusable login credential to a host of their choosing = and replay it to obtain the privileges granted to that credential. Successf=
ul exploitation requires an application using jdbc:snowflake:auto with a co= nnections.toml section that omits an explicit host and a lower-trust princi= pal able to set the account value; ordinary JDBC URLs are unaffected. The f=
ix is available in Snowflake JDBC Driver version 4.3.4. Users must manually=
upgrade. 2026-09-04 5.3 CVE-2026-85528 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85528 ] Soarkey--StudentManagement A security flaw has been dis= covered in Soarkey StudentManagement and =C3=A5=C2=AD=C2=A6=C3=A7=E2=80=9D= =C5=B8=C3=A4=C2=BF=C2=A1=C3=A6=C2=81=C2=AF=C3=A7=C2=AE=C2=A1=C3=A7=C2=90=E2= =80=A0=C3=A7=C2=B3=C2=BB=C3=A7=C2=BB=C5=B8 up to e08f7f1d5015af407aa4cca0ad= a3dea189b4937e. This affects the function CourseDao.course_ranking of the f= ile code/src/dao/CourseDao.java. Performing a manipulation of the argument = cno results in sql injection. It is possible to initiate the attack remotel=
y. The exploit has been released to the public and may be used for attacks.=
The project was informed of the problem early through an issue report but = has not responded yet. 2026-08-31 6.3 CVE-2026-82620 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-82620 ] Social Media Share Buttons & Social Sharing=
Icons--Social Media Share Buttons & Social Sharing Icons The Social Media = Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not=
escape the post title before outputting it in an inline JavaScript event h= andler, allowing users with the Contributor role and above to perform Store=
d Cross-Site Scripting attacks which are triggered when a visitor interacts=
with the affected button. Exploitation requires the Social Media Share But= tons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a n= on-default icon display configuration. 2026-09-02 6.8 CVE-2026-19719 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-19719 ] Solace Extra--Solace Extra = The Solace Extra WordPress plugin before 1.7.0 does not perform any authori= zation or post-status checks in one of its AJAX actions, allowing unauthent= icated visitors to read the content of non-published (draft, pending, priva= te, and trashed) Site Builder parts that WordPress would otherwise not serv=
e. 2026-09-02 5.3 CVE-2026-16966 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-16966 ] SolidInvoice--SolidInvoice SolidInvoice is an open-source invoi= cing platform. Prior to version 3.0.1, `UserInvitation` entities have no ex= piry timestamp. Invitation links mailed to users remain valid indefinitely,=
meaning a leaked, forwarded, or archived invitation email can be used at a=
ny time in the future to join a company or silently add a compromised email=
account to a company. Version 3.0.1 fixes the issue. 2026-09-04 6.8 CVE-20= 26-61608 [
https://www.cve.org/CVERecord?id=3DCVE-2026-61608 ] SolidInvoice= --SolidInvoice SolidInvoice is an open-source invoicing platform. Prior to = version 3.0.1, an authenticated user can view the API request history of an=
y other user's API tokens within the same company by manipulating two writa= ble Symfony UX LiveComponent props on the `DataGrid` component. Version 3.0=
.1 fixes the issue. 2026-09-04 6.5 CVE-2026-61688 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-61688 ] SolidInvoice--SolidInvoice SolidInvoice is an = open-source invoicing platform. Prior to version 3.0.1, the REST API authen= ticator accepts bearer tokens via a `?token=3D` URL query parameter as a fa= llback to the `X-API-TOKEN` header. This causes long-lived API credentials =
to be recorded in server access logs, proxy logs, browser history, and HTTP=
Referer headers sent to third-party origins. Version 3.0.1 fixes the issue=
. 2026-09-04 5.9 CVE-2026-61614 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-61614 ] SpecterOps--BloodHound A weakness has been identified in Specter= Ops BloodHound up to 9.5.1. The affected element is the function NewV2API o=
f the file cmd/api/src/api/registration/v2.go of the component Graph Write = Endpoint. Executing a manipulation can lead to improper authorization. It i=
s possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9= .6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39= d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected com= ponent. 2026-09-03 6.3 CVE-2026-85241 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-85241 ] StackStorm--st2 A weakness has been identified in StackSto=
rm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if= _user_query_param_is_provided of the file st2api/st2api/controllers/v1/acti= onexecutions.py of the component NoOp RBAC backend. This manipulation of th=
e argument User causes improper privilege management. The attack is possibl=
e to be carried out remotely. The exploit has been made available to the pu= blic and could be used for attacks. Prior advisory CVE-2022-44009 was repor= ted as a follow-up on the same sink, but this issue is distinct: it needs n=
o Jinja RBAC und affects default install with RBAC disabled. The project wa=
s informed of the problem early through an issue report but has not respond=
ed yet. 2026-09-04 6.3 CVE-2026-85513 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-85513 ] StackStorm--st2 A security vulnerability has been detected=
in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file=
st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Suc=
h manipulation of the argument api_key_api.user leads to improper privilege=
management. The attack may be performed from remote. The exploit has been = disclosed publicly and may be used. The project was informed of the problem=
early through an issue report but has not responded yet. 2026-09-04 6.3 CV= E-2026-85514 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85514 ] Stormshi= eld--Stormshield Network Security It's possible to run a stored XSS in Stor= mshield's web administration panel. To exploit this vulnerability, a SNS ad= ministrator with appropriate permissions must inject=C2=A0 some malicious s= cript in a group's comments in the webservices administration interface. 20= 26-09-04 4.3 CVE-2026-14466 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 4466 ] Strategy11 Team--Business Directory Unauthenticated Broken Access Co= ntrol in Business Directory <=3D 6.4.26 versions. 2026-09-03 6.5 CVE-2026-8= 4758 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84758 ] Strategy11 Team-= -Business Directory Unauthenticated Insecure Direct Object References (IDOR=
) in Business Directory <=3D 6.4.26 versions. 2026-09-03 6.5 CVE-2026-84769=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84769 ] Studio-42--elFinder = elFinder is an open-source file manager for web, written in JavaScript usin=
g jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinder= Connector::$csrfProtectedCmds in php/elFinderConnector.class.php, so valida= teCsrfToken() is not called for this state-changing operation. In the shipp=
ed php/connector.minimal.php-dist configuration, FTP network mounts are ena= bled by default, and attacker-controlled protocol, host, path, port, user, = pass, alias, and options arguments flow through elFinder::netmount() in php= /elFinder.class.php to php/elFinderVolumeFTP.class.php. A cross-site reques=
t can therefore persist an attacker-chosen FTP mount in the victim's sessio=
n, cause the PHP server to connect to an attacker-chosen FTP host and port,=
and send supplied credentials without an X-elFinder-CSRF token. This issue=
is fixed in version 2.1.70. 2026-08-31 5.4 CVE-2026-81890 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-81890 ] sulu--sulu Sulu is an open-source PHP=
content management system based on the Symfony framework. Prior to version=
s 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamContr= oller.php allows the /media/{id}/download/{slug} route and its administrati=
on variant to honor the inline query parameter for scriptable MIME types. T=
he vulnerable stored Content-Type values include text/html, application/xht= ml+xml, text/xml, and application/xml. An attacker with media upload permis= sion can store an HTML, XHTML, or XML document and create a link using inli= ne=3D1, causing the application to return the file on the Sulu origin inste=
ad of forcing Content-Disposition attachment. When an authenticated victim = opens the link, attacker-controlled JavaScript can execute with the victim'=
s Sulu-origin session and can read data or perform actions as that victim. = This issue is fixed in versions 2.6.25 and 3.0.8. 2026-08-31 5.4 CVE-2026-8= 2396 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82396 ] Supsystic--Ultim= ate Maps by Supsystic Missing Authorization vulnerability in Supsystic Ulti= mate Maps by Supsystic allows Exploiting Incorrectly Configured Access Cont= rol Security Levels. This issue affects Ultimate Maps by Supsystic: from n/=
a through 1.5.3. 2026-09-03 5.3 CVE-2026-85309 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-85309 ] SUSE--Rancher A flaw was found in Rancher Manager=
. The /v3/users update path did not enforce immutability of a User resource=
's `username` and `principalIds` fields. A user holding the `update` verb o=
n `users.management.cattle.io` could inject a foreign identity provider pri= ncipal into any account, so that the next login by the owner of that princi= pal was bound to the victim's account and inherited its role bindings. This=
issue affects Rancher: before 2.15.1. 2026-09-03 6.1 CVE-2026-71403 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-71403 ] svg--svgo SVGO, short for S=
VG Optimizer, is a Node.js library and command-line application for optimiz= ing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, t=
he opt-in removeScripts plugin, named removeScriptElement in versions 2 and=
3 and implemented in plugins/removeScripts.js, removes SVG and XHTML scrip=
t elements but does not inspect executable HTML content inside SVG foreignO= bject elements. Event-handler attributes such as onload and onbeforetoggle,=
srcdoc documents, and executable URLs in the action, data, formaction, hre=
f, and src attributes can remain in attacker-controlled SVG input. When an = application uses the plugin as its only protection and serves the optimized=
SVG in an active browser context, the payload can execute script in the vi= ewer's origin, expose data, modify content, or perform actions as the victi=
m. This issue is fixed in versions 2.8.4, 3.3.5, and 4.1.0. 2026-09-01 6.1 = CVE-2026-84369 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84369 ] Syster= el--S2OPC A vulnerability was determined in Systerel S2OPC up to 1.7.3. The=
affected element is the function set_range_matrix_on_string_array of the f= ile src/Common/opcua_types/sopc_builtintypes.c of the component String Arra=
y Range Writing. This manipulation causes out-of-bounds read. The attack is=
possible to be carried out remotely. The project was informed of the probl=
em early through an issue report but has not responded yet. 2026-08-31 4.3 = CVE-2026-82618 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82618 ] Syster= el--S2OPC A vulnerability was identified in Systerel S2OPC up to 1.7.3. The=
impacted element is the function monitored_item_event_filter_treatment_bs_= _init_event_filter_ctx_and_result of the file src/ClientServer/services/bge= nc/subscription_mgr.c. Such manipulation of the argument EventFilter leads =
to use after free. The attack may be performed from remote. The exploit is = publicly available and might be used. The name of the patch is a4cee16a851b= 971be447a6ed531173702c722b99. It is best practice to apply a patch to resol=
ve this issue. 2026-08-31 4.3 CVE-2026-82619 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82619 ] TechStore--TechStore 1.0 TechStore 1.0 is vulnerabl=
e to Cross Site Scripting (XSS). In contact_display, the application echoes=
the id parameter verbatim into the rendered page, permitting execution of = attacker-supplied JavaScript in users browser. 2026-08-31 6.1 CVE-2025-6360=
7 [
https://www.cve.org/CVERecord?id=3DCVE-2025-63607 ] Tencent--AI-Infra-G= uard Tencent AI-Infra-Guard's skill-scan component excludes compiled Python=
bytecode files from analysis by hardcoding __pycache__ directories and .py= c/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. A= ttackers can distribute skills with benign Python source files alongside ma= licious compiled bytecode that executes on import while the scanner reports=
a safe verdict, enabling code execution when operators install the skill. = 2026-09-02 6.5 CVE-2026-84809 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84809 ] Tenda --CP3
=C2=A0 A security vulnerability has been detected in Tenda CP3 27.5.57.101.=
Impacted is an unknown function of the file custom-x/softap/hostapd. Such = manipulation of the argument wpa_passphrase leads to hard-coded credentials=
. The attack can be launched remotely. The exploit has been disclosed publi= cly and may be used. 2026-09-05 4.1 CVE-2026-86150 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-86150 ] The4--Kalles Addons Subscriber Cross Site Scr= ipting (XSS) in Kalles Addons <=3D 1.0.6 versions. 2026-08-31 6.5 CVE-2026-= 81778 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81778 ] Theme My Login-= -Theme My Login The My Login WordPress plugin before 7.2.0 does not enforce=
the network's registration setting when processing site signups on multisi=
te installations, allowing users with a subscriber account, and unauthentic= ated users on some networks, to create new sites and be granted administrat=
or over them. 2026-09-02 5.4 CVE-2026-81583 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-81583 ] ThemeGoods--Grand Tour Cross-Site Request Forgery (C= SRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forge= ry. This issue affects Grand Tour: from n/a through 5.5.1. 2026-09-02 5.4 C= VE-2026-66652 [
https://www.cve.org/CVERecord?id=3DCVE-2026-66652 ] themoos= --core-moos MOOS core-moos through 10.4.0 fails to escape database contents=
when rendering MOOSDB HTTP pages, allowing attackers to inject malicious s= cripts. Any MOOS publisher can set variable values containing script payloa=
ds that execute in the browser of operators viewing the web interface. 2026= -09-03 6.1 CVE-2026-85453 [
https://www.cve.org/CVERecord?id=3DCVE-2026-854=
53 ] themoos--core-moos MOOS core-moos through 10.4.0 contains a buffer ove= rflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL ter= minator one byte past the serial telegram stack buffer. Attackers controlli=
ng the serial line can send a full-length telegram to trigger the off-by-on=
e write, corrupting the stack and potentially enabling code execution. 2026= -09-03 6.1 CVE-2026-85454 [
https://www.cve.org/CVERecord?id=3DCVE-2026-854=
54 ] ThimPress--LearnPress LearnPress WordPress Plugin before 4.4.6 contain=
s a stored cross-site scripting vulnerability that allows authenticated att= ackers with the Instructor role to inject persistent malicious payloads by = submitting unsanitized input into quiz question answer title fields. Attack= ers can store arbitrary JavaScript through the answer title parameter, whic=
h is rendered through an unescaped HTML sink to execute in the browsers of = any user who views the affected quiz question, including students, other in= structors, and administrators. 2026-09-03 5.4 CVE-2026-82024 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82024 ] ThimPress--LearnPress LearnPress Wo= rdPress Plugin before 4.4.6 contains a broken object-level authorization vu= lnerability that allows authenticated attackers with the Instructor role to=
add answers to quiz questions owned by other instructors by exploiting a m= issing ownership check on the question answer insert path. Attackers can su= pply arbitrary question identifiers during answer insertion, bypassing inst= ructor-boundary restrictions to persistently modify quiz content across cou= rses they do not own. 2026-09-03 4.3 CVE-2026-82023 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-82023 ] thimpress--LearnPress WordPress LMS Plugin f=
or Create and Sell Online Courses The LearnPress plugin for WordPress is vu= lnerable to SQL Injection via the 'orderby' parameter of the export_order_c=
sv AJAX action in versions up to, and including, 4.4.4. This is due to insu= fficient escaping on the user supplied parameter and lack of sufficient pre= paration on the existing SQL query in the LP_Order::handle_params_query_lis= t_orders() and DataBase::execute() functions - only the literal values 'dat=
e' and 'title' are normalized, while any other attacker-controlled string i=
s assigned directly to the filter's order_by property and concatenated into=
the ORDER BY clause without $wpdb->prepare() or an identifier whitelist. T= his makes it possible for authenticated attackers, with administrator-level=
access and above, to append additional SQL queries into already existing q= ueries that can be used to extract sensitive information from the database.=
2026-09-01 4.9 CVE-2026-77823 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-77823 ] thorsten--phpMyFAQ phpMyFAQ versions before 4.1.8 contain a store=
d cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks(=
) that calls html_entity_decode() on sanitized FAQ content, reversing entit= y-encoding protection. Authenticated users with FAQ editing privileges can = inject JavaScript payloads that execute in the browsers of all users viewin=
g the affected FAQ pages. 2026-09-04 5.4 CVE-2026-85593 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-85593 ] Toggl O--Toggl Track Extension A securit=
y vulnerability has been detected in Toggl O=C3=83=C5=93 Toggl Track Extens= ion 4.11.16. This affects an unknown function of the component postMessage = Handler. The manipulation leads to origin validation error. It is possible =
to initiate the attack remotely. The exploit has been disclosed publicly an=
d may be used. The vendor was contacted early about this disclosure but did=
not respond in any way. 2026-08-31 5.4 CVE-2026-82811 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-82811 ] ToolJet--ToolJet ToolJet through 3.0.0-ee= -beta.2 contains authorization bypass vulnerabilities in the POST /api/v2/r= esources/export endpoint that allow authenticated users to disclose Tooljet=
DB table schemas across workspace boundaries and export app definitions acr= oss granular permission boundaries. Attackers can supply a body-provided or= ganization_id parameter to access schemas from other workspaces, or bypass = per-app authorization gates to export restricted app definitions within the=
ir workspace. 2026-08-31 5 CVE-2026-82873 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-82873 ] ToolJet--ToolJet ToolJet before v3.16.208 contains an = authorization bypass vulnerability in TooljetDB controller endpoints that a= ccept organizationId from URL path without verifying it matches the authent= icated user's workspace. Authenticated users can enumerate, create, rename,=
and delete TooljetDB tables in any other workspace by manipulating the org= anizationId parameter in requests. 2026-08-31 5.5 CVE-2026-82875 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-82875 ] TOTOLINK--TOTOLINK T6 Incorrect=
access control in the setWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.7= 48_B20211015 allows unauthenticated attackers to alter when Wi-Fi is availa= ble via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 = 5.4 CVE-2026-51703 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51703 ] TO= TOLINK--TOTOLINK T6 Incorrect access control in the setApWiFiSchCfg functio=
n of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to = alter wireless availability windows via sending a crafted POST request to /= cgi-bin/cstecgi.cgi. 2026-08-31 5.9 CVE-2026-51712 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-51712 ] TOTOLINK--TOTOLINK T6 Incorrect access contro=
l in the setRoamingCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows=
unauthenticated attackers to alter roaming behavior via sending a crafted = POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 5.9 CVE-2026-51714 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-51714 ] TOTOLINK--TOTOLINK T6 Incorr= ect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.74= 8_B20211015 allows unauthenticated attackers to retrieve administrative imp= ort and export endpoint information via sending a crafted POST request to /= cgi-bin/cstecgi.cgi. 2026-08-31 5.3 CVE-2026-51727 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-51727 ] TOTOLINK--TOTOLINK T6 Incorrect access contro=
l in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 a= llows unauthenticated attackers to remove Wi-Fi schedule entries via sendin=
g a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 5.3 CVE-2026-5= 1732 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51732 ] TOTOLINK--TOTOLI=
NK T6 Incorrect access control in the clearTracerouteLog function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase trace= route logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026= -08-31 5.3 CVE-2026-51737 [
https://www.cve.org/CVERecord?id=3DCVE-2026-517=
37 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the CloudSrvVersionC= heck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated a= ttackers to trigger cloud update checks via sending a crafted POST request =
to /cgi-bin/cstecgi.cgi. 2026-08-31 5.9 CVE-2026-51739 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-51739 ] TOTOLINK--TOTOLINK T6 Incorrect access co= ntrol in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allo=
ws unauthenticated attackers to trigger WAN discovery logic via sending a c= rafted POST request to /cgi-bin/cstecgi.cgi. 2026-09-01 5.9 CVE-2026-51742 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-51742 ] TOTOLINK--TOTOLINK T6=
Incorrect access control in the updatePriStaList function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primar=
y station list via sending a crafted MQTT message to the cs_broker componen=
t. 2026-09-01 5.3 CVE-2026-51745 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-51745 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the sendStati= cInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthen= ticated attackers to update stored slave inventory records via sending a cr= afted MQTT message to the cs_broker component. 2026-09-01 5.9 CVE-2026-5174=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51748 ] TOTOLINK--TOTOLINK =
T6 Incorrect access control in the staticInfoSend function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to trigger static inf= ormation reporting to the configured master via sending a crafted MQTT mess= age to the cs_broker component. 2026-09-01 5.3 CVE-2026-51752 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51752 ] TOTOLINK--TOTOLINK T6 Incorrect ac= cess control in the meshSlaveUpgfw function of TOTOLINK T6 4.1.5cu.748_B202= 11015 allows unauthenticated attackers to start firmware flashing using exi= sting upgrade files via sending a crafted MQTT message to the cs_broker com= ponent. 2026-09-01 5.9 CVE-2026-51756 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-51756 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the upda= teLanIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticate=
d attackers to refresh the LAN address state via sending a crafted MQTT mes= sage to the cs_broker component. 2026-09-01 5.3 CVE-2026-51761 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-51761 ] TOTOLINK--TOTOLINK T6 Incorrect a= ccess control in the setWizardCfg function of TOTOLINK T6 4.1.5cu.748_B2021= 1015 allows unauthenticated attackers to reconfigure WAN, Wi-Fi, and device=
initialization state via sending a crafted POST request to /cgi-bin/cstecg= i.cgi. 2026-08-31 4.3 CVE-2026-51666 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-51666 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the getWi= FiIpMacTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthent= icated attackers to obtain Wi-Fi client MAC-to-IP mappings via sending a cr= afted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 4.3 CVE-2026-51667 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-51667 ] TOTOLINK--TOTOLINK T6 = Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.1.5c= u.748_B20211015 allows unauthenticated attackers to alter logging behavior = via sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 4.3 = CVE-2026-51678 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51678 ] TOTOLI= NK--TOTOLINK T6 Incorrect access control in the setLanCfg function of TOTOL= INK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter LAN = network configuration via sending a crafted POST request to /cgi-bin/cstecg= i.cgi. 2026-08-31 4.3 CVE-2026-51683 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-51683 ] TOTOLINK--TOTOLINK T6 Incorrect access control in the setIp= PortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauth= enticated attackers to alter firewall policies via sending a crafted POST r= equest to /cgi-bin/cstecgi.cgi. 2026-08-31 4.3 CVE-2026-51702 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-51702 ] TOTOLINK--TOTOLINK T6 Incorrect ac= cess control in the setWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B= 20211015 allows unauthenticated attackers to alter mesh configurations via = sending a crafted POST request to /cgi-bin/cstecgi.cgi. 2026-08-31 4.3 CVE-= 2026-51704 [
https://www.cve.org/CVERecord?id=3DCVE-2026-51704 ] TOTOLINK--= TOTOLINK T6 Incorrect access control in the setSmartQosCfg function of TOTO= LINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade t= raffic handling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.=
2026-08-31 4.3 CVE-2026-51706 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-51706 ] Tranquil_IT--WAPT WAPT Server versions 2.6.1.17834 and earlier co= ntains a SQL injection vulnerability in the `columns` parameter of the GET = `/api/v3/hosts` endpoint. A remote authenticated user with read-only privil= eges can inject arbitrary PostgreSQL expressions into the SQL query constru= cted by WAPT. By exploiting the injection point, an attacker can inject add= itional PostgreSQL statements, bypass the host scope restrictions applied t=
o the account, and read information from other rows or tables within the da= tabase. 2026-08-31 6.5 CVE-2026-75132 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-75132 ] triggerdotdev--trigger.dev Trigger.dev before 4.5.2 contai=
ns a server-side request forgery vulnerability in webhook alert channel del= ivery URLs that are fetched without validation or SSRF protection. Authenti= cated users with organization membership can create alert channels with URL=
s targeting internal services and metadata endpoints, allowing the server t=
o issue POST requests to restricted resources. 2026-09-04 5.4 CVE-2026-8565=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85650 ] tsi-coop--tsi-dpdp-= cms A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. Th=
is affects an unknown part of the file InterceptingFilter.java of the compo= nent Bootstrap Setup Endpoint. The manipulation leads to missing authentica= tion. The attack can be initiated remotely. The exploit is publicly availab=
le and might be used. Upgrading to version 0.5.1 is able to mitigate this i= ssue. Upgrading the affected component is recommended. 2026-09-02 6.5 CVE-2= 026-84840 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84840 ] tsi-coop--t= si-dpdp-cms A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0= .5.0. Affected by this issue is some unknown functionality of the file web.= xml of the component Admin Console/DPO Compliance Console. Executing a mani= pulation can lead to missing authentication. It is possible to launch the a= ttack remotely. The exploit has been publicly disclosed and may be utilized=
. Upgrading to version 0.5.1 can resolve this issue. It is suggested to upg= rade the affected component. 2026-09-02 5.3 CVE-2026-84839 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-84839 ] tursodatabase--turso Turso through 0.= 8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf pa=
ge reader that uses an attacker-controlled cell-count field without bounds = validation. Attackers can craft a malicious database file with a modified c= ell count value to trigger an index-out-of-bounds panic when querying, caus= ing denial of service in any application that opens untrusted database file=
s. 2026-09-04 5.5 CVE-2026-85698 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-85698 ] Tycon Systems--TPDIN-Monitor-WEB3
=C2=A0 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulner= able to a use of hard-coded credential vulnerability. This could allow an a= ttacker to intercept sensitive information or credentials. 2026-09-04 6.5 C= VE-2026-77847 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77847 ] tymotey= --Easy Waveform Player The Easy Waveform Player plugin for WordPress is vul= nerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer=
() function in all versions up to, and including, 1.2.2 due to insufficient=
input sanitization and output escaping. This makes it possible for authent= icated attackers, with Contributor-level access and above, to inject arbitr= ary web scripts in pages that will execute whenever a user accesses an inje= cted page. 2026-09-02 6.4 CVE-2025-7963 [
https://www.cve.org/CVERecord?id= =3DCVE-2025-7963 ] Typora--Typora A vulnerability was found in Typora up to=
1.13.8/1.14.6. This vulnerability affects unknown code of the component Me= rmaid Rendering Engine. The manipulation of the argument classDef/style res= ults in cross site scripting. The attack may be launched remotely. The expl= oit has been made public and could be used. Upgrading to version 1.14.8 is = able to resolve this issue. You should upgrade the affected component. The = vendor was contacted early, responded in a very professional manner and qui= ckly released a fixed version of the affected product. 2026-08-31 4.3 CVE-2= 026-82805 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82805 ] uhop--strea= m-json stream-json is a micro-library of stream components for processing J= SON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path fil= ters pick, ignore, filter, and replace in src/core/filters/filter-base.js r= ecompute the full path string from the nesting stack for every checkable to= ken. Because the stack length equals the current nesting depth and a checka= ble token is emitted at every level, a depth D document costs O(D=C3=82=C2= =B2) rather than O(D) to process. The issue is triggered by nesting depth r= ather than byte volume, including the documented pick({filter: 'data'}) tra= versal-until-match path, so an application that sends untrusted JSON throug=
h a string or RegExp filter can block the Node.js event loop and cause deni=
al of service with a small deeply nested document. The streamArray, streamO= bject, and streamValues streamers are not affected because they use the con= stant-time asm.depth getter. This issue is fixed in version 3.5.0. 2026-09-=
03 6.2 CVE-2026-71429 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71429 ]=
UKR Solution--Print Barcode Labels for your WooCommerce products/orders Su= bscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommer=
ce products/orders <=3D 4.0.0 versions. 2026-08-31 6.5 CVE-2026-81280 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-81280 ] Ultimate Before After Imag=
e Slider & Gallery--Ultimate Before After Image Slider & Gallery The Ultima=
te Before After Image Slider & Gallery WordPress plugin before 4.7.19 does = not properly escape the slider's after-label value before its bundled clien= t-side script re-injects it into the DOM, allowing users with the Author ro=
le and above to store a payload that executes in the browser of anyone (inc= luding an administrator) who views the slider. 2026-09-02 6.8 CVE-2025-1566=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15663 ] Ultimate Before Aft=
er Image Slider & Gallery--Ultimate Before After Image Slider & Gallery The=
Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1=
9 does not properly escape the slider's before-label value before its bundl=
ed client-side script re-injects it into the DOM, allowing users with the A= uthor role and above to store a payload that executes in the browser of any= one (including an administrator) who views the slider. 2026-09-02 6.8 CVE-2= 025-15664 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15664 ] Ultimate Me= mber--Ultimate Member The Ultimate Member WordPress plugin before 2.13.0 do=
es not check whether a comment has been approved, or whether the profile it=
belongs to is private, before returning profile activity to unauthenticate=
d visitors, allowing them to read the content of comments still awaiting mo= deration. 2026-09-02 5.3 CVE-2026-19251 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-19251 ] undici--undici undici's cache interceptor does not hand=
le the Set-Cookie response header anywhere in its cache path, so it neither=
refuses to store nor strips that header. In shared cache mode, which is th=
e default, an otherwise cacheable response that carries a Set-Cookie header=
, for example one marked with a public and max-age directive, is stored and=
then re-served to a later caller that matches the same cache key. As a res= ult one caller's cookie is disclosed to a different caller, and an untruste=
d server can inject cookies into cached responses served to all subsequent = callers. This violates the requirement that a shared cache must not store c= ookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0=
up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. 2026-09-04 = 6.5 CVE-2026-84933 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84933 ] un= dici--undici undici's retry handler can leave an already-exposed response b= ody pending forever. When a server returns a successful response that decla= res a Content-Length, sends only part of the body, and closes the connectio=
n, the retry handler retries the request. If the retry returns a non-retrya= ble status such as 400, the handler forwards that new response downstream a=
nd replaces its internal response stream, but the original response body th=
at the application still holds is never ended or destroyed. As a result cal=
ls that read that body never settle, and the configured body timeout does n=
ot fire because its timer is tied to the connection parser rather than the = orphaned body. An attacker-controlled server can trigger this with two shor=
t responses without keeping a connection open, and repeated requests accumu= late pending promises and streams that can exhaust application concurrency =
or memory. This affects undici versions from 7.11.0 up to 7.29.1 and from 8= .0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. 2026-09= -04 5.9 CVE-2026-18149 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18149 =
] undici--undici undici's decompress interceptor decompresses response bodi=
es according to the untrusted Content-Encoding header. While the number of = content-encoding layers is capped, the total decompressed output size is un= bounded and there is no configuration option to limit it. A malicious or fa= ulty upstream can therefore return a small compressed payload, a compressio=
n bomb, that expands to hundreds of megabytes or more in client memory, an = asymmetric resource consumption that can exhaust memory and crash the proce= ss. This affects undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up=
to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. 2026-09-04 5.9=
CVE-2026-84890 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84890 ] undic= i--undici undici's experimental WebSocketStream client crashes the whole No= de.js process when a remote peer closes the TCP connection without a WebSoc= ket close handshake. On an unclean close the internal socket-close handler = calls abort on the writable stream unconditionally and discards the returne=
d promise, but per the WHATWG Streams standard aborting a locked writable r= eturns a promise that rejects with a TypeError. Because the application hol=
ds a writer on that writable, which is the only way to write, the rejection=
is never observed and Node's default unhandled-rejection behavior terminat=
es the process. An untrusted server can therefore crash a client with a sin= gle abrupt disconnect, with no authentication and no application mistake. T= his affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.= 10.2. Users should upgrade to undici 7.29.1 or 8.10.2. 2026-09-04 5.9 CVE-2= 026-85014 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85014 ] undici--und= ici undici bundles a WebSocket client whose permessage-deflate size-limit c= leanup removes all listeners from the internal zlib inflate stream, includi=
ng its error listener, while that stream can still emit. When a remote peer=
sends a compressed payload that crosses the built-in 128 MiB decompressed-= payload limit and then contains a malformed DEFLATE byte, the inflate strea=
m emits a data error with no listener attached, which Node.js treats as a f= atal unhandled error and terminates the entire process. Exploitation is rem= ote and unauthenticated, requires no application mistake, and is asymmetric=
, since roughly 130 KB on the wire expands past the limit and crashes the p= rocess, and reconnecting can repeat the crash. This affects undici versions=
from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8= .10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2. 2026-09-04=
5.9 CVE-2026-85024 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85024 ] U= nlimited Elements--Unlimited Elements For Elementor (Free Widgets, Addons, = Templates) Missing Authorization vulnerability in Unlimited Elements Unlimi= ted Elements For Elementor (Free Widgets, Addons, Templates) allows Exploit= ing Incorrectly Configured Access Control Security Levels. This issue affec=
ts Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from=
n/a through 2.0.17. 2026-09-03 5.3 CVE-2026-85304 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-85304 ] usebruno--bruno Bruno versions through 4.1.0 = fail to validate file paths in request body declarations, allowing attacker=
s to read arbitrary local files by using parent-directory traversal segment=
s. When a collection is executed, attackers can craft a request with a body= :file path containing ../ sequences that resolve outside the collection dir= ectory, causing the application to read and exfiltrate arbitrary files to a= ttacker-controlled endpoints. 2026-09-04 6.5 CVE-2026-85665 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85665 ] User Frontend--User Frontend The Use=
r Frontend WordPress plugin before 4.3.11 does not enforce its subscription= -purchase requirement when processing frontend post submissions, only when = rendering the form, allowing unauthenticated users to create and, depending=
on the form's configuration, immediately publish posts through forms restr= icted to paying subscribers. 2026-09-02 5.3 CVE-2026-17563 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-17563 ] valkey-io--valkey A vulnerability was=
detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerabi= lity is the function createSlotImportJob of the file src/cluster_migrateslo= ts.c of the component Slot Migration. The manipulation of the argument job_= name results in out-of-bounds read. The attack can be executed remotely. Th=
e exploit is now public and may be used. Upgrading to version 9.0.5 and 9.1=
.1 addresses this issue. The patch is identified as f4dc3ca09eb650c2fe14060= 090a41c524eca803f. Upgrading the affected component is advised. 2026-09-04 = 5.3 CVE-2026-85522 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85522 ] Ve= ronaLabs--WP Statistics Unauthenticated Cross Site Scripting (XSS) in WP St= atistics <=3D 14.16.11 versions. 2026-09-03 6.1 CVE-2026-84774 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-84774 ] vidIQ--Vision for YouTube Extensi=
on A security flaw has been discovered in vidIQ Vision for YouTube Extensio=
n 3.199.0 on Chrome. The affected element is the function window.addEventLi= stener of the component postMessage Handler. Performing a manipulation of t=
he argument vidiqEvent results in information disclosure. The attack is pos= sible to be carried out remotely. The exploit has been released to the publ=
ic and may be used for attacks. The vendor explains: "At this time, vidIQ d= oes not accept security vulnerability submissions, and we do not have a bug=
bounty program in place." 2026-08-31 4.3 CVE-2026-82809 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-82809 ] VillaTheme--Product Variations Swatches=
for WooCommerce Subscriber Cross Site Scripting (XSS) in Product Variation=
s Swatches for WooCommerce <=3D 1.1.18 versions. 2026-09-03 6.5 CVE-2026-81= 282 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81282 ] vitest-dev--vites=
t Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 an=
d 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin expo= rts in packages/mocker/src/node/interceptorPlugin.ts register the vitest:in= terceptor:register handler on Vite's unauthenticated HMR WebSocket without = validating redirect targets against the file-serving allowlist. The impleme= ntation processes event.redirect without enforcing server.fs.allow and serv= er.fs.deny through isFileLoadingAllowed. A remote client that can reach an = exposed development server can submit an opaque URL scheme preserving .. se= gments, causing join(server.config.root, redirectUrl.pathname) to resolve o= utside the project root. The plugin's load hook then returns readFile(mock.= redirect, 'utf-8') as module source, disclosing local files readable by the=
dev-server process. Vitest browser mode uses a token-authenticated RPC and=
is not remotely unauthenticated by default, although the same boundary che=
ck was missing on that path. This issue is fixed in versions 4.1.11 and 5.0= .0-rc.2. 2026-09-01 5.9 CVE-2026-84373 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84373 ] wakujs--waku Waku is the minimal React framework. Prior=
to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server acti= ons without validating the request's Origin (or Sec-Fetch-Site) header. A c= ross-origin web attacker can therefore cause a victim browser to issue an a= uthenticated POST to a registered server action endpoint using a CORS-safel= isted content type (text/plain), which does not trigger a preflight. Any st= ate-mutating server action that the application exposes via 'use server' ca=
n be invoked with the victim's cookies attached. This issue has been patche=
d in version 1.0.0-beta.1. 2026-09-03 6.5 CVE-2026-49455 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-49455 ] WC Lovers--WCFM Marketplace Contributor=
Cross Site Scripting (XSS) in WCFM Marketplace <=3D 3.8.2 versions. 2026-0= 9-02 6.5 CVE-2026-83562 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83562=
] WC Lovers--WCFM Membership Missing Authorization vulnerability in WC Lov= ers WCFM Membership allows Exploiting Incorrectly Configured Access Control=
Security Levels. This issue affects WCFM Membership: from n/a through 2.11= .11. 2026-09-04 5.3 CVE-2026-32480 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-32480 ] WC Vendors--WC Vendors The WC Vendors WordPress plugin before=
2.7.2.1 does not verify ownership or the object type of user-supplied IDs = when saving product variations, allowing authenticated users with the vendo=
r role to modify product variations belonging to other vendors, and to chan=
ge the status and title of arbitrary posts, via IDOR. 2026-09-02 6.5 CVE-20= 26-81428 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81428 ] WC Vendors--=
WC Vendors The WC Vendors WordPress plugin before 2.7.2.1 does not have CSR=
F protection on some of its front-end order shipment status actions, which = could allow attackers to make a logged-in vendor change the shipment status=
of their own orders via a crafted request. 2026-09-02 4.3 CVE-2026-81426 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-81426 ] WC Vendors--WC Vendors=
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the ve= ndor submitting a front-end order shipment status change owns the reference=
d order, allowing any authenticated vendor to mark another vendor's order a=
s shipped, add an order note falsely attributed to the victim vendor, and t= rigger the customer shipment notification email. 2026-09-02 4.3 CVE-2026-81= 427 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81427 ] wger --wger
=C2=A0 wger versions through master contain an incomplete authorization byp= ass in wger/core/views/user.py where three views retain the original gym-sc= ope check using raw integer comparison instead of the is_same_gym() helper,=
allowing gym staff with gym=3DNone to delete, deactivate, or activate any = other user with gym=3DNone. Attackers with gym.manage_gym permission and gy= m=3DNone affiliation can permanently delete user accounts, lock users out v=
ia deactivation, or undo defensive deactivations by exploiting the None !=
=3D None comparison edge case. 2026-09-06 6.8 CVE-2026-86254 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-86254 ] wger --wger
=C2=A0 wger before 2.5 fails to validate the maximum duration of routine da=
te ranges, allowing authenticated users to create routines spanning arbitra= rily long periods. Attackers can trigger the date_sequence computation via = routine detail endpoints, forcing the server to iterate thousands of times = per request and exhaust worker threads, denying service to legitimate users=
. 2026-09-06 6.5 CVE-2026-86255 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-86255 ] wger--wger=C2=A0
=C2=A0 wger before 2.6 (affected versions <=3D 2.5.0) contains an open redi= rect vulnerability in the trainer_login view (wger/core/views/user.py). Aft=
er a trainer enters impersonation mode, the view redirects to the user-supp= lied 'next' GET parameter via HttpResponseRedirect() without validating it = with url_has_allowed_host_and_scheme(). An attacker who delivers a crafted = link to an authenticated trainer can redirect the trainer's browser to an a= ttacker-controlled domain, enabling phishing and leaking the wger URL struc= ture (including the impersonated user's user_pk) via the Referer header. 20= 26-09-06 5.4 CVE-2026-86256 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 6256 ] wger--wger=C2=A0
=C2=A0 wger before 2.6 fails to sanitize first_name and last_name fields in=
the gym member TSV export endpoint, allowing any gym member to inject spre= adsheet formulas. Attackers can inject formulas like =3DHYPERLINK to exfilt= rate admin data or execute code when admins open the exported file in Excel=
or LibreOffice Calc. 2026-09-06 5.4 CVE-2026-86257 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-86257 ] WordPress Plugin --Accept Stripe Payments
=C2=A0 The Accept Stripe Payments WordPress plugin before 2.1.4 does not ve= rify that the product fulfilled when a checkout is completed matches the pr= oduct the authoritative payment was actually made for, checking only that t=
he amount paid is at least the referenced product's price, allowing unauthe= nticated attackers who complete a genuine payment to obtain fulfilment for =
a different, equal- or lower-priced product than the one they paid for. 202= 6-09-05 5.3 CVE-2026-81424 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81= 424 ] WordPress Plugin --Dear Flipbook - PDF Flipbook, 3D Flipbook, PDF emb= ed, PDF viewer
=C2=A0 The Dear Flipbook - PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer=
plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the = 'post_content (class attribute of .dvcss element)' parameter in all version=
s up to, and including, 2.4.30 due to insufficient input sanitization and o= utput escaping. This makes it possible for authenticated attackers, with co= ntributor-level access and above, to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page. The payload is=
embedded as a Base64-encoded JSON object in a CSS class name on a Custom H= TML block; the frontend parseCSSElements() function decodes it client-side = with atob() and JSON.parse() and renders the logo property as raw HTML, mea= ning no server-side or client-side sanitization intercepts the malicious sc= ript before DOM insertion. 2026-09-05 6.4 CVE-2026-8623 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-8623 ] WordPress Plugin --Dear Flipbook - PDF Fl= ipbook, 3D Flipbook, PDF embed, PDF viewer
=C2=A0 The Dear Flipbook - PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer=
plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the = 'post_content (Custom HTML block inner HTML)' parameter in all versions up = to, and including, 2.4.30 due to insufficient input sanitization and output=
escaping. This makes it possible for authenticated attackers, with contrib= utor-level access and above, to inject arbitrary web scripts in pages that = will execute whenever a user accesses an injected page. A Contributor-level=
attacker can insert a crafted .df-element div with data-df-lightbox=3D'thu= mb' via a Custom HTML block, whose inner HTML is passed as the title argume=
nt to parseThumbs() at render time, enabling both innerHTML injection into =
a span element and attribute breakout via an onerror handler on a construct=
ed img element. 2026-09-05 6.4 CVE-2026-8625 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-8625 ] WordPress Plugin --Greenshift
=C2=A0 The Greenshift WordPress plugin before 13.2.0 does not properly esca=
pe a block animation attribute before outputting it within an HTML attribut=
e, allowing users with contributor-level access and above to inject arbitra=
ry web scripts that execute when the content is viewed. 2026-09-05 6.8 CVE-= 2026-83544 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83544 ] WordPress = Plugin --JetFormBuilder - Dynamic Blocks Form Builder
=C2=A0 The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate=
or strip line breaks from address values it sources from submitted form fi= elds before adding them to the headers of the e-mails it sends, allowing un= authenticated users to inject arbitrary e-mail headers, add hidden recipien=
ts and spoof the sender. Exploitation requires the site to be configured to=
take one of the message's addresses from a form field. 2026-09-06 4.8 CVE-= 2026-19862 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19862 ] WordPress = Plugin --JetFormBuilder - Dynamic Blocks Form Builder=C2=A0
=C2=A0 The JetFormBuilder - Dynamic Blocks Form Builder WordPress plugin be= fore 3.6.5.2 does not properly sanitise and escape a form field's value bef= ore including it in the HTML notification emails it sends, allowing unauthe= nticated users to inject arbitrary HTML into messages delivered to administ= rators and other recipients. Whether injected script executes depends on th=
e recipient's mail client, but the injected markup is rendered regardless. = 2026-09-05 4.7 CVE-2026-19861 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -19861 ] WordPress Plugin --Smart Post
=C2=A0 The Smart Post WordPress plugin before 4.0.8 does not check whether =
a post is password protected before returning its content and its stored pa= ssword through an unauthenticated AJAX action, allowing unauthenticated use=
rs to read protected post content and the password that guards it. 2026-09-=
05 5.3 CVE-2026-78149 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78149 ]=
WordPress Plugin-- Custom Contact Forms
=C2=A0 The Custom Contact Forms plugin for WordPress is vulnerable to autho= rization bypass in all versions up to, and including, 7.16. This is due to = the plugin not properly verifying that a user is authorized to perform an a= ction. This makes it possible for authenticated attackers, with contributor= -level access and above, to permanently force-delete arbitrary posts of any=
post type (including pages, administrator-authored posts, and WooCommerce = products) and write arbitrary ccf_field_* post meta onto any post regardles=
s of ownership or post type. The top-level form ID is checked via edit_post= /publish_posts, but the nested fields[].ID and choices[].ID paths processed=
by _create_and_map_fields() and _create_and_map_choices() carry no equival= ent capability or post-type guard, leaving those sinks fully exposed while = delete_item() and delete_submission() contain explicit post-type restrictio=
n fixes demonstrating the developer's awareness of scoping requirements. 20= 26-09-05 4.3 CVE-2026-75018 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7= 5018 ] WordPress Plugin-- Eventin
=C2=A0 The Eventin WordPress plugin before 4.1.21 does not properly validat=
e a template path value before using it to include a local file, allowing u= sers with contributor-level access and above to include and execute arbitra=
ry local PHP files. 2026-09-05 6.6 CVE-2026-84898 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-84898 ] WordPress Plugin-- Video Player for YouTube=C2= =A0
=C2=A0 The Video Player for YouTube WordPress plugin before 2.1.0 does not = properly sanitise and escape user-supplied input before using it in a SQL s= tatement, allowing users with the Contributor role and above to perform SQL=
injection attacks and read arbitrary data from the database. 2026-09-05 6.=
8 CVE-2026-84937 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84937 ] Word= Press Plugin--Accept Stripe Payments
=C2=A0 The Accept Stripe Payments WordPress plugin before 2.1.4 does not va= lidate a user-supplied URL before using it in a redirect, allowing unauthen= ticated attackers to redirect visitors to an arbitrary external website, wh= ich can be leveraged for phishing. 2026-09-05 4.3 CVE-2026-81423 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-81423 ] WordPress Plugin--B2BKing - Ult= imate WooCommerce B2B and Wholesale
=C2=A0 The B2BKing - Ultimate WooCommerce B2B and Wholesale Plugin - Wholes= ale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not = verify that a role selected during registration is one actually offered on = the registration form, allowing unauthenticated users to assign themselves =
to restricted B2B customer groups and to skip the manual account-approval w= orkflow during self-registration. 2026-09-06 5.3 CVE-2026-85038 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-85038 ] WordPress Plugin--Beaver Builder =C2=A0 The Beaver Builder Plugin (Starter Version) plugin for WordPress is = vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_= preview Parameter in all versions up to, and including, 2.11.0.1 due to ins= ufficient input sanitization and output escaping. This makes it possible fo=
r unauthenticated attackers to inject arbitrary web scripts in pages that e= xecute if they can successfully trick a user into performing an action such=
as clicking on a link. 2026-09-05 6.1 CVE-2026-18843 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-18843 ] WordPress Plugin--Bold Page Builder
=C2=A0 The Bold Page Builder WordPress plugin before 5.9.8 does not properl=
y validate a link URL before outputting it in an HTML attribute, relying on=
a filter that can be evaded, allowing users with the Contributor role and = above to inject arbitrary web scripts that execute when a user clicks the a= ffected link. 2026-09-05 6.8 CVE-2026-84021 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-84021 ] WordPress Plugin--Bold Page Builder
=C2=A0 The Bold Page Builder WordPress plugin before 5.9.8 does not sanitis=
e and escape several shortcode attributes before outputting them in HTML at= tributes, allowing users with the Contributor role and above to inject arbi= trary web scripts that execute when a user views the affected page. 2026-09= -05 6.8 CVE-2026-84022 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84022 =
] WordPress Plugin--Bold Page Builder
=C2=A0 The Bold Page Builder WordPress plugin before 5.9.9 does not sanitis=
e and escape a shortcode attribute before outputting it in an HTML attribut=
e, allowing users with the Contributor role and above to inject arbitrary w=
eb scripts that execute when a user views the affected page. 2026-09-06 6.8=
CVE-2026-84028 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84028 ] WordP= ress Plugin--CatFolders Document Gallery & PDF Library=C2=A0
=C2=A0 The CatFolders Document Gallery & PDF Library WordPress plugin befor=
e 2.0.7 does not properly validate a block attribute before using it as an = HTML tag name in its gallery output, allowing users with the Author role an=
d above to inject arbitrary web scripts that execute in the browser of anyo=
ne who views the affected post. 2026-09-05 6.8 CVE-2026-84930 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-84930 ] WordPress Plugin--Divi theme
=C2=A0 The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross= -Site Scripting via the `image_src` attribute of the `et_pb_video_slider_it= em` shortcode in all versions up to, and including, 4.27.6. This is due to = the `image_src` field not being included in the `$url_options` whitelist (w= hich only contains `url`, `button_link`, `button_url`), so it never receive=
s `esc_url_raw()` at save time. On the server side, the value is rendered i= nto a `data-image` HTML attribute using `esc_attr()`, which encodes double = quotes as `"`. However, the client-side JavaScript carousel code in `c= ustom.unified.js` reads this attribute using jQuery's `.data('image')`, whi=
ch returns the browser-decoded value (with `"` decoded back to `"`). T=
he decoded value is then concatenated directly into an HTML string and inje= cted into the DOM via `jQuery.after()` without re-escaping. This makes it p= ossible for authenticated attackers, with Contributor-level access and abov=
e, to inject arbitrary web scripts in pages that will execute whenever a us=
er hovers over the carousel thumbnail. 2026-09-05 6.4 CVE-2026-3853 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-3853 ] WordPress Plugin--Divi theme= =C2=A0
=C2=A0 The Divi theme for WordPress is vulnerable to Server-Side Request Fo= rgery in all versions up to, and including, 4.27.6. This is due to the `et_= pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()=
` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does=
not restrict requests to private or reserved IP ranges. This makes it poss= ible for authenticated attackers, with Contributor-level access and above, =
to make web requests to arbitrary locations originating from the web applic= ation server. The response body is not returned to the attacker (blind SSRF=
), but two oracles exist: a status oracle (the returned URL string differs = depending on whether the target responded with HTTP 200) and a timing oracl=
e (response time varies by target reachability). 2026-09-05 5 CVE-2026-4361=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-4361 ] WordPress Plugin--Emb= edPress
=C2=A0 The EmbedPress WordPress plugin before 4.6.4 does not have proper au= thorization on a public review-loading action, allowing unauthenticated use=
rs to force the site to make repeated billable third-party API requests usi=
ng the site's own configured API key, and to create an unbounded number of = attacker-controlled rows in the database. 2026-09-05 5.3 CVE-2026-84936 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84936 ] WordPress Plugin--Eventin =C2=A0 The Eventin WordPress plugin before 4.1.22 does not properly check a= uthorization on several of its event-management REST routes, allowing users=
with contributor-level access and above to change the site's front-page se= tting to an event they do not own and to create, edit and delete global eve=
nt and speaker taxonomy terms they should not be able to manage. 2026-09-05=
4.9 CVE-2026-84901 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84901 ] W= ordPress Plugin--Events Manager - Calendar, Bookings, Tickets, and more
=C2=A0 The Events Manager - Calendar, Bookings, Tickets, and more! plugin f=
or WordPress is vulnerable to Stored Cross-Site Scripting via event attribu=
te values in all versions up to, and including, 7.3.3. This is due to insuf= ficient input sanitization when storing attribute values (using only `wp_un= slash()` without sanitization) and lack of output escaping when rendering t=
he '#_ATT{key}' placeholder. This makes it possible for authenticated attac= kers, with Author-level access and above, or unauthenticated attackers when=
anonymous event submissions are enabled, to inject arbitrary web scripts t= hat execute when any user views the affected event page. 2026-09-05 5.4 CVE= -2025-14945 [
https://www.cve.org/CVERecord?id=3DCVE-2025-14945 ] WordPress=
Plugin--Gallery : FooGallery=C2=A0
=C2=A0 The Gallery : FooGallery plugin for WordPress is vulnerable to Store=
d Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all ver= sions up to, and including, 3.3.2 due to insufficient input sanitization an=
d output escaping. This makes it possible for authenticated attackers, with=
contributor-level access and above, to inject arbitrary web scripts in pag=
es that will execute whenever a user accesses an injected page. 2026-09-05 = 6.4 CVE-2026-85414 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85414 ] Wo= rdPress Plugin--Greenshift=C2=A0
=C2=A0 The Greenshift WordPress plugin before 13.2.0 does not validate a us= er-supplied URL before fetching it server-side, allowing users with contrib= utor-level access and above to make the server issue requests to arbitrary = hosts and read the response. 2026-09-05 4.1 CVE-2026-83543 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-83543 ] WordPress Plugin--JetFormBuilder=C2=A0 =C2=A0 The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize=
a request parameter before rendering it as message content, allowing unaut= henticated users to execute arbitrary shortcodes registered on the site on = any page displaying a form. Escaping is applied to that content before a la= ter shortcode-expansion pass rather than after it, so the escaping can be b= ypassed. 2026-09-06 6.5 CVE-2026-19859 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-19859 ] WordPress Plugin--Joli Table Of Contents=C2=A0
=C2=A0 The Joli Table Of Contents WordPress plugin before 3.0.3 does not sa= nitise or escape a shortcode attribute value before outputting it inside an=
HTML element's attribute, allowing users with the Author role and above to=
inject arbitrary HTML attributes and JavaScript that execute in the browse=
r of any user who views the post, including higher-privileged users such as=
administrators. This crosses a privilege boundary even on multisite, where=
such users are not permitted to post unfiltered HTML. 2026-09-05 6.8 CVE-2= 026-84931 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84931 ] WordPress P= lugin--King Addons for Elementor=C2=A0
=C2=A0 The King Addons for Elementor WordPress plugin before 51.1.77 does n=
ot escape a widget display-style setting before outputting it in an HTML at= tribute, allowing users with Contributor-level access and above to store Ja= vaScript that executes in the browser of any visitor to the affected page, = including logged-in administrators. 2026-09-05 6.8 CVE-2026-84896 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-84896 ] WordPress Plugin--Kirki
=C2=A0 The Kirki WordPress plugin before 6.3.0 does not escape a user-suppl= ied identifier before using it in a SQL query, allowing users with editor-l= evel access and above to append arbitrary SQL and read the contents of the = database, including user credentials. 2026-09-05 6.8 CVE-2026-84221 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84221 ] WordPress Plugin--LearnDash = LMS=C2=A0
=C2=A0 The LearnDash LMS plugin for WordPress is vulnerable to authorizatio=
n bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly=
verifying that a user is authorized to perform an action. This makes it po= ssible for unauthenticated attackers to enroll arbitrary users in paid cour= ses without payment verification, bypassing the entire payment system and g= aining unauthorized access to premium educational content. 2026-09-05 5.4 C= VE-2026-12843 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12843 ] WordPre=
ss Plugin--Masteriyo LMS
=C2=A0 The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise an=
d escape some course settings before outputting them in a page available to=
all visitors, allowing users with a course-author role to perform Stored C= ross-Site Scripting attacks that run in the session of anyone viewing the c= ourse, including a logged-in administrator. 2026-09-05 6.8 CVE-2026-82846 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82846 ] WordPress Plugin--Ninj=
a Forms - Save Progress=C2=A0
=C2=A0 The Ninja Forms - Save Progress plugin for WordPress is vulnerable t=
o Missing Authorization in versions up to, and including, 3.0.30. This is d=
ue to the lack of capability checks and nonce verification in the 'bulk_act= ions' function. This makes it possible for authenticated attackers, with su= bscriber-level access and above, to delete arbitrary database records from = the 'wp_nf3_objects' table, such as saved submissions. 2026-09-05 4.3 CVE-2= 026-15550 [
https://www.cve.org/CVERecord?id=3DCVE-2026-15550 ] WordPress P= lugin--Ninja Forms=C2=A0
=C2=A0 The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not=
prevent shortcodes in request-derived values from being executed when it s= ubstitutes them into content it later processes for shortcodes, allowing un= authenticated users to run any shortcode registered on the site. 2026-09-06=
4.8 CVE-2026-80437 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80437 ] W= ordPress Plugin--Pods - Custom Content Types and Fields
=C2=A0 The Pods - Custom Content Types and Fields plugin for WordPress is v= ulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribut=
e in all versions up to, and including, 3.3.9.1 due to insufficient input s= anitization and output escaping. This makes it possible for authenticated a= ttackers, with contributor-level access and above, to inject arbitrary web = scripts in pages that will execute whenever a user accesses an injected pag=
e. 2026-09-05 6.4 CVE-2026-76573 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-76573 ] WordPress Plugin--Real Estate Papi=C2=A0
=C2=A0 The Real Estate Papi WordPress theme through 1.0.5 does not perform = capability or CSRF checks on one of its AJAX actions, allowing any authenti= cated user, such as a subscriber, to install a fixed set of companion from = the WordPress.org repository. Where the request runs in the session of a us=
er who can activate , those are activated as well. 2026-09-06 4.3 CVE-2026-= 13159 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13159 ] WordPress Plugi= n--Redirection for Contact Form 7
=C2=A0 The Redirection for Contact Form 7 WordPress plugin from 2.2.7 befor=
e 3.2.11 does not prevent shortcodes in submitted form values from being ex= ecuted when it substitutes those values into an action's settings and then = processes those settings for shortcodes, allowing unauthenticated users to = run any shortcode registered on the site and read its output. 2026-09-06 4.=
8 CVE-2026-80439 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80439 ] Word= Press Plugin--Search Atlas SEO=C2=A0
=C2=A0 The Search Atlas SEO WordPress plugin before 2.6.24 does not perform=
a nonce or capability check before processing a settings update in one of = its early-priority handlers, allowing any authenticated user such as a Subs= criber to overwrite or delete the site's stored Google service-account cred= entials. 2026-09-05 5.4 CVE-2026-15247 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-15247 ] WordPress Plugin--Social Chat - Click To Chat App Button =C2=A0 The Social Chat - Click To Chat App Button plugin for WordPress is v= ulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribu=
te in .qlwapp data-box in all versions up to, and including, 8.6.2 due to i= nsufficient input sanitization and output escaping. This makes it possible = for authenticated attackers, with contributor-level access and above, to in= ject arbitrary web scripts in pages that will execute whenever a user acces= ses an injected page. The exploit requires no user interaction beyond page = load, as setting auto_open and consent_enabled to 'yes' in the injected dat= a-box JSON causes the consent box - and the embedded script - to execute im= mediately on page load. 2026-09-05 6.4 CVE-2026-18404 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-18404 ] WordPress Plugin--SureCart
=C2=A0 The SureCart WordPress plugin before 4.7.0 does not consult the site=
's user registration setting before creating WordPress accounts, allowing u= nauthenticated users to create an account and receive a logged-in session e= ven when registration is disabled. 2026-09-06 6.5 CVE-2026-75793 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-75793 ] WordPress Plugin--Theme My Logi= n=C2=A0
=C2=A0 The Theme My Login plugin for WordPress is vulnerable to Missing Aut= horization in versions up to, and including, 7.1.15 on Multisite installati= ons. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherb= log` branch failing to enforce the network's `active_signup` registration p= olicy, checking only `is_user_logged_in()` while sibling branches such as `= validate-blog-signup` apply the full policy gate. This makes it possible fo=
r authenticated attackers, with Subscriber-level access and above, to direc= tly POST `stage=3Dgimmeanotherblog` to Theme My Login's signup route, bypas= sing the configured registration policy entirely - even when it is set to `= none` or `user` - which causes `wpmu_create_blog()` to execute with the att= acker's user ID, after which WordPress core assigns the Administrator role =
on the newly created subsite via `add_user_to_blog()`. The privilege gain i=
s scoped to the newly created subsite only; the attacker's account retains = Subscriber-level access on the main site and does not obtain Super Admin or=
network-level capabilities such as `manage_network` or `manage_sites`. 202= 6-09-05 4.3 CVE-2026-83628 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83= 628 ] WordPress Plugin--Unlimited Elements For Elementor
=C2=A0 The Unlimited Elements For Elementor plugin for WordPress is vulnera= ble to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all v= ersions up to, and including, 2.0.17 due to insufficient input sanitization=
and output escaping. This makes it possible for unauthenticated attackers =
to inject arbitrary web scripts in pages that execute if they can successfu= lly trick a user into performing an action such as clicking on a link. The = front-end AJAX handler is registered on the public 'wp' action with no nonc=
e, capability, or referer check, and the raw attacker-controlled id value i=
s interpolated verbatim into an exception message that is echoed back witho=
ut escaping; when the response is served as text/html rather than applicati= on/json, the browser parses the injected markup. 2026-09-05 6.1 CVE-2026-75= 586 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75586 ] WordPress Plugin-= -VikWidgetsLoader
=C2=A0 The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitis=
e or escape a block attribute before outputting it inside an inline script,=
allowing users with the Contributor role to store arbitrary JavaScript tha=
t executes in the browser of any user viewing the affected post, including = the administrator who reviews the pending submission. 2026-09-05 6.8 CVE-20= 26-84899 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84899 ] WordPress Pl= ugin--WP File Download
=C2=A0 The WP File Download plugin for WordPress is vulnerable to Directory=
Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' = parameter. This makes it possible for authenticated attackers, with subscri= ber-level access and above, to read the contents of arbitrary files on the = server, which can contain sensitive information. An authenticated attacker = with Subscriber-level access first poisons the _wpfd_file_metadata['file'] = post-meta value via the unprotected file.save handler, after which the stre= aming endpoint - hooked on init with no authentication requirement - resolv=
es and streams the traversed file path to any caller, including unauthentic= ated visitors. 2026-09-05 6.5 CVE-2026-14975 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-14975 ] Worklenz--worklenz Worklenz before 3.0.0 fails to v= erify task ownership by organization when resolving task-scoped API endpoin= ts, allowing authenticated users to access another tenant's task data. Atta= ckers can query task endpoints with arbitrary task UUIDs to retrieve work l= ogs, comments, attachments, and project insights belonging to other organiz= ations. 2026-09-03 6.5 CVE-2026-85389 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-85389 ] WP Chill--Gallery PhotoBlocks Contributor Cross Site Scrip= ting (XSS) in Gallery PhotoBlocks <=3D 1.3.4 versions. 2026-09-02 6.5 CVE-2= 026-84781 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84781 ] Wp Edit Pas= sword Protected--Wp Edit Password Protected The Wp Edit Password Protected = WordPress plugin before 1.3.5 allows protecting page content, but this prot= ection can be bypassed by using the REST API. 2026-09-02 5.3 CVE-2025-8945 =
[
https://www.cve.org/CVERecord?id=3DCVE-2025-8945 ] WP Express Checkout--W=
P Express Checkout The WP Express Checkout WordPress plugin before 2.4.9 do=
es not verify server-side that a payment was actually completed before mark= ing an order as paid, allowing unauthenticated users to forge a completed o= rder without paying. 2026-09-02 5.3 CVE-2026-83533 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-83533 ] WP Fastest Cache--WP Fastest Cache The WP Fas= test Cache WordPress plugin before 1.5.1 does not include a set of tracking= -related query parameters in its page-cache key while still caching pages r= equested with them, allowing unauthenticated attackers to have a page rende= red under their own request context stored under, and served from, the clea=
n URL's cache entry to every subsequent visitor. 2026-09-01 6.5 CVE-2026-74= 916 [
https://www.cve.org/CVERecord?id=3DCVE-2026-74916 ] WP Manage Ninja--= FluentBooking Pro Unauthenticated Bypass Vulnerability in FluentBooking Pro=
<=3D 2.2.1 versions. 2026-09-03 5.9 CVE-2026-84766 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-84766 ] WP Swings--Ultimate Gift Cards For WooCommer=
ce Unauthenticated Broken Access Control in Ultimate Gift Cards For WooComm= erce <=3D 3.2.9 versions. 2026-09-02 5.3 CVE-2026-84760 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-84760 ] wpbakery--WPBakery Page Builder The WPBa= kery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site S= cripting via the 'data' parameter in all versions up to, and including, 8.7=
.4 due to insufficient input sanitization and output escaping. This makes i=
t possible for authenticated attackers, with subscriber-level access and ab= ove, to inject arbitrary web scripts in pages that will execute whenever a = user accesses an injected page. The wp_kses_post sanitization applied durin=
g save does not neutralize the payload because the malicious script content=
is base64-encoded as plain alphanumeric text with no HTML tags to strip; t=
he vc_raw_html shortcode template then decodes and echoes this content unes= caped at render time. 2026-09-01 6.4 CVE-2026-15101 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-15101 ] wpdevteam--BetterDocs AI Documentation, Know= ledge Base, MCP Server, Docs, Wikis, FAQ & Chatbot The BetterDocs - AI Docu= mentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPre=
ss is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute =
in Post Content in all versions up to, and including, 4.8.1 due to insuffic= ient input sanitization and output escaping. This makes it possible for aut= henticated attackers, with contributor-level access and above, to inject ar= bitrary web scripts in pages that will execute whenever a user accesses an = injected page. The exploit survives wp_kses_post because entity-encoded quo= tes in a heading id attribute are treated as a single legitimate attribute = value at save time; the dangerous payload only materialises after process_c= ontent_for_toc() calls html_entity_decode() on the stored content and the b= roken id is extracted by a lazy regex before being echoed unescaped into th=
e Table of Contents output. 2026-09-01 6.4 CVE-2026-75980 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-75980 ] WPExperts--Post SMTP Missing Authoriza= tion vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Con= figured Access Control Security Levels. This issue affects Post SMTP: from = 4.0.0 through beta.1. 2026-08-31 5.4 CVE-2026-81278 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-81278 ] WPFunnels--Mail Mint Unauthenticated Broken = Access Control in Mail Mint <=3D 1.31.0 versions. 2026-09-03 6.5 CVE-2026-8= 4755 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84755 ] WPFunnels--WPFun= nels Unauthenticated Broken Access Control in WPFunnels <=3D 3.12.13 versio= ns. 2026-09-03 6.5 CVE-2026-84754 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-84754 ] WPFunnels--WPFunnels The WPFunnels WordPress plugin before 3.1= 3.0 does not check whether user registration is enabled on the site before = creating accounts from opt-in form submissions, relying on a value supplied=
in the request instead, allowing unauthenticated attackers to create WordP= ress user accounts even when registration is disabled. This is an incomplet=
e fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the t= hree registration paths. 2026-09-04 5.3 CVE-2025-15691 [
https://www.cve.or= g/CVERecord?id=3DCVE-2025-15691 ] WPFunnels--WPFunnels The WPFunnels WordPr= ess plugin before 3.13.0 does not verify that the product requested through=
a checkout order bump is the product that bump's discount was configured f= or, allowing unauthenticated users to obtain any purchasable product at a d= iscount intended for a different one, with the reduced price carried throug=
h to the total of the order they place. 2026-09-04 5.3 CVE-2026-79630 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-79630 ] WPFunnels--WPFunnels The W= PFunnels WordPress plugin before 3.13.0 does not restrict access to the log=
files it writes to a predictable location under the public uploads directo= ry, allowing unauthenticated users to download customer order details and o= pt-in form submissions when logging is enabled. 2026-09-04 5.3 CVE-2026-796=
31 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79631 ] WPFunnels--WPFunne=
ls The WPFunnels WordPress plugin before 3.13.0 does not perform any author= isation or nonce check in one of its opt-in submission handlers, and takes = the notification recipients and subject from the request, allowing unauthen= ticated users to make the site send emails to arbitrary recipients with an = arbitrary subject. 2026-09-04 5.3 CVE-2026-79632 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-79632 ] WPGMaps--WP Go Maps Unauthenticated Denial of S= ervice Attack in WP Go Maps <=3D 10.1.08 versions. 2026-09-02 5.3 CVE-2026-= 84780 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84780 ] wpinsider-1--Si= mple Membership The Simple Membership plugin for WordPress is vulnerable to=
Authentication Bypass leading to Administrator Account Takeover in version=
s up to, and including, 4.8.0. This is due to improper identity verificatio=
n during the public registration flow in WordPress Multisite environments, = where the plugin binds new Simple Membership records to existing global Wor= dPress users based solely on matching username and email, without requiring=
password verification or ownership proof, and fails to properly detect Adm= inistrator roles on child sites. This makes it possible for unauthenticated=
attackers to take over Administrator accounts on child sites in a Multisit=
e network by registering a Simple Membership account with a victim's creden= tials on a site where public registration is enabled, then updating the vic= tim's global WordPress password through the profile edit functionality. The=
vulnerability was partially patched in version 4.8.1. 2026-09-01 5.3 CVE-2= 026-77194 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77194 ] WPKoi WordP= ress Themes--WPKoi Templates for Elementor Improper Neutralization of Input=
During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi=
WordPress Themes WPKoi Templates for Elementor allows DOM-Based XSS. This = issue affects WPKoi Templates for Elementor: from n/a through 3.7.2. 2026-0= 9-03 6.5 CVE-2026-85302 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85302=
] WPLP Cookie Consent--WPLP Cookie Consent The WPLP Cookie Consent WordPre=
ss plugin before 4.4.2 does not properly validate a pagination parameter be= fore using it in a SQL query, allowing users with administrator privileges =
to perform SQL injection attacks. 2026-09-04 4.1 CVE-2026-82186 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-82186 ] WPMU DEV--Broken Link Checker Ed= itor Server Side Request Forgery (SSRF) in Broken Link Checker <=3D 2.4.14 = versions. 2026-09-02 5.5 CVE-2026-84772 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84772 ] WPvivid Backup, Migration & Staging--WPvivid Backup, Mi= gration & Staging The WPvivid - Backup, Migration & Staging WordPress plugi=
n before 0.9.134 does not validate a user supplied file name before using i=
t to build a write path, allowing administrators to write files of permitte=
d types to arbitrary locations on the server and to overwrite existing file=
s. 2026-09-04 5.5 CVE-2026-82193 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-82193 ] WPvivid Backup, Migration & Staging--WPvivid Backup, Migration =
& Staging The WPvivid - Backup, Migration & Staging WordPress plugin before=
0.9.134 does not validate a user supplied path before using it in a file d= eletion routine, allowing administrators to delete arbitrary files on the s= erver, including files outside the web root. 2026-09-04 5.5 CVE-2026-82194 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82194 ] WPvivid Backup, Migra= tion & Staging--WPvivid Backup, Migration & Staging The WPvivid - Backup, M= igration & Staging WordPress plugin before 0.9.133 does not sanitise a user=
supplied list of identifiers before using it in a SQL query, allowing admi= nistrators to perform SQL injection attacks. 2026-09-02 4.1 CVE-2026-82182 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-82182 ] WSO2--WSO2 API Manage=
r The API Publisher component previously used a non-cryptographic pseudoran= dom number generator (PRNG) to create shared secrets for Webhook HMAC valid= ation. This PRNG lacks sufficient entropy for security-sensitive operations=
, allowing a sophisticated attacker to predict future secrets. This enables=
malicious actors to forge event payloads with valid HMAC signatures, bypas= sing the API Gateway's authenticity verification. Successful exploitation c= ould allow an attacker to predict shared secrets used for Webhook HMAC vali= dation and forge event payloads with valid signatures. This may enable bypa= ssing API Gateway authenticity checks, leading to unauthorized event inject= ion, data manipulation, or downstream system compromise. 2026-09-03 5.9 CVE= -2026-3416 [
https://www.cve.org/CVERecord?id=3DCVE-2026-3416 ] WWBN --AVid= eo=C2=A0
=C2=A0 WWBN AVideo generates passwords for external-login accounts using ra= nd() instead of a cryptographic generator, producing only 31-bit integers. = Attackers with access to password hashes can recover plaintext passwords in=
minutes through offline brute-force attacks due to unsalted MD5-based hash= ing. 2026-09-05 5.9 CVE-2026-86187 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-86187 ] WWBN--AVideo AVideo through commit c91b5975d contains a cross= -site request forgery vulnerability in plugin/Live/saveLive.php that lacks = forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft m= alicious image tags to overwrite authenticated streamers' RTMP keys, passwo= rds, and titles, hijacking live broadcasts. 2026-09-03 6.5 CVE-2026-85162 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85162 ] WWBN--AVideo AVideo th= rough commit c91b5975d contains a server-side request forgery vulnerability=
in the EPG parser that allows authenticated uploaders to fetch arbitrary i= nternal URLs. An attacker can supply an internal URL via the epg_link param= eter during video upload, which is validated only for syntax and later fetc= hed server-side during EPG generation without SSRF protection checks. 2026-= 09-03 6.5 CVE-2026-85163 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8516=
3 ] WWBN--AVideo AVideo Live_schedule::setTitle() and setDescription() stor=
e POST input without sanitization, allowing users with streaming permission=
to inject malicious scripts. Unauthenticated attackers can access remindMe= .php to execute stored XSS payloads in victim browsers without requiring au= thentication. 2026-09-01 5.4 CVE-2026-84477 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-84477 ] WWBN--AVideo WWBN AVideo through commit 9c39d8c8 con= tains an incomplete authentication bypass in encryptPass.json.php that allo=
ws unauthenticated attackers to compute valid HMAC tokens using the public = site URL and current time. Attackers can forge authentication tokens by com= puting hash_hmac with the site's base URL as the key and submit arbitrary p= asswords to receive encrypted hashes, enabling offline precomputation attac=
ks against stolen password databases. 2026-09-01 5.3 CVE-2026-84483 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-84483 ] WWBN--AVideo WWBN AVideo fai=
ls to properly validate access controls on the public channel page, allowin=
g unauthenticated visitors to view unlisted and group-restricted videos thr= ough hardcoded visibility flags and an undefined property. Attackers can ac= cess the channel endpoint to retrieve sensitive video content that should b=
e hidden, including full URLs to unlisted videos and thumbnails of member-o= nly content, regardless of the operator's hidePrivateVideos setting. 2026-0= 9-03 5.3 CVE-2026-85156 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85156=
] WWBN--AVideo WWBN AVideo contains a broken access control vulnerability =
in the unauthenticated feed/index.php endpoint that disables per-video visi= bility checks when a program_id parameter is supplied. Attackers can enumer= ate playlist identifiers and retrieve unlisted and group-restricted videos =
by requesting the RSS feed with any visible playlist id, including empty pl= aylists that return the entire site's hidden video catalogue. 2026-09-03 5.=
3 CVE-2026-85157 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85157 ] WWBN= --AVideo AVideo through commit c91b5975d contains a reflected cross-site sc= ripting vulnerability in videoEmbeded.php that echoes the link parameter in= side an HTML comment with zero escaping. Attackers can close the comment wi=
th --> and inject arbitrary JavaScript that executes when victims visit the=
crafted embed URL. 2026-09-03 5.4 CVE-2026-85158 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-85158 ] WWBN--AVideo AVideo through commit c91b5975d c= ontains a reflected cross-site scripting vulnerability in userLogin.php whe=
re the cancelUri parameter is echoed in an href attribute after isSafeRedir= ectURL checks protocol only, not HTML characters. Unauthenticated attackers=
can inject event handlers via relative URLs with embedded quotes to execut=
e arbitrary JavaScript when users interact with the Cancel button. 2026-09-=
03 5.4 CVE-2026-85159 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85159 ]=
WWBN--AVideo AVideo through commit c91b5975d contains a reflected cross-si=
te scripting vulnerability in userLogin.php that allows unauthenticated att= ackers to inject arbitrary JavaScript by closing the script tag with </scri= pt>. Attackers can craft a malicious URL with an error parameter containing=
script breakout sequences to execute arbitrary JavaScript in the victim's = browser context on the login page. 2026-09-04 5.4 CVE-2026-85577 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-85577 ] WWBN--AVideo AVideo through com= mit c91b5975d contains a cross-site request forgery vulnerability in remove= Poster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attac= kers can craft malicious image tags to delete authenticated victims' live p= oster and thumbnail files via GET requests. 2026-09-03 4.3 CVE-2026-85161 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85161 ] xibosignage--xibo-cms = Xibo is an open source digital signage platform with a web content manageme=
nt system and Windows display player software. Prior to 4.4.3, missing Auth= orization in Module::settingsForm allows to view (not change) super admin-r= estricted module settings and leak the full module entity. Exploitation of = the vulnerability is possible on behalf of an authorized user who has acces=
s to the Module View feature, which are not granted to non-admins as standa= rd. Users should upgrade to version 4.4.3 which fixes this issue. Upgrading=
to a fixed version is necessary to remediate. Users unable to upgrade shou=
ld revoke such privileges from users they do not trust. 2026-08-31 4.3 CVE-= 2026-52730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52730 ] Xinhu--Rai= nrock RockOA A weakness has been identified in Xinhu Rainrock RockOA up to = 2.7.6. Affected by this issue is the function getOrder of the file webmain/= webmainAction.php. Executing a manipulation of the argument highorder can l= ead to sql injection. The attack can be launched remotely. The exploit has = been made available to the public and could be used for attacks. The vendor=
was contacted early about this disclosure but did not respond in any way. = 2026-09-01 6.3 CVE-2026-84109 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84109 ] Xinhu--Rainrock RockOA A vulnerability was determined in Xinhu Rai= nrock RockOA up to 2.3.2. The impacted element is the function toaddval of = the file /index.php?m=3Dindex&a=3Dpublicsavevalue&ajaxbool=3Dtrue. Executin=
g a manipulation of the argument Value can lead to sql injection. The attac=
k may be performed from remote. The exploit has been publicly disclosed and=
may be utilized. The vendor was contacted early about this disclosure but = did not respond in any way. 2026-09-01 6.3 CVE-2026-84153 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84153 ] Xpro Addons 140+ Widgets for Elementor= --Xpro Addons 140+ Widgets for Elementor The Xpro Addons - 140+ Widgets for=
Elementor WordPress plugin before 1.7.8 does not perform any capability or=
post-status check before rendering a WooCommerce product summary from a su= pplied product identifier, allowing unauthenticated visitors to retrieve th=
e title, price, SKU, description and stock details of products that are not=
publicly published (draft, pending, private or scheduled status). 2026-09-=
04 5.3 CVE-2026-84146 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84146 ]=
Xpro Addons--Xpro Addons The Xpro Addons WordPress plugin before 1.7.4 doe=
s not properly escape some of its widgets' settings before outputting them = within HTML attributes, which could allow users with the Contributor role a=
nd above to perform Stored Cross-Site Scripting attacks. 2026-09-02 6.8 CVE= -2026-83547 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83547 ] Xtemos--W= oodMart Improper Neutralization of Input During Web Page Generation ('Cross= -site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. Th=
is issue affects WoodMart: from n/a before 8.3.8. 2026-09-04 6.5 CVE-2026-2= 7086 [
https://www.cve.org/CVERecord?id=3DCVE-2026-27086 ] XueZhiSi--Open S= ource Exam System XueZhiSi Open Source Exam System <=3D 3.9.0 has a privile=
ge escalation vulnerability in the teacher-end interface POST /api/teacher/= user/page/list. The role parameter in UserPageRequestVM is fully controllab=
le by the requester. 2026-08-31 6.5 CVE-2026-75460 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-75460 ] yaojingang--GEOFlow A security vulnerability = has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknow=
n part of the file app/Http/Controllers/Site/HomeController.php of the comp= onent JSON-LD Theme Handler. The manipulation of the argument Search leads =
to cross site scripting. The attack is possible to be carried out remotely.=
The exploit has been disclosed publicly and may be used. Upgrading to vers= ion 2.1.1 is able to mitigate this issue. The identifier of the patch is 67= abfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is=
recommended. 2026-08-31 4.3 CVE-2026-82664 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-82664 ] yaojingang--GEOFlow A flaw has been found in yaojing= ang GEOFlow up to 2.1.0. This issue affects the function preview of the fil=
e app/Http/Controllers/Admin/SiteThemeEditorController.php of the component=
Superadmin Theme Editor. This manipulation of the argument blade causes co=
de injection. It is possible to initiate the attack remotely. The exploit h=
as been published and may be used. Upgrading to version 2.1.1 is capable of=
addressing this issue. Patch name: 67abfd864a15d169a78429f3290c91cb3b93e84=
9. Upgrading the affected component is advised. 2026-08-31 4.7 CVE-2026-826=
66 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82666 ] yaojingang--GEOFlo=
w A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impacte=
d is the function DistributionController.isValidHttpEndpoint of the file ap= p/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of th=
e argument endpoint_url leads to server-side request forgery. It is possibl=
e to launch the attack remotely. The exploit has been disclosed to the publ=
ic and may be used. Upgrading to version 2.1.1 is recommended to address th=
is issue. The name of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849=
. It is advisable to upgrade the affected component. 2026-08-31 4.7 CVE-202= 6-82667 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82667 ] YesWiki -- Ye= sWiki
=C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Baz=
ar form-field templates still apply |raw('html') to field.label / field.hin=
t in attribute and label-body contexts, resulting stored XSS in form render=
s. This issue has been patched in version 4.6.6. 2026-09-05 5.5 CVE-2026-52= 772 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52772 ] YesWiki--YesWiki = YesWiki is a wiki system written in PHP. From version 4.1.0 to before versi=
on 4.6.6, YesWiki's archived-revision view reflects the time GET parameter = into a hidden HTML input in handlers/page/show.php without escaping. Becaus=
e MySQL coerces malformed DATETIME strings, an attacker can append HTML or = JavaScript to a valid archived revision timestamp, still load that archived=
revision, and execute arbitrary JavaScript in the victim's browser. The vu= lnerable form is only rendered when the victim can both read and edit the t= arget page. In restricted deployments this requires a victim with read and = write access to that page. On a default doryphore 4.6.5 install, public pag=
es such as PagePrincipale were editable anonymously during validation, so t=
he issue can also affect unauthenticated visitors in that configuration. Th=
is issue has been patched in version 4.6.6. 2026-09-05 6.1 CVE-2026-52773 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-52773 ] YesWiki--YesWiki YesWi=
ki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar=
widget handler reflects the id GET parameter into HTML attributes using st= rip_tags() only. Because strip_tags() does not escape double quotes, an att= acker can break out of the attribute value, inject an event handler such as=
onmouseover, and execute arbitrary JavaScript in the victim's browser. Thi=
s issue is reachable without authentication. During validation, the vulnera= ble widget route returned the injected HTML for both /HomePage/widget?id=3D= ... and /NoSuchPage/widget?id=3D..., which shows that no login, no page own= ership, no edit rights, and not even a valid page tag were required. The on=
ly routing prerequisite observed was that the Bazar extension is enabled an=
d the request includes an id parameter. This issue has been patched in vers= ion 4.6.6. 2026-09-05 6.1 CVE-2026-52774 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-52774 ] YesWiki--YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the=
recentchanges action (actions/recentchanges.php) accepts a period argument=
from two disjoint parameter spaces. A whitelist validates only the URL for=
m against ['day','week','month']. The action-argument form takes the else b= ranch with no validation, and the value flows into PageManager::getRecently= Changed(), where it is interpolated into a WHERE time >=3D '...' ORDER BY t= ime DESC clause without escaping or parameterization. UNION-based injection=
succeeds, the leaked rows render into the response page, so any visitor of=
the trigger page sees the exfiltrated data. The vulnerability provides arb= itrary read of the YesWiki database to anyone who can save the trigger page=
. On a default install (default_write_acl=3D'*'), this includes anonymous u= sers, subject to the hashcash JS check on the page-edit form. Once the trig= ger page is saved, every subsequent view fires the injection as the SQLi is=
stored. Stored SQL injection is reachable through the page-edit flow, with=
arbitrary database read. This issue has been patched in version 4.6.6. 202= 6-09-05 6.5 CVE-2026-52763 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52= 763 ] Yoast SEO Premium--Yoast SEO Premium The Yoast SEO Premium WordPress = plugin before 27.6.1 does not sanitize control characters from redirect ori= gins before writing them to the site's Apache configuration file when the f= ile-based redirect mode is enabled, and the redirect-creation endpoint is r= eachable by users with only Author-level access. This allows such users to = inject arbitrary newline-delimited Apache directives into the root .htacces=
s file. On Apache servers that honour PHP directives, the injection can be = chained with the user's own media upload (a polyglot image carrying a PHP p= ayload) and an auto_prepend_file directive to achieve Remote Code Execution=
. 2026-09-02 6.6 CVE-2026-10821 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-10821 ] Yordam Information Technology Consulting, Training and Electroni=
c Systems Industry and Trade Inc.--Library Information and Document Automat= ion Program Improper neutralization of input during web page generation ('c= ross-site scripting') vulnerability in Yordam Information Technology Consul= ting, Training and Electronic Systems Industry and Trade Inc. Library Infor= mation and Document Automation Program allows XSS Targeting HTML Attributes=
. This issue affects Library Information and Document Automation Program: b= efore v22.2. 2026-09-04 6.1 CVE-2026-19727 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-19727 ] Yordam Information Technology Consulting, Training an=
d Electronic Systems Industry and Trade Inc.--Library Information and Docum= ent Automation Program Improper neutralization of input during web page gen= eration ('cross-site scripting') vulnerability in Yordam Information Techno= logy Consulting, Training and Electronic Systems Industry and Trade Inc. Li= brary Information and Document Automation Program allows Content Spoofing. = This issue affects Library Information and Document Automation Program: fro=
m v22.1 before v22.2. 2026-09-04 6.1 CVE-2026-77818 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-77818 ] zephyrproject--zephyr The Silicon Labs SiWx9=
17 WiFi driver's transmit callback siwx91x_send() in drivers/wifi/siwx91x/s= iwx91x_wifi.c frees a network packet it does not own. In the Zephyr TX path=
the net_pkt is owned by the L2/networking stack; the driver only borrows i=
t to copy the frame bytes into a local net_buf. Before the fix, after trans= mitting, siwx91x_send() additionally called net_pkt_unref(pkt) on the calle= r-owned packet, dropping its last reference and returning it to the shared = packet pool prematurely. This code path is compiled in by default (CONFIG_W= IFI_SILABS_SIWX91X_NET_STACK_NATIVE). The caller, ethernet_send() in subsys= /net/l2/ethernet/ethernet.c, keeps using the packet after the driver return=
s: it reads net_pkt_get_len(pkt), updates TX statistics, and then performs = its own net_pkt_unref(pkt). Because the driver already released the packet,=
these are use-after-free reads followed by a second unref (a double free).=
When concurrent network activity recycles the freed slab slot between the = two unrefs, the trailing unref decrements a different, live packet's refere= nce count and frees it, corrupting the net_pkt pool shared by both the rece= ive and transmit paths. The defect is exercised by ordinary transmission ov=
er the native-stack SiWx917 WiFi interface, and an adjacent attacker on the=
same WiFi network can induce transmissions (for example ARP or ICMP echo r= eplies, or TCP handshakes) to drive the path. The primary observable impact=
is loss of availability (transmit hangs and crashes from pool corruption),=
with race-dependent memory corruption of the kernel networking buffer pool=
. The fix removes the erroneous net_pkt_unref(pkt) from siwx91x_send(); the=
driver's receive-path unref, which correctly frees a packet the driver its= elf allocated, is unaffected. 2026-08-31 6.4 CVE-2026-14366 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-14366 ] zephyrproject--zephyr When Ethernet = bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process(=
) in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame re= ceived on a bridge member interface is handled. For frames that must also b=
e delivered to the local stack, the code called eth_bridge_handle_locally()=
and returned NET_OK. That helper does not consume the packet - it only cal=
ls bridge_iface_recv() (via virtual_recv()), which returns NET_CONTINUE wit= hout taking ownership of pkt. The NET_OK verdict then propagates through et= hernet_recv() up to processing_data() in subsys/net/ip/net_core.c, where NE= T_OK is interpreted as "the packet was consumed, do not free it." Because n=
o consumer actually took ownership, the RX net_pkt is never returned to the=
pool and is leaked. The concretely reproducible leak occurs for frames who=
se EtherType has no registered L3 handler when CONFIG_NET_ETHERNET_FORWARD_= UNRECOGNISED_ETHERTYPE is set (default y when CONFIG_NET_SOCKETS_PACKET is = enabled): the fall-through L3 dispatch does not overwrite the NET_OK verdic=
t, so ethernet_recv() returns NET_OK and the buffer is never released. Any = device on a bridged L2 segment can emit broadcast/multicast frames carrying=
an arbitrary EtherType with no authentication. Each such frame permanently=
consumes one buffer from the finite RX pool (CONFIG_NET_PKT_RX_COUNT), so =
a brief broadcast flood exhausts the pool and the device can no longer rece= ive traffic until it is rebooted - a persistent denial of service. There is=
no confidentiality or integrity impact. The fix makes eth_bridge_handle_lo= cally() propagate the real net_verdict and return NET_CONTINUE for locally-= kept frames, writing the bridge interface back through a new dst_iface out-= parameter so the packet follows the normal receive path and is unreferenced=
exactly once. 2026-08-31 6.5 CVE-2026-14696 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-14696 ] zephyrproject--zephyr net_ipv6_send_ns() in subsys/= net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation.=
When it is called with a data packet pending on an unresolved neighbor and=
that neighbor's pending_queue is already non-empty (an NS is already outst= anding), the function appends the data packet and returns early without eve=
r sending the NS via net_send_data() or releasing it with net_pkt_unref(). = The freshly allocated NS net_pkt and its attached TX buffers are held only =
by a local variable and are leaked permanently, never returning to CONFIG_N= ET_PKT_TX_COUNT / CONFIG_NET_BUF_TX_COUNT. The leaking branch sits on the n= ormal IPv6 transmit path: net_ipv6_prepare_for_send() (called from net_if.c=
) invokes net_ipv6_send_ns() for any outbound or forwarded IPv6 packet whos=
e next hop is not yet in the neighbor cache. An on-link (adjacent) attacker=
can drive it deterministically by sending a burst of request packets (for = example ICMPv6 echo requests or UDP datagrams) that all spoof a single non-= existent on-link source address: the node generates a reply to each, the fi= rst reply queues an NS, and every subsequent reply during the roughly three= -second INCOMPLETE resolution window takes the leaking branch and loses one=
TX packet. Router-configured nodes forwarding attacker traffic toward a no= n-existent on-link host leak identically. Because the leaked packets are ne= ver reclaimed and CONFIG_NET_PKT_TX_COUNT defaults to only 4 (14 for Ethern= et), a brief low-rate burst exhausts the TX pool. Once exhausted the node c=
an no longer allocate any transmit packet and cannot send TCP/UDP, ARP/ND, =
or any reply at all, producing a complete and persistent network denial of = service that does not self-heal until reboot. The fix releases the unsent N=
S packet with net_pkt_unref(pkt) before the early return. 2026-08-31 6.5 CV= E-2026-14697 [
https://www.cve.org/CVERecord?id=3DCVE-2026-14697 ] zephyrpr= oject--zephyr The LwM2M JSON content formatter's get_string() in subsys/net= /lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-suppli=
ed buffer and NUL-terminates it. The length guard used if (string_length > = buflen), which accepts a string whose length is exactly buflen. After memcp= y() fills the whole buffer, buf[string_length] =3D ' ' then writes one byte=
past the end of the buffer (CWE-787). The string value and its length are = taken directly from the incoming CoAP payload during a LwM2M WRITE: do_writ= e_op_json() parses the payload obtained from coap_packet_get_payload(), and=
get_string() is invoked from lwm2m_write_handler() (engine_get_string() in=
subsys/net/lib/lwm2m/lwm2m_message_handling.c) for a LWM2M_RES_TYPE_STRING=
resource. The destination buf/buflen is either the resource instance's fix=
ed data buffer (res_inst->data_ptr/max_data_len) or the engine validation b= uffer (msg->ctx->validate_buf). A LwM2M server (the client's DTLS peer) can=
therefore write a string resource with a value whose length equals the tar= get buffer size and force a one-byte overflow. The overflow is a single out= -of-bounds write of the constant byte 0x00 immediately past the resource or=
validation buffer, corrupting the adjacent byte in memory. It is not an in= formation leak and the written value is fixed, so it is not a direct code-e= xecution primitive, but it can corrupt adjacent state (an adjacent resource=
value, a length/flag field, or a struct field) and cause data corruption o=
r a crash. Triggering the write is deterministic; the resulting impact depe= nds on memory layout. The fix changes the guard to string_length >=3D bufle=
n, rejecting the exact-length case and aligning the JSON formatter with the=
other content formatters (lwm2m_rw_plain_text.c, lwm2m_rw_oma_tlv.c, lwm2m= _rw_senml_json.c, lwm2m_rw_cbor.c, lwm2m_rw_senml_cbor.c), which already us=
ed the correct boundary check. 2026-08-31 5.4 CVE-2026-14368 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-14368 ] zhayujie--CowAgent A vulnerability = was found in zhayujie CowAgent up to 2.1.3. This impacts the function Brows= erTool of the file agent/tools/browser/browser_tool.py of the component Bro= wser Tool. Performing a manipulation results in denial of service. The atta=
ck can be initiated remotely. The exploit has been made public and could be=
used. The vendor was contacted early about this disclosure but did not res= pond in any way. 2026-09-02 4.3 CVE-2026-84425 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-84425 ] zhayujie--CowAgent A vulnerability was determined=
in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the f= ile agent/tools/bash/bash.py of the component Bash Tool. Executing a manipu= lation can lead to denial of service. The attack can be launched remotely. = The exploit has been publicly disclosed and may be utilized. The vendor was=
contacted early about this disclosure but did not respond in any way. 2026= -09-02 4.3 CVE-2026-84427 [
https://www.cve.org/CVERecord?id=3DCVE-2026-844=
27 ] ZhongBangKeJi--CRMEB A weakness has been identified in ZhongBangKeJi C= RMEB up to 6.0.0. Affected by this vulnerability is the function eval of th=
e file /adminapi/system/crontab/save of the component Custom Scheduled Task=
Feature. This manipulation of the argument customCode causes os command in= jection. It is possible to initiate the attack remotely. The exploit has be=
en made available to the public and could be used for attacks. Vendor docum= ents this as deliberate debug-only behavior. But isSafePhpCode blacklist of= fers no real RCE containment. 2026-09-03 4.7 CVE-2026-85040 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85040 ] zhongyu09--OpenChatBI A security fla=
w has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this=
vulnerability is the function _validate_sql_safety of the file openchatbi/= text2sql/generate_sql.py. Performing a manipulation results in sql injectio=
n. The attack can be initiated remotely. Versions v0.2.0 through v0.2.2 hav=
e no SQL safety validation at all, while v0.3.0 introduced a validator and = v1.0.0b1/main kept the same incomplete one with an optional stricter mode. = The vendor was contacted early about this disclosure but did not respond in=
any way. 2026-09-01 6.3 CVE-2026-84061 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84061 ] =C2=A0JeecgBoot-- JeecgBoot
=C2=A0 A security vulnerability has been detected in JeecgBoot up to 3.9.3.=
This vulnerability affects the function exportXls of the file jeecg-boot/j= eecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/ai= rag/llm/controller/AiragModelController.java. Such manipulation of the argu= ment credential leads to improper access controls. It is possible to launch=
the attack remotely. The exploit has been disclosed publicly and may be us= ed. Upgrading to version 3.9.5 is able to resolve this issue. The name of t=
he patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade th=
e affected component. 2026-09-06 4.3 CVE-2026-86228 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-86228 ] =C2=A0jofpin-- trape A security vulnerabilit=
y has been detected in jofpin trape 2.0. This vulnerability affects unknown=
code of the file core/user.py of the component Telemetry Endpoint. Such ma= nipulation of the argument vId leads to race condition. The attack can be e= xecuted remotely. Attacks of this nature are highly complex. It is stated t= hat the exploitability is difficult. The exploit has been disclosed publicl=
y and may be used. The project was informed of the problem early through an=
issue report but has not responded yet. 2026-09-04 5.6 CVE-2026-85639 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-85639 ] =C2=A0jofpin-- trape
=C2=A0 A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affec= ted by this issue is the function join_room of the file core/sockets.py of = the component Admin Endpoint. The manipulation results in missing authentic= ation. The attack may be launched remotely. The exploit has been released t=
o the public and may be used for attacks. The project was informed of the p= roblem early through an issue report but has not responded yet. 2026-09-04 = 5.3 CVE-2026-85637 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85637 ]=20
Back to top [ #top ]
Low Vulnerabilities
Primary
Vendor -- Product Description Published CVSS Score Source Info AMD--AMD Rad= eon PRO V620 Graphics Products A malicious virtual function can invoke the = certain command handlers in the SMU, causing a denial of service due to out= -of-bounds memory read. 2026-08-31 3.3 CVE-2023-31308 [
https://www.cve.org= /CVERecord?id=3DCVE-2023-31308 ] arubanetworks -- fabric_composer A vulnera= bility in the web-based management interface of HPE Networking Fabric Compo= ser could allow an unauthenticated remote attacker to gain insight into som=
e data handled by the affected interface. A successful exploit could allow =
an attacker to gain access to some data in a cleartext format possibly expo= sing other network infrastructure to further compromise. 2026-09-01 3.7 CVE= -2026-73743 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73743 ] arubanetw= orks -- fabric_composer A denial-of-service vulnerability exists in the web= -based management interface of HPE Networking Fabric Composer that could al= low an authenticated low privilege operator user to cause a denial of servi= ce. Successful exploitation could allow an attacker to disrupt the availabi= lity of the affected interface. 2026-09-01 3.5 CVE-2026-73744 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-73744 ] arubanetworks -- fabric_composer A=
vulnerability in the API endpoint of HPE Networking Fabric Composer could = allow an unauthenticated remote attacker to view some information handled b=
y the affected system. Successful exploitation could allow an attacker to g= ain insight into internal services and workflows, increasing the risk of un= authorized access when combined with other vulnerabilities. 2026-09-01 3.1 = CVE-2026-73745 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73745 ] aruban= etworks -- fabric_composer A denial-of-service vulnerability exists in the = API of HPE Networking Fabric Composer that could allow an authenticated low=
privilege operator user to cause a denial of service. Successful exploitat= ion could allow an attacker to interrupt the normal operation of the affect=
ed service. 2026-09-01 3.1 CVE-2026-73746 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-73746 ] arubanetworks -- fabric_composer A local privilege-esc= alation vulnerability has been discovered in HPE Networking Fabric Composer=
. Successful exploitation could allow an authenticated low privilege operat=
or user with local access to elevate their user privileges and make limited=
modifications on the affected system. 2026-09-01 2.5 CVE-2026-73747 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-73747 ] arubanetworks -- fabric_com= poser A vulnerability in the affected interface of HPE Networking Fabric Co= mposer allows an attacker with administrative privileges to access sensitiv=
e information in a cleartext format. A successful exploit allows an attacke=
r to retrieve information which could be used to potentially gain further a= ccess to network services supported by HPE Networking Fabric Composer. 2026= -09-01 2.2 CVE-2026-73748 [
https://www.cve.org/CVERecord?id=3DCVE-2026-737=
48 ] code-projects--Employee Leave Managing System A security vulnerability=
has been detected in code-projects Employee Leave Managing System 1.0. Aff= ected is an unknown function of the file /EmpManageSys/editaction.php of th=
e component Employee Profile Update. The manipulation of the argument Name = leads to cross site scripting. The attack can be initiated remotely. The ex= ploit has been disclosed publicly and may be used. 2026-08-31 3.5 CVE-2026-= 82622 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82622 ] code-projects--= Task Management System 1.0
=C2=A0 A vulnerability was found in code-projects Task Management System 1.=
0. Affected by this issue is some unknown functionality of the file /user/U= pdateUserProfile.php of the component User Profile Update. The manipulation=
of the argument lname results in cross site scripting. The attack can be l= aunched remotely. The exploit has been made public and could be used. 2026-= 09-06 3.5 CVE-2026-86181 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8618=
1 ] Directorist: AI-Powered Business Directory, Listings & Classified Ads--= Directorist: AI-Powered Business Directory, Listings & Classified Ads The D= irectorist: AI-Powered Business Directory, Listings & Classified Ads WordPr= ess plugin before 8.9 does not verify that the requesting user owns the pos=
t being modified before writing uploaded file references to its metadata, a= llowing users with the subscriber role and above to overwrite image metadat=
a on posts belonging to other users. 2026-09-04 3.1 CVE-2026-84066 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-84066 ] Drupal--CAPTCHA Protected Pag=
e Authentication Bypass Using an Alternate Path or Channel vulnerability in=
Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue affe= cts CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2. 2026-09-02 3.7 CV= E-2026-81168 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81168 ] Drupal--= Commerce CyberSource Observable Timing Discrepancy vulnerability in Drupal = Commerce CyberSource allows Brute Force. This issue affects Commerce CyberS= ource versions: from 0.0.0 to 1.10.0. 2026-09-02 3.7 CVE-2026-81159 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-81159 ] Drupal--Content Moderation N= otifications Privilege Defined With Unsafe Actions vulnerability in Drupal = Content Moderation Notifications allows Privilege Escalation. This issue af= fects Content Moderation Notifications versions: from 0.0.0 to 3.9.0. 2026-= 09-02 3.3 CVE-2026-81161 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8116=
1 ] elastic -- elastic_cloud_on_kubernetes Incomplete Cleanup (CWE-459) in = Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privi= lege Abuse (CAPEC-122). Authentication credentials persist after a cross-na= mespace association has been denied by RBAC enforcement, allowing a low-pri= vileged tenant to retain unauthorized read access to the associated Elastic= search cluster. 2026-09-02 3.5 CVE-2026-78600 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-78600 ] elastic -- fleet_server Incorrect Authorization (C= WE-863) in Fleet Server can lead to a denial of service of agent upload ope= rations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly ve= rify session ownership during multi-part data upload operations, allowing a=
ny authenticated agent to interfere with the active upload sessions belongi=
ng to other enrolled agents. 2026-09-02 3.1 CVE-2026-78587 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-78587 ] Eleveo--Call Recording Software A fla=
w has been found in Eleveo Call Recording Software 9.7.0. This affects an u= nknown part of the file /callrec/roleAddAction.do. Executing a manipulation=
of the argument name/username can lead to cross site scripting. The attack=
may be launched remotely. The exploit has been published and may be used. = The vendor was contacted early about this disclosure but did not respond in=
any way. 2026-09-04 3.5 CVE-2026-85405 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85405 ] Eleveo--Quality Management A vulnerability has been fou=
nd in Eleveo Quality Management 9.7.0. This vulnerability affects unknown c= ode of the component Conversation Review. The manipulation leads to cross s= ite scripting. Remote exploitation of the attack is possible. The exploit h=
as been disclosed to the public and may be used. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-09-04 3.5 C= VE-2026-85406 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85406 ] ellite-= -Wallos Wallos is an open-source, self-hostable personal subscription track= er. Prior to version 5.0.0, Wallos lets any authenticated user store an arb= itrary SMTP host - including private and cloud-metadata IP addresses - in t= heir personal email notification settings, with no server-side SSRF validat= ion. When the scheduled notification cron job runs, it passes the stored ho=
st directly to PHPMailer, causing the Wallos server to open an outbound TCP=
connection to whatever address the attacker specified. This gives a low-pr= ivileged attacker a reliable mechanism to probe internal network services f= rom the server's perspective. This issue has been patched in version 5.0.0.=
2026-08-31 3.5 CVE-2026-77351 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-77351 ] extension.vn--2FA Authenticator Extension A weakness has been ide= ntified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The = impacted element is the function chrome.runtime.onMessageExternal.addListen=
er of the component Background Service Worker. Executing a manipulation of = the argument sender.id can lead to information disclosure. The attack requi= res local access. The exploit has been made available to the public and cou=
ld be used for attacks. The vendor was contacted early about this disclosur=
e. 2026-08-31 3.3 CVE-2026-82810 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-82810 ] F5--BIG-IP A vulnerability exists in an undisclosed BIG-IP Conf= iguration utility page that may allow an attacker to spoof error messages= =C2=A0 Impact: An attacker may trick authenticated BIG-IP users into access= ing malicious links and reflect a spoofed error message in the victim's BIG= -IP Configuration utility web browser session. This is a control plane issu=
e; there is no data plane exposure. Note: Software versions which have reac= hed End of Technical Support (EoTS) are not evaluated. 2026-09-02 3.1 CVE-2= 026-63020 [
https://www.cve.org/CVERecord?id=3DCVE-2026-63020 ] filamentphp= --filament Filament is a collection of full-stack components for accelerate=
d Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/s= rc/Auth/Pages/Login.php presents the multi-factor authentication challenge = before evaluating canAccessPanel(). For an account that canAccessPanel() de= nies, submitting the correct password renders the MFA challenge while an in= correct password returns the generic authentication failure, allowing an un= authenticated attacker to confirm whether a candidate password is valid for=
that account. When email-based MFA is configured, the correct-password pat=
h also sends a login code to the account holder. The issue applies only to = accounts that have MFA enabled and are denied panel access. Authentication =
is not bypassed because canAccessPanel() still runs after the challenge, an=
d no session is created. This issue is fixed in versions 4.12.5 and 5.7.5. = 2026-09-01 3.7 CVE-2026-84307 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -84307 ] google -- chrome Missing authorization in FileSystem in Google Chr= ome prior to 152.0.7977.75 allowed a remote attacker who had compromised th=
e renderer process to bypass web origin policy via a crafted HTML page. (Ch= romium security severity: Medium) 2026-09-02 3.1 CVE-2026-84328 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-84328 ] google -- chrome Incorrect autho= rization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote = attacker who had compromised the renderer process to bypass web origin poli=
cy via a crafted HTML page. (Chromium security severity: Low) 2026-09-02 3.=
1 CVE-2026-84331 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84331 ] goog=
le -- chrome Incorrect authorization in Navigation in Google Chrome prior t=
o 152.0.7977.75 allowed a remote attacker who had compromised the renderer = process to bypass web origin policy via a crafted HTML page. (Chromium secu= rity severity: Medium) 2026-09-02 3.1 CVE-2026-84355 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-84355 ] google -- chrome Information leak in Skia i=
n Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had co= mpromised the renderer process to leak cross-origin data via a crafted HTML=
page. (Chromium security severity: High) 2026-09-02 3.1 CVE-2026-84359 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-84359 ] Google--Chrome Out of bo= unds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed=
a remote attacker who had compromised the renderer process to read memory = outside the sandbox via a crafted HTML page. (Chromium security severity: H= igh) 2026-09-03 3.1 CVE-2026-85052 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-85052 ] GutenKit--GutenKit The GutenKit WordPress plugin before 2.5.1=
does not validate or escape style settings saved against a post before usi=
ng them to build the CSS it outputs on the front end, allowing users with t=
he Contributor role and above to inject arbitrary CSS into pages served to = other users and to anonymous visitors. JavaScript execution is not possible=
at that role, so the impact is limited to defacement, interface redressing=
and forcing external resources to load. 2026-09-02 3.5 CVE-2026-19698 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-19698 ] hapijs--joi joi is a sche=
ma description language and data validator for JavaScript. From 16.0.0 unti=
l 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementa= tion used by object().rename() permits a schema that renames keys with a re= gular-expression source and a Joi.expression() or Joi.x() target that inter= polates the pattern's own match data, combined with { multiple: true }, to = derive a target from an attacker-controlled input key. An attacker can send=
x-__proto__ with an object value, causing the target to render as __proto_=
_ and set the prototype of the object returned by validate() instead of cre= ating an own key. The global Object.prototype is not modified, so the effec=
t is confined to the object returned by that validation call. Static-string=
targets and schemas using the default { multiple: false } are not affected=
. This issue is fixed in versions 17.13.5 and 18.2.4. 2026-09-01 3.7 CVE-20= 26-84367 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84367 ] hapijs--joi = joi is a schema description language and data validator for JavaScript. Fro=
m 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and=
the successor joi package contain prototype pollution in lib/messages.js, = where exports.compile() and exports.merge() reuse inherited objects for att= acker-controlled language keys supplied through messages(), message(), pref= s({ messages }), Joi.extend({ messages }), or rule({ message }). A language=
key named __proto__ writes properties onto Object.prototype, and construct=
or writes to the Object function's static properties. A consuming applicati=
on that gates on the presence of an inherited property can take the wrong b= ranch for every inspected object. The flaw is not reachable from data that = joi validates and requires an application to feed untrusted input directly = into schema-construction configuration. This issue is fixed in joi versions=
17.13.6 and 18.2.5; no fixed @hapi/joi version is available. 2026-09-01 3.=
7 CVE-2026-84368 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84368 ] HCLS= oftware--Connections HCL Connections is vulnerable to an information disclo= sure vulnerability which could allow a user to obtain sensitive information=
they are not entitled to, caused by improper handling of request data they=
are not entitled to, caused by improper handling of request data. 2026-08-=
31 3.1 CVE-2026-21827 [
https://www.cve.org/CVERecord?id=3DCVE-2026-21827 ]=
HKUDS--AI-Trader A vulnerability has been found in HKUDS AI-Trader up to d= 03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element is an unknown=
function of the file service/server/routes_agent.py of the component selfR= egister API Endpoint. Such manipulation of the argument initial_balance lea=
ds to business logic errors. The attack may be launched remotely. This atta=
ck is characterized by high complexity. The exploitability is described as = difficult. The exploit has been disclosed to the public and may be used. Th=
is product operates on a rolling release basis, ensuring continuous deliver=
y. Consequently, there are no version details for either affected or update=
d releases. profit_percent_for_display() divides by INITIAL_CAPITAL + depos= ited, and challenge scoring's return_pct also normalises against the attack= er-inflated starting_cash. So an inflated initial_balance does not yield ar= tificial percent returns - it inflates the absolute cash/equity column only=
, which is a cosmetic/leaderboard-gaming concern in a simulated game. 2026-= 09-03 3.7 CVE-2026-85030 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8503=
0 ] hulumi--baseline @hulumi/baseline versions before 1.3.2 fail to fully d= etect CloudTrail selector tampering events, reducing audit logging configur= ation change coverage. Attackers can modify CloudTrail event selectors with= out complete detection, potentially evading audit trail monitoring. 2026-08= -31 3.3 CVE-2026-82863 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82863 =
] IBM--i IBM i 7.6, and 7.5 could allow a local authenticated attacker to o= btain information from a privileged file when using SSH. 2026-09-04 3.3 CVE= -2026-18858 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18858 ] Icegram E= xpress--Icegram Express The Icegram Express WordPress plugin before 5.8.6 d= oes not properly escape a list description setting before outputting it wit= hin an HTML attribute, which could allow users with the Administrator role = and above to perform Stored Cross-Site Scripting attacks. 2026-09-02 3.5 CV= E-2025-15692 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15692 ] IObit--U= nlocker A vulnerability has been found in IObit Unlocker 1.3.0.12. This vul= nerability affects the function ZwTerminateProcess in the library IObitUnlo= cker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation l= eads to improper privilege management. An attack has to be approached local= ly. The vendor was contacted early about this disclosure but did not respon=
d in any way. 2026-08-31 3.4 CVE-2026-82671 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-82671 ] itsourcecode--Online Medicine Delivery System A vuln= erability was identified in itsourcecode Online Medicine Delivery System 1.=
0. Impacted is an unknown function of the file /index.php?q=3Dorderdetails.=
Such manipulation of the argument location leads to cross site scripting. = The attack may be launched remotely. The exploit is publicly available and = might be used. 2026-09-03 3.5 CVE-2026-85207 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-85207 ] Jenkins Project--Jenkins Jenkins 2.421 through 2.57=
9 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not c= orrectly perform permission checks in the Appearance configuration page, al= lowing attackers with Overall/Manage permission to modify Appearance config= uration options they should not have access to. 2026-09-02 3.5 CVE-2026-846=
53 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84653 ] kyverno--kyverno K= yverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_= ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their=
TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 at= tack (CVE-2016-2183), which, over very long-lived TLS connections carrying = large volumes of traffic, could allow an attacker to recover small amounts =
of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0. 2026-09-01 3.=
7 CVE-2023-54356 [
https://www.cve.org/CVERecord?id=3DCVE-2023-54356 ] lang= genius--dify A vulnerability was identified in langgenius dify 1.13.0. Affe= cted by this vulnerability is the function router.replace of the file web/a= pp/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the=
component WebApp Sign-In. Such manipulation of the argument redirect_url l= eads to cross site scripting. The attack may be performed from remote. The = exploit is publicly available and might be used. The vendor was contacted e= arly about this disclosure but did not respond in any way. 2026-09-03 3.5 C= VE-2026-85022 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85022 ] Latency= Utils--LatencyUtils A vulnerability was determined in LatencyUtils up to 2.= 0.3. Affected by this issue is the function LatencyStats.recordDetectedPaus=
e of the file src/main/java/org/LatencyUtils/LatencyStats.java of the compo= nent PauseDetector. Executing a manipulation can lead to memory corruption.=
The attack needs to be launched locally. The exploit has been publicly dis= closed and may be utilized. The project was informed of the problem early t= hrough an issue report but has not responded yet. 2026-08-31 3.3 CVE-2026-8= 2596 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82596 ] libxml2 -- libxm= l2=C2=A0
=C2=A0 In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bound=
s read, aka an out-of-bounds read in the NXT macro in xmlregexp. 2026-09-05=
2.9 CVE-2026-86137 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86137 ] l= ibxml2 --libxml2=C2=A0
=C2=A0 xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in=
xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a = string length after NULL checking. 2026-09-05 2.9 CVE-2026-86141 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-86141 ] MasterStudy LMS WordPress Plugi= n--MasterStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plugin Wo= rdPress plugin before 3.7.46 does not properly verify ownership of a curric= ulum object before acting on it, allowing authenticated users with the inst= ructor role to delete or modify curriculum sections and materials belonging=
to courses owned by other instructors. 2026-09-02 3.8 CVE-2026-81198 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-81198 ] MasterStudy LMS WordPress = Plugin--MasterStudy LMS WordPress Plugin The MasterStudy LMS WordPress Plug=
in WordPress plugin before 3.7.46 does not properly verify ownership of qui=
z question identifiers, allowing users with instructor access to read other=
instructors' quiz questions, including the correct answers and explanation=
s. 2026-09-02 2.7 CVE-2026-81196 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-81196 ] MongoDB--C Driver A memory-handling error in the BSON-to-JSON c= onversion helpers of the MongoDB C Driver can write a small number of bytes=
past the end of a heap buffer when a binary field is encoded and the outpu=
t is cut short at a caller-configured length limit. A party who supplies th=
e document content, with no privileges on the application that links the dr= iver, may cause a small amount of data outside the intended buffer to be al= tered. 2026-09-03 3.7 CVE-2026-84969 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-84969 ] mwiede jsch --mwiede jsch=C2=A0
=C2=A0 A security flaw has been discovered in mwiede jsch up to 2.28.5. Aff= ected is the function getRevokedKeys of the file src/main/java/com/jcraft/j= sch/KnownHosts.java. Performing a manipulation of the argument known_hosts = results in improper check for certificate revocation. The attack is possibl=
e to be carried out remotely. The attack is considered to have high complex= ity. The exploitability is told to be difficult. The exploit has been relea= sed to the public and may be used for attacks. Upgrading to version 2.28.6 =
is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be= 3fd66bcafc42d23. You should upgrade the affected component. 2026-09-06 3.7 = CVE-2026-86231 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86231 ] OpenCa= rt--OpenCart A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The imp= acted element is an unknown function of the file catalog/controller/account= /address.php of the component Autocomplete Workflow. The manipulation of th=
e argument address_1 results in cross site scripting. It is possible to lau= nch the attack remotely. The exploit has been made public and could be used=
. The vendor was contacted early about this disclosure but did not respond =
in any way. 2026-09-02 3.5 CVE-2026-84437 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-84437 ] OpenCart--OpenCart A vulnerability was determined in O= penCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catal= og/controller/account/edit.php of the component Autocomplete Workflow. This=
manipulation of the argument firstname causes cross site scripting. The at= tack can be initiated remotely. The exploit has been publicly disclosed and=
may be utilized. The vendor was contacted early about this disclosure but = did not respond in any way. 2026-09-02 3.5 CVE-2026-84438 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-84438 ] PocketMine-MP --PocketMine-MP=C2=A0
=C2=A0 PocketMine-MP before 4.0.3 does not perform case-insensitive matchin=
g when removing operator entries from ops.txt. The removeOp function lowerc= ases the supplied name but only removes an exactly matching entry, so an op= erator name stored with non-lowercase letters cannot be revoked using the d= eop command, leaving the player as an operator until the entry is removed f= rom ops.txt manually. 2026-09-06 3.3 CVE-2021-48006 [
https://www.cve.org/C= VERecord?id=3DCVE-2021-48006 ] Projectwolds--Online Attendance System 1.0 =C2=A0 A security flaw has been discovered in Projectwolds Online Attendanc=
e System 1.0. Affected by this issue is some unknown functionality of the f= ile profile.php. The manipulation of the argument email results in cross si=
te scripting. The attack may be performed from remote. The exploit has been=
released to the public and may be used for attacks. 2026-09-06 3.5 CVE-202= 6-86226 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86226 ] ramon-victor-= -freegpt-webui
=C2=A0 A security flaw has been discovered in ramon-victor freegpt-webui up=
to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the functi=
on getJailbreak of the file server/config.py of the component Jailbreak Mod=
e. The manipulation results in race condition. It is possible to launch the=
attack remotely. The attack requires a high level of complexity. The explo= itability is assessed as difficult. The exploit has been released to the pu= blic and may be used for attacks. This product takes the approach of rollin=
g releases to provide continious delivery. Therefore, version details for a= ffected and updated releases are not available. This vulnerability only aff= ects products that are no longer supported by the maintainer. 2026-09-04 3.=
7 CVE-2026-85704 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85704 ] Rank=
Math SEO--Rank Math SEO The Rank Math SEO WordPress plugin before 1.0.277 = does not verify that the post whose schema it renders on the front end is p= ublicly viewable, allowing unauthenticated visitors to disclose the schema = and associated content of draft, pending, private, scheduled and password-p= rotected posts. 2026-09-02 3.7 CVE-2026-77783 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-77783 ] Rank Math SEO--Rank Math SEO The Rank Math SEO Wor= dPress plugin before 1.0.277 does not verify that the requesting user is pe= rmitted to read the specific post referenced in a request before returning = its content and SEO metadata, allowing users with the Author role and above=
to read the title, body and metadata of other users' non-public posts. 202= 6-09-02 2.7 CVE-2026-77785 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77= 785 ] Rank Math SEO--Rank Math SEO The Rank Math SEO WordPress plugin befor=
e 1.0.277 does not perform a capability check when bulk metadata updates ta= rget taxonomy terms, and reuses the supplied object identifier across objec=
t types, allowing users with the Author role and above to modify the SEO me= tadata of terms they cannot edit and to overwrite the titles of posts belon= ging to other users. 2026-09-02 2.7 CVE-2026-77787 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-77787 ] Rank Math SEO-Rank Math SEO The Rank Math SEO=
WordPress plugin before 1.0.277 does not verify that a user is allowed to = edit the object being modified before updating its SEO indexing metadata, a= llowing users with the Author role and above to alter that metadata on cont= ent, taxonomy terms and user profiles they do not own, and to remove other = users' content from the site's sitemap and search engine index. 2026-09-02 = 2.7 CVE-2026-77784 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77784 ] rp= m-software-management--popt A flaw was found in popt. This vulnerability al= lows an attacker to provide specially crafted configuration content to a ho= st, which, when loaded, can lead to a small memory corruption issue. This o= ccurs because of an error in how the `poptConfigFileToString` function real= locates memory for buffers. Successful exploitation could result in heap me= tadata corruption, potentially causing the affected process to become unava= ilable (denial of service). 2026-09-01 2.5 CVE-2026-18743 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-18743 ] runZero--Platform An authorization byp= ass in the runZero Platform MCP service has been resolved in version 5.1.26= 0826.0. This issue is an instance of CWE-639: Authorization Bypass Through = User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/P= R:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low). 2026-09-01 3.5 CVE-2026-81846 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-81846 ] sambitraj--Student Management = System A flaw has been found in sambitraj Student Management System up to 5= 6ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function o=
f the file aca.sql of the component Password Handler. Executing a manipulat= ion of the argument Password can lead to cleartext storage of sensitive inf= ormation. The attack can be executed remotely. The exploit has been publish=
ed and may be used. This product implements a rolling release for ongoing d= elivery, which means version information for affected or updated releases i=
s unavailable. 2026-08-31 2.7 CVE-2026-82699 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82699 ] sambitraj--Student-Management-System A security vul= nerability has been detected in sambitraj Student-Management-System up to 5= 6ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the functi=
on session_start. Such manipulation leads to cookie without 'httponly' flag=
. The attack may be launched remotely. A high complexity level is associate=
d with this attack. The exploitability is regarded as difficult. The exploi=
t has been disclosed publicly and may be used. This product operates on a r= olling release basis, ensuring continuous delivery. Consequently, there are=
no version details for either affected or updated releases. The project wa=
s informed of the problem early through an issue report but has not respond=
ed yet. 2026-08-31 3.7 CVE-2026-82697 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-82697 ] sdcb--chats A flaw has been found in sdcb chats up to 1.12= .0. This impacts the function DownloadPublic of the file src/BE/web/Control= lers/Chats/Files/FileController.cs of the component Signed File Download En= dpoint. This manipulation causes missing authentication. Remote exploitatio=
n of the attack is possible. The attack's complexity is rated as high. The = exploitability is said to be difficult. The exploit has been published and = may be used. The vendor was contacted early about this disclosure but did n=
ot respond in any way. 2026-08-31 3.7 CVE-2026-82906 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-82906 ] thorsten--phpMyFAQ phpMyFAQ before 4.1.8 co= ntains an authorization bypass vulnerability in the question creation endpo= int where the isAddingQuestionsAllowed() method grants access to all caller=
s when main.enableAskQuestions is enabled, ignoring the records.allowQuesti= onsForGuests setting. Unauthenticated attackers can submit questions via th=
e question/create API endpoint to bypass guest submission restrictions and = inject spam into the admin moderation queue. 2026-09-04 3.7 CVE-2026-85592 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85592 ] Timetics--Timetics Th=
e Timetics WordPress plugin through 1.0.61 does not enforce per-object owne= rship when updating appointments through its REST API, allowing users with = its custom staff role to modify, disable, or take over appointments belongi=
ng to other staff members. 2026-09-02 3.8 CVE-2026-14326 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-14326 ] ugrep --ugrep=C2=A0
=C2=A0 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in=
the LZW decompressor when processing crafted .Z archive files. Attackers c=
an supply malformed .Z files that cause the decompressor to read one byte p= ast the allocated heap buffer, potentially crashing the process. 2026-09-05=
3.3 CVE-2025-15614 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15614 ] u= ndici--undici undici's retry interceptor can append the body of a ranged re= try response to bytes already delivered from an earlier partial response wh= ile still presenting the original response's status and headers. This happe=
ns when an upstream server delivers part of a body without a trustworthy re= sume checkpoint, for example a non-success response whose headers were alre= ady sent or a partial-content response with an unusable content range, then=
closes the connection and answers the resumed range request with more byte=
s. As a result the response body can be longer than the Content-Length that=
the application observes. An application that relays such a response to a = downstream HTTP/1.1 peer without normalizing the framing can emit a body th=
at exceeds the forwarded Content-Length, and the excess bytes can be interp= reted as the start of a following response, which enables downstream respon=
se splitting or desynchronization. Exploitation requires an attacker-contro= lled upstream server and an application that forwards the response through =
a framing-sensitive path. This affects undici versions before 6.28.1, from = 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to un= dici 6.28.1, 7.29.1, or 8.10.2. 2026-09-04 3.7 CVE-2026-18540 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-18540 ] undici--undici undici's dump inter= ceptor reads and discards a response body up to a configurable maximum size=
. When a response declares a Content-Length that exceeds the maximum, the i= nterceptor aborts cleanly, but when a response has no Content-Length and is=
chunked, the interceptor instead signals completion early once the accumul= ated size reaches the maximum, without pausing or aborting the request. Bec= ause the underlying parser keeps delivering body bytes, a second completion=
signal fires and trips an internal assertion, which aborts the request and=
tears down the connection. The application is left observing a misleading = successful status with an empty or truncated body while the connection has = actually been disconnected. This affects undici versions from 7.1.0 up to 7= .29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or=
8.10.2. 2026-09-04 3.7 CVE-2026-84947 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84947 ] undici--undici undici's cache interceptor documents tha=
t only safe HTTP methods are cached, but its logic to skip caching is built=
by subtracting the configured methods from the set of safe methods, so an = unsafe method such as POST, PUT, or DELETE is never placed in the skip list=
and instead falls through to the full cache-read path. The response-storag=
e gate also lacked a method check, so a response to an unsafe request that =
is heuristically cacheable or carries an explicit Cache-Control directive i=
s stored and later replayed from cache. Because response headers from a rem= ote origin are untrusted, an origin can answer once with a cacheable status=
and then have the client's own subsequent state-changing requests to that = path served from the stale cache entry without ever reaching the origin, an=
integrity failure that occurs under the interceptor's default configuratio=
n. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up t=
o 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2. 2026-09-04 3.7 C= VE-2026-85008 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85008 ] valkey-= io--valkey A security flaw has been discovered in valkey-io valkey 9.1.0. T=
he affected element is the function handleClientsBlockedOnKey of the file s= rc/blocked.c of the component Blocked-on-keys Subsystem. The manipulation r= esults in use after free. The attack may be performed from remote. A high c= omplexity level is associated with this attack. The exploitability is descr= ibed as difficult. The exploit has been released to the public and may be u= sed for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a06= 7a0d6d20b. Applying a patch is advised to resolve this issue. 2026-08-31 2.=
2 CVE-2026-82631 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82631 ] valk= ey-io--valkey A vulnerability was determined in valkey-io valkey 9.1.0. Imp= acted is the function moduleTimerHandler of the file src/module.c of the co= mponent Module Timer Subsystem. This manipulation causes double free. The a= ttack can be initiated remotely. The exploit has been publicly disclosed an=
d may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To=
fix this issue, it is recommended to deploy a patch. 2026-08-31 2.4 CVE-20= 26-82677 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82677 ] valkey-io--v= alkey
=C2=A0 A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1=
. This affects the function kvstoreGetHashtable of the file src/kvstore.c. = This manipulation of the argument didx causes out-of-bounds read. It is pos= sible to initiate the attack remotely. The attack is considered to have hig=
h complexity. It is indicated that the exploitability is difficult. The exp= loit has been made available to the public and could be used for attacks. P= atch name: 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it =
is recommended to deploy a patch. Exploitation requires cluster mode plus a= ttacker-controlled dump.rdb at startup (data-dir write access, replication = feed, or a stored crafted RDB) - an attacker-position DoS at boot, not netw= ork pre-auth. The issue report was closed stating it "is worth fixing for t=
he sake of memory safety=C2=A6 but I don't think it meets our bar for a sec= urity disclosure." 2026-09-06 3.1 CVE-2026-86227 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-86227 ] wakujs--waku Waku is the minimal React framewor=
k. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported f= rom waku/router/server (packages/waku/src/router/define-router.tsx:156-161)=
accepts an arbitrary string and reflects it unchanged into the HTTP Locati=
on response header with no URL validation, scheme restriction, or path-only=
enforcement. Any application that passes user-controlled input to this hel= per - the natural pattern documented in the JSDoc and official fixtures - i=
s vulnerable to open redirect attacks. An attacker who convinces a victim t=
o click a crafted link can silently redirect the browser to an arbitrary ex= ternal domain, enabling phishing, credential harvesting, and OAuth token th= eft. Additionally, scheme-relative URLs (//evil.example/) bypass naive http= s?://-only allow-list filters that developers might add as ad-hoc mitigatio= ns. This issue has been patched in version 1.0.0-beta.1. 2026-09-03 3.1 CVE= -2026-49456 [
https://www.cve.org/CVERecord?id=3DCVE-2026-49456 ] Weaver Sh=
ow Posts--Weaver Show Posts The Weaver Show Posts WordPress plugin before 1= .8.1 unserialises the content of an imported file, which could lead to PHP = object injections issues when a high privilege user import a malicious file=
and a suitable gadget chain is present on the blog. 2026-09-02 3.3 CVE-202= 3-3360 [
https://www.cve.org/CVERecord?id=3DCVE-2023-3360 ] WordPress Plugi=
n --EmbedPress
=C2=A0 The EmbedPress WordPress plugin before 4.6.4 does not correctly rest= rict access to one of its Google Reviews REST routes to administrators, all= owing any authenticated user with contributor-level access or above to read=
the site administrator's email address, a value WordPress core withholds f= rom that role. 2026-09-05 2.7 CVE-2026-84926 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-84926 ] WordPress Plugin --EmbedPress
=C2=A0 The EmbedPress WordPress plugin before 4.6.4 does not perform a suff= icient authorization check on one of its Google Reviews REST API routes, al= lowing users with the Contributor role and above to modify a site-wide stor=
e, deleting entries an administrator configured and injecting their own, wh= ich are rendered publicly across the site. 2026-09-05 2.7 CVE-2026-84927 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-84927 ] WordPress Plugin --Joli=
Table Of Contents
=C2=A0 The Joli Table Of Contents WordPress plugin before 2.8.1 does not sa= nitise and escape some of its settings before outputting them in an admin p= age, which could allow high-privilege users such as administrators to perfo=
rm Stored Cross-Site Scripting attacks even when the unfiltered_html capabi= lity is disallowed, for example in a multisite setup. 2026-09-05 3.5 CVE-20= 25-15694 [
https://www.cve.org/CVERecord?id=3DCVE-2025-15694 ] WordPress Pl= ugin --My Private Site
=C2=A0 The My Private Site WordPress plugin before 4.2.3 does not apply its=
site-privacy access control to certain unauthenticated front-end read surf= aces, allowing unauthenticated users to view post content, comments and pos=
t URLs from a site the administrator placed behind mandatory login. 2026-09= -05 3.7 CVE-2026-81348 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81348 =
] WordPress Plugin--Events Calendar
=C2=A0 The Events Calendar WordPress plugin before 6.17.3.1 does not restri=
ct non-public content to the users entitled to read it on its public REST a= rchives, allowing users with a low-privilege role such as contributor to re=
ad the full contents of every unpublished record on the site, including oth=
er users'. 2026-09-05 2.7 CVE-2026-84745 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-84745 ] WordPress Plugin--JCH Optimize
=C2=A0 The JCH Optimize WordPress plugin before 5.0.1 does not properly res= trict a directory path provided to one of its administrative image-browsing=
features to within the site, allowing high-privilege users, administrators=
on single-site and sub-site administrators on multisite, to enumerate dire= ctories and file names outside the web root. 2026-09-05 2.7 CVE-2025-15693 =
[
https://www.cve.org/CVERecord?id=3DCVE-2025-15693 ] WordPress Plugin--Kir=
ki
=C2=A0 The Kirki WordPress plugin before 6.3.0 does not check that a user i=
s allowed to act on a collaboration comment before changing its state, allo= wing users whom an administrator has granted content-level access to the pa=
ge builder to modify comments left by other users, including on pages they = cannot themselves open. 2026-09-05 2.2 CVE-2026-84225 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-84225 ] WordPress Plugin--Smart Post
=C2=A0 The Smart Post WordPress plugin before 4.0.8 does not check the type=
, ownership or status of the post it is asked to duplicate, allowing users = with contributor privileges and above to copy any private or password prote= cted post into a draft of their own and read its content and metadata. 2026= -09-05 2.7 CVE-2026-78150 [
https://www.cve.org/CVERecord?id=3DCVE-2026-781=
50 ] yaojingang--GEOFlow A vulnerability was detected in yaojingang GEOFlow=
up to 2.1.0. This vulnerability affects the function unlink of the file ap= p/Http/Controllers/Admin/ImageLibraryController.php of the component Image = Library Cleanup. The manipulation of the argument file_path results in path=
traversal. The attack may be performed from remote. The exploit is now pub= lic and may be used. Upgrading to version 2.1.1 is able to resolve this iss= ue. The patch is identified as 67abfd864a15d169a78429f3290c91cb3b93e849. It=
is recommended to upgrade the affected component. 2026-08-31 3.8 CVE-2026-= 82665 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82665 ] zephyrproject--= zephyr The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out stati= cally-allocated work nodes through a free-list i3c_ibi_work_nodes_free impl= emented as a plain sys_slist_t, which provides no synchronization. The allo= cation helpers (i3c_ibi_work_enqueue, i3c_ibi_work_enqueue_target_irq, i3c_= ibi_work_enqueue_hotjoin, i3c_ibi_work_enqueue_controller_request, i3c_ibi_= work_enqueue_cb) called sys_slist_get() directly from ISR context, while th=
e workqueue handler i3c_ibi_work_handler() returned nodes with sys_slist_ap= pend() from the workqueue thread, with no lock on either side. Because sys_= slist_get() and sys_slist_append() are neither atomic nor interrupt-safe, a=
n IBI interrupt that fires while the workqueue thread is mid-append (or a t= ruly parallel access under CONFIG_SMP) races on the shared list. This corru= pts the list linkage: a node may be handed to two consumers, a node may be = lost, or the head/tail pointers may be left inconsistent so sys_slist_get()=
returns a stale or garbage pointer. In the double-hand-out case the subseq= uent memcpy(ibi_node, ibi_work, sizeof(*ibi_node)) overwrites a node still =
in flight; a garbage pointer turns the same memcpy into an out-of-bounds wr= ite. The race is driven by I3C bus traffic - IBIs, hot-joins, and controlle= r-role requests originate from target devices on the bus, and I3C supports = hot-joining devices. An attacker controlling an I3C peripheral on the board=
's chip-to-chip bus can generate high-frequency interrupts timed to collide=
with the free operation. Exploitation requires physical access to the bus = and winning a narrow timing window; the most realistic impact is a crash or=
hang (denial of service), with memory corruption possible but hard to cont= rol. The fix wraps all free-list sys_slist_get()/sys_slist_append() operati= ons in the new ibi_work_alloc()/ibi_work_free() helpers, each guarded by a = k_spinlock (ibi_work_lock), closing the race across ISR and thread contexts=
. 2026-08-31 3.1 CVE-2026-14367 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-14367 ]=20
Back to top [ #top ]
Severity Not Yet Assigned
Primary
Vendor -- Product Description Published CVSS Score Source Info 1Hive--garde= ns-v2 Gardens v2 is a modular governance framework that enables communities=
to create and manage multiple governance pools with customizable parameter=
s and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f=
9, StreamingEscrow.claim() correctly rejects withdrawals while an escrow is=
disputed, but the permissionless syncOutflow() path performs the same exce= ss-balance transfer without checking disputed. After a streaming proposal i=
s challenged, anyone can call syncOutflow() to transfer escrowed SuperToken=
s to the proposal beneficiary while the dispute is pending. If the proposal=
is later rejected, those tokens cannot be recovered by drainToStrategy(). = This issue has been patched in 0xc9d4e0dacd937364793278180551e59d93cd43f9. = 2026-09-03 not yet calculated CVE-2026-53924 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-53924 ] 1Hive--gardens-v2 Gardens v2 is a modular governanc=
e framework that enables communities to create and manage multiple governan=
ce pools with customizable parameters and voting mechanisms. In dfba919e218= e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in=
StreamingEscrow preserve depositAmount() while an active stream needs an e= scrow reserve. However, the approve-side dispute resolution path drains the=
whole available escrow balance to the proposal beneficiary. At time of pub= lication, there are no publicly known patches. 2026-09-03 not yet calculate=
d CVE-2026-57445 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57445 ] adal= tas--node-csv node-csv is a full-featured CSV parser with a simple API that=
is tested against large datasets. Prior to 7.0.2, csv-parse with the colum=
ns and group_columns_by_name options enabled treats a duplicate __proto__ h= eader as an existing property in packages/csv-parse/lib/api/index.js, assig=
ns an attacker-controlled array through obj['__proto__'], and replaces the = parsed record object's prototype. A malicious CSV header can therefore inje=
ct inherited array values into the returned record, hide those inherited va= lues from JSON serialization, and affect property enumeration and type or s= hape checks in applications that process the record. This issue is fixed in=
version 7.0.2. 2026-09-03 not yet calculated CVE-2026-85063 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-85063 ] AMD--AMD Radeon Instinct MI25 Graph= ics Products Release of an invalid pointer in the AMD kernel mode driver (K= MD) could allow a privileged attacker to create a double free condition pot= entially leading to arbitrary code execution. 2026-08-31 not yet calculated=
CVE-2023-20511 [
https://www.cve.org/CVERecord?id=3DCVE-2023-20511 ] andia= lbrecht--sqlparse sqlparse is a non-validating SQL parser module for Python=
. Prior to 0.6.0, sqlparse.format(sql, reindent=3DTrue) and sqlformat --rei= ndent route attacker-controlled parenthesized tuple lists through ReindentF= ilter._get_offset() in sqlparse/filters/reindent.py, where _flatten_up_to_t= oken() repeatedly rebuilds and joins the statement prefix. Thousands of off= set calculations walk an expanding token tree, producing quadratic CPU cons= umption for inputs that remain below MAX_GROUPING_TOKENS and causing reques=
t delays, reduced throughput, or worker starvation. This issue is fixed in = version 0.6.0. 2026-09-01 not yet calculated CVE-2026-84305 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-84305 ] Apache Software Foundation--Apache A= llura Apache Allura's=C2=A0webhooks=C2=A0are vulnerable to Server-Side Requ= est Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users=
are recommended to upgrade to version 1.21.0, which fixes the issue. 2026-= 09-04 not yet calculated CVE-2026-80181 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80181 ] Apache Software Foundation--Apache SkyWalking PagerDuty=
alarm hook transmits the integration routing key over cleartext HTTP. Page= rDuty serves this endpoint over HTTPS and will normally answer plain HTTP w= ith a redirect. That does not remove the exposure. The initial POST -- incl= uding the JSON body containing the routing key -- is written to the socket = unencrypted before any redirect response is received. Redirection affects o= nly whether the request is retried securely, not whether the first copy lef=
t the host in the clear. This issue affects Apache SkyWalking: from 9.6.0 t= hrough 11.0.0. Users are recommended to upgrade to version 11.0.0, which fi= xes the issue. 2026-09-04 not yet calculated CVE-2026-71216 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-71216 ] AppNitro -- MachForm
=C2=A0 An arbitrary file upload vulnerability in AppNitro MachForm v30 allo=
ws attackers to execute arbitrary code via uploading a crafted .phar file. = 2026-09-04 not yet calculated CVE-2026-78839 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-78839 ] ash-project--ash Improper Validation of Specified Q= uantity in Input vulnerability in ash-project ash allows an attacker to sub= mit a non-finite decimal value that bypasses numeric bounds constraints or = fails later operations on the value. Ash.Type.Decimal cast input through Ec= to's decimal cast in cast_input/2 and cast_stored/2 (lib/ash/type/decimal.e=
x) without checking that the resulting value is finite. Elixir's Decimal re= presents Infinity and NaN as valid structs, so a value such as "Infinity" o=
r "NaN" passed casting and was persisted. Because NaN compares as false aga= inst every bound, min and max constraints do not reject it, and the stored = special value later raises when used in Decimal arithmetic or is refused by=
the data layer, failing subsequent requests. The fix rejects any non-finit=
e Decimal during casting. This issue affects ash: from 1.28.0 before 3.32.2=
. 2026-09-01 not yet calculated CVE-2026-82734 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-82734 ] ash-project--ash Uncontrolled Resource Consumptio=
n vulnerability in ash-project ash allows an attacker to force an expensive=
regular expression to run on input that a length constraint should have al= ready rejected. Ash.Type.String.apply_constraints/2 (lib/ash/type/string.ex=
) evaluated the :match regex regardless of the min_length and max_length co= nstraints on the same attribute. Because the length check did not gate the = regex, an over-length value that the length constraint rejects still had th=
e pattern applied to it, so the length limit that would otherwise bound the=
work never constrained the regex input. Against a backtracking pattern thi=
s yields catastrophic regex evaluation on attacker-sized input, and even a = linear pattern runs on arbitrarily large input, consuming CPU per request. = The fix skips the :match regex whenever a length constraint is violated, ma= king the two checks order-independent. This issue affects ash: from 0.10.0 = before 3.32.2. 2026-09-01 not yet calculated CVE-2026-82735 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-82735 ] ash-project--ash Incorrect Behavior = Order: Validate Before Canonicalize vulnerability in ash-project ash lets a=
n attacker store a case-insensitive string value that violates its length o=
r match constraints. Ash.Type.CiString.apply_constraints/2 (lib/ash/type/ci= _string.ex) validated the max_length, min_length, and match constraints aga= inst the value as submitted, while the type case-folds the string (per its = casing) for storage and comparison. Because validation ran before folding, =
an attacker can submit a value whose folded form breaks a constraint but wh= ose original form passes: for example, against a match pattern requiring up= percase, an uppercase value that is stored lowercased persists a value the = pattern rejects. The fix case-folds the value at the start of apply_constra= ints/2, so the constraints are checked against the form that is actually st= ored. This issue affects ash: from 1.29.0-rc0 before 3.32.2. 2026-09-01 not=
yet calculated CVE-2026-82736 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-82736 ] ash-project--ash Integer Overflow or Wraparound vulnerability in = ash-project ash lets an attacker corrupt a stored vector and crash later re= ads of it by submitting a vector with more than 65,535 elements. Ash.Vector= .new/1 (lib/ash/vector.ex) encodes a vector as <<dim::unsigned-16, 0::unsig= ned-16>> followed by the element floats, packing the element count into a 1= 6-bit field without checking its range. A list of more than 65,535 elements=
wraps the dimension modulo 65,536, so the encoded header records a dimensi=
on that disagrees with the number of stored floats. from_binary/1 later rea=
ds binary-size(dim)-unit(32) from the wrapped header, so every read of the = corrupted value misparses and raises, denying access to the affected record=
. The fix rejects any vector whose dimension exceeds 65,535. This issue aff= ects ash: from 2.14.13 before 3.32.2. 2026-09-01 not yet calculated CVE-202= 6-82737 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82737 ] ash-project--= ash Improper Input Validation vulnerability in ash-project ash allows an at= tacker to persistently deny reads of a record by storing a non-version-7 UU=
ID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts an=
y well-formed UUID string, including non-version-7 UUIDs, and stores it as =
a 16-byte binary. On read, cast_stored/2 (lib/ash/type/uuid_v7.ex) routes t=
he stored binary back through cast_input/2, which since an input-validation=
tightening in v3.6.3 matches only version-7 (and optionally version-4) 16-= byte binaries and otherwise expects a 36-character string. A stored non-v7 = 16-byte binary matches neither clause and returns :error, so every later re=
ad of that record fails. An attacker able to set such an attribute poisons = the row permanently. The fix decodes any 16-byte stored binary directly in = cast_stored/2. This issue affects ash: from 3.6.3 before 3.32.2. 2026-09-01=
not yet calculated CVE-2026-82738 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-82738 ] ash-project--ash Generation of Error Message Containing Sensi= tive Information vulnerability in ash-project ash discloses the stored valu=
e of a confirmed field to an actor who fails its confirmation check. Ash.Re= source.Validation.Confirm's atomic implementation (atomic/2 in lib/ash/reso= urce/validation/confirm.ex) built the mismatch error with its value set to = the field being confirmed. When the actor supplies only the confirmation ar= gument and not the field itself, value resolves through atomic_ref/2 to the=
field's current stored value, so the mismatch error echoes that stored val=
ue back to the actor. Against a confirmation guarding a sensitive attribute=
, an actor can submit a deliberately wrong confirmation and read the real v= alue from the returned error. The fix reports the actor-supplied confirmati=
on in the error instead of the stored field value. This issue affects ash: = from 2.17.20 before 3.32.2. 2026-09-01 not yet calculated CVE-2026-82739 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-82739 ] ash-project--ash Improp=
er Input Validation vulnerability in ash-project ash fails to enforce the o= uter array constraints on a doubly-nested {:array, {:array, type}} attribut=
e, letting invalid input pass validation. Ash.Type.apply_constraints/3 (lib= /ash/type/type.ex) handled the {:array, {:array, type}} case by mapping onl=
y the inner {:array, type} constraints over each element, so constraints de= clared on the outer array (such as min_length, max_length, and nil_items?) = were never applied. An attacker could submit an outer list that violates th= ose constraints (too many elements, or nil entries where disallowed) and ha=
ve it accepted and persisted. The fix enforces the outer array constraints = and adds explicit handling for nil and non-list inputs. This issue affects = ash: from 2.16.1 before 3.32.2. 2026-09-01 not yet calculated CVE-2026-8274=
0 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82740 ] ash-project--ash Im= proper Validation of Specified Type of Input vulnerability in ash-project a=
sh lets an attacker confuse the stored type tag of an Ash.Type.Union value = that uses storage: :map_with_tag, bypassing that member's validation and an=
y tag-based authorization. For a union with storage: :map_with_tag, each me= mber is identified in storage by a configured tag and tag_value. Ash.Type.U= nion.dump_to_native/2 (lib/ash/type/union.ex) did not force the configured = tag when writing the value, so a tag carried in the submitted value was per= sisted verbatim. An attacker can therefore store a value whose data belongs=
to one member but whose tag names a different member. On read the value is=
re-selected by its tag and treated as the incompatible member (a type conf= usion), bypassing the real member's constraints and any logic or policy tha=
t branches on the union tag. The fix drops any incoming tag and forces the = configured tag value on dump. This issue affects ash: from 2.14.18 before 3= .32.2. 2026-09-01 not yet calculated CVE-2026-82741 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-82741 ] ash-project--ash Uncontrolled Resource Consu= mption vulnerability in ash-project ash lets an attacker exhaust node memor=
y by matching a filter that spans multiple to-many relationships in memory.=
Ash.Filter.Runtime matches a filter against an in-memory record by first e= xpanding the record into combinations of its related rows. flatten_relation= ships/2 (lib/ash/filter/runtime.ex) eagerly built the full Cartesian produc=
t across the filter's to-many relationship paths, so a record with K to-man=
y relationships of M rows each materialized on the order of M^K scenarios b= efore any predicate was checked. A filter or dataset that reaches several s= izeable to-many relationships therefore allocates memory combinatorially an=
d can exhaust the node. The fix streams the expansion lazily and short-circ= uits on the first matching scenario, bounding the work. This issue affects = ash: from 1.29.0-rc0 before 3.32.2. 2026-09-01 not yet calculated CVE-2026-= 82742 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82742 ] ash-project--as=
h Uncontrolled Resource Consumption vulnerability in ash-project ash lets a=
slow asynchronous read spin a scheduler thread at full CPU while the frame= work waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (lib/= ash/actions/read/async_limiter.ex) waited for concurrent async read tasks b=
y polling each with Task.yield(task, 0) in a tight loop rather than blockin=
g. While every outstanding task is still running (a slow related-data load =
or calculation), the loop returns immediately and repeats, busy-spinning an=
d holding a BEAM scheduler at full CPU for the whole duration of the slow r= ead; concurrent slow reads tie up further schedulers. The fix waits with Ta= sk.yield_many (a non-blocking sweep followed by a blocking wait with timeou=
t: :infinity), so the process sleeps until a task completes instead of spin= ning. This issue affects ash: from 2.19.0 before 3.32.2. 2026-09-01 not yet=
calculated CVE-2026-82743 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 743 ] ash-project--ash Not Failing Securely (Failing Open) vulnerability in=
ash-project ash skips an Ash.Reactor change when the guard controlling it = raises, so a change meant to run does not. An Ash.Reactor change step can b=
e gated by where validations that decide whether the change runs. Ash.React= or.ChangeStep (lib/ash/reactor/steps/change_step.ex) evaluated those guards=
in apply_where_clauses/3, and apply_validation rescued any exception into = {:error, error}. The reduce treated that identically to a guard whose condi= tion was simply not met and bypassed the change. So when a guard raises (fo=
r example on attacker-influenced input), a change that enforces a security-= relevant modification is skipped rather than failing the step. The fix dist= inguishes a raised exception (now {:raised, error}) and halts the step with=
an error, failing closed. This issue affects ash: from 3.0.0-rc.17 before = 3.32.2. 2026-09-01 not yet calculated CVE-2026-82744 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-82744 ] ash-project--ash Improper Access Control vu= lnerability in ash-project ash lets a create action overwrite an existing r= ecord when the ETS or Mnesia data layer is used, because neither enforced p= rimary-key uniqueness on insert. Unlike a SQL data layer, whose unique prim= ary-key constraint rejects a duplicate, the ETS and Mnesia data layers impl= emented create as a keyed insert that replaces any existing entry with the = same primary key (lib/ash/data_layer/ets/ets.ex, lib/ash/data_layer/mnesia/= mnesia.ex). An actor who can set the primary key on a create (for example a=
user-supplied string or integer key) can submit a create whose key matches=
an existing record and silently overwrite it, destroying and replacing ano= ther entity's data without going through the update action or its policies.=
The fix rejects a create whose primary key already exists with an already-= taken error, and only allows duplicates for keyless resources. This issue a= ffects ash: from 0.4.0 before 3.32.2. 2026-09-01 not yet calculated CVE-202= 6-82745 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82745 ] ash-project--= ash Missing Authorization vulnerability in ash-project ash allows an actor =
to update records forbidden by resource policies through the atomic path of=
Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a = data-layer update_many, for example a SQL MERGE) whenever an atomic strateg=
y is used and the data layer supports it. Ash.Actions.Update.UpdateMany (li= b/ash/actions/update/update_many.ex) took that path even under authorize?: = true without applying the resource's policies, so the statement updated eve=
ry row matched by primary key regardless of the policy filter that authoriz= ation would impose. An actor could therefore update records the policies fo= rbid, such as rows belonging to another actor or tenant. The fix restricts = the atomic path to data layers supporting changeset filters when authorizin=
g, authorizes each changeset, and merges the resulting policy filter into e= ach changeset so the statement only touches authorized rows. This issue aff= ects ash: from 3.29.0 before 3.32.2. 2026-09-01 not yet calculated CVE-2026= -82746 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82746 ] ash-project--a=
sh Incorrect Authorization vulnerability in ash-project ash returns records=
that a runtime read policy denies to any actor. When a resource has an acc= ess_type :runtime read policy (a check evaluated per record rather than com= piled to a filter), Ash.Policy.Authorizer decides each record in check_resu= lt/1 (lib/ash/policy/authorizer/authorizer.ex) by discarding impossible pol= icy scenarios and inspecting what remains. When every scenario for a record=
was impossible, meaning no policy can authorize it and it must be forbidde=
n, the empty-scenario branch instead kept the record ({[record | data], aut= horizer, any_forbidden?}) and returned it as authorized. As a result, recor=
ds the runtime read policy denies are returned to any actor. The fix forbid=
s a record whose scenarios are all impossible. This issue affects ash: from=
3.4.44 before 3.32.2. 2026-09-01 not yet calculated CVE-2026-82747 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-82747 ] ash-project--ash Incorrect A= uthorization vulnerability in ash-project ash authorizes an aggregate under=
one read action while computing it under another, so an aggregate can run = with policies that do not match the action it was authorized against. Ash.A= ctions.Aggregate groups aggregates by their {authorize?, read_action} and a= uthorizes each group under that read action, but when building the data que=
ry it selected the action as opts[:action] || read_action || <primary read>=
(lib/ash/actions/aggregate.ex). When a caller passed an :action option, th=
e aggregate query ran under that action while authorization had been comput=
ed for the group's own read_action. If the run action's read policies are m= ore permissive than the authorized one, the aggregate (a count or sum) is c= omputed over records the authorized action's policies would have excluded, = disclosing information about data the actor cannot read. The fix runs the a= ggregate under the same read_action it is authorized against. This issue af= fects ash: from 3.5.13 before 3.32.2. 2026-09-01 not yet calculated CVE-202= 6-82748 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82748 ] ash-project--= ash Incorrect Authorization vulnerability in ash-project ash widens a relat= ionship's parent(...) scoping filter to match unintended records when the r= eferenced parent field cannot be resolved. Loading a relationship whose fil= ter references parent(...) resolves that expression against the parent reco= rd. resolve_parent_in_filter/3 (lib/ash/actions/read/relationships.ex) reso= lved an unresolvable parent reference (for example when the referenced fiel=
d was not selected on the source query) to nil rather than failing. A scopi=
ng predicate such as org_id =3D=3D parent(org_id) then becomes an IS NULL m= atch, and a guard like is_nil(parent(org_id)) or org_id =3D=3D parent(org_i=
d) activates its unrestricted branch, so the relationship returns records t=
he scope was meant to exclude. The fix fails the read with an error when a = parent(...) reference cannot be resolved, instead of defaulting to nil. Thi=
s issue affects ash: from 3.13.2 before 3.32.2. 2026-09-01 not yet calculat=
ed CVE-2026-82749 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82749 ] ash= -project--ash_admin Reliance on Cookies without Validation and Integrity Ch= ecking vulnerability in ash-project ash_admin lets an attacker who controls=
a sibling subdomain rebind an admin's session to a different actor, tenant=
, or authorization mode. AshAdmin's client JavaScript read its state cookie=
s (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, a= ctor_authorizing, actor_paused) by matching the cookie name with an unancho= red regular expression (new RegExp(name + "=3D([^;]+)")) against the whole = document.cookie. Any cookie whose name merely ends with the requested name = therefore matches, and whichever is serialized first wins. Because cookies = are shared across a registrable domain, a compromised sibling subdomain can=
set a shadowing cookie (for example xactor_authorizing) with Domain=3D.exa= mple.com that flows unvalidated into the admin's LiveSocket connect params.=
The fix matches cookie names by exact equality. This issue affects ash_adm= in: from 0.9.1 before 1.3.1. 2026-08-31 not yet calculated CVE-2026-75757 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-75757 ] ash-project--ash_admin=
Stored Cross-site Scripting vulnerability in ash-project ash_admin execute=
s attacker-supplied record content as script in an administrator's browser.=
The relationship typeahead components AshAdmin.Components.Resource.Relatio= nshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectField = highlight the matched search term by wrapping it in <b> tags and rendering = the whole string with Phoenix.HTML.raw/1. The highlighted value is the dest= ination record's label_field, ordinary database content that is often writt=
en by lower-privileged users. Because raw/1 disables output escaping for th=
e entire string, a stored label such as <img src=3Dx onerror=3D...> runs as=
JavaScript in the admin's session as soon as a matching record appears in = the dropdown, giving the attacker the admin's privileges over everything As= hAdmin exposes. The fix HTML-escapes the label before inserting the highlig=
ht markup. This issue affects ash_admin: from 0.13.0 before 1.3.1. 2026-08-=
31 not yet calculated CVE-2026-77850 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-77850 ] ash-project--ash_admin Use of Insufficiently Random Values = vulnerability in ash-project ash_admin ships a hardcoded, publicly known CS=
P nonce, defeating nonce-based Content-Security-Policy protection. When mou= nted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted t=
he img, style, and script nonces to the literal constant ash_admin-Ed55GFnX=
, which AshAdmin.Layouts wrote verbatim into the nonce attribute of its inl= ine <style> and <script> tags on every response. The value is a compile-tim=
e constant published in the repository and is never rotated per request. If=
an application's CSP script-src allow-lists that documented default, any H= TML-injection sink on an admin page can reuse the known nonce to run inline=
scripts the policy was meant to block. The fix generates a fresh random no= nce per request. This issue affects ash_admin: from 0.10.8 before 1.3.1. 20= 26-08-31 not yet calculated CVE-2026-81852 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-81852 ] ash-project--ash_admin Authorization Bypass Through U= ser-Controlled Key vulnerability in ash-project ash_admin turns a record-lo= okup URL into an equality oracle over sensitive attributes. AshAdmin.Helper= s.decode_primary_key/2 decodes the composite-primary-key form (Base64 plus = ETF) and returns the decoded map verbatim as the lookup filter, without che= cking that its keys are the resource's primary-key fields. The deserializat= ion guards bound size, block new atoms and funs, and reject nested expressi= ons, but none restricts which fields come back, and :safe still allows any = already-interned attribute name. An attacker can therefore encode %{api_tok= en: "guess"} and have it spliced into the lookup filter, brute-forcing a se= nsitive attribute value (API token, reset token) one equality guess at a ti= me; Map.to_list/1 also accepts structs, yielding a bogus __struct__ key. Th=
e fix rejects any decoded key that is not a real primary-key field. This is= sue affects ash_admin: from 0.1.0 before 1.3.1. 2026-08-31 not yet calculat=
ed CVE-2026-81853 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81853 ] ash= -project--ash_admin Improper Limitation of a Pathname to a Restricted Direc= tory (Path Traversal) vulnerability in ash-project ash_admin allows writing=
attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Compo= nents.Resource.Form.consume_file_uploads/1 builds the destination as Path.j= oin([tmp_dir, entry.client_name]) and writes it with File.cp!/2. entry.clie= nt_name is the browser-supplied filename and is not sanitized, and Path.joi= n/1 does not normalize ... An upload named ../../../../var/www/app/priv/sta= tic/x.png therefore escapes the random temp directory and lands anywhere th=
e BEAM user can write, enabling arbitrary file write and potentially remote=
code execution by overwriting application assets, configuration, or cron/s=
sh files. The only guard is an extension allowlist defaulting to :any that = checks only the extension. The fix strips path components with Path.basenam= e/1 before joining. This issue affects ash_admin: from 0.13.7 before 1.3.1.=
2026-08-31 not yet calculated CVE-2026-82673 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-82673 ] ash-project--ash_admin Improper Encoding or Escapi=
ng of Output vulnerability in ash-project ash_admin lets an attacker who co= ntrols a record's string primary key rewrite the target of AshAdmin's row-a= ction links. The Table, DataTable, and Show components built row-action URL=
s by raw string interpolation, splicing the primary key (and table, domain,=
and resource names) into the query string without URL-encoding. Ash resour= ces routinely use user-settable string primary keys (slugs, emails). Becaus=
e Plug.Conn.Query resolves duplicate parameters last-wins and primary_key i=
s interpolated last, a stored key such as foo&action_type=3Ddestroy injects=
parameters that override the link, so an admin clicking edit is sent to a = destroy form or an arbitrary resource; a # truncates the query into a fragm= ent. The fix builds every link with URI.encode_query/1, encoding all interp= olated values. This issue affects ash_admin: from 0.3.0-rc.0 before 1.3.1. = 2026-08-31 not yet calculated CVE-2026-82681 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82681 ] ash-project--ash_admin Allocation of Resources With= out Limits or Throttling vulnerability in ash-project ash_admin lets any cl= ient that can reach the admin LiveView exhaust the BEAM atom table and cras=
h the entire node. Two LiveView event handlers interned atoms from unvalida= ted client input: AshAdmin.PageLive's set_actor built modules from the reso= urce/domain payload with Module.concat/1, and AshAdmin.Components.Resource.= Show's calculate converted every submitted form key with String.to_atom/1. = Atoms are never garbage collected and the table is capped, so flooding eith=
er event with random names mints a new atom per request until the VM aborts=
, taking down every application on the node. The fix resolves the submitted=
resource/domain against the known shown resources and maps calculation key=
s to declared arguments, so no client-supplied string is interned. This iss=
ue affects ash_admin: from 0.1.0 before 1.3.1. 2026-08-31 not yet calculate=
d CVE-2026-82722 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82722 ] ash-= project--ash_ai Generation of Error Message Containing Sensitive Informatio=
n vulnerability in ash-project ash_ai discloses provider request state and = credentials in a user-facing validation error. In AshAi.Changes.Vectorize, = when the embedding provider call fails the change added a changeset error w= hose message inspected the raw error term (An error occurred while generati=
ng embeddings: #{inspect(error)}). A plain-string add_error produces an Ash= .Error.Changes.InvalidChanges in the :invalid class, which AshJsonApi and A= shGraphql render back to the caller. The embedding client's error term is n=
ot sanitized, so it can carry the request URL, the provider response body, = and, for HTTP clients that keep the request in the error struct, the outbou=
nd Authorization header with the provider API key. Failures are attacker-re= achable via oversized or malformed vectorized content. The fix logs the raw=
error and returns a generic message. This issue affects ash_ai: from 0.1.0=
before 1.0.0. 2026-08-31 not yet calculated CVE-2026-75760 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-75760 ] ash-project--ash_ai Improper Control=
of Generation of Code (Code Injection) vulnerability in ash-project ash_ai=
allows a remote, unauthenticated client to execute arbitrary Elixir code. = AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. Th=
e documented prompt: fn input, context -> ... end form lets the prompt cont= ent be built from action arguments, so when a prompt action's text incorpor= ates request data, that attacker-controlled text is compiled and run as an = EEx template (Elixir source). Content such as <%=3D System.cmd(...) %> ther= efore executes on the server before any model request is made, requiring no=
authentication beyond reaching a prompt action. The fix stops evaluating f= unction-supplied prompt content as EEx; only statically configured template=
s are evaluated. This issue affects ash_ai: from 0.1.0 before 1.0.0. 2026-0= 8-31 not yet calculated CVE-2026-77956 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-77956 ] ash-project--ash_ai Origin Validation Error vulnerabili=
ty in ash-project ash_ai allows a malicious web page to bypass the MCP serv= er's DNS-rebinding protection and issue cross-site requests to a user's loc=
al MCP server with that user's actor. In AshAi.Mcp.Server, with the default=
allowed_origins: nil, origin_allowed?/3 accepts an origin when uri.host = =3D=3D conn.host and the forwarded scheme is https. Both values are attacke= r-controlled: conn.host comes from the Host header and the scheme is read f= rom the raw x-forwarded-proto header with no trusted-proxy check. Under DNS=
rebinding the browser sends the attacker's origin and a matching host, and=
page JavaScript may set X-Forwarded-Proto: https, so the check passes with=
no TLS or proxy involved. The fix trusts only localhost origins by default=
; other origins require an explicit allowed_origins allowlist. This issue a= ffects ash_ai: from 0.8.0 before 1.0.0. 2026-08-31 not yet calculated CVE-2= 026-81315 [
https://www.cve.org/CVERecord?id=3DCVE-2026-81315 ] ash-project= --ash_ai Authorization Bypass Through User-Controlled Key vulnerability in = ash-project ash_ai allows a caller of an identity-configured tool to update=
or destroy records it never identified, including every row in the table. =
In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter = directly from the raw tool arguments as [{key, Map.get(arguments, to_string= (key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a=
predicate expression rather than a literal, so a caller can send {"public_= ref": {"not_eq": "<own-ref>"}} and, combined with Ash.Query.limit(1) and As= h.bulk_update!/Ash.bulk_destroy!, retarget the write at a record it never i= dentified; an omitted key yields an IS NULL filter that matches an arbitrar=
y row. The fix casts each identity value to the field type, rejecting non-s= calar inputs. This issue affects ash_ai: from 0.6.0 before 1.0.0. 2026-08-3=
1 not yet calculated CVE-2026-82564 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-82564 ] ash-project--ash_ai Loop with Unreachable Exit Condition (In= finite Loop) vulnerability in ash-project ash_ai allows an attacker who can=
influence a model's output to hang the tool loop and drive unbounded, repe= ated model requests. AshAi.ToolLoop classifies a model response of :tool_ca= lls, then filters the calls through normalize_tool_calls/2 and unprocessed_= tool_calls/2. Both can empty the list: a call missing a valid name, or one = reusing a tool_call_id that already has a result in history, is dropped. Wi=
th an empty list the loop appended nothing and recursed with a byte-identic=
al message list, so the conversation never advanced and the same request wa=
s re-sent every iteration. Under the supported max_iterations: :infinity th=
is never terminated; otherwise it exhausted the full budget. Prompt-injecte=
d content can make the model re-emit a spent tool_call_id. The fix treats a=
n empty post-filter list as terminal. This issue affects ash_ai: from 0.6.0=
before 1.0.0. 2026-08-31 not yet calculated CVE-2026-82579 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-82579 ] ash-project--ash_ai Generation of Er= ror Message Containing Sensitive Information vulnerability in ash-project a= sh_ai discloses internal error text to chat users. In AshAi.ToolLoop and As= hAi.Tools, an exception raised while executing a tool was serialized verbat=
im with Exception.message/1 into the tool-result content. That content is a= ppended to the conversation, emitted as a {:tool_result, ...} stream event,=
and sent back to the model, which typically relays it to the user. No filt= ering happened first, so anything raised inside a tool callback or lifecycl=
e hook (database constraint messages, adapter errors, query fragments, poli=
cy or validation internals) was echoed as-is. A chat user who can steer too=
l arguments into a raising code path receives the raw internal text. The fi=
x routes raised tool errors through the same safe formatter used for other = tool errors. This issue affects ash_ai: from 0.6.0 before 1.0.0. 2026-08-31=
not yet calculated CVE-2026-82580 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-82580 ] ash-project--ash_phoenix Incorrect Authorization vulnerabilit=
y in ash-project ash_phoenix invokes the SubdomainHook authorization callba=
ck with a nil tenant, so tenant-scoped access checks never see the tenant t= hey are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 atta= ched a handle_params hook to assign the tenant and then immediately called = handle_subdomain in the same on_mount. The tenant assign is only written wh=
en LiveView later runs handle_params, strictly after on_mount returns, so h= andle_subdomain read an unset assign and ran as apply(m, f, [socket, nil | = a]). A consumer gate that halts when the user does not belong to the tenant=
instead evaluated nil, either crashing or taking a permissive branch, and =
it was never re-run once the real subdomain was assigned or on later naviga= tions. The fix runs handle_subdomain inside the handle_params hook with the=
real tenant on every navigation. This issue affects ash_phoenix: from 2.1.=
26 before 2.3.25. 2026-08-31 not yet calculated CVE-2026-82724 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-82724 ] ash-project--ash_phoenix Authoriz= ation Bypass Through User-Controlled Key vulnerability in ash-project ash_p= hoenix lets an attacker who controls filter form parameters filter across r= elationships the resource author marked non-public, turning the returned ro=
ws into a boolean oracle over private related data. AshPhoenix.FilterForm r= esolved every relationship hop in the user-supplied path with Ash.Resource.= Info.related/2, which traverses private relationships, and only checked the=
terminal field for publicity. parse_path_and_field/2 also rewrote a field = naming a relationship into an extra path segment, so field=3Dsome_private_r=
el was accepted too. Both path and field come straight from form params, an=
d the resulting ref went to Ash.Query.do_filter/2 without the public-only e= nforcement of Ash.Filter.parse_input/2. The fix resolves each hop with Ash.= Resource.Info.public_relationship/2, rejecting the first non-public hop, an=
d requires the terminal field to be public. This issue affects ash_phoenix:=
from 0.6.0-rc.1 before 2.3.25. 2026-08-31 not yet calculated CVE-2026-8272=
5 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82725 ] ash-project--ash_ph= oenix Permissive Regular Expression vulnerability in ash-project ash_phoeni=
x lets a remote client select the tenant an Ash application uses, or degrad=
e the request, by sending a crafted Host header. AshPhoenix.Helpers.get_sub= domain/2 stripped the root domain with String.replace(host, ~r/.?#{root_hos= t}/, ""). The root host was interpolated raw, so each . became a wildcard a=
nd any metacharacter a pattern, and the replace was global and unanchored, =
so a match was removed from anywhere in the string. With root_host example.= com, Host: foo.exampleXcom.attacker.net returned the tenant foo.attacker.ne=
t. A metacharacter-bearing or nil root host degraded the pattern or raised =
on every request. The comparison was also case-sensitive, so TENANT.EXAMPLE= .COM and EXAMPLE.COM slipped past the root-host allowlist. conn.host comes = from the client Host header. The fix matches the root host case-insensitive=
ly and only as an exact trailing suffix. This issue affects ash_phoenix: fr=
om 2.1.26 before 2.3.25. 2026-08-31 not yet calculated CVE-2026-82726 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-82726 ] ash-project--ash_phoenix G= eneration of Error Message Containing Sensitive Information vulnerability i=
n ash-project ash_phoenix writes the entire raw submitted param map into an=
exception message, so secrets submitted alongside a union form field leak = into logs, crash reports and the dev error page. When AshPhoenix.Form.Auto = builds a union sub-form and the submitted _union_type does not match a conf= igured type, both raise sites built the message with inspect(params, pretty=
: true), embedding the full untrusted param map, and also inspected the int= ernal union constraints[:types]. Because the message is constructed by the = library rather than Phoenix's parameter logger, config :phoenix, :filter_pa= rameters never redacts it. An attacker controls both the trigger and the co= ntents: submitting %{"_union_type" =3D> "nope", "password" =3D> "..."} puts=
the password verbatim in the raised message. The fix reports only the offe= nding _union_type and the valid type names, dropping the param and constrai= nts dumps. This issue affects ash_phoenix: from 1.2.17 before 2.3.25. 2026-= 08-31 not yet calculated CVE-2026-82727 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82727 ] ash-project--ash_typescript Allocation of Resources Wit= hout Limits or Throttling vulnerability in ash-project ash_typescript allow=
s an unauthenticated attacker to exhaust the BEAM atom table and abort the = node via client-supplied RPC field names. AshTypescript.FieldFormatter.conv= ert_to_field_atom/2 in lib/ash_typescript/field_formatter.ex converts a cli= ent-supplied field name to an atom with String.to_atom/1 when no matching a= tom already exists. It delegates first to parse_input_field/2, which resolv=
es the name with String.to_existing_atom/1 and falls back to returning the = plain string; convert_to_field_atom/2 then mints an atom from that string r= ather than treating the name as unknown. RPC field selection reaches it for=
every requested field name through AshTypescript.Rpc.FieldProcessing.Field= Selector, which resolves each name before checking that the field exists, w= ith no allowlist, length bound, or rate limit. Atoms are never garbage coll= ected, so each distinct name mints a permanent one and the VM aborts once t=
he atom table limit is reached. A field name over 255 characters additional=
ly raises an uncaught SystemLimitError. This issue affects ash_typescript: = from 0.1.0 before 0.18.0. 2026-09-01 not yet calculated CVE-2026-74837 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-74837 ] ash-project--ash_typescri=
pt Allocation of Resources Without Limits or Throttling vulnerability in as= h-project ash_typescript allows an unauthenticated attacker to exhaust the = BEAM atom table and abort the node via client-supplied typed struct field n= ames. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_processi= ng/field_selector.ex looks a client-supplied field name up in the typed str= uct's reverse map and, when it finds no match, falls back to String.to_atom= /1. Because this runs before any field-existence check, an unresolvable nam=
e mints a permanent atom rather than being rejected as unknown. Atoms are n= ever garbage collected, so a request carrying many distinct names on a type=
d struct field grows the atom table until the VM aborts at its limit. This = issue affects ash_typescript: from 0.11.0 before 0.18.0. 2026-09-01 not yet=
calculated CVE-2026-77856 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77= 856 ] ash-project--ash_typescript Generation of Error Message Containing Se= nsitive Information vulnerability in ash-project ash_typescript allows an u= nauthenticated attacker to receive unredacted internal error data by provok= ing an error shape the configured error handler does not match. apply_error= _handler/3 in lib/ash_typescript/rpc/errors.ex is the only hook an applicat= ion has for redacting or suppressing errors before they reach the client, w= ith a nil return dropping the error entirely. Its rescue clause logs a warn= ing and then returns the original, pre-handler error map. Error handlers ar=
e conventionally written as pattern-matching functions over expected error = shapes, so an unmatched shape raises FunctionClauseError and the raw transf= ormed error, including any secrets carried in vars, is emitted instead. An = intent to suppress an error becomes an intent to publish it. The rescue cat= ches exceptions only, so a handler that throws or exits still propagates. T= his issue affects ash_typescript: from 0.8.0 before 0.18.0. 2026-09-01 not = yet calculated CVE-2026-77950 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -77950 ] ash-project--ash_typescript Incorrect Authorization vulnerability =
in ash-project ash_typescript allows an unauthorized RPC caller to read att= ribute values that Ash field policies denied. When a field policy denies an=
attribute, Ash substitutes %Ash.ForbiddenField{}, which retains the real v= alue in original_value because embedded resources must remain writable, and=
hides it from Inspect rather than removing it. AshTypescript.Rpc.ResultPro= cessor strips these markers to nil on its template-driven paths, but normal= ize_primitive/1 in lib/ash_typescript/rpc/result_processor.ex had no such c= lause, so a marker fell through to the generic struct branch which calls Ma= p.from_struct/1 and serializes every key, original_value included. The deni=
ed value is returned to the caller inside the marker that represents its ow=
n denial. The simplest trigger is an action returning an embedded resource =
as a map, which routes through normalize_resource_struct/2 with an empty te= mplate. normalize_value_for_json/1 is a public, unguarded entry point to th=
e same path. This issue affects ash_typescript: from 0.11.0 before 0.18.0. = 2026-09-01 not yet calculated CVE-2026-82730 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-82730 ] ash-project--ash_typescript URL Redirection to Untr= usted Site ('Open Redirect') vulnerability in ash-project ash_typescript al= lows an attacker who controls a path-parameter value to redirect a generate=
d client's request, and the credentials attached to it, to an unintended ro= ute or an external origin. The URL builders in lib/ash_typescript/typed_con= troller/codegen/route_renderer.ex replace each :param placeholder with a ba=
re template interpolation and never call encodeURIComponent, so the value r= eaches executeTypedControllerRequest raw. A value containing ../ is normali= sed away by the fetch URL resolver and reaches a different route, while ? o=
r # truncates the path and can smuggle or override query parameters. For a = route whose path begins with a parameter, a value such as /evil.example.com=
/x yields the protocol-relative URL //evil.example.com/x, sending the reque=
st and the credentials from TypedControllerConfig to an attacker-controlled=
host. Nothing constrains the value at runtime: get_path_param_type/2 emits=
only a TypeScript type, which is erased. The query-string path is unaffect= ed, since URLSearchParams.set encodes its own values. This issue affects as= h_typescript: from 0.15.0 before 0.18.0. 2026-09-01 not yet calculated CVE-= 2026-82731 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82731 ] ash-projec= t--ash_typescript Improper Input Validation vulnerability in ash-project as= h_typescript allows a remote attacker to submit argument values outside a d= eclared allowlist or bound on typed-controller routes. AshTypescript.TypedC= ontroller.RequestHandler in lib/ash_typescript/typed_controller/request_han= dler.ex calls Ash.Type.cast_input/3 and treats an {:ok, cast} result as ful=
ly validated. In Ash these are separate steps: cast_input/3 only coerces th=
e term, while every constraint declared on the argument is applied by Ash.T= ype.apply_constraints/3, which this path never calls. Constraints such as o= ne_of, max_length, min and max, and match are therefore inert, so a value o= utside a declared allowlist is accepted and passed to the route handler. Co= degen renders the same constraints into the generated TypeScript types, so =
an allowlist appears enforced to a TypeScript caller while any other HTTP c= lient ignores it. Empty-string to nil normalization also lives in apply_con= straints, so the allow_nil?: false check accepts "" for a required argument=
. Where a constraint gates a role, a status, or a sort direction, this beco= mes a privilege or state-machine bypass. This issue affects ash_typescript:=
from 0.15.0 before 0.18.0. 2026-09-01 not yet calculated CVE-2026-82732 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-82732 ] ash-project--ash_typesc= ript Generation of Error Message Containing Sensitive Information vulnerabi= lity in ash-project ash_typescript allows an unauthenticated attacker to re=
ad internal application data from an HTTP 500 response body. When a typed-c= ontroller route handler returns anything other than a %Plug.Conn{}, dispatc= h/3 in lib/ash_typescript/typed_controller/request_handler.ex passes the va= lue to unexpected_return/2, which interpolates inspect(value, limit: 50) di= rectly into the response message. The limit option bounds elements per coll= ection rather than the term as a whole, so a handler falling through with a=
term such as {:error, %User{}} or a changeset serialises its full field se=
t, including hashed passwords, tokens, and tenant identifiers, into the JSO=
N error returned to the caller. This contradicts the module's own posture e= lsewhere: the rescue clause gates Exception.message/1 behind AshTypescript.= typed_controller_show_raised_errors?/0 and otherwise returns a generic mess= age, while this path is ungated and always echoes. This issue affects ash_t= ypescript: from 0.15.0 before 0.18.0. 2026-09-01 not yet calculated CVE-202= 6-82733 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82733 ] ash-project--= ash
=C2=A0 Improper Validation of Specified Quantity in Input vulnerability in = ash-project ash allows an attacker to store a value of arbitrary size in an=
attribute whose length constraint should bound it. Ash measures string len= gth with Elixir's String.length/1, which counts Unicode graphemes, in the m= ax_length and min_length constraints of Ash.Type.String (apply_constraints/=
2 in lib/ash/type/string.ex), in Ash.Resource.Validation.StringLength, and =
in the string_length expression function. A grapheme carries an unbounded n= umber of combining marks, so a base character followed by a million combini=
ng acute accents is one grapheme and megabytes of data, and satisfies max_l= ength: 2. Where the data layer imposes no independent limit (ETS, Mnesia, o=
r a Postgres text column) the whole value is persisted, so an attacker can = write an entire request body into an attribute declared with a small maximu=
m and grow storage without bound. The counting unit also disagrees with the=
storage layer, which counts codepoints rather than graphemes, so a value a= ccepted by the constraint can still be rejected or truncated by the column.=
A Postgres varchar(n) column bounds the value itself and is not exposed. T= his issue affects ash: from 0.10.0 before 3.33.0. 2026-09-05 not yet calcul= ated CVE-2026-82752 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82752 ] A= SUS--Control Center Enterprise (ACC) Missing Authentication for Critical Fu= nction, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentia=
ls in ASUS Control Center=C2=A0allow an unauthorized user to obtain the enc= ryption key via an HTTP request, causing a local service to enable SSH on p= ort 2222. The attacker can then log in with the hardcode credentials=C2=A0t=
o obtain a root shell, enabling direct reading, writing, and deletion of da=
ta on ASUS Control Center, as well as remote control of all servers, PCs, a=
nd workstations within the company. Refer to the 'Security Update for ASUS = Control Center' section on the ASUS Security Advisory for more information.=
2026-09-04 not yet calculated CVE-2026-75754 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-75754 ] Authen-SASL::Perl::DIGEST_MD5
=C2=A0 Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accep=
t replayed authentication responses via unverified nonce in server_step. se= rver_start generates a fresh nonce and sends it in the challenge, and nothi=
ng later compares that value against the nonce the client returns. server_s= tep derives the expected digest from the client's own parameters, so a resp= onse verifies whenever its digest matches the nonce it carries. The count t= able it also checks is keyed on the client-supplied nonce and starts empty =
in each new server object, so a captured first response, carrying `nc=3D000= 00001`, passes that too. RFC 2831 defines the nonce in the response as the = value the server sent in the preceding challenge. An attacker who observes = one successful `qop=3Dauth` exchange can replay the captured response again=
st a later session for the same service, host, realm and user, and authenti= cate as that user without knowing the password. 2026-09-06 not yet calculat=
ed CVE-2026-86219 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86219 ] Bac= kblaze--Backblaze Client A vulnerability in the Backblaze Client allows a l= ocal user to make the system not bootable by creating a link from Backblaze=
's folder to Windows OS system files during a backup. Successful exploitati=
on requires an administrator-level system change that results in the absenc=
e of specific Windows OS security controls. This vulnerability is due to im= proper link resolution. 2026-09-01 not yet calculated CVE-2026-19820 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-19820 ] Baserow--Baserow Baserow 2.= 3.3 contains a SQL injection vulnerability in the index() formula function.=
A low-privileged authenticated user who can create or modify formula field=
s can provide an undocumented fourth argument that is treated as a SQL temp= late and interpolated directly into a PostgreSQL expression. The vulnerable=
expression is executed when Baserow recalculates formula field values. Bec= ause the generated SQL runs through Baserow's database connection, the inje= cted SQL executes with the privileges of the Baserow PostgreSQL role rather=
than the permissions of the authenticated application user. This issue aff= ects Baserow: 2.3.3. 2026-09-02 not yet calculated CVE-2026-19754 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-19754 ] Checkmk GmbH--Checkmk Improper=
certificate validation in Checkmk <2.5.0p10 allows a relay and a push agen=
t that share the same UUID to reuse each other's mTLS certificate to authen= ticate against agent receiver endpoints in either direction, because the en= dpoints do not verify that the certificate was issued by their own root cer= tificate. 2026-09-04 not yet calculated CVE-2026-15937 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-15937 ] composer--composer Composer is a dependen=
cy Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malici= ous dependency package from a custom Composer repository or an untrusted co= mposer.lock file could set source.type to perforce and source.url to an rsh=
: or jsh: P4PORT value. When the Perforce p4 client was installed and Compo= ser installed the package from source through composer install or composer = update, including --prefer-source, Composer\Util\Perforce passed the addres=
s to p4 without validation, causing p4 to run a local command with the priv= ileges of the user or CI account. Packagist.org does not permit Perforce so= urce metadata. This issue is fixed in versions 2.2.30 and 2.10.3. 2026-09-0=
1 not yet calculated CVE-2026-84361 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-84361 ] craftcms--cms The vulnerability allows any authenticated use=
r to change their own password without providing the current password or ha= ving an active elevated session. It also allows the attacker to change othe=
r users' passwords if the attacker's account has=C2=A0Edit users=C2=A0permi= ssion (which doesn't allow changing others' passwords) and lacks=C2=A0Admin= istrate users=C2=A0permission (which is required to change others' password= s). 2026-09-02 not yet calculated CVE-2026-79989 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-79989 ] craftcms--cms Craft CMS GraphQL entry mutation = resolvers (saveEntry,=C2=A0deleteEntry) read=C2=A0siteIddirectly from$argum= entswithout passing throughArgumentManagerprepareArguments(), which is the = function that enforces site-scope filtering via=C2=A0array_intersect=C2=A0a= gainst the GraphQL schema's allowed sites. The query path (ElementResolverp= repareElementQuery) correctly calls=C2=A0prepareArguments()`, so queries to=
unauthorized sites return empty. But mutations bypass this entirely - an a= ttacker with a token scoped to Site A can create, modify, or delete entries=
in Site B by passing siteId in the mutations argument. 2026-09-02 not yet = calculated CVE-2026-79990 [
https://www.cve.org/CVERecord?id=3DCVE-2026-799=
90 ] craftcms--cms Craft CMS GraphQL entry mutation resolvers (saveEntry,= =C2=A0deleteEntry) read=C2=A0siteIddirectly from$argumentswithout passing t= hroughArgumentManagerprepareArguments(), which is the function that enforce=
s site-scope filtering via=C2=A0array_intersect=C2=A0against the GraphQL sc= hema's allowed sites. The query path (ElementResolverprepareElementQuery) c= orrectly calls=C2=A0prepareArguments()`, so queries to unauthorized sites r= eturn empty. But mutations bypass this entirely - an attacker with a token = scoped to Site A can create, modify, or delete entries in Site B by passing=
siteId in the mutations argument. 2026-09-02 not yet calculated CVE-2026-7= 9991 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79991 ] CRMEB --CRMEB v6= .0.0
=C2=A0 An arbitrary file deletion vulnerability in the /adminapi/file/video= _data_save component of CRMEB v6.0.0 allows authenticated attackers to dele=
te arbitrary files via crafted POST request. 2026-09-04 not yet calculated = CVE-2026-79426 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79426 ] curl -= -curl
=C2=A0 A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) inst= ead of space (ascii code 32) immediately before the `Secure` attribute caus=
es curl to store the cookie without its Secure flag. The cookie might then = wrongfully be sent over plaintext HTTP on subsequent requests to the same h= ost. 2026-09-06 not yet calculated CVE-2026-80255 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-80255 ] dignifiedquire--async-tar async-tar is a tar a= rchive reading/writing library for async Rust. Prior to version 0.6.1, asyn= c-tar mis-applies a buffered PAX size extension to an intermediary extensio=
n header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead =
of to the next file entry. POSIX requires a PAX extended-header record set =
to describe the next file entry, never an intervening extension header. Bec= ause poll_next_raw (src/archive.rs) threads the buffered PAX records into t=
he size computation of whatever raw header it reads next - and that header = can be an intermediary L - the stream cursor is advanced by an attacker-cho= sen amount when the L body is consumed. The parser then desyncs relative to=
a POSIX-correct tar parser (e.g. GNU tar), reading subsequent bytes at the=
wrong block boundary. This issue has been patched in version 0.6.1. 2026-0= 9-02 not yet calculated CVE-2026-53600 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-53600 ] easyadmin --easyadmin =C2=A0v2.0.2.2
=C2=A0 easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with=
Dangerous Type in the background management interface which allows authent= icated remote attackers to execute arbitrary code and gain server privilege=
s via a crafted file upload. 2026-09-04 not yet calculated CVE-2026-50894 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-50894 ] Eclipse Foundation--Ec= lipse aeriOS In the current development version of Eclipse aeriOS, which ha=
s not yet had an official release, the KrakenD instance included in the API=
Gateway component had the disable_jwk_security parameter hard-coded to tru=
e, with no option to override it through the Helm chart configuration. This=
setting disables TLS certificate verification when KrakenD retrieves the J= SON Web Key Set (JWKS) used to validate bearer tokens, potentially allowing=
an attacker with the ability to intercept this communication to provide a = malicious JWKS and compromise token validation. The issue has been addresse=
d by making the parameter configurable through the boolean Helm value krake= nd.config.disableJwkSecurity and setting its default value to false, ensuri=
ng that TLS certificate verification is enabled by default. 2026-09-02 not = yet calculated CVE-2026-82955 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -82955 ] Eclipse Foundation--Eclipse aeriOS In the current development vers= ion of Eclipse aeriOS, for which no official release has yet been published=
, the Federator component disables TLS certificate validation for outbound = HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environme=
nt variable is unset or set to false, the component configures its HTTP tra= nsport to skip TLS certificate verification. As a result, an attacker able =
to intercept network communications between the Federator and external serv= ices could impersonate those services and intercept sensitive information t= ransmitted over HTTPS, including OAuth client credentials and bearer tokens=
. The issue has been addressed by enabling TLS certificate validation by de= fault. The TLS_CERTIFICATE_VALIDATION environment variable is now set to tr=
ue in the default configuration provided by the Helm chart and Docker Compo=
se deployment. 2026-09-03 not yet calculated CVE-2026-84736 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-84736 ] Eclipse Foundation--Eclipse aeriOS E= clipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path trav= ersal vulnerability in the REST API. User-controlled identifiers used to cr= eate, update, or delete Self-orchestrator resources were incorporated into = filesystem paths without adequate validation or sanitization. An unauthenti= cated remote attacker able to access the Self-orchestrator API could theref= ore supply specially crafted identifiers containing path traversal sequence=
s to write or delete JSON files outside the intended application directorie=
s, subject to the filesystem permissions of the Self-orchestrator process. = The impact is increased by the absence of authentication on the affected AP=
I and by the container running with elevated privileges in the affected dep= loyment configuration. The issue has been addressed in version 1.2.1 by int= roducing validation and sanitization of user-controlled identifiers before = they are used to construct filesystem paths, preventing path separator char= acters from being used to escape the intended directories. 2026-09-03 not y=
et calculated CVE-2026-85199 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 85199 ] Eclipse Foundation--Eclipse Arrowhead In Eclipse Arrowhead versions=
from 5.0.0 to 5.2.1 the management-authorization gate that protects every = //mgmt/ REST endpoint decides whether to apply its check by calling request= .getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestUR= L() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded = path. Requesting /serviceregistry/%6Dgmt/systems (%6D =3D=3D m) therefore f= ails the substring check - the filter falls through without authorising - y=
et is decoded to /serviceregistry/mgmt/systems and dispatched to the manage= ment controller. Spring Security's StrictHttpFirewall (active via spring-bo= ot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and=
null bytes, so percent-encoded ASCII letters pass through. Any authenticat=
ed system - regardless of privilege - can reach every management operation,=
including POST /authentication/mgmt/identities which creates new sysop acc= ounts, yielding full administrative takeover of the local cloud. 2026-09-03=
not yet calculated CVE-2026-80515 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-80515 ] Eclipse Foundation--Eclipse Arrowhead In Eclipse Arrowhead ve= rsions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificat=
e authentication policy, CertificateMqttFilter parses an X.509 certificate = that the client sends inside the MQTT message payload (the authentication f= ield of MqttRequestTemplate) and treats its Subject DN as the authenticated=
identity. The certificate is decoded with CertificateFactory.generateCerti= ficate() but its signature is never verified and its issuer chain is never = validated against any trust store. Authorisation is reduced to two string c= omparisons on attacker-supplied data: the DN-qualifier must equal "sy" or "= op", and the cloud-name part of the CN must match the server's. Both values=
are public (the cloud name is in the server's own TLS certificate). An att= acker who can publish to the MQTT broker can therefore mint a self-signed c= ertificate with CN=3DSysop.<cloud>.<org>.arrowhead.eu, dnQualifier=3Dop, se=
nd it as the authentication field, and be authenticated as the cloud's syst=
em operator with isSysOp =3D=3D true. This passes the downstream Management= ServiceMqttFilter (request.isSysOp() =C3=A2=E2=80=A0=E2=80=99 allowed) and = gives full management access over MQTT. The HTTP CertificateFilter is not a= ffected - it reads the certificate from jakarta.servlet.request.X509Certifi= cate, which Tomcat populates only after a successful mTLS handshake against=
the configured trust store. 2026-09-03 not yet calculated CVE-2026-82180 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-82180 ] Eclipse Foundation--Ec= lipse Ditto In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCrea= tionMessageMapper of the connectivity service builds a CreateThing command =
by substituting placeholder values (e.g. {{ header:device_id }}) resolved f= rom inbound message headers into a pre-configured JSON "thing" template as = raw, un-escaped strings, and then parses the resulting string as JSON. Beca= use the placeholder engine performs no JSON escaping and is unaware of the = surrounding JSON string context, a resolved value containing a double-quote=
character can break out of its string and inject additional JSON structure=
. When a connection is configured to use this mapper with a template that r= eflects a header whose value a publishing device can control (for example a=
n MQTT 5 user property, an AMQP 1.0 application property, or a Kafka record=
header), an attacker able to publish on that connection can inject an inli=
ne _policy object. The inline policy overrides the administrator-configured=
policyId, letting the attacker assign an arbitrary access-control policy t=
o the newly created digital twin - gaining full read/write access to it and=
potentially revoking the legitimate owner's access, with no administrator = interaction. Exploitation requires all of the following: the connection use=
s the (non-default) ImplicitThingCreation mapper; its template reflects an = attacker-controllable header; and, for the policy-override impact, the conn= ection's authorization subjects are permitted to create policies (the defau= lt). Deployments that restrict the connection's subjects to thing creation = only via the entity-creation configuration are not affected by the policy-o= verride impact. 2026-09-02 not yet calculated CVE-2026-82958 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-82958 ] Eclipse Foundation--Eclipse Ditto I=
n Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (We=
b of Things) ThingModels over HTTP from URLs supplied by API users in the d= efinition field of a Thing or Feature, without validating the target host, = and follows HTTP redirects without re-validating the redirect target and wi= thout a hop limit. An authenticated user who is permitted to create a Thing=
, or who holds WRITE permission on an existing Thing, can thereby cause the=
Things service to issue arbitrary HTTP GET requests from inside the deploy= ment's network - including to cloud instance-metadata endpoints and other i= nternal services - and can use the differing error responses returned to th=
e caller to enumerate internal services. Versions 2.4.0 to 2.5.x contain th=
e same code, but are only affected where the operator explicitly enabled th=
e WoT integration feature toggle, which is disabled by default in those ver= sions. 2026-09-02 not yet calculated CVE-2026-84175 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-84175 ] elixir-mint--mint Allocation of Resources Wi= thout Limits or Throttling vulnerability in elixir-mint mint allows a remot=
e HTTP server to exhaust memory on the client host and cause a denial of se= rvice. Two HTTP/1 response-parser states accumulate server data without any=
cap. In lib/mint/http1.ex, decode_status_line/4 stores the unconsumed data=
in conn.buffer when the status line is incomplete, and decode_body/5 does = the same for an unterminated chunk-extension line. Both wait for a CRLF the=
server never has to send, and conn.buffer is prepended to every subsequent=
socket message. The :max_header_list_size budget is wired only into decode= _headers/5 and decode_trailer_headers/4, so neither of these states is cove= red by it. A malicious server, or one reached through an attacker-controlle=
d redirect or a fetched URL, streams bytes indefinitely until the BEAM node=
is killed by the operating system out-of-memory handler. The chunk-extensi=
on variant is reached after a valid status line and a complete, valid heade=
r section, so an intermediary inspecting only headers sees an ordinary 200 = response. This issue affects mint: from 0.1.0 before 1.10.0. 2026-09-04 not=
yet calculated CVE-2026-82728 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-82728 ] elixir-mint--mint Inefficient Algorithmic Complexity vulnerabilit=
y in elixir-mint mint allows a remote HTTP server to exhaust CPU on the cli= ent host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http= 1/parse.ex folds each hex digit of a chunked response's chunk-size field in=
to an arbitrary-precision accumulator with acc * 16 + digit and imposes no = limit on the digit count. Because the accumulator grows without bound, the = multiplication is not constant time and one pass over N digits costs O(N sq= uared). handle_data/2 prepends conn.buffer and re-parses from the start on = every socket message, so a server that dribbles the digits out in small pac= kets makes the client pay that cost repeatedly. A run of roughly 512,000 he=
x digits costs over ten seconds of CPU in a single pass, measured on stock = defaults. The parser reaches this state after a valid status line and a com= plete, valid header section, so an intermediary inspecting only headers see=
s an ordinary 200 response. This issue affects mint: from 1.9.3 before 1.10= .0. 2026-09-04 not yet calculated CVE-2026-82729 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-82729 ] ellite--Wallos Wallos is an open-source, self-h= ostable personal subscription tracker. Prior to version 4.9.4, login.php ge= nerates an OIDC state nonce stored in $_SESSION['oidc_state'], but checkses= sion.php dispatches the OIDC callback without comparing the incoming state = against the session value. An attacker can trick a victim into visiting a c= rafted URL, causing Wallos to exchange the attacker's authorization code an=
d log the victim into the attacker's account. This issue has been patched i=
n version 4.9.4. 2026-08-31 not yet calculated CVE-2026-54599 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-54599 ] ellite--Wallos Wallos is an open-s= ource, self-hostable personal subscription tracker. Prior to version 4.9.4,=
endpoints/db/import.php has no authentication. The only guard is a user-ta= ble row count - if zero (fresh/unconfigured install), an unauthenticated at= tacker can replace the entire database. This issue has been patched in vers= ion 4.9.4. 2026-08-31 not yet calculated CVE-2026-54600 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-54600 ] ellite--Wallos Wallos is an open-source,=
self-hostable personal subscription tracker. Prior to version 4.9.6, POST = /endpoints/notifications/testemailnotifications.php accepts smtpaddress and=
smtpport from POST body with zero SSRF validation. PHPMailer connects to a= ttacker-supplied host:port. Every other notification endpoint uses ssrf_hel= per.php but email was missed. Any authenticated user can probe internal net= work, cloud metadata. This issue has been patched in version 4.9.6. 2026-08= -31 not yet calculated CVE-2026-61638 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-61638 ] ellite--Wallos Wallos is an open-source, self-hostable per= sonal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/rest= ore.php calls ZipArchive::extractTo() without validating entry names for ..=
/ sequences. Admin uploads crafted zip with entry logos/../../endpoints/she= ll.php to write webshell to webroot. Extension filter only applies to post-= extraction logo copy step. This issue has been patched in version 4.9.6. 20= 26-08-31 not yet calculated CVE-2026-61639 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-61639 ] ellite--Wallos Wallos is an open-source, self-hostabl=
e personal subscription tracker. Prior to version 4.9.6, Admin-configured O= IDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:1= 8-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo= /webhook URLs which have validate_webhook_url_for_ssrf(), OIDC URLs bypass = all protections. Admin sets URL to
http://169.254.169.254/latest/meta-data/=
for cloud metadata access or internal network pivoting. This issue has bee=
n patched in version 4.9.6. 2026-08-31 not yet calculated CVE-2026-61640 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-61640 ] emlog--emlog Emlog is a=
n open source website building system. In versions 2.6.29 and prior, the em= UnZip() function extracts all ZIP entries via ZipArchive::extractTo() witho=
ut validating entry paths for ../ traversal sequences. Only the first entry=
's subdirectory structure is checked. An attacker can overwrite arbitrary f= iles on the server filesystem, including config.php for immediate RCE. At t= ime of publication, there are no publicly known patches. 2026-09-04 not yet=
calculated CVE-2026-53757 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53= 757 ] emlog--emlog Emlog is an open source website building system. In vers= ions 2.6.29 and prior, article content is processed by Parsedown without en= abling safe mode, which means raw HTML including <script> tags embedded in = Markdown is passed through unescaped. The output is rendered with no additi= onal sanitization, resulting in stored XSS visible to all site visitors. At=
time of publication, there are no publicly known patches. 2026-09-04 not y=
et calculated CVE-2026-53758 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 53758 ] emlog--emlog Emlog is an open source website building system. In ve= rsions 2.6.29 and prior, tag names in emlog are not HTML-encoded when rende= red in the article editor. An attacker can create a tag containing ');alert= (document.domain);//. The addslashes() function does not escape HTML entiti= es, so ' is stored as-is. When the browser renders the page, it decodes ' b= ack to a literal single quote before evaluating the JavaScript, breaking ou=
t of the string and executing arbitrary code. At time of publication, there=
are no publicly known patches. 2026-09-04 not yet calculated CVE-2026-7384=
8 [
https://www.cve.org/CVERecord?id=3DCVE-2026-73848 ] EMX Tecnologia--Ges= tao X EMX Tecnologia Gestao X version <=3D 8.4 contains a Stored Cross-Site=
Scripting (XSS) vulnerability in the Help Chat functionality. Improper neu= tralization of user-controlled input during web page generation allows auth= enticated attackers to execute arbitrary JavaScript in the context of other=
authenticated users, potentially resulting in session hijacking, account t= akeover, and unauthorized actions. 2026-09-04 not yet calculated CVE-2026-7= 9418 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79418 ] EMX Tecnologia--= Gestao X A reflected cross-site scripting (XSS) vulnerability exists in EMX=
Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is c= aused by insufficient validation and sanitization of the mensagem parameter=
in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated atta= cker to inject arbitrary JavaScript code that is reflected and executed in = the context of a victim's browser. 2026-09-04 not yet calculated CVE-2026-7= 9419 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79419 ] enchant97--note-= mark Note Mark is an open-source note-taking application. Prior to version = 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma=
tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Pat= tern) and tests it with patternRe.MatchString(str), an UNANCHORED match. Be= cause the pattern is not anchored (^...$), any string that merely CONTAINS = one [a-z0-9-] substring passes validation. A slug such as ../../../../../..= /tmp/escape is accepted and stored verbatim. The data-export CLI commands (= note-mark migrate export and note-mark migrate export-v1) join these unsani= tized slugs straight into the output path with path.Join / filepath.Join, t= hen os.MkdirAll the directory and os.Create the note file. path.Join resolv=
es the ../ segments, so the note content file is written OUTSIDE the config= ured export directory. The export process commonly runs as root (default in=
Docker / bare-metal admin usage), so this is a root-privilege arbitrary di= rectory create + file write. This issue has been patched in version 0.19.5.=
2026-09-04 not yet calculated CVE-2026-50553 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-50553 ] Erlang--OTP The Erlang/OTP httpc HTTP client does = not enforce a limit on the total size of response headers received from a s= erver. The max_header_size option defaults to nolimit, and httpc_response:p= arse_headers/6 accumulates every header into a list before the length check=
runs (which only fires after the terminating CRLF CRLF is received). A mal= icious or compromised HTTP server can send an arbitrarily large number of h= eaders, or headers with very large values, causing the client process to al= locate unbounded memory until the system runs out of memory or the BEAM VM = crashes. A proof-of-concept server sending 100,000 headers of roughly 4000 = bytes each caused the client VM to allocate over 13 GB of memory in under 3=
0 seconds. Any application using httpc:request/4,5 to connect to untrusted = servers is affected. No authentication is required: any server the client c= onnects to (including via a redirect or man-in-the-middle) can trigger the = exhaustion. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.= 4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 b= efore OTP=C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7, fro=
m 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP=C2= =A017.0, corresponding to inets before 5.10, is affected is unknown. 2026-0= 9-01 not yet calculated CVE-2026-55951 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-55951 ] Erlang--OTP Improper Validation of Specified Quantity i=
n Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degr= ade availability by supplying a URI whose port component is a very long run=
of digits. uri_string:get_port/1 passes the port substring to binary_to_in= teger/1 with no length bound, catching only error:badarg, so a syntacticall=
y valid port of up to roughly 1.26 million digits converts successfully and=
costs the calling process hundreds of milliseconds of arbitrary-precision = arithmetic. The conversion is reached from every authority-parsing path in = uri_string:parse/1, including the host, registered-name, and IPv4 and IPv6 = forms. parse/1 is the documented interface for parsing URIs, so any applica= tion that parses an attacker-supplied URI is exposed without further config= uration. The conversion function is documented to accept integers of any si= ze, so bounding the input is the caller's responsibility. This issue affect=
s OTP from OTP=C2=A021.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 befo=
re OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corres= ponding to stdlib from 3.5 before 6.2.2.5, from 7.0 before 7.3.0.2, and fro=
m 8.0 before 8.0.4. 2026-09-01 not yet calculated CVE-2026-59696 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-59696 ] Erlang--OTP httpd has never imp= lemented obs-fold (RFC 2616 =C3=82=C2=A72.2 / RFC 7230 =C3=82=C2=A73.2.4 he= ader continuation lines). Every CRLF followed by a non-CRLF octet unconditi= onally starts a new header. This missing feature became a security concern =
as the understanding of HTTP request smuggling attacks evolved. This issue = affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.=
0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, = corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, a=
nd from 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0, corresponding t=
o inets before 5.10, is affected is unknown. 2026-09-01 not yet calculated = CVE-2026-66357 [
https://www.cve.org/CVERecord?id=3DCVE-2026-66357 ] Erlang= --OTP Path Equivalence vulnerability in Erlang/OTP inets httpd allows a rem= ote unauthenticated attacker to read files inside a mod_auth protected dire= ctory by prefixing the request path with an extra slash. httpd_request:vali= date_uri/1 normalises the request URI with uri_string:normalize/1, which pe= rforms RFC 3986 dot-segment removal but does not collapse empty path segmen= ts, so a doubled slash survives. mod_alias:real_name/3 concatenates the doc= ument root with that URI, and mod_auth:secret_path/3 then decides whether t=
he result lies inside a protected directory block by running the configured=
directory path as an unanchored regular expression against it. The doubled=
slash breaks the contiguous substring the regex needs, so the request is t= reated as unprotected and no authentication challenge is issued, while mod_= get opens the same path and the operating system collapses the doubled slas=
h and returns the protected file. The same path mismatch also evades the pe= r-path accounting in mod_security. This issue affects OTP from OTP=C2=A017.=
0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, a=
nd from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 5= .10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whe= ther OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is affec= ted is unknown. 2026-09-01 not yet calculated CVE-2026-66835 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-66835 ] Erlang--OTP Missing Release of Reso= urce after Effective Lifetime vulnerability in Erlang/OTP inets httpd allow=
s an unauthenticated remote attacker to cause denial of service by sending =
a request with a chunked body whose chunk-size line is not a hexadecimal nu= mber. The worker serving the connection is never released and no timeout re= claims it, so repeating the request across connections occupies every avail= able worker and denies service to legitimate clients. No authentication is = required and the default configuration is affected. The chunk-size line mus=
t arrive in a write separate from the headers. When the body accompanies th=
e headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 in= side a try ... catch throw:Error, so the {error, {chunk_size, _}} thrown by=
http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk = size arrives later, the decoder is resumed through a bare catch in httpd_re= quest_handler:handle_info/2, which converts the throw into a return value r= ather than raising it; the resulting error tuple is then treated as the nex=
t decoder continuation, the socket is re-armed, and the worker waits for da=
ta that never comes. The request timeout has already been cancelled at the = point the headers were accepted, and the periodic byte-rate check is only a= rmed when minimum_bytes_per_second is configured, which it is not by defaul=
t. This issue affects OTP from OTP=C2=A018.1.4 before OTP=C2=A027.3.4.17, f= rom OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before O= TP=C2=A029.0.6, corresponding to inets from 6.0.3 before 9.3.2.7, from 9.4 = before 9.6.2.3, and from 9.7 before 9.7.2. 2026-09-01 not yet calculated CV= E-2026-69664 [
https://www.cve.org/CVERecord?id=3DCVE-2026-69664 ] Erlang--= OTP Allocation of Resources Without Limits or Throttling vulnerability in E= rlang/OTP inets httpd allows an unauthenticated remote attacker to cause de= nial of service by opening and holding open a large number of connections. = The max_clients option is documented to default to 150, and the inets harde= ning guide presents that limit as the first layer of denial-of-service defe= nce, but a server that does not set it explicitly accepts an unlimited numb=
er of simultaneous connections. Establishing the connections is sufficient;=
no valid request and no authentication are required. The accept gate in ht= tpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup= /2, which returns undefined when the key is absent, rather than the three-a= rgument form carrying the 150 default that the neighbouring get_ustate/2 us= es. Erlang term ordering places every integer before every atom, so the Cou=
nt =3D< Max guard holds for any connection count and the server never retur=
ns {reject, busy}. Each accepted connection occupies a worker process and a=
socket for as long as it is held, driving the node towards process, memory=
and file descriptor exhaustion. Servers that set max_clients explicitly ar=
e unaffected, because a configured value is applied as intended. This issue=
affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028=
.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6,=
corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, = and from 9.7 before 9.7.2. 2026-09-01 not yet calculated CVE-2026-70399 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-70399 ] Erlang--OTP Improper Val= idation of Specified Quantity in Input vulnerability in Erlang/OTP snmp all= ows a remote attacker to degrade availability by sending an SNMP message co= ntaining a BER INTEGER whose length field is arbitrarily large. snmp_pdus:d= ec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_= notag/2 then accumulates the value across every declared byte with a recurs= ive shift and bitwise or. Work grows superlinearly in the declared length b= ecause each operation acts on a progressively larger bignum. The size-limit=
ed variant dec_integer_notag/2 exists but is reached from only one call sit=
e, dec_snmp_version/1, which bounds the version field to ten bytes; the req= uest identifier, error status and index, generic and specific trap fields, = engine boots and time, and every varbind value decoded by dec_value/1 all u=
se the unbounded form. The decode runs before the PDU is processed, so no v= alid request is required beyond what the deployment demands to accept the m= essage at all. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027= .3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.=
0 before OTP=C2=A029.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1=
, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP bef= ore OTP=C2=A017.0, corresponding to snmp before 4.25.1, is affected is unkn= own. 2026-09-01 not yet calculated CVE-2026-70405 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-70405 ] Erlang--OTP Improper Validation of Specified Q= uantity in Input vulnerability in Erlang/OTP eldap allows a malicious or co= mpromised LDAP server to degrade availability by returning a referral URL w= hose port component is a very long run of digits. eldap:parse_port/2 passes=
the port substring straight to list_to_integer/1 with no length bound. The=
surrounding try ... catch only rejects a value that fails to parse, so a s= yntactically valid port of up to roughly 1.26 million digits converts succe= ssfully and costs the caller hundreds of milliseconds of arbitrary-precisio=
n arithmetic per referral. The conversion function itself is documented to = accept integers of any size, so bounding the input is the caller's responsi= bility. Reaching the flaw requires the application to pass a server-supplie=
d referral to eldap:parse_ldap_url/1, which eldap never calls itself: refer= ral strings are returned to the caller unparsed. This issue affects OTP fro=
m OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2= =A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding t=
o eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1=
.3 before 1.3.1. 2026-09-01 not yet calculated CVE-2026-70409 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-70409 ] Erlang--OTP Missing Release of Res= ource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allo=
ws an unauthenticated remote attacker to cause denial of service by sending=
valid request headers with a large Content-Length and then stalling before=
the body is complete. httpd_request_handler:handle_info/2 cancels the requ= est timeout as soon as a parse step succeeds, which includes the headers, a=
nd the clause that handles a decoder asking for more data re-arms the socke=
t with {active, once} without setting any further timer. httpd_request:whol= e_body/2 returns such a continuation whenever the bytes received are fewer = than the announced Content-Length, so a well-formed request that stops mid-= body leaves the worker waiting indefinitely. The periodic byte-rate check t= hat would reclaim it is armed only when minimum_bytes_per_second is configu= red, which it is not by default. Repeating this across connections occupies=
every worker permitted by max_clients and denies service to legitimate cli= ents at negligible bandwidth cost. This issue affects OTP from OTP=C2=A017.=
0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, a=
nd from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 5= .10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whe= ther OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is affec= ted is unknown. 2026-09-01 not yet calculated CVE-2026-71380 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-71380 ] Erlang--OTP Improper Validation of = Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows =
a malicious or compromised HTTP server to degrade availability by returning=
a numeric header whose value is a very long run of digits. httpc_handler.e=
rl converts the server-supplied Content-Length with list_to_integer/1 befor=
e comparing it against max_body_size, so the size check cannot protect the = conversion, and the option defaults to nolimit in any case. The same unboun= ded conversion appears in httpc_response:format_response/1 for Content-Leng=
th and in httpc_response:get_ms_from_retry_after/1 for Retry-After, which i=
s guarded only by a check that the first character is a digit. A value of u=
p to roughly 1.26 million digits converts successfully and costs the reques= ting process hundreds of milliseconds of arbitrary-precision arithmetic per=
response. The conversion function is documented to accept integers of any = size, so bounding the input is the caller's responsibility. This issue affe= cts OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 be= fore OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corr= esponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and f= rom 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0, corresponding to in= ets before 5.10, is affected is unknown. 2026-09-01 not yet calculated CVE-= 2026-71562 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71562 ] Erlang--OT=
P Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets h= ttpd allows a remote unauthenticated attacker to read files inside a mod_au=
th protected directory by requesting them with different casing, on deploym= ents whose filesystem is case-insensitive. mod_auth:secret_path/3 decides w= hether a resolved filesystem path lies inside a protected directory block b=
y running the configured directory path through re:run/3 without the casele=
ss option. A request for /secret/file against a directory configured as /Se= cret therefore does not match, so the request is treated as unprotected and=
no authentication challenge is issued, while the filesystem resolves the d= ifferently cased path to the same file and mod_get serves it. Deployments o=
n case-sensitive filesystems are unaffected, because there the filesystem i= tself rejects the mismatched casing. This issue affects OTP from OTP=C2=A01= 7.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6,=
and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from=
5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. W= hether OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is aff= ected is unknown. 2026-09-01 not yet calculated CVE-2026-73270 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-73270 ] Erlang--OTP Gracefulness code ign= ored cases that should be rejected, resulting in possible HTTP Request Smug= gling opportunities. This issue affects OTP from OTP=C2=A022.2 before OTP= =C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP= =C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 7.1.2 before=
9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. 2026-09-01 no=
t yet calculated CVE-2026-73276 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-73276 ] Erlang--OTP httpd function check_header/3 rejects duplicate Cont= ent-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence = that RFC 9112 =C3=82=C2=A76.3 identifies as a probable smuggling attempt. h= andle_body/3 frames by chunked and silently discards Content-Length. A CL-p= referring front-end paired with chunked-preferring inets creates a classic = CL.TE front-end/back-end desync. This issue affects OTP from OTP=C2=A017.0 = before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and=
from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 5.1=
0 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Wheth=
er OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is affecte=
d is unknown. 2026-09-01 not yet calculated CVE-2026-73812 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-73812 ] Erlang--OTP The inets application HTT=
P server httpd fails to enforce a configured body-size limit on chunked req= uest. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, = from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before = OTP=C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 = before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0=
, corresponding to inets before 5.10, is affected is unknown. 2026-09-01 no=
t yet calculated CVE-2026-74835 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-74835 ] Erlang--OTP The mod_auth module in OTP's inets httpd server, whe=
n configured with dets or mnesia authentication backends and multiple direc= tory configuration blocks, collapses all directory blocks into a single sha= red user/group namespace. A user added to one protected directory is accept=
ed as valid for all other protected directories on the same server instance=
. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from=
OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP= =C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 bef= ore 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0, c= orresponding to inets before 5.10, is affected is unknown. 2026-09-01 not y=
et calculated CVE-2026-74994 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 74994 ] Erlang--OTP An attacker that connects to an open Erlang TCP port th=
at uses the inet driver with {packet,4} mode can use a signed overflow in a=
n incorrect packet length calculation to overflow the receive buffer into t=
he VM allocator area and beyond up to about 2 GB. This would easily trash t=
he allocated block's allocator metadata footer, and the next block, if any,=
and most likely cause the BEAM VM to crash. Utilizing this with precision = enough to achieve Remote Code Execution would be extremely unfeasible. This=
issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP= =C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2= =A029.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 befor=
e 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP=C2=A017.0, = corresponding to erts before 6.0, is affected is unknown. 2026-09-01 not ye=
t calculated CVE-2026-75538 [
https://www.cve.org/CVERecord?id=3DCVE-2026-7= 5538 ] esoTalk--esoTalk v.1.0.0g4
=C2=A0 An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute ar= bitrary code via the core/models/ETMemberModel.class.php, core/controllers/= ETMemberController.class.php, and core/lib/ET.class.php components 2026-09-=
04 not yet calculated CVE-2026-71624 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-71624 ] Extend Themes--Kubio AI Website Builder Improper input vali= dation vulnerability in Extend Themes Kubio AI Website Builder. This issue = affects Kubio AI Website Builder: before 2.9.1. 2026-08-31 not yet calculat=
ed CVE-2026-83492 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83492 ] fra= ppe--crm Frappe CRM is an open-source customer relationship management tool=
. Prior to version 1.73.0, there is an authentication bypass vulnerability = via logged invitation keys in crm/api. This issue has been patched in versi=
on 1.73.0. 2026-09-04 not yet calculated CVE-2026-53761 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-53761 ] Free5GC -- Free5GC v4.2.2
=C2=A0 An issue in Free5GC v.4.2.2 allows a remote attacker to cause a deni=
al of service via the UPF component 2026-09-04 not yet calculated CVE-2026-= 75439 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75439 ] getkirby--kirby=
Kirby is an open-source content management system. From 5.0.0 until 5.5.2,=
Kirby's REST API chunk upload handler in src/Api/Upload.php did not run th=
e relevant upload authorization preflight in Kirby\Api\Upload::process() be= fore Kirby\Api\Upload::processChunk() persisted chunk data. An authenticate=
d user with the access.panel permission enabled but with files.create, file= s.replace, and user/users.update permissions disabled could submit requests=
with an Upload-Length header and leave unfinished chunks in site/cache/.up= loads for 24 hours. Repeating this process could consume attacker-controlle=
d temporary storage, prevent other users from uploading files, or prevent s= ite logic from storing data, although final permission checks still prevent=
ed unauthorized files from reaching the content or site/accounts directorie=
s. This issue is fixed in version 5.5.2. 2026-08-31 not yet calculated CVE-= 2026-71415 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71415 ] getkirby--= kirby Kirby is an open-source content management system. Prior to 4.9.5 and=
5.5.2, depending on the release line, Kirby's media handler used incomplet=
e filesystem containment checks in src/Filesystem/Dir.php and src/Filesyste= m/F.php through Kirby\Filesystem\Dir::realpath() and Kirby\Filesystem\F::re= alpath(). The checks accepted a sibling directory whose path shared the int= ended root's string prefix, such as /var/www/site2 next to /var/www/site, b= ecause they did not require an exact match or a DIRECTORY_SEPARATOR boundar=
y. A remote attacker could use Kirby\Cms\Media::thumb() to create and acces=
s thumbnails from image files in a PHP-readable sibling directory when that=
directory contained a valid .json thumbnail job file, potentially exposing=
staging sites, backups, or other internal sites and deleting the job file = during processing. This issue is fixed in versions 4.9.5 and 5.5.2. 2026-08= -31 not yet calculated CVE-2026-75592 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-75592 ] getkirby--kirby Kirby is an open-source content management=
system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's m= edia handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to appen=
d a path-bearing filename to a validated parent media directory. On nginx, = PHP's built-in server, or Apache with AllowEncodedSlashes enabled, a remote=
attacker could submit encoded slash characters such as %2f in the filename=
and traverse outside the parent's media directory. Differences between res= ponses for existing and nonexistent thumbnail configurations disclosed whet= her an arbitrary .json file existed, and a .json file containing a valid fi= lename key could cause the referenced image to be returned and the job file=
to be deleted. The related file::version path in src/Filesystem/Asset.php = also accepted ../ sequences outside the intended index root. This issue is = fixed in versions 4.9.5 and 5.5.2. 2026-08-31 not yet calculated CVE-2026-7= 5594 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75594 ] GitHub--Enterpri=
se Server A server-side request forgery (SSRF) vulnerability was identified=
in GitHub Enterprise Server that allowed an unauthenticated attacker to ca= use the Manage API to send crafted outbound requests to an attacker-control= led host. An unauthenticated endpoint parsed an attacker-supplied cluster c= onfiguration and issued gateway-to-agent requests whose HMAC authenticated = only a timestamp, not the request path or body. An attacker positioned to i= ntercept the outbound request could capture this token and replay it agains=
t privileged management agent endpoints. High-availability deployments were=
not affected due to a topology restriction. This vulnerability affected al=
l versions of GitHub Enterprise Server prior to 3.22 and was fixed in versi= ons 3.17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4. This vulnerability was r= eported via the GitHub Bug Bounty program. 2026-09-01 not yet calculated CV= E-2026-18730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18730 ] GitHub--= Enterprise Server A time-of-check time-of-use race condition vulnerability = was identified in GitHub Enterprise Server that allowed remote code executi= on. Exploitation required an authenticated user with write access to a repo= sitory and precise timing of concurrent upload requests. This vulnerability=
affected all versions of GitHub Enterprise Server prior to 3.22 and was fi= xed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnera= bility was reported via the GitHub Bug Bounty program. 2026-09-01 not yet c= alculated CVE-2026-19118 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1911=
8 ] GitHub--Enterprise Server A Server-Side Request Forgery (SSRF) vulnerab= ility was identified in GitHub Enterprise Server that allowed remote code e= xecution on the instance. Insufficient network isolation allowed malicious = pre-receive hook code to impersonate an internal service and redirect trust=
ed internal requests to a privileged service, leading to elevated code exec= ution. Exploitation required pre-receive hook networking to be enabled and = either site administrator privileges or write access to a repository contai= ning a configured pre-receive hook. This vulnerability affected all version=
s of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.= 20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was reported v=
ia the GitHub Bug Bounty program. 2026-09-01 not yet calculated CVE-2026-76= 851 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76851 ] Google Cloud--Age=
nt Development Kit (ADK) A Path Traversal vulnerability in the builder endp= oint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.2= 1.0 on Python allows an unauthenticated remote attacker to read arbitrary f= iles using a crafted file_path query parameter. 2026-09-04 not yet calculat=
ed CVE-2026-79707 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79707 ] Goo= gle Cloud--Google Cloud Build An Incorrect Authorization vulnerability in G= itHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on = Google Cloud Platform allows a remote attacker to execute unreviewed code i=
n the build environment using webhook suppression. This vulnerability was p= atched on 24 June 2026, and no customer action is needed. 2026-08-31 not ye=
t calculated CVE-2026-19410 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 9410 ] Google Cloud--Integration Connectors A Missing Authorization vulnera= bility in HTTP Connector in Google Cloud Integration Connectors versions pr= ior to 2025-12-11 on Google Cloud Platform allows an authenticated user to = escalate privileges and take over a Google Cloud Project using unauthorized=
service account attachment. This vulnerability was patched on 11 December = 2025, and no customer action is needed. 2026-09-04 not yet calculated CVE-2= 026-4644 [
https://www.cve.org/CVERecord?id=3DCVE-2026-4644 ] Grav API Plug= in--Grav API Plugin
=C2=A0 Grav API plugin versions before 1.0.20 build password reset links fr=
om the untrusted Host header in the forgot-password endpoint, allowing unau= thenticated attackers to redirect reset tokens to attacker-controlled domai= ns. Attackers can send password reset requests for any account with a malic= ious Host header, intercept the reset token from victim emails, and complet=
e account takeover including super-admin accounts. 2026-09-05 not yet calcu= lated CVE-2026-86196 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86196 ] = Grav Form Plugin--Grav Form Plugin
=C2=A0 Grav Form Plugin before 9.1.22 fails to verify page authorization wh=
en resolving forms by name across pages, allowing anonymous visitors to exe= cute form actions defined on login-restricted or unpublished pages. Attacke=
rs can POST to any public page with a restricted form's name to trigger sav=
e, upload, email, or call actions without authentication. 2026-09-05 not ye=
t calculated CVE-2026-86194 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 6194 ] Grav--Grav
=C2=A0 Grav before 2.0.20 contains a cross-site scripting vulnerability in = the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Co= mmon\Assets without proper output escaping. Page editors can inject arbitra=
ry script by registering malicious assets or injecting attributes, which ar=
e rendered unescaped into document head tags and executed for all visitors = including administrators. 2026-09-05 not yet calculated CVE-2026-86197 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-86197 ] grav-plugin-api--grav-plu= gin-api
=C2=A0 grav-plugin-api before 1.0.20 fails to validate group-inherited supe=
r permissions in user-management guards, allowing non-super user managers t=
o modify super-admin accounts. Attackers with api.access and api.users.writ=
e can patch password fields on group-super accounts to gain full administra= tive control. 2026-09-05 not yet calculated CVE-2026-86193 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-86193 ] grav-plugin-api--grav-plugin-api
=C2=A0 grav-plugin-api versions before 1.0.20 contain a privilege escalatio=
n vulnerability in the InvitationsController where the stripSuperFlags() me= thod only removes nested super flags but fails to strip dot-keyed equivalen=
ts like api.super. A non-super user manager with api.access and api.users.w= rite permissions can create an invitation with a dot-keyed super flag in th=
e access payload that bypasses the guard and persists to the new account. A= ttackers can accept the invitation through the public endpoint without real=
invitee interaction to create a super-admin account and immediately receiv=
e a valid JWT for full site control. 2026-09-05 not yet calculated CVE-2026= -86195 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86195 ] GROWI, Inc.--G= ROWI GROWI contains a vulnerability with an authorization bypass through us= er-controlled key in the bookmark folder APIs. If this vulnerability is exp= loited, an authenticated attacker could retrieve, tamper with, and/or delet=
e the other user's bookmark data. 2026-08-31 not yet calculated CVE-2026-53= 620 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53620 ] GROWI, Inc.--GROW=
I GROWI contains an incorrect authorization vulnerability. If this vulnerab= ility is exploited, an unauthenticated attacker could retrieve the other us= er's bookmark data. 2026-08-31 not yet calculated CVE-2026-68951 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-68951 ] grpc--grpc-go gRPC-Go is the Go=
language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter=
in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher = names in normalizeHeaderMatcher even though incoming metadata keys are lowe= rcase. A DENY policy using a mixed-case name such as X-Role or User-Agent t= herefore does not match and fails open, allowing requests that should be re= jected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC=
A41 validation and prevents Host from being rewritten to :authority. This = issue is fixed in version 1.83.1. 2026-09-01 not yet calculated CVE-2026-84= 303 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84303 ] grpc--grpc-go gRP= C-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/t= ransport/transport.go stores each fragmented HTTP/2 DATA frame as a separat=
e recvMsg in recvBuffer, so millions of one-byte frames can consume disprop= ortionate heap memory even when payload bytes remain within connection and = stream flow-control windows. An unauthenticated remote attacker can use con= current multiplexed streams to exhaust process memory and cause a runtime p= anic or out-of-memory termination. Receive-buffer compaction is enabled by = default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_= RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1. 2026-09-0=
1 not yet calculated CVE-2026-84304 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-84304 ] HiDPT--Weyon HiDPTAndroid An issue in HiDPT/ Weyon HiDPTAndr= oid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrar=
y code via the Android Debug Bridge (ADB) daemon (adbd) 2026-09-04 not yet = calculated CVE-2026-78745 [
https://www.cve.org/CVERecord?id=3DCVE-2026-787=
45 ] Hitachi Energy--MicroSCADA SYS600 A CSV injection vulnerability exists=
in SYS600. Injected malicious formulas can add or modify data to the sprea= dsheet, insert links, exfiltrate data, and in some cases, depending on how = the user has their environment configured, execute malicious code on the us= er's machine. To exploit this issue attackers would need a way to create ar= bitrary log messages. This could be achieved through normal functionality v=
ia SCIL scripts, a log injection vulnerability, or via the SYS600 broker. T= his vulnerability affects all Windows users regardless of their privilege l= evel who can run the Notify service and export the log. 2026-09-03 not yet = calculated CVE-2026-9852 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9852=
] Hitachi Energy--MicroSCADA SYS600 A vulnerability exists in SYS600 which=
allows any user authenticated to the operating system of the server hostin=
g the application to read and modify application objects without being auth= enticated to the SYS600 system itself. Only the SYS600 system users should =
be permitted to view and modify application objects. 2026-09-03 not yet cal= culated CVE-2026-9853 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9853 ] = Hitachi Energy--MicroSCADA SYS600 A vulnerability exists in SYS600 RBAC mec= hanism where users having access to the engineering tools could elevate the=
ir privileges to administrator level on the underlying Windows host, granti=
ng themselves full control over the host machine. 2026-09-03 not yet calcul= ated CVE-2026-9854 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9854 ] HP = Inc--HP ImageDiags A potential security vulnerability has been identified i=
n the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could=
potentially allow a local attacker to escalate privileges due to insuffici= ent access controls. 2026-08-31 not yet calculated CVE-2026-82346 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82346 ] HP Inc.--HP Support Assistant =
A potential security vulnerability has been identified in the HP Support As= sistant for versions prior to 9.53.2.0. The vulnerability could potentially=
allow a local attacker to escalate privileges due to insufficient access c= ontrols. 2026-09-03 not yet calculated CVE-2026-15431 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-15431 ] HubCore--HubCore Cross-site scripting (XSS=
) vulnerability in the /loginController/doLogin endpoint of the HubCore pla= tform (version 14.1.1) allows a remote unauthenticated attacker to inject a= rbitrary JavaScript into the application's response via the language POST p= arameter. 2026-09-04 not yet calculated CVE-2026-75170 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-75170 ] HubCore--HubCore An issue in HubCore v.14= .1.1 allows a remote attacker to escalate privileges via the HUBCOREID sess= ion cookie handling component. 2026-09-04 not yet calculated CVE-2026-75171=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-75171 ] IBM--Verify Identity=
Access Advanced Access Control
=C2=A0 IBM Verify Identity Access Advanced Access Control may be vulnerable=
to an information disclosure attack. 2026-09-04 not yet calculated CVE-202= 6-13297 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13297 ] Imagination T= echnologies--Graphics DDK Kernel software installed and running inside a Gu= est VM may post improper commands to the GPU Firmware to trigger a read and= /or write data outside the Guest's virtualised GPU memory. The firmware use=
s data provided by the Guest VM to set up accesses to memory. It validated = this before use, but a TOCTOU bug was present which allowed the earlier che=
ck results to be invalidated. 2026-09-04 not yet calculated CVE-2026-45197 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-45197 ] Imagination Technolog= ies--Graphics DDK Software installed and run as a non-privileged user may c= onduct improper GPU driver IOCTL calls to create an allocation scenario tha=
t when freed would cause double free and kernel heap corruption. Scenario c= aused by fabricating a specific combination of flags on the allocation inte= rface that would cause an incorrect double free event when freed. 2026-09-0=
4 not yet calculated CVE-2026-45200 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-45200 ] Italtel--NetMatch
=C2=A0 Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under N= P_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-= WebGui/storage.jsp via the name parameter. A malicious user leveraging this=
vulnerability could inject arbitrary JavaScript. The malicious payload wil=
l then be triggered every time an authenticated user browses the page conta= ining it. 2026-09-04 not yet calculated CVE-2022-26961 [
https://www.cve.or= g/CVERecord?id=3DCVE-2022-26961 ] j2commerce.com--J2Store extension for Joo= mla Joomla Extension - j2commerce.com - Unauthenticated PayPal callback for= gery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0= .21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN= ()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made it=
s verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored i=
ts verdict in a field nothing downstream ever checked - so processing conti= nued regardless of the outcome. Separately, the paid-amount comparison only=
ran when `mc_gross` was a positive number; omitting the field from the POS=
T body (`floatval(null) =3D=3D 0`) skipped the check entirely. Combined wit=
h a merchant-configured `receiver_email` and a sequential, enumerable order=
id read from the `custom` field, an anonymous POST was enough to move a pe= nding order straight to `CONFIRMED` with no payment, or force another custo= mer's pending order to `FAILED`. `paypalv2.php` performed no amount check u= nder any circumstances. 2026-09-03 not yet calculated CVE-2026-77999 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-77999 ] j2commerce.com--J2Store ext= ension for Joomla Joomla Extension - j2commerce.com - Reflected XSS via `fi= lter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21,=
4.1.0-4.1.6 - Four task handlers accepted a base64-encoded URL from user i= nput and redirected to it without validating the destination host, enabling=
phishing using the shop's trusted domain. No authentication required. 2026= -09-03 not yet calculated CVE-2026-78000 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-78000 ] j2commerce.com--J2Store extension for Joomla Joomla Ext= ension - j2commerce.com - Anonymous cart-record tampering via inherited FOF=
`save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `fof.xml`=
grants the `carts` view's tasks a wildcard `true` ACL, and FOF only enforc=
es CSRF tokens on back-end HTML requests, not on front-end `format=3Draw` r= equests. `J2StoreControllerCarts` already scoped `remove()` to the caller's=
own session, but never overrode the generic FOF `save` task, so it remaine=
d reachable to insert new cart rows with an attacker-chosen `user_id`/`sess= ion_id`, or overwrite an existing row by id. 2026-09-03 not yet calculated = CVE-2026-78064 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78064 ] j2comm= erce.com--J2Store extension for Joomla Joomla Extension - j2commerce.com - = Guest checkout address disclosure to any authenticated user (IDOR) in J2Sto=
re 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `editAddress()` redirected non= -owners away only when the loaded address row had a **non-empty** `user_id`=
belonging to someone else. Guest-checkout address rows have an empty `user= _id`, so that check never triggered for them - any logged-in account guessi=
ng a small, sequential `address_id` got a guest customer's full name, stree=
t address, and phone number rendered prefilled into the edit form. 2026-09-=
03 not yet calculated CVE-2026-78065 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-78065 ] j2commerce.com--J2Store extension for Joomla Joomla Extensi=
on - j2commerce.com - Missing authorization on Apps controller delegation c= hain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControlle= rApps`'s `appTask` delegation path instantiates app-plugin controllers with=
no ACL check anywhere in the code. It currently returns 403 only as a side=
effect of `fof.xml`'s wildcard-deny resolving under the singularised ACL k=
ey `app`, which has no explicit allow rule - not because of any deliberate = check. Behind that path, `applocalizationdata::getInstallerTool()` used a c= aller-influenced table name with no allow-list, both to select a `#__j2stor= e_*` table for truncation and to build a path to SQL files it then executes=
- a path-traversal-capable file read/execute. 2026-09-03 not yet calculate=
d CVE-2026-78069 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78069 ] JAL = Information Technology Co., Ltd.--PALLET CONTROL PALLET CONTROL products co= ntain an incorrect default permission vulnerability, which may allow a loca=
l attacker to execute arbitrary code with SYSTEM privileges on the affected=
product. 2026-09-04 not yet calculated CVE-2026-81302 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-81302 ] jetperch--pymonocypher pymonocypher uses = cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argo= n2i_32 implementation does not check the nb_blocks size. If the caller does=
not provide a sufficiently large buffer based on the API contract, then ar= gon2i_32 will write past the end of the buffer and possibly corrupt the hea=
p. This issue has been patched in version 4.0.2.8. 2026-09-03 not yet calcu= lated CVE-2026-53720 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53720 ] = joodb.feenders.de--JooDatabase Lite extension for Joomla Joomla Extension -=
feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - = The cid parameter is used in queries without validation, allowing SQLi vect= ors. 2026-09-03 not yet calculated CVE-2026-78080 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-78080 ] joomshaper.com--Helix Ultimate extension for J= oomla Joomla Extension - joomshaper.com - Broken Object-Level Authorization=
in Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()`=
checked whether the user was authorized to edit the article ID passed in t=
he request, but did not verify whether the specified image path (src) belon= ged to that article. On Joomla 3 builds where physical file deletion was tr= iggered, an author could supply their own article ID alongside an arbitrary=
file path under the `/images/` directory to delete arbitrary files. 2026-0= 8-31 not yet calculated CVE-2026-78075 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-78075 ] joomshaper.com--Helix Ultimate extension for Joomla Joo= mla Extension - joomshaper.com - Broken Access Control & Missing Authorizat= ion in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJAX endpoint sav= e-megamenu-settings failed to enforce item-level and menu-level edit permis= sions (core.edit on com_menus.item.{id} or core.admin). An authenticated us=
er could submit modified layout parameters for arbitrary menu items without=
proper authorization. 2026-08-31 not yet calculated CVE-2026-78076 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-78076 ] joomshaper.com--Helix Ultima=
te extension for Joomla Joomla Extension - joomshaper.com - Stored Cross-Si=
te Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ult= imate < 2.2.10 - Unsanitized column and item configuration values stored wi= thin the MegaMenu layout JSON were rendered without complete contextual esc= aping, allowing injection of malicious HTML/JS. Stricter sanitization and t=
ag allowlists via `InputFilter` and `htmlspecialchars` were implemented. 20= 26-08-31 not yet calculated CVE-2026-78077 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-78077 ] joomshaper.com--Helix Ultimate extension for Joomla J= oomla Extension - joomshaper.com - Privileged File Upload Bypass via Conten=
t Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously validated = only file extension and basic size parameters. Non-image files disguised wi=
th raster extensions could be uploaded. Added strict MIME verification and =
GD binary raster decoding (imagecreatefromstring) to reject invalid/malform=
ed images fail-closed. 2026-08-31 not yet calculated CVE-2026-78078 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-78078 ] joomshaper.com--Helix Ultima=
te extension for Joomla Joomla Extension - joomshaper.com - Open Redirect v=
ia Base64 Return Parameter in Helix Ultimate < 2.2.10 - Return redirect par= ameters accepted arbitrary Base64 strings without verifying whether the res= olved target was an internal site URL via Uri::isInternal. 2026-08-31 not y=
et calculated CVE-2026-78079 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 78079 ] kamailio--kamailio v6.1.1 An issue in kamailio v.6.1.1 and before a= llows a remote attacker to cause a denial of service via the ims_registrar_= pcscf module, specifically the pcscf_save_pending/save_pending path and sec= urity-agreement parsing in sec_agree.c:parse_sec_agree() 2026-09-01 not yet=
calculated CVE-2026-52023 [
https://www.cve.org/CVERecord?id=3DCVE-2026-52= 023 ] libcurl --libcurl
=C2=A0 A flaw in libcurl's handling of HTTP/2 Server Push streams, when the=
parent handle is set to share connections with other handles, can lead to = use-after-free in the cleanup process. 2026-09-06 not yet calculated CVE-20= 26-18924 [
https://www.cve.org/CVERecord?id=3DCVE-2026-18924 ] libcurl --li= bcurl=C2=A0
=C2=A0 A flaw in the libcurl SASL negotiation for LDAP authentication allow=
s an incomplete handshake sequence to be misinterpreted as a successful cry= ptographic verification. An attacker executing a Man-in-the-Middle (MITM) a= ttack can inject a premature or shortcut response that bypasses complete pe=
er validation. 2026-09-06 not yet calculated CVE-2026-13608 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-13608 ] libcurl--libcurl
=C2=A0 When performing transfers via libcurl's multi interface, pooled TLS = connections can outlive their originating easy handles. In OpenSSL 3 provid=
er configurations, libcurl attaches an allocated library context to the eas=
y handle's state and passes it to OpenSSL without acquiring an ownership re= ference; destroying the easy handle prematurely frees this context while th=
e active connection retains a dangling pointer, leading to a heap-use-after= -free upon subsequent I/O or post-handshake operations. 2026-09-06 not yet = calculated CVE-2026-80229 [
https://www.cve.org/CVERecord?id=3DCVE-2026-802=
29 ] libcurl--libcurl
=C2=A0 When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that = disable standard peer verification (`CURLOPT_SSL_VERIFYPEER =3D 0` and `CUR= LOPT_SSL_VERIFYHOST =3D 0`), libcurl fails to enforce public key pinning on=
connections established without a presented server certificate. Bypassing = the pinning check under these disabled-verification conditions allows unaut= henticated connections to succeed when they should be rejected. 2026-09-06 = not yet calculated CVE-2026-80230 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-80230 ] libcurl--libcurl
=C2=A0 A flaw in libcurl makes it wrongly reuse an existing HTTPS connectio=
n setup for a given hostname even when using a different Native CA Store se= tting (`CURLSSLOPT_NATIVE_CA`) than when the connection was created. 2026-0= 9-06 not yet calculated CVE-2026-80231 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80231 ] libcurl--libcurl
=C2=A0 When libpsl support is enabled, libcurl fails to enforce the Public = Suffix List boundary check when processing a `Set-Cookie` header where the = `Domain` attribute explicitly matches an origin host that is itself a publi=
c suffix (e.g., `Domain=3Dco.uk` set by `co.uk`). Instead of coercing it in=
to a strict host-only cookie, libcurl saves the cookie with wildcard domain=
scope (`.co.uk`). Consequently, the cookie is inappropriately included in = subsequent outbound requests or HTTP redirects to arbitrary sibling subdoma= ins under the same public suffix (e.g., `attacker.co.uk`). 2026-09-06 not y=
et calculated CVE-2026-82209 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 82209 ] libcurl--libcurl=C2=A0
=C2=A0 A flaw in libcurl makes it wrongly reuse an HTTP connection setup fo=
r a given hostname using Negotiate authentication, when the initial request=
is done using empty credentials. This can make user B's request get sent o= ver user A's previously authenticated connection. 2026-09-06 not yet calcul= ated CVE-2026-19931 [
https://www.cve.org/CVERecord?id=3DCVE-2026-19931 ] l= ibrenms--librenms LibreNMS through 26.2.0 contains a stored cross-site scri= pting vulnerability in legacy PHP template pages that render unescaped SNMP= -sourced data fields including BGP peer descriptions, VRF names, process in= formation, and SLA tags. Attackers with device management access or network=
access to enroll a rogue SNMP device can inject malicious JavaScript that = executes when admins view affected routing and device pages, enabling crede= ntial theft and CSRF token exfiltration. 2026-09-01 not yet calculated CVE-= 2026-84193 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84193 ] librenms--= librenms LibreNMS versions >=3D 23.10.0 and < 26.2.0 (fixed in 26.4.0) cont= ain an authenticated OS command injection vulnerability in libvirt discover=
y. When libvirt support is enabled (enable_libvirt=3Dtrue), the device host= name ($this->getDevice()->hostname) is concatenated into shell commands (ss=
h, virsh list/dumpxml/domstate) in VminfoLibvirt.php and passed to exec() w= ithout escapeshellarg() or argument separation. An authenticated admin can = set a crafted device hostname to inject arbitrary OS commands, leading to r= emote code execution in the discovery worker context. 2026-09-01 not yet ca= lculated CVE-2026-84194 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84194=
] Linux--Linux In the Linux kernel, the following vulnerability has been r= esolved: x86/mce: Set up the polling timer before CMCI discovery I hit the = following on one of my machines: mce: CPU0 BANK15 CMCI inherited storm ----= --------[ cut here ]------------ ODEBUG: assert_init not available (active = state 0) object: (____ptrval____) object type: timer_list hint: 0x0 WARNING=
: lib/debugobjects.c:632 at debug_object_assert_init+0x178/0x230, CPU#0: sw= apper/0/0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PRE= EMPTLAZY RIP: 0010:debug_object_assert_init+0x18f/0x230 Call Trace: <TASK> = __mod_timer mce_timer_kick cmci_discover intel_init_cmci mce_intel_feature_= init mcheck_cpu_init identify_cpu identify_boot_cpu arch_cpu_finalize_init = start_kernel A second splat follows right after, from timer_setup() finding=
that same timer already queued: ODEBUG: init active (active state 0) objec=
t: (____ptrval____) object type: timer_list hint: stub_timer+0x0/0x10 This =
is happening because CMCI storm detection is trying to modify the timer bef= ore latter was properly set up. Set up the timer first. __mcheck_cpu_setup_= timer() only calls timer_setup(), and depends on neither the generic nor th=
e vendor init. [ bp: Massage commit message. ] 2026-09-03 not yet calculate=
d CVE-2026-80727 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80727 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: Revert "drm/amdgpu: fix aperture mapping leak" devres teardown is LIFO. T=
he aperture devres node was registered after the DRM device node, so devres= _release_all() unmaps the aperture before the DRM device release callback f= ires amdgpu_device_fini_sw(). IP sw_fini callbacks (e.g. vcn_v4_0_sw_fini) = write to fw_shared through a pointer derived from aper_base_kaddr, causing =
a kernel page fault on probe failure / rollback: BUG: unable to handle page=
fault ... PMD 0 RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu] Call Trace: amdg= pu_device_fini_sw amdgpu_driver_release_kms devm_drm_dev_init_release devre= s_release_all This reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a.=
(cherry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f) 2026-= 09-03 not yet calculated CVE-2026-80728 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80728 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: mm/huge_memory: initialise workingset state befor=
e folio split xas_try_split() adds __GFP_ACCOUNT for page-cache xa_nodes, b=
ut __folio_split() leaves the xa_state's xa_lru unset. That lets a live, me= mcg-charged xa_node exist without being linked into the mapping's shadow_no= des list_lru; when reclaim later walks the list_lru it trips VM_WARN_ON(!cs= s_is_dying()). Use mapping_set_update() to install both the workingset upda=
te callback and the shadow_nodes list_lru on the xa_state. 2026-09-03 not y=
et calculated CVE-2026-80729 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 80729 ] Linux--Linux In the Linux kernel, the following vulnerability has b= een resolved: ring-buffer: Fix crash passing ERR_PTR to kthread_stop() In t= est_ringbuffer()'s out_free cleanup loop, the check `!rb_threads[cpu]` only=
catches NULL entries and misses entries that hold an ERR_PTR. rb_threads[]=
is static, so unassigned slots are NULL. But when kthread_run_on_cpu() fai=
ls for a cpu, it stores ERR_PTR(-ENOMEM) (or -EINTR) in rb_threads[cpu] bef= ore the creation loop jumps to out_free. That entry is non-NULL, so the old=
`!ptr` check does not break, and the cleanup proceeds to call kthread_stop=
() on the ERR_PTR. kthread_stop() then dereferences the bogus pointer, cras= hing the kernel during the late_initcall self-test. crash logs: BUG: kernel=
NULL pointer dereference, address: 000000000000001c Oops: 0002 [#1] SMP NO= PTI CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(la= zy) RIP: 0010:kthread_stop+0x2e/0x220 RBX: fffffffffffffff4 CR2: 0000000000= 00001c Call Trace: <TASK> test_ringbuffer+0x1ec/0x650 do_one_initcall+0x6c/= 0x2c0 kernel_init_freeable+0x21d/0x420 kernel_init+0x15/0x1c0 ret_from_fork= +0x21b/0x320 </TASK> Kernel panic - not syncing: Fatal exception 2026-09-03=
not yet calculated CVE-2026-80730 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-80730 ] Linux--Linux In the Linux kernel, the following vulnerability=
has been resolved: net: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop=
() can be called for sockets that are neither AF_INET nor AF_INET6 (e.g. AF= _PACKET sockets when sending packets via raw/packet socket over virtual dev= ices such as VRF or ipvlan). In such cases, sk_family is not AF_INET/AF_INE=
T6 and sk_mc_loop() falls through the switch statement and triggers WARN_ON= _ONCE(1). Non-INET sockets do not support IP_MULTICAST_LOOP or IPV6_MULTICA= ST_LOOP options, so loopback should default to true without generating a wa= rning. 2026-09-03 not yet calculated CVE-2026-80733 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-80733 ] Linux--Linux In the Linux kernel, the follow= ing vulnerability has been resolved: net/mlx5e: TC, Check if flow is PEER b= efore acquiring devcom lock In case __mlx5e_add_fdb_flow() fails in lower l= evels, the flow is deleted via mlx5e_tc_del_flow(), and mlx5e_tc_del_flow()=
is acquiring ESW devcom lock without condition. In addition, in case of pe= er_flow, __mlx5e_add_fdb_flow() is called while holding ESW devcom comp loc=
k. This results in an AA deadlock. To fix this, introduce a new PEER flag t= hat is set on flows created as peer flows (the duplicate flows on peer devi= ces), and check it in mlx5e_tc_del_flow() before acquiring ESW devcom lock.=
Lockdep splat: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
WARNING: possible recursive locking detected =3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Possible unsafe locking scenario: CPU0 ---- = lock(&comp->lock_key#2); lock(&comp->lock_key#2); *** DEADLOCK *** Call Tra= ce: <TASK> dump_stack_lvl+0x69/0xa0 print_deadlock_bug.cold+0xbd/0xca __loc= k_acquire+0x1671/0x2ec0 lock_acquire+0x10e/0x2e0 down_read+0x95/0x430 mlx5_= devcom_for_each_peer_begin+0x4e/0xe0 [mlx5_core] mlx5e_tc_del_flow+0x11d/0x= a70 [mlx5_core] mlx5e_flow_put+0x99/0x100 [mlx5_core] __mlx5e_add_fdb_flow+= 0x409/0xf00 [mlx5_core] mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core] ml= x5e_rep_setup_tc_cls_flower+0x12f/0x1b0 [mlx5_core] mlx5e_rep_setup_tc_cb+0= x153/0x750 [mlx5_core] tc_setup_cb_add+0x1dc/0x470 fl_change+0x2f4d/0x626d = [cls_flower] tc_new_tfilter+0x79b/0x2310 rtnetlink_rcv_msg+0x778/0xad0 do_s= yscall_64+0x70/0x960 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> 2026-= 09-03 not yet calculated CVE-2026-80739 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80739 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: drm/log: Fix infinite loop when scale is too larg=
e for display When scale is large enough that scaled_font exceeds the displ=
ay dimensions, rows or columns become 0. A columns value of 0 causes an inf= inite loop in drm_log_draw_kmsg_record() because the loop never decrements = len. Check for zero rows/columns in drm_log_setup_modeset() and return an e= rror, cleaning up the already allocated buffer to avoid a leak. 2026-09-03 = not yet calculated CVE-2026-80740 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-80740 ] Linux--Linux In the Linux kernel, the following vulnerability = has been resolved: af_packet: Don't send zero-byte data in tpacket_snd(). s= yzbot reported a WARNING in __dev_queue_xmit() triggered via tpacket_snd():=
skb_assert_len WARNING: at include/linux/skbuff.h:2753 skb_assert_len WARN= ING: at __dev_queue_xmit+0x21bc/0x4970 net/core/dev.c:4781 Call Trace: <TAS=
dev_queue_xmit include/linux/netdevice.h:3448 [inline] packet_xmit+0x243=
/0x310 net/packet/af_packet.c:276 tpacket_snd net/packet/af_packet.c:2907 [= inline] packet_sendmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134 When sendi=
ng 0-byte packets via TPACKET ring buffer on devices with no hard header (e= .g. dev->hard_header_len =3D=3D 0), tpacket_fill_skb() populates an skb wit=
h skb->len =3D=3D 0 and returns 0. tpacket_snd() then forwards this empty s=
kb to packet_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb).=
Similar checks exist in packet_snd() via commit dc633700f00f ("net/af_pack= et: check len when min_header_len equals to 0") and in packet_sendmsg_spkt(=
) via commit 6a341729fb31 ("af_packet: Don't send zero-byte data in packet_= sendmsg_spkt()."). Return -EINVAL in tpacket_fill_skb() when skb->len is ze=
ro to reject zero-length packets in tpacket_snd(). 2026-09-03 not yet calcu= lated CVE-2026-80742 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80742 ] = Linux--Linux In the Linux kernel, the following vulnerability has been reso= lved: ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers The ir=
q handlers take a struct device pointer and call dev_get_drvdata() to obtai=
n the driver data. However, the driver data is only set at the end of probe=
, after devm_request_irq(), so an interrupt taken in between causes the han= dlers to pass a NULL pointer to readl() and crash. Pass the private data di= rectly as the devm_request_irq() argument instead of the device pointer, ma= tching what the handlers expect. 2026-09-03 not yet calculated CVE-2026-807=
43 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80743 ] Linux--Linux In th=
e Linux kernel, the following vulnerability has been resolved: netfilter: n= f_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path In nft_flo= w_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every error durin=
g rollback, including -ENOMEM. Memory allocation failures are expected unde=
r low-memory conditions and do not indicate a kernel bug. Trace for example=
: nft_flow_offload_chain() // FLOW_BLOCK_BIND nft_flow_block_chain() nft_ch= ain_offload_cmd() nft_block_offload_cmd() ->ndo_setup_tc() nsim_setup_tc() = flow_block_cb_setup_simple() flow_block_cb_alloc() // fails to -ENOMEM The = warning was reproduced on the 5.10 stable kernel under memory pressure via = fault injection, but the underlying bug exists in mainline as well, as demo= nstrated by the ENOMEM trace above. The following splat was triggered durin=
g nf_tables transaction processing: WARNING: CPU: 0 PID: 8567 at net/netfil= ter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/netfilter/nf_ta= bles_offload.c:532 [inline] WARNING: CPU: 0 PID: 8567 at net/netfilter/nf_t= ables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/= nf_tables_offload.c:591 Modules linked in: CPU: 0 PID: 8567 Comm: syz-execu= tor.0 Not tainted 5.10.260-syzkaller #0 Hardware name: QEMU Standard PC (i4= 40FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:nft_flow_rule_offloa= d_abort net/netfilter/nf_tables_offload.c:532 [inline] RIP: 0010:nft_flow_r= ule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.c:591 Call T= race: nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api.c:8604 nfne= tlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509 nfnetlink_rcv_sk= b_batch net/netfilter/nfnetlink.c:579 [inline] nfnetlink_rcv+0x3b3/0x420 ne= t/netfilter/nfnetlink.c:597 netlink_unicast_kernel net/netlink/af_netlink.c= :1314 [inline] netlink_unicast+0x6cd/0xa00 net/netfilter/af_netlink.c:1340 = netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919 sock_sendmsg_no= sec net/socket.c:651 [inline] __sock_sendmsg+0x155/0x190 net/socket.c:663 _= ___sys_sendmsg+0x705/0x870 net/socket.c:2379 ___sys_sendmsg+0x100/0x170 net= /socket.c:2433 __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462 do_syscall_64+0x3= 3/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwframe+0x67/0xd1 = Change the condition to WARN_ON_ONCE(err && err !=3D -ENOMEM) so that warni= ngs are only emitted for unexpected errors. This aligns with the common ker= nel practice of not warning on -ENOMEM. Found by Linux Verification Center = (linuxtesting.org) with Syzkaller. 2026-09-03 not yet calculated CVE-2026-8= 0744 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80744 ] Linux--Linux In = the Linux kernel, the following vulnerability has been resolved: clk: qcom:=
dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK Eliza EV=
K (eliza-cqs-evk.dts) does not have display enabled, however its Display Cl= ock Controller is enabled and references parent clocks from DSI PHYs, which=
causes clock reparenting issues during probe (init) and warning on Eliza E= VK: disp_cc_mdss_mdp_clk_src: rcg didn't update its configuration. WARNING:=
drivers/clk/qcom/clk-rcg2.c:136 at update_config+0xd4/0xe4, CPU#1: udevd/2=
73 ... update_config (drivers/clk/qcom/clk-rcg2.c:136 (discriminator 2)) (P=
) clk_rcg2_shared_disable (drivers/clk/qcom/clk-rcg2.c:1471) clk_rcg2_share= d_init (drivers/clk/qcom/clk-rcg2.c:1540) __clk_register (drivers/clk/clk.c= :3959 drivers/clk/clk.c:4368) devm_clk_hw_register (drivers/clk/clk.c:4448 = (discriminator 1) drivers/clk/clk.c:4672 (discriminator 1)) devm_clk_regist= er_regmap (drivers/clk/qcom/clk-regmap.c:104) qcom_cc_really_probe (drivers= /clk/qcom/common.c:418) qcom_cc_probe (drivers/clk/qcom/common.c:445) disp_= cc_eliza_probe (dispcc-eliza.c:?) dispcc_eliza platform_probe (drivers/base= /platform.c:1432) 2026-09-03 not yet calculated CVE-2026-80746 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-80746 ] Linux--Linux In the Linux kernel,=
the following vulnerability has been resolved: selinux: reject a permissio=
n value exceeding the class permission count perm_read() bounds a permissio=
n value by SEL_VEC_MAX but never by the nprim of the owning class or common=
, which is taken verbatim from the policy image. security_get_permissions()=
then writes perms[value - 1] into an nprim-sized kcalloc() array, so a cla=
ss declaring fewer permissions than its largest permission value drives an = out-of-bounds heap write. The top-level symbol tables are validated this wa=
y; the nested per-class permission table is not. Reject a permission whose = value exceeds nprim, which is already set when perm_read() runs. Well-forme=
d policies are unaffected. [PM: tweak comment for line length] 2026-09-03 n=
ot yet calculated CVE-2026-80755 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-80755 ] Linux--Linux In the Linux kernel, the following vulnerability h=
as been resolved: selinux: do not cancel a policy conversion that never sta= rted sel_write_load() calls selinux_policy_cancel() when sel_make_policy_no= des() fails, and that helper dereferences the outgoing policy to cancel its=
sidtab conversion. On the first policy load there is no outgoing policy: s= ecurity_load_policy() returns early for that case, before it converts anyth= ing, and state->policy is still NULL. A first load that fails while buildin=
g the selinuxfs tree therefore takes a NULL dereference in selinux_policy_c= ancel(), reached from a write(2) to /sys/fs/selinux/load. Skip the cancel w= hen there is no old policy, mirroring the check security_load_policy() alre= ady makes before it converts. 2026-09-03 not yet calculated CVE-2026-80756 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80756 ] Linux--Linux In the L= inux kernel, the following vulnerability has been resolved: selinux: reject=
a class permission count below its inherited common security_get_permissio= ns() maps an inherited common's permissions into an array sized by the clas= s's own permissions.nprim, but class_read() takes that nprim verbatim from = the policy image and never checks that it covers the common. A class that i= nherits a common of N permissions while declaring a smaller nprim is accept= ed, and on load the common's permissions are written past the class-sized a= rray -- an out-of-bounds heap write. Reject a class whose permission count =
is below its inherited common's. Well-formed policies, where the class coun=
t already includes the inherited permissions, are unaffected. 2026-09-03 no=
t yet calculated CVE-2026-80757 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-80757 ] Linux--Linux In the Linux kernel, the following vulnerability ha=
s been resolved: futex: Avoid private hash use-after-free on final put fute= x_private_hash_put() drops the reference to fph before evaluating fph->mm f=
or wake_up_var(). futex_ref_put() enables preemption again before returning=
. If that put drops the final reference and the task is preempted, another = task can pivot to the replacement hash and free the old hash after an RCU g= race period. The first task then reads fph->mm from the freed allocation wh=
en it resumes. KASAN reports a slab-use-after-free in futex_private_hash_pu= t(), with the read at offset 24 in a freed kmalloc-512 allocation. The allo= cation and free stacks point to futex_hash_allocate() and the RCU free path=
, respectively. Load the mm pointer while the fph reference is still held a=
nd pass the saved value to wake_up_var(). wake_up_var() uses the pointer as=
a waitqueue key and does not dereference the mm through it. 2026-09-04 not=
yet calculated CVE-2026-80758 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-80758 ] Linux--Linux In the Linux kernel, the following vulnerability has=
been resolved: Bluetooth: hci_aml: validate firmware segment lengths aml_d= ownload_firmware() reads two lengths from the firmware header and uses them=
to build pointers before checking that the header and segment data are pre= sent. A truncated or inconsistent firmware image can make the driver read p= ast firmware->data while constructing TCI commands. Reject images shorter t= han the header and ensure that the ICCM and DCCM ranges fit within the load=
ed firmware before downloading either segment. 2026-09-04 not yet calculate=
d CVE-2026-80759 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80759 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sy= nc() checks that the message length agrees with params_len but puts no uppe=
r bound on it. params_len is __le16 while the parameter length in the HCI c= ommand header is a u8: struct hci_command_hdr { __le16 opcode; __u8 plen; }=
__packed; hci_cmd_sync_alloc() assigns one to the other: hdr->plen =3D ple=
n; if (plen) skb_put_data(skb, param, plen); so a params_len of 256 leaves = plen at 0 while all 256 bytes are still appended. The frame handed to the d= river then declares no parameters and carries 256 of them. On a length fram=
ed transport such as H:4 the controller takes the trailing bytes as the sta=
rt of the next packet. The mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params= _len can reach about 1KB this way. Commit 03f1700b9b4d ("Bluetooth: MGMT: r= eject malformed HCI_CMD_SYNC commands") only made params_len agree with the=
message length, a value that fits the message but not the header field is = still accepted. Reject params_len that does not fit the header field. 2026-= 09-04 not yet calculated CVE-2026-80760 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80760 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: Bluetooth: ISO: zero the sockaddr before returnin=
g it in getname iso_sock_getname() fills a struct sockaddr_iso in place and=
returns its size without clearing it first, so bytes it does not write are=
copied to user space from the kernel stack. The getsockname(2) and getpeer= name(2) paths both run through do_getsockname(), which hands getname() an u= ninitialized sockaddr_storage on the stack and copies back up to the number=
of bytes getname() returns, so the driver has to initialize every byte it = accounts for. Two ranges are left uninitialized: - struct sockaddr_iso is 1=
0 bytes but only 9 are written (family, iso_bdaddr, iso_bdaddr_type), leaki=
ng the trailing pad byte on every call. - for a broadcast peer (BIS_LINK or=
PA_LINK) the returned length grows by sizeof(struct sockaddr_iso_bc), but = only bc_sid, bc_num_bis and bc_bis are filled; bc_bdaddr and bc_bdaddr_type=
, the first 7 bytes of that structure, are never written. An unprivileged p= rocess can open a BTPROTO_ISO socket and reach the pad leak with getsocknam= e(); the broadcast leak needs an established BIS/PA connection. l2cap and r= fcomm already memset their sockaddr in getname for the same reason; do the = same here. 2026-09-04 not yet calculated CVE-2026-80761 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-80761 ] Linux--Linux In the Linux kernel, the fo= llowing vulnerability has been resolved: Bluetooth: hci_sync: Fix accept li=
st UAF during suspend hci_update_event_filter_sync() walks hdev->accept_lis=
t while sending a synchronous HCI command for each remote-wakeup device. Th=
e suspend path holds hdev->req_lock, but accept-list updates are serialized=
by hdev->lock. Consequently, remove_device() can free the current list ent=
ry during the controller wait. The following interleaving causes the use-af= ter-free: hci_update_event_filter_sync() remove_device() fetch accept-list = entry hci_set_event_filter_sync() wait for controller response hci_dev_lock=
() list_del() kfree() hci_dev_unlock() read the freed list.next KASAN repor= ted: BUG: KASAN: slab-use-after-free in hci_suspend_sync+0x835/0x910 Read o=
f size 8 at addr ffff88810bec8440 by task kworker/0:1/10 Workqueue: events = vhci_suspend_work Call Trace: hci_suspend_sync+0x835/0x910 hci_suspend_dev+= 0x182/0x450 process_one_work+0x661/0x1090 worker_thread+0x45b/0xd10 Allocat=
ed by task 86: hci_bdaddr_list_add_with_flags+0x1a8/0x400 add_device+0x381/= 0x820 hci_sock_sendmsg+0x1033/0x1ea0 Freed by task 91: kfree+0x131/0x3c0 re= move_device+0x429/0xb70 hci_sock_sendmsg+0x1033/0x1ea0 Snapshot the remote-= wakeup addresses under hdev->lock. Release the lock before sending HCI comm= ands. Clear the controller event filter before building the snapshot, and s= kip allocation and the second list traversal when there are no matching ent= ries. This preserves the original filter and scan-state updates without ret= aining an accept-list node across a controller wait. 2026-09-04 not yet cal= culated CVE-2026-80762 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80762 =
] Linux--Linux In the Linux kernel, the following vulnerability has been re= solved: Bluetooth: hci_event: validate LE Set CIG Parameters response The C= ommand Complete dispatch validates only the fixed part of the LE Set CIG Pa= rameters response. After that part is pulled from the skb, hci_cc_le_set_ci= g_params() trusts num_handles and reads each entry in the trailing handle a= rray. Matching num_handles against the command's num_cis does not guarantee=
that the response contains the advertised handles. A truncated response fr=
om a malfunctioning controller can therefore make the handler read beyond t=
he skb data. Validate that the remaining skb data contains all advertised h= andles. Include this in the existing response validation so malformed respo= nses also follow the established CIG failure handling. 2026-09-04 not yet c= alculated CVE-2026-80763 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8076=
3 ] Linux--Linux In the Linux kernel, the following vulnerability has been = resolved: Bluetooth: hci_event: fix LE list UAF on reset hci_cc_reset() cle= ars the LE accept and resolving lists without taking hdev->lock. Other comm= and-complete handlers serialize updates to these lists with that lock, and = the debugfs readers hold it while walking them. This permits the reset comp= letion and a debugfs read to interleave as follows: hci_rx_work debugfs rea= der ----------- -------------- lock hdev->lock fetch current entry list_del= (entry) kfree(entry) read entry fields The reader then dereferences a freed=
list entry and may follow its stale next pointer. KASAN reported: BUG: KAS= AN: slab-use-after-free in white_list_show+0x15f/0x180 Read of size 1 at ad=
dr ffff8881015dab16 by task poc/95 Call Trace: white_list_show+0x15f/0x180 = seq_read_iter+0x3ff/0x1190 seq_read+0x267/0x3d0 vfs_read+0x177/0xa20 ksys_r= ead+0xf7/0x1c0 Allocated by task 91: hci_bdaddr_list_add+0x1a6/0x3a0 hci_cc= _le_add_to_accept_list+0xab/0x140 hci_cmd_complete_evt+0x26c/0x9a0 hci_even= t_packet+0x454/0xb20 hci_rx_work+0x293/0x730 Freed by task 90: kfree+0x131/= 0x3c0 hci_bdaddr_list_clear+0xd8/0x160 hci_cc_reset+0x28a/0x370 hci_cmd_com= plete_evt+0x26c/0x9a0 hci_event_packet+0x454/0xb20 hci_rx_work+0x293/0x730 = Take hdev->lock around both list clears. This matches the existing mutation=
and traversal locking convention. 2026-09-04 not yet calculated CVE-2026-8= 0764 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80764 ] Linux--Linux In = the Linux kernel, the following vulnerability has been resolved: HID: hyper=
v: validate initial device info bounds The Hyper-V synthetic HID host suppl= ies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor fo= llowed by the report descriptor bytes. mousevsc_on_receive_device_info() tr= usts bLength and wDescriptorLength without checking that the received packe=
t contains both byte ranges. A malformed host or backend message can theref= ore make the guest read past the received VMBus packet while copying the re= port descriptor. Pass the received initial-device-info size into the parser=
and reject descriptor lengths that exceed the packet. Impact: A malicious = Hyper-V host or backend can crash a guest by sending a short initial device= -info message with an oversized HID report descriptor length. 2026-09-04 no=
t yet calculated CVE-2026-80765 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-80765 ] Linux--Linux In the Linux kernel, the following vulnerability ha=
s been resolved: HID: uclogic: fix use-after-free of inrange_timer on remov=
e uclogic_remove() cancels the pen in-range timer and then stops the device=
: timer_delete_sync(&drvdata->inrange_timer); hid_hw_stop(hdev); timer_dele= te_sync() only guarantees the timer is idle at that instant. uclogic_raw_ev= ent_pen() keeps delivering pen reports until hid_hw_stop() stops the transp= ort several lines later, and every report with pen->inrange =3D=3D UCLOGIC_= PARAMS_PEN_INRANGE_NONE re-arms the timer: mod_timer(&drvdata->inrange_time=
r, jiffies + msecs_to_jiffies(100)); A report landing between the timer_del= ete_sync() call and the transport teardown in hid_hw_stop() re-arms inrange= _timer after it was cancelled. uclogic_remove() then returns and the devm d= rvdata is freed, while hid_hw_stop() has already freed the input device drv= data->pen_input points at, so when the timer fires ~100 ms later uclogic_in= range_timeout() dereferences freed memory -- a use-after-free in timer-soft= irq context. Swapping the two calls is not a fix: stopping the device first=
frees drvdata->pen_input via hidinput_disconnect() while the timer may sti=
ll be pending, so a timer already armed before removal fires on the freed i= nput device in the window before timer_delete_sync() runs. Use timer_shutdo= wn_sync() before hid_hw_stop() instead. It cancels the timer, waits for a r= unning callback while pen_input is still valid, and prevents any further re= -arming -- a later mod_timer() from an in-flight report is silently ignored=
-- so the timer is provably dead before hid_hw_stop() frees the inputs. Th=
is is the ordering the timer core documents for this "timer re-armed from a= nother path" teardown case. 2026-09-04 not yet calculated CVE-2026-80766 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-80766 ] Linux--Linux In the Lin=
ux kernel, the following vulnerability has been resolved: HID: sensor: cust= om: Fix use-after-free in enable_sensor enable_sensor_store() can call set_= power_report_state(), which dereferences sensor_inst->power_state and senso= r_inst->report_state. These pointers refer to entries in sensor_inst->field=
s. Create the field attributes before exposing the enable_sensor sysfs attr= ibute, so enable_sensor cannot be accessed before the state it depends on h=
as been initialized. On remove, delete enable_sensor before freeing the fie=
ld attributes, so a concurrent sysfs write cannot dereference freed memory = through power_state or report_state. 2026-09-04 not yet calculated CVE-2026= -80767 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80767 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: HID: ft2= 60: fix stack-use-after-return write in I2C read race ft260_i2c_read() poin=
ts dev->read_buf at a caller-supplied buffer (often an on-stack variable), = arms a completion and waits up to five seconds for the device to return the=
data. The HID input callback ft260_raw_event() runs in the input/IRQ path,=
independent of the dev->lock mutex held by the read path, and copies the d= evice-supplied payload into dev->read_buf after a plain NULL check. These t=
wo paths share read_buf, read_idx and read_len with no serialization. If th=
e device delays its response until the read times out, ft260_i2c_read() res= ets the controller, clears read_buf and returns, unwinding the stack frame = the buffer lived in. A response that arrives at that moment lets ft260_raw_= event() pass the NULL check and then memcpy() the device-controlled payload=
into the now-freed stack location, a bounded but attacker-influenced stack= -use-after-return write triggerable by malicious or malfunctioning hardware=
. Add a dedicated spinlock that serializes every access to read_buf, read_i=
dx and read_len. ft260_raw_event() now holds it across the NULL check, the = memcpy and the index update, while the read path takes it when arming and w= hen clearing the buffer, so the teardown can no longer slip between the che=
ck and the copy. 2026-09-04 not yet calculated CVE-2026-80768 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-80768 ] Linux--Linux In the Linux kernel, = the following vulnerability has been resolved: HID: rapoo: fix missing hid_= is_usb() check to_usb_interface() can only be used on a hid_device whose pa= rent is really USB; uhid can create devices that identify as being on BUS_U= SB, but don't actually have a USB parent. Fix the use of to_usb_interface()=
without a hid_is_usb() check. Add a dependency on USB_HID for hid_is_usb()=
, as other HID drivers do; the alternative would be to provide a simple stu=
b implementation on !USB_HID builds. I have verified that it is currently p= ossible to trigger a kernel splat due to this bug in an ASAN build, and tha=
t this commit fixes the issue. 2026-09-04 not yet calculated CVE-2026-80769=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80769 ] Linux--Linux In the = Linux kernel, the following vulnerability has been resolved: HID: nintendo:=
stop device IO before hid_hw_stop on probe failure nintendo_hid_probe() ca= lls hid_device_io_start() before joycon_init() and joycon_leds_create(). If=
either fails, the error path jumps to err_close which calls hid_hw_close()= /hid_hw_stop() without first calling hid_device_io_stop(). hid_hw_stop() do=
es not stop device IO, so hid_input_report() may still run and access drive=
r data that is being torn down, resulting in a use-after-free. Add an err_i= o_stop label that calls hid_device_io_stop() before hid_hw_close(), and poi=
nt the two post-io_start error paths at it. 2026-09-04 not yet calculated C= VE-2026-80770 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80770 ] Linux--= Linux In the Linux kernel, the following vulnerability has been resolved: H= ID: nintendo: register input device after capabilities are set input_regist= er_device() exposes the device to userspace immediately. In joycon_input_cr= eate() it was called before joycon_config_rumble() configures the FF_RUMBLE=
capability and the memless force-feedback device, so a concurrent EVIOCSFF=
could dereference a NULL dev->ff. Registering early also means the initial=
udev event lacks button and axis information, which can make input manager=
s ignore the device. Move input_register_device() to the end of joycon_inpu= t_create(), after all capabilities, the IMU input device and the force-feed= back callbacks have been configured. 2026-09-04 not yet calculated CVE-2026= -80771 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80771 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: HID: nin= tendo: fix out-of-bounds read in joycon_ctlr_read_handler() joycon_ctlr_rea= d_handler() casts an incoming HID input report to struct joycon_input_repor=
t and parses it, guarding the cast only with a 12-byte length check: if (si=
ze >=3D 12) /* make sure it contains the input report */ joycon_parse_repor= t(ctlr, (struct joycon_input_report *)data); struct joycon_input_report is =
49 bytes: a 13-byte header followed by a union whose IMU arm is 36 bytes. F=
or an IMU report joycon_parse_report() -> joycon_parse_imu_report() walks t= hat union (struct offsets 13..48), so a report of exactly 12 bytes with dat= a[0] =3D=3D JC_INPUT_IMU_DATA passes the guard yet is read up to 37 bytes p= ast its declared length. The over-read bytes are decoded into accelerometer= /gyroscope values and forwarded to userspace through the "(IMU)" input devi= ce, leaking driver-internal memory. data[0] and size are fully controlled b=
y a malicious or spoofed Joy-Con/Pro Controller. Receive buffers are sized =
to the maximum report length, so this is an over-read within the allocation=
rather than a slab OOB, but the decoded bytes still reach userspace. The s= ibling subcmd path in joycon_ctlr_handle_event() already bounds the same ca=
st correctly: if (size < sizeof(struct joycon_input_report) || data[0] !=3D=
JC_INPUT_SUBCMD_REPLY) break; Use the same sizeof(struct joycon_input_repo= rt) bound here. 2026-09-04 not yet calculated CVE-2026-80772 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-80772 ] Linux--Linux In the Linux kernel, t=
he following vulnerability has been resolved: HID: huawei: fix missing hid_= is_usb() check to_usb_interface() can only be used on a hid_device whose pa= rent is really USB; uhid can create devices that identify as being on BUS_U= SB, but don't actually have a USB parent. Fix the use of to_usb_interface()=
without a hid_is_usb() check. I have verified that it is currently possibl=
e to trigger a kernel splat due to this bug in an ASAN build, and that this=
commit fixes the issue. 2026-09-04 not yet calculated CVE-2026-80773 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-80773 ] Linux--Linux In the Linux = kernel, the following vulnerability has been resolved: HID: asus: fix missi=
ng hid_is_usb() check to_usb_interface() can only be used on a hid_device w= hose parent is really USB; uhid can create devices that identify as being o=
n BUS_USB, but don't actually have a USB parent. Fix the use of to_usb_inte= rface() without a hid_is_usb() check. I have verified that it is currently = possible to trigger a kernel splat due to this bug in an ASAN build, and th=
at this commit fixes the issue. 2026-09-04 not yet calculated CVE-2026-8077=
4 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80774 ] Linux--Linux In the=
Linux kernel, the following vulnerability has been resolved: futex: Fix ra=
ce on the initial mm->futex.phash.ref allocation futex_hash_allocate() allo= cates mm->futex.phash.ref without any locking. Commit d9b05321e21e ("futex:=
Move futex_hash_free() back to __mmput()") moved the allocation here and a= ssumed that the process has just a single thread at this point. Commit ee9d= ce44362b ("futex: Drop CLONE_THREAD requirement for private default hash al= loc") widened need_futex_hash_allocate_default() to cover any CLONE_VM clon=
e, but left out vfork because the parent is suspended and cannot race. That=
no longer holds once vfork is nested. If a vfork child calls vfork again a=
nd is then killed with SIGKILL, the parent is released from its vfork wait = and runs concurrently with the grandchild in the same mm. Neither of them w= ent through futex_hash_allocate_default(). When both call prctl(PR_FUTEX_HA= SH, PR_FUTEX_HASH_SET_SLOTS) at the same time, each one sees mm->futex.phas= h.ref as NULL and stores its own percpu counter. Only the last store surviv= es. The counter stored first is no longer reachable from the mm, so the ref= erences on it are not seen by __futex_ref_atomic_end(). A private hash that=
still has references is then considered dead and freed, and a task that st= ill holds one of its buckets writes into freed memory in futex_q_lock(). St= ore the counter once with cmpxchg() and let the loser free_percpu() its own=
. The initial reference has to be taken before the store, otherwise another=
task can install a private hash while the counter is still 0. 2026-09-04 n=
ot yet calculated CVE-2026-80775 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-80775 ] Linux--Linux In the Linux kernel, the following vulnerability h=
as been resolved: futex: Fix race in futex_pivot_pending() during private h= ash resize A task performing a custom private hash resize can remain blocke=
d in uninterruptible sleep indefinitely. The hung-task detector reports: IN= FO: task futex-resizer:314 blocked for more than 10 seconds. task:futex-res= izer state:D stack:14824 pid:314 tgid:312 ppid:311 Call Trace: __schedule+0= x521/0xf30 schedule+0x22/0xa0 futex_hash_allocate+0x3db/0x490 __do_sys_prct= l+0x6f5/0xbd0 do_syscall_64+0xf9/0x530 entry_SYSCALL_64_after_hwframe+0x77/= 0x7f Kernel panic - not syncing: hung_task: blocked tasks futex_pivot_pendi= ng() allows the resize request to continue when either no replacement hash =
is pending (hash_new =3D=3D NULL) or the current hash reference count has r= eached zero. After the final-reference wake, another futex task can complet=
e the pivot between the two observations: T1 T2 futex_hash_allocate() wait_= var_event(mm, ...) futex_pivot_pending(mm) hash_new !=3D NULL futex_hash() = futex_ref_get(old) -> false futex_pivot_hash(mm) hash_new =3D NULL __futex_= pivot_hash(mm, new) rcu_assign_pointer(hash, new) fph =3D rcu_dereference(h= ash) /* new */ futex_ref_is_dead(fph) -> false schedule() The pivot changes=
the state from hash_new !=3D NULL with a dead current hash to hash_new =3D= =3D NULL with a live current hash. Because futex_pivot_pending() reads hash= _new and hash without serialization, the resize task can observe hash_new i=
n the pre-pivot state and hash in the post-pivot state, causing futex_pivot= _pending() to return false even though the pivot has completed. The task th=
en goes to sleep after the wakeup has already been consumed. Serialize stat=
e reads in futex_pivot_pending() using futex_mm_phash::lock. This guarantee=
s that futex_pivot_pending() observes hash_new and hash atomically, elimina= ting the race condition. 2026-09-04 not yet calculated CVE-2026-80776 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-80776 ] Linux--Linux In the Linux = kernel, the following vulnerability has been resolved: futex/pi: Plug priva=
te futex exec() race The check for private futexes whether the waiter's mm,=
which is stored in the futex_key and copied into the pi_state, is the same=
as the owner's mm is not sufficient for exec(). exec() has a gap where the=
mm check fails to give the correct answer: exec() ... exec_release_mm() fu= tex_exec_release() tsk::futex::exit_state =3D EXITING; cleanup_robust_list(=
); 1) tsk::futex::exit_state =3D OK; ... old_mm =3D tsk::mm; 2) tsk::mm =3D=
mm; Between #1 and #2 the check for the mm is wrong as that mm is about =
to be swapped out and eventually freed. Plug this gap by: 1) Setting tsk::f= utex::exit_state to FUTEX_STATE_DEAD in futex_exec_release() 2) Setting tsk= ::futex::exit_state to FUTEX_STATE_OK after the mm has been switched. From =
a futex point of view the task is dead after it finished the robust list cl= eanup up to the point where it sets the state to OK again. 2026-09-04 not y=
et calculated CVE-2026-80777 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 80777 ] Linux--Linux In the Linux kernel, the following vulnerability has b= een resolved: futex/pi: Reject cross-mm private futex owners A private fute=
x key borrows the waiter's mm without taking an mm_users reference. Neverth= eless, attach_to_pi_owner() currently accepts an owner from a different add= ress space and copies the private key into the owner's PI state. When that = owner exits, exit_pi_state_list() uses the saved key to find the hash bucke=
t and acquires a reference to the waiter's private hash. If the last user o=
f the waiter's mm exits concurrently, futex_hash_free() frees the hash whil=
e the owner still uses its bucket and reference. Prevent this by validating=
in attach_to_pi_owner() that, for private futexes, the owner mm and waiter=
mm are the same. Perform the check with the owner's pi_lock held and after=
validating owner::futex::state to serialize against a concurrent PI-state = exit cleanup. [ tglx: Amended comment ] 2026-09-04 not yet calculated CVE-2= 026-80778 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80778 ] Linux--Linu=
x In the Linux kernel, the following vulnerability has been resolved: net/i= onic: avoid OOB TX partner lookup for hwstamp RXQ The dedicated hardware ti= mestamp RX queue is allocated with q->index equal to lif->ionic->nrxqs_per_= lif. The normal txqcqs array only contains the regular queue pairs, so usin=
g that index to set rxq->partner can read one entry past txqcqs[] and then = write through the derived pointer. Only link RX/TX partners for normal queu= e-pair indexes. Leave the hwstamp RX queue unpaired, and make the XDP_TX pa=
th abort cleanly if an RX queue has no TX partner. 2026-09-04 not yet calcu= lated CVE-2026-80779 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80779 ] = Linux--Linux In the Linux kernel, the following vulnerability has been reso= lved: HID: pidff: fix OOB write when hid->inputs is empty hid_pidff_init_wi= th_quirks() derives its input_dev from list_entry(hid->inputs.next, struct = hid_input, list) without first checking that hid->inputs is non-empty. The = list member of struct hid_input is at offset 0, so on an empty list list_en= try() yields &hid->inputs itself and the following hidinput->input load rea=
ds an unrelated member of struct hid_device. dev is then a type-confused po= inter, and force-feedback init writes through it: each set_bit(FF_*, dev->f= fbit) stores 8 bytes at dev + 192, past the end of the object dev actually = aliases, and input_ff_create() adds further writes of a heap pointer and tw=
o function pointers. Until hid-universal-pidff the only caller was hid_pidf= f_init() from usbhid, which runs under HID_CLAIMED_INPUT and therefore alwa=
ys has at least one hid_input. universal_pidff_probe() starts the device wi=
th HID_CONNECT_DEFAULT & ~HID_CONNECT_FF and then calls hid_pidff_init_with= _quirks() directly whenever the descriptor carries a PID usage page, bypass= ing that gate. A report descriptor whose only application collection is on = HID_UP_PID leaves hid->inputs empty while hid_connect() still succeeds thro= ugh the hidraw claim, so probe reaches the unguarded list_entry(). The writ=
e happens in the USB probe path, on the hotplug workqueue, so plugging in a=
malicious device is enough to trigger it; no attacker software and no logg= ed-in user are required. KASAN reports an 8-byte out-of-bounds write in hid= _pidff_init_with_quirks() reached from universal_pidff_probe(). Check for a=
n empty list before deriving dev and return -ENODEV, as the other HID force= -feedback drivers already do. universal_pidff_probe() propagates the error = and unwinds. Discovered by XBOW, triaged by Baul Lee <
baul.lee@xbow.com> 20= 26-09-04 not yet calculated CVE-2026-80780 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-80780 ] Linux--Linux In the Linux kernel, the following vulne= rability has been resolved: HID: core: fix OOB read of field->usage in hid_= set_field() hid_set_field() hands field->usage + offset to hid_dump_input()=
before the guard that bounds offset: hid_dump_input(field->report->device,=
field->usage + offset, value); if (offset >=3D field->report_count) { hid_= err(...); return -1; } Under CONFIG_DEBUG_FS hid_dump_input() dereferences = that pointer, with buf =3D hid_resolv_usage(usage->hid, NULL). The usage[] = array is allocated inline with the hid_field in hid_register_field() and ho= lds field->maxusage entries, so an offset past it reads off the end of the = kvzalloc()ed allocation and into a neighbouring object. Had the guard run f= irst, offset < report_count <=3D maxusage would already have confined the p= ointer to the array. A caller supplies such an offset today. picolcd_fb_sen= d_tile() validates only report->maxfield before issuing hid_set_field(repor= t->field[0], 11 + i, ...) for i =3D 0..31, so its offsets are fixed at 11..=
42 and are never checked against the bound field. When the device registers=
that field with fewer usages, the framebuffer deferred-io work drives the = read on every tile. KASAN reports a 4-byte slab-out-of-bounds read in hid_d= ump_input() below hid_set_field(), and the same boot logs "offset (1) excee=
ds report_count (1)" from the guard that runs only afterwards. Move the hid= _dump_input() call below the guard. Because field->maxusage >=3D field->rep= ort_count, the guard then establishes that field->usage + offset lies insid=
e the array before it is dereferenced, for every caller and without changin=
g behaviour on the valid path. Discovered by XBOW, triaged by Baul Lee <bau=
l.lee@xbow.com> 2026-09-04 not yet calculated CVE-2026-80781 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-80781 ] Linux--Linux In the Linux kernel, t=
he following vulnerability has been resolved: HID: magicmouse: do not keep =
a stale msc->input if no input is claimed magicmouse_input_mapping() caches=
the first hid_input's input_dev in msc->input while the report descriptor =
is parsed, and the rest of the driver treats a non-NULL msc->input as proof=
that an input device was registered. That does not hold on the hid-input e= rror path. If hidinput_connect() fails -- for instance because input_regist= er_device() returns an error -- it unwinds through hidinput_disconnect(), w= hich frees every input_dev it created, including the one cached in msc->inp= ut. The failure does not abort the probe. hid_connect() only skips the clai=
m: if ((connect_mask & HID_CONNECT_HIDINPUT) && !hidinput_connect(hdev, con= nect_mask & HID_CONNECT_HIDINPUT_FORCE)) hdev->claimed |=3D HID_CLAIMED_INP= UT; and the "device has no listeners" bailout below it does not fire for th=
is driver, which sets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpa=
d 2 paths hidraw and hiddev are claimed as well. hid_hw_start() therefore r= eturns 0 and magicmouse_probe() continues with msc->input pointing at freed=
memory. Being non-NULL, it passes the "input not registered" check in prob=
e and the NULL checks in ->raw_event and ->event, so the next input report = dereferences freed memory. Clear msc->input when the HID core did not claim=
an input device, so the existing NULL checks cover this case as well. 2026= -09-04 not yet calculated CVE-2026-80782 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80782 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: HID: magicmouse: prevent unbounded recursion in m= agicmouse_raw_event() magicmouse_raw_event() handles DOUBLE_REPORT_ID (0xf7=
) packets, which pack two touch reports into one, by splitting the packet a=
nd calling itself on each half. The only guard against runaway recursion is=
a "size < 1" check, which stops zero-sized calls but does not bound the re= cursion depth. A malicious HID device that matches this driver can send a r= eport starting with DOUBLE_REPORT_ID and filled with the sequence [0xf7, 0x= 00]. Each level consumes two bytes and recurses on the remainder, so an inc= oming report of up to HID_MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nest=
ed calls. That easily exhausts the 16 KiB kernel stack, leading to a stack = overflow: a panic with CONFIG_VMAP_STACK, or memory corruption without it. =
A double report only ever wraps two normal reports; it is never legitimatel=
y nested. Refuse to re-enter the DOUBLE_REPORT_ID case from a recursive cal=
l so the recursion depth is bounded to two, while all valid packets keep be= ing parsed exactly as before. 2026-09-04 not yet calculated CVE-2026-80783 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80783 ] Linux--Linux In the L= inux kernel, the following vulnerability has been resolved: mptcp: pm: fix = memory leak from alloc-during-teardown race mptcp_pm_destroy() empties msk-= >pm.anno_list and msk->pm.userspace_pm_local_addr_list under msk->pm.lock d= uring socket teardown, dropping the lock between the two. A concurrent user= space PM genl ANNOUNCE on the same msk holds a sock reference via mptcp_tok= en_get_sock() and, in mptcp_pm_nl_announce_doit(), calls mptcp_userspace_pm= _append_new_local_addr() and mptcp_pm_announced_alloc(). Both take msk->pm.= lock briefly to add to their respective lists. Because the genl handler hol=
ds a sock reference, mptcp_pm_destroy() may run on the same msk via mptcp_d= isconnect(), which invokes mptcp_destroy_common() without dropping the sock=
refcount, before the handler completes. If the lock acquisitions interleav=
e such that mptcp_pm_destroy() empties a list first, the later alloc adds i=
ts entry to a list head that nothing else iterates for this msk, and the en= try leaks. kmemleak reports both mptcp_pm_add_addr objects (from mptcp_pm_a= nnounced_alloc()) and mptcp_pm_addr_entry objects (from mptcp_userspace_pm_= append_new_local_addr()) under sustained concurrent ANNOUNCE + close load a= gainst the userspace PM. Add an MPTCP_PM_DESTROYING bit in msk->pm.status, = set by mptcp_pm_destroy() under pm.lock before the lists are emptied and ch= ecked under pm.lock by the alloc paths. Either the alloc takes pm.lock firs=
t, in which case its entry is on the list when mptcp_pm_destroy() frees it;=
or mptcp_pm_destroy() takes pm.lock first, in which case the later alloc o= bserves the bit and refuses. Found by an MPTCP protocol-flow harness extend= ing BRF (arXiv:2305.08782). 2026-09-04 not yet calculated CVE-2026-80784 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-80784 ] Linux--Linux In the Lin=
ux kernel, the following vulnerability has been resolved: fbdev: serialize = mode sysfs access with lock_fb_info() show_mode(), show_modes(), and store_= mode() access fb_info->modelist and fb_info->mode without holding lock_fb_i= nfo(). store_modes() takes lock_fb_info() while replacing the modelist and = freeing the old one. A concurrent reader or writer can load a pointer to an=
old modelist entry before store_modes() frees it, then dereference freed m= emory or store a stale freed pointer in fb_info->mode. Take lock_fb_info() =
in show_mode(), show_modes(), and store_mode() to serialize with store_mode= s(). In show_mode(), copy the mode to the stack and format after dropping t=
he lock. In store_mode(), split activate() into a _locked variant to avoid = double-locking, and hold the locks for the modelist walk, mode conversion, = activation, and fb_info->mode assignment together. 2026-09-04 not yet calcu= lated CVE-2026-80785 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80785 ] = Linux--Linux In the Linux kernel, the following vulnerability has been reso= lved: fbdev: Wrap user-invoked calls to fb_set_var() in helper Handle fbcon=
during display updates in fb_set_var_from_user(). Check with fbcon if the = mode change is possible, update hardware state and finally update fbcon. Up= date all callers. Only the FBIOPUT_VSCREENINFO ioctl currently does all ste= ps. Other mode-changes callers in sysfs and driver code are missing fbcon-r= elated steps. With the new helper, ps3fb and sh_mobile_lcdcfb no longer mai= ntain fbcon state themselves. 2026-09-04 not yet calculated CVE-2026-80786 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80786 ] Linux--Linux In the L= inux kernel, the following vulnerability has been resolved: nvmet: pci-epf:=
fix use-after-free in nvmet_pci_epf_exec_iod_work() nvmet_pci_epf_exec_iod= _work() submits an I/O command with req->execute() and then waits for the c= ommand to complete and transfers the data back to the host. This wait is no=
t needed for commands that do not transfer data from the device to the host=
. To decide whether that wait is needed, it reads iod->data_len and iod->dm= a_dir after calling req->execute(). However, once req->execute() is called,=
the command may complete asynchronously on another CPU. For commands that =
do not require a device-to-host data transfer, nvmet_pci_epf_queue_response=
() calls nvmet_pci_epf_complete_iod() directly, which can free the iod befo=
re it reads iod->data_len and iod->dma_dir, resulting in the KFENCE use-aft= er- free: BUG: KFENCE: use-after-free read in nvmet_pci_epf_exec_iod_work+0= x288/0x798 [nvmet_pci_epf] Use-after-free read at 0x00000000fdfa6d03 (in kf= ence-#63): nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf] process_= one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from= _fork+0x10/0x20 kfence-#63: 0x00000000e3de0e71-0x00000000c938ad62, size=3D7= 12, cache=3Dkmalloc-1k allocated by task 10 on cpu 0 at 73.995480s (0.00512=
2s ago): mempool_kmalloc+0x1c/0x28 mempool_alloc_noprof+0x40/0x9c nvmet_pci= _epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_epf] process_one_work+0x15c/0x4f0 = worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 freed=
by task 131 on cpu 3 at 73.995521s (0.008385s ago): mempool_kfree+0x10/0x2=
0 mempool_free+0x44/0x64 nvmet_pci_epf_free_iod+0x88/0x98 [nvmet_pci_epf] n= vmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci_epf] process_one_work+0x15c/0x4f=
0 worker_thread+0x18c/0x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 Fix=
this by referring to iod->data_len and iod->dma_dir before calling req->ex= ecute(). The remaining iod accesses such as iod->status are only reached on=
the device-to-host read path. In this case, nvmet_pci_epf_queue_response()=
signals iod->done instead of freeing the iod, so the iod stays valid. 2026= -09-04 not yet calculated CVE-2026-80787 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80787 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: nvmet-tcp: Do not WARN on remotely-controlled ove= rsized SGL allocations When fuzzing the nvme target code, I tripped a kerne=
l warning in nvmet_tcp_map_data() because the length passed into the alloca= tor is controlled by the remote initiator. A remote initiator that sends a = command with an SGL claiming a huge number, can create a scatterlist and io= vec allocation of over 1 million entries, which causes the backing kmalloc = call to exceed MAX_PAGE_ORDER and then the page allocator will trip on a WA= RN_ON_ONCE_GFP() message: WARNING: mm/page_alloc.c:5280 __alloc_frozen_page= s_noprof Workqueue: nvmet_tcp_wq nvmet_tcp_io_work ... sgl_alloc_order nvme= t_tcp_map_data nvmet_tcp_try_recv_pdu As it's never good to trip a kernel w= arning remotely due to many systems having panic-on-warn enabled, let's sil= ence it by just add GFP_NOWARN to the allocation flags. 2026-09-04 not yet = calculated CVE-2026-80788 [
https://www.cve.org/CVERecord?id=3DCVE-2026-807=
88 ] Linux--Linux In the Linux kernel, the following vulnerability has been=
resolved: nvmet-tcp: bound SGL data length before allocating command buffe=
rs nvmet_tcp_map_data() reads the host-controlled 32-bit sgl->length and, f=
or the in-capsule offset descriptor (type 0x01), checks it against port->in= line_data_size before use. Any other SGL descriptor type -- including the n= on-inline transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DAT= A_DESC << 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-= of-capsule writes) skips that check entirely and falls straight through to:=
cmd->req.sg =3D sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt); with len tak=
en directly from the wire, unbounded up to 4 GiB. nvmet_req_init() only par= ses the command and never inspects sgl->length, and nvmet_check_transfer_le= n() -- the only other place transfer_len is validated -- runs later, from r= eq->execute(), after the allocation has already happened. For a write comma=
nd the target responds with an R2T and parks the command waiting for the ho=
st to send the data; if the host (or an unauthenticated peer that simply ne= ver follows up) never does, the sgl_alloc() buffer stays resident for the l= ife of the command. NVMe/TCP has no mandatory authentication in the default=
configuration, so any peer able to reach the target portal and complete a = Fabrics connect can drive this with a single crafted command, repeatable ac= ross queues and connections for amplification. This is unbounded kernel mem= ory allocation triggered by a remote, effectively unauthenticated peer. Val= idate len against the same NVMET_TCP_MAXH2CDATA ceiling this file already u= ses to bound per-PDU H2C data, for every SGL descriptor type, before doing = any allocation. This closes the gap for the non-inline descriptor while lea= ving the existing, tighter inline_data_size check in place for the in-capsu=
le case. Runtime-verified on a v6.19 KASAN stand: with this bound in place,=
a crafted write command carrying an oversized non-inline SGL length is rej= ected before sgl_alloc() runs, where the same request previously drove an u= nbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed resident pend= ing an R2T the host never satisfies. 2026-09-04 not yet calculated CVE-2026= -80789 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80789 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: nvmet-fc=
: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advance=
s iod while initializing the LS IOD array. If an rqstbuf allocation or resp= onse buffer DMA mapping fails, the unwind loop decrements iod past the star=
t of the array. The final kfree(iod) therefore frees an address before the = allocated object. This can be reproduced with nvme-fcloop and failslab by s= etting fail-nth to 6 before creating a target port. KASAN reports: BUG: KAS= AN: invalid-free in nvmet_fc_register_targetport Free of addr ffff88816cf8f= f48 by task nvmet_fail_nth/9552 Free the original allocation base stored in=
tgtport->iod instead. With this fix applied, the same sysfs write with fai= l-nth=3D6 returns -ENOMEM without any KASAN report. 2026-09-04 not yet calc= ulated CVE-2026-80790 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80790 ]=
Linux--Linux In the Linux kernel, the following vulnerability has been res= olved: nvmet-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth= _receive() allocates the response buffer with kmalloc() sized by the host-s= upplied AUTH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write=
only a fixed-size message into it. The full allocation length is then copi=
ed to the wire by nvmet_copy_to_sgl(), so a remote initiator receives the b= ytes past the built message -- up to nearly a page of uninitialized slab --=
during the pre-authentication handshake. Allocate the buffer with kzalloc(=
) so the unwritten tail is zeroed before it is sent; conforming responses a=
re unaffected. 2026-09-04 not yet calculated CVE-2026-80791 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-80791 ] Linux--Linux In the Linux kernel, th=
e following vulnerability has been resolved: ipv6: fix use-after-free in ip= 6_finish_output2() ip6_finish_output2() caches a pointer to the IPv6 destin= ation address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF transmit=
path or other encapsulation operations within lwtunnel_xmit() can realloca=
te the skb head, freeing the memory that daddr points to. When lwtunnel_xmi= t() returns LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale=
daddr pointer to compute the nexthop and to look up or create the neighbou=
r entry. This results in a use-after-free read, which can leak sensitive ke= rnel data, pollute the neighbour table with arbitrary values, misdirect tra= ffic, or crash the system. Fix this by re-fetching the IPv6 header and the = destination address pointer after lwtunnel_xmit() returns LWTUNNEL_XMIT_CON= TINUE, ensuring that the subsequent nexthop computation and neighbour looku=
p operate on valid memory. 2026-09-04 not yet calculated CVE-2026-80792 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-80792 ] Linux--Linux In the Linu=
x kernel, the following vulnerability has been resolved: ipv4: reject under= sized MTUs in ip_do_fragment() ip_do_fragment() subtracts the IPv4 header l= ength from the effective MTU and passes the resulting payload MTU to ip_fra= g_next(). If the effective MTU is smaller than hlen + 8, ip_frag_next() rou= nds the fragment payload length down to zero. The fragmentation state then = never makes forward progress: state->left, state->ptr and state->offset sta=
y unchanged while ip_do_fragment() keeps allocating and transmitting header= -only fragments until the softlockup detector fires. This is reproducible w= ith a route installed using "mtu lock 20", but it is also reproducible with= out route MTU lock, for example by forwarding a packet to a device whose MT=
U is 20. Fix it in ip_do_fragment() by rejecting mtu < hlen + 8 with -EMSGS= IZE, matching the existing IPv6 fragmentation check. 2026-09-04 not yet cal= culated CVE-2026-80793 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80793 =
] Linux--Linux In the Linux kernel, the following vulnerability has been re= solved: nfc: nci: fix uninit-value in the RF discover/activated NTF handler=
s nci_rf_discover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each = parse a notification into an on-stack struct (nci_rf_discover_ntf / nci_rf_= intf_activated_ntf) that is not initialised. The RF technology-specific par= ameters are only extracted when rf_tech_specific_params_len is non-zero, so=
a notification that reports a zero length leaves the rf_tech_specific_para=
ms union uninitialised - and both handlers then pass it to nci_add_new_prot= ocol(), which reads it: - discover: nci_add_new_target() -> nci_add_new_pro= tocol(); - activated: nci_target_auto_activated() -> nci_add_new_protocol()=
. nci_add_new_protocol() uses nfca_poll->nfcid1_len as both a branch condit= ion and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->tar= gets, which is later exposed to user space via NFC_CMD_GET_TARGET. BUG: KMS= AN: uninit-value in nci_add_new_protocol+0x624/0x6c0 nci_add_new_protocol+0= x624/0x6c0 nci_ntf_packet+0x25b2/0x3c30 nci_rx_work+0x318/0x5d0 process_sch= eduled_works+0x84b/0x17a0 worker_thread+0xc10/0x11b0 kthread+0x376/0x500 Lo= cal variable ntf.i created at: nci_ntf_packet+0xbc2/0x3c30 Zero-initialise = both on-stack notifications so the union reads back as zero when no technol= ogy-specific parameters are present. 2026-09-04 not yet calculated CVE-2026= -80794 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80794 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: nfc: nci=
: fix out-of-bounds write in nci_target_auto_activated() nci_target_auto_ac= tivated() appends a target to the fixed-size array ndev->targets[NCI_MAX_DI= SCOVERED_TARGETS] and increments ndev->n_targets without first checking the=
array is full; unlike its sibling nci_add_new_target(), which bails out wh=
en n_targets already equals NCI_MAX_DISCOVERED_TARGETS. ndev->n_targets is = only cleared by nci_clear_target_list(), so an NFCC that repeatedly re-runs=
discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY without clearing=
the target list) and reports an auto-activated target (RF_INTF_ACTIVATED_N= TF) drives n_targets past the limit. The append then writes a struct nfc_ta= rget past the end of the array (a slab out-of-bounds write), and nfc_target= s_found() goes on to walk the array with the inflated count: BUG: KASAN: sl= ab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci] Write of size 2 a=
t addr ffff0000c7299a18 by task kworker/u8:0/12 Workqueue: nfc0_nci_rx_wq n= ci_rx_work [nci] Call trace: nci_add_new_protocol+0x94/0x2ac [nci] nci_ntf_= packet+0xddc/0x11a0 [nci] nci_rx_work+0x15c/0x1e0 [nci] process_one_work+0x= 2dc/0x500 worker_thread+0x240/0x460 kthread+0x1c0/0x1d0 ret_from_fork+0x10/= 0x20 The buggy address belongs to the cache kmalloc-2k of size 2048 The bug=
gy address is located 1024 bytes to the right of allocated 1560-byte region=
[ffff0000c7299000, ffff0000c7299618) Guard nci_target_auto_activated() wit=
h the same check used by nci_add_new_target(). 2026-09-04 not yet calculate=
d CVE-2026-80795 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80795 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: nfc: nci: add data_len bound checks to activation parameter extractors nc= i_extract_activation_params_iso_dep() and nci_extract_activation_params_nfc= _dep() read an inner length byte from the NCI RF_INTF_ACTIVATED_NTF payload=
and use it to memcpy() into fixed kernel buffers, but neither function rec= eives the caller-validated activation_params_len. A crafted NCI notificatio=
n with activation_params_len=3D1 and an inner length byte of up to 20 (NFC-=
A) or 50 (NFC-B) causes memcpy() to read that many bytes past the one valid=
byte in the activation params region -- a slab out-of-bounds read of kerne=
l memory adjacent to the NCI skb. The sibling nci_extract_rf_params_*() fam= ily was given equivalent protection by commit 571dcbeb8e63 ("net: nfc: nci:=
Fix parameter validation for packet data"), but the two activation paramet=
er extractors were not updated at that time. Add a data_len parameter to bo=
th functions, guard against an empty region before consuming the inner leng=
th byte, decrement the remaining count after consuming it, and clamp the co=
py length to what is actually available. Update both call sites to pass ntf= .activation_params_len, which is already validated against the skb at ntf.c= :801. 2026-09-04 not yet calculated CVE-2026-80796 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-80796 ] Linux--Linux In the Linux kernel, the followi=
ng vulnerability has been resolved: nfc: pn533: purge fragmented skbs durin=
g cleanup pn53x_common_clean() purges resp_q before freeing the common PN53=
3 state, but it leaves fragment_skb untouched. The fragmentation helpers qu= eue transmit fragments there while sending large initiator or target-mode f= rames, and those skbs remain owned by the driver until they are sent or dis= carded. If the device is removed while fragments are still queued, the comm=
on cleanup path frees the PN533 state without releasing the queued fragment=
skbs, leaking them. Purge fragment_skb during cleanup alongside resp_q. 20= 26-09-04 not yet calculated CVE-2026-80797 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-80797 ] Linux--Linux In the Linux kernel, the following vulne= rability has been resolved: nfc: llcp: reject PDUs shorter than the LLCP he= ader Every LLCP PDU begins with a two-byte header (DSAP/SSAP + PTYPE), but = the receive path never checked that a frame is at least LLCP_HEADER_SIZE by= tes before parsing it. nfc_llcp_rx_skb() reads the header via nfc_llcp_ptyp= e()/nfc_llcp_dsap()/ nfc_llcp_ssap(), which dereference pdu->data[0] and pd= u->data[1], and a CONNECT or CC PDU then computes tlv_array_len =3D skb->le=
n - LLCP_HEADER_SIZE; as a size_t and hands it to the TLV walk. When the fr= ame is shorter than the header the subtraction wraps to a huge value and th=
e walk runs far past the buffer, an out-of-bounds read. A nearby NFC device=
can reach this without authentication; LLCP link activation happens automa= tically after NFC-DEP. Guard the common receive choke point __nfc_llcp_recv= (), shared by both the target (nfc_llcp_data_received()) and initiator (nfc= _llcp_recv()) paths, so a short skb is dropped before the rx_work worker pa= rses it. Use pskb_may_pull() rather than a skb->len test so the two header = bytes are guaranteed to sit in the skb linear area even for a non-linear sk=
b, matching how the sibling NCI and HCI receive paths validate their header=
s. Reproduced with a KFENCE out-of-bounds read via /dev/virtual_nci on linu= x-next. Found by 0sec automated security-research tooling (
https://0sec.ai)=
. 2026-09-04 not yet calculated CVE-2026-80798 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-80798 ] Linux--Linux In the Linux kernel, the following v= ulnerability has been resolved: nfc: llcp: fix OOB read and u8 offset wrap =
in TLV parsers nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv() = contain three related bugs in their TLV parsing loops: 1. 'offset' is decla= red u8 but tlv_array_len is u16. When TLV data advances offset past 255 it = silently wraps to zero, causing infinite loops or double-processing of buff=
er data. 2. Before reading tlv[0] (type) and tlv[1] (length) there is no ch= eck that offset+2 <=3D tlv_array_len. A truncated TLV causes an OOB read of=
one byte past the buffer end. 3. After reading the length field, the value=
bytes are accessed without checking offset+2+length <=3D tlv_array_len. A = crafted length=3D0xFF on a short buffer causes up to 255 bytes of OOB read = past the buffer end. Both functions are reachable without authentication vi=
a nfc_llcp_set_remote_gb() which feeds remote LLCP general bytes directly i= nto nfc_llcp_parse_gb_tlv() with no additional validation. Fix all three is= sues by widening offset from u8 to u16 and adding bounds checks for both th=
e TLV header and value field before each access. 2026-09-04 not yet calcula= ted CVE-2026-80799 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80799 ] Li= nux--Linux In the Linux kernel, the following vulnerability has been resolv= ed: nfc: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e=
("nfc: llcp: bound SNL TLV parsing to the skb and add length checks") fixe=
d the unbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd2dedbde5 ("= nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers") subsequently bo= unded nfc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv(). One sibl= ing parser sharing the same pattern remains unbounded: nfc_llcp_connect_sn(=
). nfc_llcp_connect_sn() walks a TLV list, reading a two-byte header (type,=
length) followed by length bytes of value, without checking that the two h= eader bytes or the declared length stay within the buffer. It returns a poi= nter to a service name of up to 255 bytes that may point past the end of th=
e skb; it is subsequently consumed by memcmp() in nfc_llcp_sock_from_sn(). =
In addition tlv_array_len was computed as "skb->len - LLCP_HEADER_SIZE" in = size_t, so a CONNECT/CC frame shorter than the LLCP header underflows to a = huge length and the walk runs far past the buffer. nfc_llcp_connect_sn() is=
reachable from nfc_llcp_recv_connect() and nfc_llcp_recv_cc(), i.e. from r= eceived CONNECT and CC PDUs. A nearby NFC device can reach this without aut= hentication; LLCP link activation happens automatically after NFC-DEP, and = the nfc_llcp_rx_skb() dispatcher applies no minimum-length guard. Walk the = TLV list by pointer, bounded by skb_tail_pointer(skb), and validate each de= clared length before use, matching the approach already used for nfc_llcp_r= ecv_snl(). Starting the walk at &skb->data[LLCP_HEADER_SIZE] against the ta=
il pointer also removes the size_t underflow for short frames. Found by 0se=
c automated security-research tooling (
https://0sec.ai). 2026-09-04 not yet=
calculated CVE-2026-80800 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80= 800 ] Linux--Linux In the Linux kernel, the following vulnerability has bee=
n resolved: nfc: microread: validate target discovery payload lengths micro= read_target_discovered() parses target discovery payloads from skb->data ac= cording to the HCI gate. The fixed field offsets and UID copies were checke=
d only against the destination nfc_target buffers, not against the actual s=
kb length. Validate that each gate-specific payload contains the fixed fiel=
ds and UID bytes before reading or copying them. 2026-09-04 not yet calcula= ted CVE-2026-80801 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80801 ] Li= nux--Linux In the Linux kernel, the following vulnerability has been resolv= ed: nfc: fdp: bound the device-reported read length and fix an skb leak fdp= _nci_i2c_read() takes the next packet length from two device-supplied bytes=
and never validates it. The value is a u16 used as the i2c_master_recv() c= ount into a 261-byte on-stack buffer: a malicious, counterfeit or malfuncti= oning controller (or an i2c bus interposer) can drive it far past the buffe=
r for a stack out-of-bounds write that clobbers the canary and return addre= ss, or below the minimum frame size (directly, or by truncating the compute=
d sum) so the header/LRC strip and the next length read run past a short re= ceive. Reject a length outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PA= YLOAD], as a corrupted packet already is, and force resynchronization. The = same loop allocates one data skb per iteration and assumes a length packet = followed by a data packet; a device that sends two data packets in one call=
leaks the first skb when the second allocation overwrites it. Free a previ= ously allocated skb before allocating the next. 2026-09-04 not yet calculat=
ed CVE-2026-80802 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80802 ] Lin= ux--Linux In the Linux kernel, the following vulnerability has been resolve=
d: nfc: digital: clamp SENSF_RES length to the destination buffer digital_i= n_recv_sensf_res() memcpy()s resp->len bytes from a remote NFC-F device res= ponse into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res field without an=
upper-bound check. A nearby malicious NFC-F device can send an oversized S= ENSF_RES response to overflow the stack-local struct nfc_target. Clamp resp= ->len to NFC_SENSF_RES_MAXSIZE before the copy. Found by 0sec automated sec= urity-research tooling (
https://0sec.ai). 2026-09-04 not yet calculated CVE= -2026-80803 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80803 ] Linux--Li= nux In the Linux kernel, the following vulnerability has been resolved: xfs=
: restore nofs context unconditionally in xfs_trans_roll When __xfs_trans_c= ommit() fails in xfs_trans_roll(), the NOFS context is cleared but only res= tored in the success path. This leaves the error path without nofs protecti= on, causing a circular lock dependency between xfs_nondir_ilock_class and f= s_reclaim: CPU0 CPU1 ---- ---- lock(&xfs_nondir_ilock_class); lock(fs_recla= im); lock(&xfs_nondir_ilock_class); lock(fs_reclaim); Fix this by moving xf= s_trans_set_context() before the error check so that nofs context is always=
restored on the new transaction. 2026-09-04 not yet calculated CVE-2026-80= 804 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80804 ] Linux--Linux In t=
he Linux kernel, the following vulnerability has been resolved: xfs: valida=
te attr entry pointer before field access xfs_attr3_leaf_verify_entry() acc= esses lentry/rentry fields (namelen, valuelen) before checking if the entry=
pointer itself is within bounds. If nameidx is crafted to point near the e=
nd of the buffer, these field accesses can read out-of-bounds before the bo= unds check at name_end > buf_end is performed. Add explicit bounds checks f=
or entry pointers before accessing their fields. Use offsetof() to check th=
at the start of the flexible array member (nameval/name) is within bounds, = which ensures all preceding fields are safe to access. 2026-09-04 not yet c= alculated CVE-2026-80805 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8080=
5 ] Linux--Linux In the Linux kernel, the following vulnerability has been = resolved: ext4: don't enable DAX on new encrypted files Currently, when a n=
ew encrypted regular file is created, the call to ext4_set_inode_flags(inod=
e, init=3Dtrue) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT is = set. As a result, it can set S_DAX if the filesystem is mounted with "-o da= x=3Dalways". EXT4_INODE_ENCRYPT then actually gets set a bit later in __ext= 4_new_inode(), when it calls fscrypt_set_context() which calls ext4_set_con= text(). ext4_set_context() sets EXT4_INODE_ENCRYPT and calls ext4_set_inode= _flags(inode, init=3Dfalse) to set S_ENCRYPTED too. This was intended to cl= ear S_DAX as well. However, this was broken by commit 043546e46dc7 ("fs/ext=
4: Only change S_DAX on inode load"). This causes data written to the file =
to bypass encryption, also causing xfstests failures such as generic/548 (w= hen "-o dax=3Dalways" is used). Fix this by simplifying the flow by making = __ext4_new_inode() set EXT4_INODE_ENCRYPT earlier. This makes it take effec=
t in ext4_set_inode_flags(inode, init=3Dtrue), making S_DAX never be set. S= imilarly, make EXT4_STATE_MAY_INLINE_DATA never be set in the first place o=
n new encrypted inodes. Then it doesn't need to be cleared. As a result of = these simplifications, ext4_set_context() no longer needs to change inode f= lags or state when 'handle !=3D NULL'. Remove that too. 2026-09-04 not yet = calculated CVE-2026-80806 [
https://www.cve.org/CVERecord?id=3DCVE-2026-808=
06 ] Linux--Linux In the Linux kernel, the following vulnerability has been=
resolved: nilfs2: reject invalid block index in GC ioctl Syzbot reported l= ist corruption caused by a double list_add_tail() call on bh->b_assoc_buffe=
rs within nilfs_lookup_dirty_data_buffers(). Analysis revealed that the roo=
t cause was the insertion of a page/folio with a page index of ULONG_MAX in=
to the page cache via the GC ioctl. filemap_get_folios_tag(), called by nil= fs_lookup_dirty_data_buffers(), repeatedly detects a dirty folio with a pag=
e index of ULONG_MAX due to index wrap-around, leading to duplicate process= ing of dirty buffers. As a preparatory step, the GC ioctl loads the page/fo= lio of the block to be moved during GC and inserts it into the page cache b= ased on information in the nilfs_vdesc structure passed as an argument. Nor= mally, this does not cause issues because the user-space GC library configu= res the nilfs_vdesc structure properly. However, since there is no range ch= eck on the parameters determining the page index, a request with artificial=
ly crafted parameters -- such as those generated by Syzbot -- can result in=
a page/folio being inserted with a page index of ULONG_MAX, triggering the=
above problem. This resolves the issue by checking the ranges of 'vd_offse=
t' and 'vd_vblocknr' in the nilfs_vdesc structure that determine the page i= ndex, thereby preventing the invalid page/folio insertions. 2026-09-04 not = yet calculated CVE-2026-80807 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -80807 ] Linux--Linux In the Linux kernel, the following vulnerability has = been resolved: ext4: stop retrying saturated xattr cache entries ext4_xattr= _block_set() retries when a cache entry selected for reuse has a saturated = reference count after taking the buffer lock. The retry returns to the mbca= che lookup without making that entry ineligible, so it can select the same = unusable entry indefinitely. A task spinning there can hold the parent dire= ctory's i_rwsem and leave concurrent rmdir callers blocked. Normally a reus= able entry has a reference count below EXT4_XATTR_REFCOUNT_MAX because the = count and MBE_REUSABLE_B are updated under the same buffer lock. A corrupte=
d filesystem can violate that invariant. The syzbot reproducer reports allo= cator and xattr corruption before triggering this retry loop. Check the unt= rusted on-disk count before incrementing it, avoiding overflow, and clear M= BE_REUSABLE_B when it is already saturated. The next lookup then skips the = entry that was just proven unusable. This mirrors the normal transition at = EXT4_XATTR_REFCOUNT_MAX; the release path marks the entry reusable again on=
the exact 1024-to-1023 transition. Using the same QEMU harness and guest p= arameters, current unpatched Linux hung in 6 of 8 420-second trials with th=
e do_rmdir signature; representative NMI backtraces caught the owner spinni=
ng in ext4_xattr_block_set(). The patched kernel completed 28 of 28 trials = without a hung-task report; the final twelve trials exercised the reviewed = overflow-safe form of the change. syzbot's patch testing also completed wit= hout reproducing the hang. 2026-09-04 not yet calculated CVE-2026-80808 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-80808 ] Linux--Linux In the Linu=
x kernel, the following vulnerability has been resolved: ocfs2: fix missing=
metadata reservation for large xattrs [BUG] lsetxattr() panics the kernel = when setting a large xattr value on a fragmented filesystem where the file = already has an external xattr block. [CAUSE] ocfs2_calc_xattr_set_need() ne= ver reserves metadata blocks for a new xattr value's extent tree when the f= ile already has an external xattr block. The not_found path leaves meta_add=
at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocation() runs. A n=
ew value root has room for a single extent record. On a fragmented filesyst= em, the allocator cannot satisfy the xattr value in one contiguous run, so = each non-contiguous run requires its own extent record. When the value root=
's extent list is full and meta_ac is NULL, ocfs2_add_clusters_in_btree() r= eturns RESTART_META, and ocfs2_xattr_extend_allocation() hits BUG_ON(why = =3D=3D RESTART_META). [FIX] The case where no xattr block exists yet alread=
y calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to reserve value tree = metadata. Add the same reservation to the case where an xattr block already=
exists, making the two cases consistent. Replace the BUG_ON with a -ENOSPC=
return so that if RESTART_META is returned despite the reservation, the er= ror propagates to userspace instead of panicking the kernel. 2026-09-04 not=
yet calculated CVE-2026-80809 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-80809 ] Linux--Linux In the Linux kernel, the following vulnerability has=
been resolved: io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec(=
) io_vec_fill_bvec() computes the folio size with a plain int 1: unsigned l= ong folio_size =3D 1 << imu->folio_shift; imu->folio_shift is unsigned int = and comes from folio_shift() of the folio backing the registered buffer, so=
it can be 32 or more on a 64 bit kernel. Shifting int 1 that far is undefi= ned, and on x86 and arm64 the count is taken modulo 32, so a shift of 34 yi= elds 4 rather than 16G. Every other folio_shift shift in this file already = uses 1UL. The result is that the segment estimate and the fill loop disagre=
e. io_estimate_bvec_size() sizes the bvec array with the real shift: max_se=
gs +=3D (iov[i].iov_len >> shift) + 2; so a 1M iovec on a 16G folio is char= ged 2 segments, while io_vec_fill_bvec() then walks the same iovec in folio= _size chunks of 4 bytes and writes res_bvec[bvec_idx] a quarter of a millio=
n times, past the end of the array it was given. src_bvec is advanced once = per iteration as well, so imu->bvec is read past its end at the same time. = validate_fixed_range() only checks that the range is inside the registered = buffer and does not bound the segment count. Reaching it needs a folio with=
a shift of at least 32, which means a gigantic hugetlb page: 16G on arm64 = with 64K pages, where CONT_PMD_SHIFT is 34 and hugetlb_add_hstate(CONT_PMD_= SHIFT - PAGE_SHIFT) registers that size, and likewise on powerpc. x86_64 to=
ps out at 1G, so a shift of 30, which still fits in int and is unaffected. = Use 1UL, as the rest of the file does. 2026-09-04 not yet calculated CVE-20= 26-80810 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80810 ] Linux--Linux=
In the Linux kernel, the following vulnerability has been resolved: io_uri= ng/cmd: fix iovec leak when the async cmd is not recycled An io_async_cmd c= arries an iovec array in ->vec.iovec, allocated when the vec has to grow an=
d kept across recycling through ctx->cmd_cache. On two paths nothing frees =
it and io_clean_op()'s kfree(req->async_data) drops the io_async_cmd withou=
t it. io_req_uring_cleanup() clears the async data flags only when io_alloc= _cache_put() succeeds, and the cache holds IO_ALLOC_CACHE_MAX =3D=3D 128 en= tries, so once it is full the put fails and the vec is left behind. An NVMe=
passthrough workload gets there without doing anything unusual: nvme_uring= _cmd_io() returns -EIOCBQUEUED, so the io_async_cmd stays attached for the = lifetime of the command and the live object count tracks the queue depth. A= bove 128 the puts start failing. ->cleanup is the last chance to free an in= herited vec, since io_req_uring_cleanup() returns early for an io-wq issued=
command and is not called at all for one completed without ever being issu= ed. But io_clean_op() calls ->cleanup only if REQ_F_NEED_CLEANUP is set, an=
d for uring_cmd that happens only where the vec has to grow, so a command r= eusing a large enough cached vec never sets it. io_rw_alloc_async() and io_= msg_alloc_async() flag an inherited vec for exactly this reason; io_uring_c= md_prep() does not. Flag an inherited vec in io_uring_cmd_prep(), and free = the vec when the cache put fails, as io_req_rw_cleanup() does. The leak is = invisible under KASAN, where io_alloc_cache_vec_kasan() frees the vec uncon= ditionally. 2026-09-04 not yet calculated CVE-2026-80811 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-80811 ] Linux--Linux In the Linux kernel, the f= ollowing vulnerability has been resolved: ALSA: dummy: Check card index val= idity at probe snd_dummy_probe() blindly trusts that the given devptr->id v= alue is within the proper card index range. It's OK for the devices the dri= ver itself creates at the module probe time, but if the device is bound man= ually via sysfs interface, this could be -1 as "none", and this leads to OO=
B access for index[] and other parameters. Add a sanity check for the card = index and warn/correct it if it's a value out of the range. 2026-09-04 not = yet calculated CVE-2026-80812 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -80812 ] Linux--Linux In the Linux kernel, the following vulnerability has = been resolved: nvmet: fix NULL pointer dereference in nvmet_execute_identif= y_nslist() When a host issues an Identify command with CNS 07h (Active Name= space ID List for a specific I/O Command Set), nvmet_execute_identify_nslis= t() is called with match_css set. The command-set filter dereferences req->= ns, but this handler never calls nvmet_req_find_ns(), so req->ns is always = NULL (nvmet_req_init() resets it to NULL). As soon as an enabled namespace = with an NSID greater than the requested value exists, req->ns->csi derefere= nces a NULL pointer and oopses. Besides the crash, the comparison is logica= lly wrong: to filter the list by command set it must test the command set o=
f the namespace being iterated, not a single fixed value. Use the loop vari= able ns->csi. 2026-09-04 not yet calculated CVE-2026-80813 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-80813 ] Linux--Linux In the Linux kernel, the=
following vulnerability has been resolved: rndis_host: add overflow check =
in rndis_rx_fixup() Add an overflow check to ensure that data_offset + data= _len + 8 does not wrap, which would enable an OOB read of the USB data buff= er. 2026-09-04 not yet calculated CVE-2026-80814 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-80814 ] Linux--Linux In the Linux kernel, the following=
vulnerability has been resolved: ALSA: scarlett2: Use a private URB for th=
e notification endpoint scarlett2_init_notify() used mixer->urb, which snd_= usb_mixer_status_create() allocates for the UAC2 status interrupt endpoint = and mixer.c manages. On a device with that endpoint, the "already in use" c= heck fires on the status URB and returns 0 for success without doing anythi= ng. No notification URB is submitted, and cmd_done is left zeroed because i=
t is initialised past that check and nowhere else. scarlett2_usb_init() the=
n issues SCARLETT2_USB_INIT_1 and wait_for_completion_timeout() would crash=
adding to the zeroed wait.head. Use a separate URB in scarlett2_data, as d= one for FCP, and initialise cmd_done in scarlett2_init_private(). mixer.c w=
as also freeing the URB in snd_usb_mixer_free() and resubmitting it in snd_= usb_mixer_activate(), so scarlett2 must now do both: add scarlett2_cleanup_= urb(), called from private_free and private_suspend, and a private_resume c= allback to re-establish the URB after resume. scarlett2_init_notify() is re= ached from there, and the URB kill path in scarlett2_notify() completes cmd= _done, leaving a stale count that would satisfy the next command's wait bef= ore the device ACKs. Use reinit_completion() to clear it. Also free the URB=
if the transfer buffer allocation fails, and both if usb_submit_urb() fail=
s. Move scarlett2_init_notify() up next to scarlett2_cleanup_urb() so scarl= ett2_init_private() can reference it without a forward declaration. 2026-09= -04 not yet calculated CVE-2026-80815 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-80815 ] Linux--Linux In the Linux kernel, the following vulnerabil= ity has been resolved: ALSA: FCP: Use a private URB for the notification en= dpoint fcp_init_notify() used mixer->urb, which snd_usb_mixer_status_create=
() allocates for the optional UAC2 status interrupt endpoint and mixer.c ki= lls, resubmits and frees. On a device with that endpoint, fcp_init_notify()=
's "already set up" early return fires on the status URB and returns succes=
s without doing anything. No FCP notification URB is submitted, and cmd_don=
e is left zeroed because it is initialised past that early return and nowhe=
re else. fcp_init() then issues init1_opcode and wait_for_completion_timeou= t() would crash adding to the zeroed wait.head. fcp_cleanup_urb() would als=
o kill and free mixer.c's status URB. Use a separate URB in fcp_data, and i= nitialise cmd_done in fcp_init_private() where fcp_data is allocated. fcp_i= nit_notify() is reached again after suspend via fcp_reinit(), and the URB k= ill path in fcp_notify() completes cmd_done, leaving a stale count that wou=
ld satisfy the next command's wait before the device ACKs. Use reinit_compl= etion() to clear it. 2026-09-04 not yet calculated CVE-2026-80816 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-80816 ] Linux--Linux In the Linux kern= el, the following vulnerability has been resolved: iommu/iommufd: Fix NULL = pointer deref in iommufd_ioas_change_process when racing with iopt_map_file= _pages iommufd_ioas_change_process() iterates every IOAS area while only ho= lding every IOAS iova_rwsem, so it assumes every area has a non-NULL pages = pointer. That assumption can be false when it runs concurrently with iopt_m= ap_file_pages(). iopt_map_pages() executes in two phases. It first creates = the area and inserts it into the interval tree under iova_rwsem, with area-= >pages still NULL. It then drops iova_rwsem and later fills area->pages und=
er domains_rwsem. This leaves a window between area creation and area->page=
s fill where a concurrent iommufd_ioas_change_process() can observe the are=
a and dereference a NULL area->pages pointer, leading to a NULL pointer der= eference: BUG: kernel NULL pointer dereference, address: 00000000000000c0 #= PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-pre= sent page PGD 4b655067 P4D 4b655067 PUD 0 Oops: Oops: 0000 [#1] SMP NOPTI C= PU: 0 UID: 0 PID: 11841 Comm: syz.1.628 Not tainted 7.1.0 #3 PREEMPT(full) = Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996)=
, BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:iommufd_ioas_change_proc= ess+0x419/0xd50 drivers/iommu/iommufd/ioas.c:538 Code: 48 89 c3 48 85 c0 0f=
84 cc 00 00 00 e8 10 f5 cb fd 48 8d 7b 68 e8 a7 b5 eb fd 48 8b 6b 68 48 8d=
bd c0 00 00 00 e8 17 b2 eb fd <8b> ad c0 00 00 00 bf 01 00 00 00 89 ee e8 =
85 ef cb fd 83 fd 01 74 RSP: 0018:ffffc90015c17d28 EFLAGS: 00010246 RAX: ff= ff8880186d5328 RBX: ffff88801d25e240 RCX: 0000000080000000 RDX: 00000000000= 002d7 RSI: ffffffff83ba9e10 RDI: 00000000000000c0 RBP: 0000000000000000 R08=
: ffffffff8e781eb8 R09: 0000000000000000 R10: 00000000000000c0 R11: fffffff= f83ba9e29 R12: ffff88802e216008 R13: ffff88802e216000 R14: 0000000000000001=
R15: 0000000000000000 FS: 00007f4aea3f66c0(0000) GS:ffff8880b1fa1000(0000)=
knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR=
2: 00000000000000c0 CR3: 000000004b75c000 CR4: 0000000000350ef0 Call Trace:=
<TASK> iommufd_fops_ioctl+0x287/0x400 drivers/iommu/iommufd/main.c:533 vfs= _ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:597 [inline] __se_s= ys_ioctl fs/ioctl.c:583 [inline] __x64_sys_ioctl+0x120/0x170 fs/ioctl.c:583=
x64_sys_call+0x1092/0x1fb0 arch/x86/include/generated/asm/syscalls_64.h:17=
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x10a= /0x680 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0= x7f RIP: 0033:0x7f4aec1a82bd Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f=
3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 2=
4 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01=
48 RSP: 002b:00007f4aea3f6018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 = RAX: ffffffffffffffda RBX: 00007f4aec436090 RCX: 00007f4aec1a82bd RDX: 0000= 200000000180 RSI: 0000000000003b92 RDI: 0000000000000003 RBP: 00007f4aec250= 295 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: = 0000000000000246 R12: 0000000000000000 R13: 00007f4aec436128 R14: 00007f4ae= c436090 R15: 00007ffd04ef23e0 </TASK> Modules linked in: CR2: 0000000000000= 0c0 ---[ end trace 0000000000000000 ]--- RIP: 0010:iommufd_ioas_change_proc= ess+0x419/0xd50 drivers/iommu/iommufd/ioas.c:538 Code: 48 89 c3 48 85 c0 0f=
84 cc 00 00 00 e8 10 f5 cb fd 48 8d 7b 68 e8 a7 b5 eb fd 48 8b 6b 68 48 8d=
bd c0 00 00 00 e8 17 b2 eb fd <8b> ad c0 00 00 00 bf 01 00 00 00 89 ee e8 =
85 ef cb fd 83 fd 01 74 RSP: 0018:ffffc90015c17d28 EFLAGS: 00010246 RAX: ff= ff8880186d5328 RBX: ffff88801d25e240 RCX: 0000000080000000 RDX: 00000000000= 002d7 RSI: ffffffff83ba9e10 RDI: 00000000000000c0 RBP: 0000000000000000 R08=
: ffffffff8e781eb8 R09: 0000000000000000 R10: 00000000000000c0 R11: fffffff= f83ba9e29 R12: ffff88802e216008 R13: ffff88802e216000 R14: 0000000000000001=
R15: 0000000000000000 FS: 00007f4aea3f66c0(000 ---truncated--- 2026-09-04 = not yet calculated CVE-2026-80817 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-80817 ] Linux--Linux In the Linux kernel, the following vulnerability = has been resolved: iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on tea= rdown arm_smmu_impl_remove() is registered as a devres action in arm_smmu_i= mpl_probe(), before arm_smmu_init_queues() allocates smmu->cmdq.q.base. On =
a devres unwind, whether a failed probe or an unbind, the queue is freed fi= rst and arm_smmu_impl_remove() then runs tegra241_cmdqv_remove_vintf(), who=
se VINTF deinit issues a CMD_SYNC on the freed memory. Observed during test= ing with a QEMU hack that makes the VCMDQ fail to enable, so the impl reset=
fails and probe aborts into the devres unwind: platform NVDA200C:00: tegra= 241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: failed to enable, STATUS=3D0x00000000 pl= atform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: GERRORN=3D0x0, = GERROR=3D0x4, CONS=3D0x0 platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMD= Q0/LVCMDQ0: uncleared error detected, resetting arm-smmu-v3 arm-smmu-v3.0.a= uto: failed to reset impl arm-smmu-v3 arm-smmu-v3.0.auto: probe with driver=
arm-smmu-v3 failed with error -110 Unable to handle kernel paging request =
at virtual address ffff8000891e0098 ... Internal error: Oops: 0000000096000= 047 [#1] SMP ... Call trace: arm_smmu_cmdq_issue_cmdlist+0x320/0x6fc (P) te= gra241_vcmdq_hw_deinit+0x98/0x168 tegra241_vintf_hw_deinit+0x5c/0x1b0 tegra= 241_cmdqv_remove_vintf+0x34/0xec tegra241_cmdqv_remove+0x40/0x9c arm_smmu_i= mpl_remove+0x20/0x30 devm_action_release+0x14/0x20 devres_release_all+0xa8/= 0x110 device_unbind_cleanup+0x18/0x84 really_probe+0x1f0/0x29c Drop the VIN=
TF deinit from tegra241_cmdqv_remove_vintf() so the unwind no longer touche=
s the freed queue. Quiesce the VINTFs earlier instead. Add a device_disable=
() impl op and run it from arm_smmu_disable_action() while the CMDQ is stil=
l up. That handles a live unbind. A failed reset is already handled because=
tegra241_vintf_hw_init() deinits the VINTF on its own error path. tegra241= _cmdqv_remove_vintf() is also used by the iommufd viommu destroy path, so q= uiesce there too. 2026-09-04 not yet calculated CVE-2026-80818 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-80818 ] Linux--Linux In the Linux kernel,=
the following vulnerability has been resolved: Bluetooth: RFCOMM: take rfc= omm_mutex for the deferred setup accept rfcomm_sock_recvmsg() completes a d= eferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM loc=
k: if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) { rfcomm_dlc_acce= pt(d); return 0; } and rfcomm_dlc_accept() dereferences the session on its = first line: struct sock *sk =3D d->session->sock->sk; Every other path that=
touches d->session runs under rfcomm_mutex: rfcomm_dlc_open(), rfcomm_dlc_= close(), rfcomm_dlc_exists(), rfcomm_dlc_send_rpn(), and the RFCOMM thread = through rfcomm_process_sessions(). rfcomm_connect_ind() is even documented =
as "called under rfcomm_lock()". This call site is the only one that skips = it. The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against = teardown, since __rfcomm_dlc_close() returns early when it wins the test_an= d_clear. But rfcomm_recv_disc() forces the state first: d->state =3D BT_CLO= SED; __rfcomm_dlc_close(d, err); and the early return only covers BT_CONNEC=
T, BT_CONFIG, BT_OPEN and BT_CONNECT2. With the state already BT_CLOSED tha=
t switch does not match, the bit is never consulted, and __rfcomm_dlc_close=
() falls through to rfcomm_dlc_unlink(), which sets d->session =3D NULL. So=
a remote DISC on a deferred dlc clears the session while leaving RFCOMM_DE= FER_SETUP set. The next recvmsg() then passes the test_and_clear and derefe= rences a NULL session. No timing window is needed: once the DISC has been p= rocessed, the dereference is unconditional. Give rfcomm_dlc_accept() the sa=
me shape as rfcomm_dlc_open() and rfcomm_dlc_close(): an exported wrapper t= hat takes rfcomm_mutex and re-checks the session, around a __rfcomm_dlc_acc= ept() that the two in-core callers, which already hold the mutex, keep usin=
g. Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated=
over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM = PSM, starts a session, opens a dlc on a channel bound with BT_DEFER_SETUP, = and sends DISC after the socket is accepted. recv() on the accepted socket = then hits: Oops: general protection fault KASAN: null-ptr-deref in range [0= x0000000000000010-0x0000000000000017] RIP: 0010:rfcomm_dlc_accept+0x54/0x35=
0 Call Trace: rfcomm_sock_recvmsg+0x1cd/0x230 sock_recvmsg+0x166/0x1c0 __sy= s_recvfrom+0x20d/0x300 0x10 is the offset of sock in struct rfcomm_session.=
With this patch the same run completes with recv() returning 0 and no repo= rt, and lockdep stays quiet, confirming rfcomm_mutex is still taken before = lock_sock on this path as it is on the thread side. 2026-09-04 not yet calc= ulated CVE-2026-80819 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80819 ]=
Linux--Linux In the Linux kernel, the following vulnerability has been res= olved: xfs: don't livelock in scrub on a circular unlinked list LOLLM point=
s out that online fsck can livelock if an unlinked inode list contains a lo= op. Use a bitmap to detect cycles. 2026-09-04 not yet calculated CVE-2026-8= 0820 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80820 ] Linux--Linux In = the Linux kernel, the following vulnerability has been resolved: nvmet: pci= -epf: put CQ ref on create_cq mapping failure nvmet_pci_epf_create_cq() cal=
ls nvmet_cq_create(), which takes a reference on the controller and install=
s the completion queue. If the subsequent PCI address-space mapping fails o=
r returns a too-small partial mapping, the function jumps to err_internal /=
err_unmap_queue without calling nvmet_cq_put(). The matching put in nvmet_= pci_epf_delete_cq() is gated on NVMET_PCI_EPF_Q_LIVE, which is only set aft=
er the mapping succeeds, so teardown never releases these references. A rem= ote PCI host that drives Create IO CQ commands with a failing PRP1/pci_addr=
therefore leaks the CQ and a controller reference on each attempt. Drop th=
e CQ reference on the mapping-failure paths. The err_internal and err_unmap= _queue labels are only reachable after nvmet_cq_create() has succeeded, so = this pairs the create/put correctly. 2026-09-04 not yet calculated CVE-2026= -80821 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80821 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: mailbox:=
mchp-ipc-sbi: Add null check for devm_kasprintf() Add a check to see if de= vm_kasprintf() is not NULL in mchp_ipc_get_cluster_aggr_irq(), returning -E= NOMEM if the function failed. 2026-09-04 not yet calculated CVE-2026-80822 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80822 ] Linux--Linux In the L= inux kernel, the following vulnerability has been resolved: nfc: st21nfca: = validate ATR_REQ length against the received frame st21nfca_tm_recv_atr_req=
() checks that the received ATR_REQ frame is at least ST21NFCA_ATR_REQ_MIN_= SIZE and that the self-declared atr_req->length is at least sizeof(struct s= t21nfca_atr_req), but never checks that atr_req->length does not exceed the=
actual received length (skb->len). st21nfca_tm_send_atr_res() then trusts = the declared length: gb_len =3D atr_req->length - sizeof(struct st21nfca_at= r_req); ... memcpy(atr_res->gbi, atr_req->gbi, gb_len); so an RF peer that = sends a short frame but sets atr_req->length larger than the frame makes gb= _len exceed the general bytes actually present, and the memcpy reads out of=
bounds past the received skb. Those bytes are placed in the ATR_RES and se=
nt back to the peer (kernel-memory disclosure to a proximity attacker); a l= arger declared length is an out-of-bounds read (DoS). Reject frames whose d= eclared length exceeds the received length. The adjacent nfc_tm_activated()=
path in the same function already derives its general-bytes length from sk= b->len rather than the declared field. Found by 0sec (
https://0sec.ai) usin=
g automated source analysis; the missing bound is evident from source. Comp= ile-tested. 2026-09-04 not yet calculated CVE-2026-80823 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-80823 ] Linux--Linux In the Linux kernel, the f= ollowing vulnerability has been resolved: usb: usbfs: fix use-after-free of=
usb_device in usbdev_release() usbdev_release() drops its reference to the=
struct usb_device before draining the list of completed async URBs, but th=
at drain path reads back through the same object: free_async() calls dec_us= b_memory_use_count() for any URB whose buffer came from the usbfs mmap() re= gion, and its first statement is bus_to_hcd(ps->dev->bus). After a disconne=
ct the usbfs reference can be the last one, in which case usb_put_dev() fre=
es the device and the subsequent loop reads offset 80 of freed memory and u= ses the result as a struct usb_hcd *, which hcd_buffer_free_pages() then de= references. This is reachable by an unprivileged process that has read/writ=
e access to a /dev/bus/usb node: mmap() the fd, submit one URB with a buffe=
r inside the mapping, wait for the device to be unplugged, then munmap() an=
d close(). It reproduces on every attempt rather than being a race, because=
a live MAP_SHARED vma holds a reference on the struct file, so usbdev_rele= ase() cannot run until the last vma is gone and the freeing branch of dec_u= sb_memory_use_count() is always taken. BUG: KASAN: slab-use-after-free in d= ec_usb_memory_use_count+0x3ae/0x410 Read of size 8 at addr ffff8880122ee050=
by task poc/769 CPU: 1 UID: 1000 PID: 769 Comm: poc Tainted: G B 6.12.94 #=
3 Call Trace: dec_usb_memory_use_count+0x3ae/0x410 free_async+0x2aa/0x4f0 u= sbdev_release+0x375/0x460 __fput+0x3ea/0xb50 __x64_sys_close+0x86/0x100 All= ocated by task 11: usb_alloc_dev+0x55/0xd90 hub_event+0x2524/0x43d0 Freed b=
y task 769: kfree+0x121/0x360 device_release+0xd2/0x280 usb_put_dev+0x23/0x=
30 usbdev_release+0x2d8/0x460 Release the device reference after the drain = loop instead. Nothing between the two points requires it to have been dropp= ed. 2026-09-04 not yet calculated CVE-2026-80824 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-80824 ] Linux--Linux In the Linux kernel, the following=
vulnerability has been resolved: wifi: mt76: mt7925: ensure tx headroom in=
usb_sdio_tx_prepare_skb mt7925_usb_sdio_tx_prepare_skb() pushes a TX descr= iptor and a USB header onto every skb and assumes the headroom for them is = already there. That holds for locally generated traffic, where mac80211 res= erves hw->extra_tx_headroom, but forwarded frames are sent through ieee8021= 1_8023_xmit(), which does not reserve it. Bridge a wired interface to an mt= 7925u AP and the first forwarded frame that arrives short panics the kernel=
: skbuff: skb_under_panic: len:415 put:4 tail:0x19b end:0x640 dev:wlan1 ker= nel BUG at net/core/skbuff.c:212! Call trace: skb_panic+0x58/0x60 (P) skb_p= ush+0x58/0x60 mt7925_usb_sdio_tx_prepare_skb+0xf8/0x1b8 [mt7925_common] mt7= 6u_tx_queue_skb+0xa0/0x1f8 [mt76_usb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] = mt76_txq_schedule.part.0+0x204/0x478 [mt76] mt76_txq_schedule_all+0x50/0x80=
[mt76] mt792x_tx_worker+0x68/0x100 [mt792x_lib] __mt76_worker_fn+0x84/0x15=
0 [mt76] Whether a given setup hits it depends on how much headroom the ing= ress netdev leaves in its rx skbs. Reproduced on a Raspberry Pi 5 bridging = onboard ethernet to a Netgear A9000; originally reported on an MT7986 route=
r running OpenWrt. Nick Morrow's testing on a Pi 4 (bcmgenet), which leaves=
more headroom, helped narrow the trigger to the ingress path. The same bug=
was fixed on mt7921 by commit 98c4d0abf5c4 ("mt76: mt7921: don't assume ad= equate headroom for SDIO headers"), but mt7925 was copied from mt7921 witho=
ut the fix. Add the same guard here. 2026-09-04 not yet calculated CVE-2026= -80825 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80825 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: USB: c67= x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails for = the last packet of an isochronous URB, c67x00_add_iso_urb() gives the URB b= ack before updating the endpoint scheduling state. c67x00_giveback_urb() fr= ees the URB private data, and the completion callback may release the final=
URB reference. The following accesses to urbp->ep_data, urb->interval, and=
urbp->cnt can therefore use freed memory. Update next_frame and cnt before=
giving back the failed final packet, making the giveback the last operatio=
n that uses the URB and its private data. 2026-09-04 not yet calculated CVE= -2026-80826 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80826 ] Linux--Li= nux In the Linux kernel, the following vulnerability has been resolved: USB=
: serial: option: fix slab OOB read in interrupt URB callback The interrupt=
URB buffer is allocated in setup_port_interrupt_in() based on the endpoint=
's wMaxPacketSize: buffer_size =3D usb_endpoint_maxp(epd); port->interrupt_= in_buffer =3D kmalloc(buffer_size, GFP_KERNEL); When a USB device declares = wMaxPacketSize =3D 8 on its interrupt IN endpoint, the buffer is allocated = from kmalloc-8 cache (exactly 8 bytes). If the device sends a short packet = (actual_length < wMaxPacketSize), the URB completes with status =3D=3D 0 an=
d the callback proceeds to read: data[sizeof(struct usb_ctrlrequest)] which=
evaluates to data[8], accessing 1 byte beyond the allocated 8-byte buffer.=
This results in a slab out-of-bounds read. Fix this by adding the missing = bounds check: first verify that the actual length is large enough to contai=
n the struct usb_ctrlrequest header before accessing req_pkt->bRequestType = and req_pkt->bRequest, and then verify that there is an additional byte for=
the modem signal state before reading data[sizeof(struct usb_ctrlrequest)]=
inside the conditional. Use sizeof(*req_pkt) instead of sizeof(struct usb_= ctrlrequest) for consistency. [ johan: use dev_err(); split signals declara= tion and initialisation ] 2026-09-04 not yet calculated CVE-2026-80827 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-80827 ] Linux--Linux In the Linux=
kernel, the following vulnerability has been resolved: ALSA: usb-audio: Co= mplete cleanup after system-resume errors A failed system resume can leave = the card unusable until reboot. usb_audio_resume() jumps to err_out when sn= d_usb_pcm_resume() or snd_usb_mixer_resume() fails. The error path skips th=
e out: block, which restores D0 and decrements chip->num_suspended_intf. Th=
e card stays in SNDRV_CTL_POWER_D3hot, so later control access blocks in sn= d_power_ref_and_wait(). USB core logs an interface resume callback error. I=
t does not retry that callback, so a later callback cannot complete the ski= pped cleanup. usb_audio_suspend() increments num_suspended_intf before retu= rning success. A system-resume callback must consume the system-suspend cou=
nt even if a component resume fails. Otherwise, the stranded count skews la= ter suspend and resume cycles. Do not apply this cleanup to runtime-resume = errors. Runtime PM can retry -EAGAIN or -EBUSY without another suspend call= back. The count must continue to describe that suspended interface. Other r= untime-resume errors latch runtime_error in the PM core and do not cause an=
immediate callback retry. Both parts of the system-resume error path are l= ongstanding. Commit 88a8516a2128a ("ALSA: usbaudio: implement USB autosuspe= nd") introduced err_out past the D0 restore. Commit 862b2509d157c ("ALSA: u= sb-audio: Fix inconsistent card PM state after resume") later moved num_sus= pended_intf-- into the out: block. The error path now skips both operations=
. No third-party code is needed to reach the error path. snd_usb_mixer_resu= me() ends in snd_usb_mixer_activate(), which returns the result of usb_subm= it_urb() for devices that have a mixer status URB. Its mixer->private_resum=
e hook can also fail through scarlett2_init_notify(). snd_usb_pcm_resume() = issues a SET_CUR request to a UAC3 power domain. It can return -EPIPE or -E=
IO when the device stalls the request. Route a component error through out:=
only when system_suspend is nonzero. Continue to return runtime-resume err= ors through err_out. Later component resume stages remain skipped. The orig= inal error still reaches USB core. A later transfer can fail if the device = did not recover. I reproduced the system-resume failure on an Audient iD14 = MkI with an out-of-tree diagnostic mixer resume hook. An injected -EIO on t=
he unpatched core left control readers in uninterruptible sleep in snd_powe= r_ref_and_wait() until a reboot. With this patch, the same failure restored=
control access. A second system suspend and resume also succeeded after I = disabled fault injection. 2026-09-04 not yet calculated CVE-2026-80828 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-80828 ] Linux--Linux In the Linux=
kernel, the following vulnerability has been resolved: ALSA: usb-audio: fi=
x OOB write in snd_usbmidi_novation_output() snd_usbmidi_novation_output() = lays out a two-byte header at transfer_buffer[0..1] and passes &transfer_bu= ffer[2] together with a length of ep->max_transfer - 2 to snd_rawmidi_trans= mit(): count =3D snd_rawmidi_transmit(ep->ports[0].substream, &transfer_buf= fer[2], ep->max_transfer - 2); ep->max_transfer comes from the output endpo= int's wMaxPacketSize via usb_maxpacket(). A malformed or malicious device c=
an advertise a bulk OUT endpoint with a wMaxPacketSize of 1 - the USB core = only clamps this value downwards - so ep->max_transfer becomes 1 and the co= unt argument becomes -1. snd_rawmidi_transmit() passes the negative count o=
n to __snd_rawmidi_transmit_peek(), where "if (count1 > count) count1 =3D c= ount" leaves count1 negative; get_aligned_size() keeps it negative for a by= te-stream substream, so the following memcpy(buffer, ..., count1) runs with=
a (size_t)-1 length and writes far past the transfer buffer, which was all= ocated with usb_alloc_coherent(ep->max_transfer). This is the same class of=
bug that was fixed for snd_usbmidi_akai_output() in commit 0970274613fb ("= ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()"); the novation=
output routine was left unguarded. Bail out when the endpoint cannot hold = the two-byte header plus at least one payload byte. 2026-09-04 not yet calc= ulated CVE-2026-80829 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80829 ]=
Linux--Linux In the Linux kernel, the following vulnerability has been res= olved: usb: core: Add lock to usb_wakeup_notification() Add a spin lock to = usb_wakeup notification to prevent a race condition with dereferencing free=
d memory. This could be hit by the xHCI driver as it calls this function fr=
om an IRQ and could race with the hub_disconnect() function, which properly=
grabs this lock to protect the state of the device. 2026-09-04 not yet cal= culated CVE-2026-80830 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80830 =
] Linux--Linux In the Linux kernel, the following vulnerability has been re= solved: crypto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_= block_crypt() uses sg_dma_len() without mapping the source scatterlist with=
dma_map_sg() first. Therefore, sg_dma_len() is invalid and could return ze=
ro or a stale DMA length, causing encryption and decryption to process the = wrong number of bytes when CONFIG_NEED_SG_DMA_LENGTH=3Dy. Use the original = scatterlist length instead. 2026-09-04 not yet calculated CVE-2026-80831 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-80831 ] Linux--Linux In the Lin=
ux kernel, the following vulnerability has been resolved: crypto: qce - fix=
CCM AAD buffer underallocation The AAD buffer allocated in qce_aead_ccm_pr= epare_buf_assoclen() can be smaller than the length later programmed into t=
he DMA scatterlist. The allocation size is currently calculated as: ALIGN(a= ssoclen, 16) + MAX_CCM_ADATA_HEADER_LEN while the DMA length is set to: ALI= GN(assoclen + adata_header_len, 16) Since ALIGN() does not distribute over = addition, the allocation can be smaller than the DMA length. For example, w= hen assoclen =3D 32 and adata_header_len =3D 2: allocation =3D ALIGN(32, 16=
) + 6 =3D 38 DMA length =3D ALIGN(32 + 2, 16) =3D 48 As a result, the QCE h= ardware can read beyond the allocated buffer while computing the CBC-MAC ov=
er the associated data. The extra bytes are folded into the authentication = tag, resulting in an incorrect tag and causing CCM self-test failures such = as: alg: aead: ccm-aes-qce encryption test failed (wrong result) on test ve= ctor 8 Fix the allocation by adding the maximum possible AAD header length = before alignment: ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16) This guara= ntees that the allocated buffer is large enough for the fully padded AAD da=
ta for all supported header sizes. 2026-09-04 not yet calculated CVE-2026-8= 0832 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80832 ] Linux--Linux In = the Linux kernel, the following vulnerability has been resolved: crypto: su= n8i-ss - Remove crypto_rng interface Since the crypto_rng interface for har= dware PRNGs is unused and is redundant with hwrng and the actual Linux RNG,=
it's being phased out. Most drivers for it were already removed. Go ahead = and remove the sun8i-ss support which is one of the only remaining ones. As=
usual for crypto_rng, this driver was also buggy: its ->generate() functio=
n had a use-after-free vulnerability due to using wait_for_completion_inter= ruptible_timeout() without handling shutting down the DMA operation if a si= gnal is sent. Also, it had a buffer overread bug in the line 'memcpy(ctx->s= eed, d + dlen, ctx->slen);'. There's no point in fixing these bugs separate=
ly only to remove the code anyway, so this commit is marked with Fixes and =
Cc stable. 2026-09-04 not yet calculated CVE-2026-80833 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-80833 ] Linux--Linux In the Linux kernel, the fo= llowing vulnerability has been resolved: crypto: sun8i-ce - Remove crypto_r=
ng interface Since the crypto_rng interface for hardware PRNGs is unused an=
d is redundant with hwrng and the actual Linux RNG, it's being phased out. = Most drivers for it were already removed. Go ahead and remove the sun8i-ce = support which is one of the only remaining ones. Note that the sun8i-ce sup= port for hwrng remains in place. That is the interface that actually matter=
s. As usual for crypto_rng, this driver was also buggy: its ->generate() fu= nction had a use-after-free vulnerability due to using wait_for_completion_= interruptible_timeout() without handling shutting down the DMA operation if=
a signal is sent. There's no point in fixing this separately only to remov=
e the code anyway, so this commit is marked with Fixes and Cc stable. 2026-= 09-04 not yet calculated CVE-2026-80834 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80834 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: crypto: qcom-rng - Remove crypto_rng interface qc= om-rng.c exposes the same hardware through two completely separate interfac= es, crypto_rng and hwrng. However, the implementation of this is buggy beca= use it permits generation operations from these interfaces to run concurren= tly with each other, accessing the same registers. That is, qcom_rng_genera= te() synchronizes with itself but not with qcom_hwrng_read(). This results =
in potential repetition of output from the RNG, output of non-random values=
, etc. Fortunately, there's actually no point in hardware RNG drivers imple= menting the crypto_rng interface. It's not actually used by anything beside=
s the "rng" algorithm type of AF_ALG, which in turn is not actually used in=
practice. Other crypto_rng hardware drivers are likewise being phased out,=
leaving just the hwrng support. Thus, remove it to simplify the code and a= void conflict (and confusion) with the hwrng interface which is the one tha=
t actually matters. 2026-09-04 not yet calculated CVE-2026-80835 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-80835 ] Linux--Linux In the Linux kerne=
l, the following vulnerability has been resolved: crypto: virtio - bound th=
e akcipher result length virtio_crypto_dataq_akcipher_callback() sets the r= esult length from the device-reported response length without bounding it t=
o the destination buffer, which was allocated for the original request leng= th. sg_copy_from_buffer() then reads that many bytes from the destination b= uffer; a backend reporting a larger length over-reads adjacent kernel heap = into the caller's scatterlist (an out-of-bounds read). Clamp the reported l= ength to the originally requested destination length. A conforming device r= eports no more than that, so valid results are unaffected. 2026-09-04 not y=
et calculated CVE-2026-80836 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 80836 ] Linux--Linux In the Linux kernel, the following vulnerability has b= een resolved: netfilter: nf_tables: don't queue packet path object notifica= tions All file:line references below are against v7.2-rc4 (ac5b0e5651b1). T=
he trace was captured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the sam=
e lines apply. nft_obj_notify() is exported and reached from the packet pat=
h. Its only in-tree caller is nft_quota_obj_eval() (net/netfilter/nft_quota= .c:68), which notifies with GFP_ATOMIC while evaluating a rule for a transi= ting packet, holding no mutex. Since commit 67cc570edaa0 ("netfilter: nf_ta= bles: coalesce multiple notifications into one skbuff") that notification i=
s no longer sent immediately. __nft_obj_notify() queues it onto nft_net->no= tify_list via nft_notify_enqueue() (net/netfilter/nf_tables_api.c:1211), wh= ich is a bare list_add_tail(). notify_list has no lock of its own (include/= net/netfilter/nf_tables.h:1951), it is serialised by commit_mutex: the six = other enqueue sites all run inside a netlink transaction, and the drain in = nft_commit_notify() (net/netfilter/nf_tables_api.c:10746) does list_del() +=
kfree_skb() from nf_tables_commit() with commit_mutex held. Sending packet=
s through a chain that references a depleted quota object therefore races a=
n unlocked list_add_tail() against list_del() + kfree_skb() on another CPU.=
The WRITE_ONCE(prev->next, new) in __list_add() then stores through an sk_= buff that has already been freed: BUG: KASAN: slab-use-after-free in __nft_= obj_notify+0x2c5/0x2d0 Write of size 8 at addr ff110001047183c0 by task poc= /76 CPU: 0 UID: 1000 PID: 76 Comm: poc Tainted: G W 7.2.0-rc6-kasan72rc6 #4=
Call Trace: <IRQ> __nft_obj_notify (include/linux/list.h:164 include/linux= /list.h:191 net/netfilter/nf_tables_api.c:1211 net/netfilter/nf_tables_api.= c:8743) nft_quota_obj_eval (net/netfilter/nft_quota.c:68) nft_do_chain_inet=
nf_hook_slow __ip_local_out ip_push_pending_frames udp_send_skb udp_sendms=
g __x64_sys_sendto Allocated by task 77: __alloc_skb (net/core/skbuff.c:704=
) __nft_obj_notify (include/net/netlink.h:1055 net/netfilter/nf_tables_api.= c:8731) nft_quota_obj_eval (net/netfilter/nft_quota.c:68) nft_do_chain Free=
d by task 79: nf_tables_commit (include/linux/skbuff.h:1332 net/netfilter/n= f_tables_api.c:10759 net/netfilter/nf_tables_api.c:11185) nfnetlink_rcv_bat=
ch (net/netfilter/nfnetlink.c:574) netlink_unicast netlink_sendmsg The bugg=
y address belongs to the cache skbuff_head_cache of size 232 Queueing from = the packet path is wrong even leaving the race aside: notify_list is only d= rained by nft_commit_notify() from nf_tables_commit() (:11185), so a notifi= cation enqueued outside a transaction is not sent until some later netlink = batch commits, if one ever does. The gfp argument that nft_obj_notify() sti=
ll takes is a leftover of the pre-67cc570edaa0 behaviour, where this path c= alled nfnetlink_send() directly. Restore that: split the message constructi=
on out into nft_obj_notify_alloc() and let each caller decide what to do wi=
th the skb. nft_obj_notify(), the exported one reached from the packet path=
, sends it straight away; nf_tables_obj_notify(), which runs under commit_m= utex, keeps queueing it, so transaction notifications are still coalesced. = 2026-09-04 not yet calculated CVE-2026-80837 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-80837 ] Linux--Linux In the Linux kernel, the following vul= nerability has been resolved: vxlan: keep the last remote linked during FDB=
flush A non-nexthop FDB entry is expected to have at least one remote whil=
e it remains reachable through the FDB hash table. A filtered bulk flush vi= olates this invariant when every remote matches: It unlinks the last remote=
in vxlan_fdb_dst_destroy() and only afterwards tells vxlan_flush() to dest= roy the parent FDB entry. An RCU reader can find the parent during this int= erval. first_remote_rcu() then applies list_entry_rcu() to the empty list h= ead, producing an invalid remote pointer that the receive learning path can=
read from and write to. When a matching remote is the sole remaining remot=
e, leave it linked and ask the caller to destroy the entire FDB entry. vxla= n_fdb_destroy() keeps the remote attached while sending the deletion notifi= cation and removing the parent from the lookup structures. 2026-09-04 not y=
et calculated CVE-2026-80838 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 80838 ] Linux--Linux In the Linux kernel, the following vulnerability has b= een resolved: batman-adv: reject unrepresentable multicast TVLV offsets The=
network and transport header fields in struct sk_buff are 16-bit offsets f= rom skb->head, and U16_MAX is reserved as the unset transport header value.=
batadv_tvlv_call_handler() sets both fields from a received multicast TVLV=
without checking whether the TVLV end is representable. If the end offset = exceeds the field's range, skb_set_transport_header() truncates it so that = the transport header precedes the network header. The negative difference i=
s then returned by skb_network_header_len() as a large u32. batadv_mcast_fo= rw_packet() consequently accepts an oversized multicast tracker and accesse=
s memory beyond the skb data. Add skb_set_transport_header_careful(), an of= fset-aware counterpart to skb_reset_transport_header_careful(), which valid= ates the final head-relative offset before assigning it. Use the new helper=
in batadv_tvlv_call_handler() and reject unrepresentable TVLVs before sett= ing the network header. 2026-09-04 not yet calculated CVE-2026-80839 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-80839 ] Linux--Linux In the Linux k= ernel, the following vulnerability has been resolved: ipv6: seg6: clear IPv=
4 control block on IPIP decapsulation End.DX4 and End.DT4 decapsulate an IP=
v4 packet through decap_and_validate() and send it directly to IPv4 routing=
. The inner packet therefore bypasses ip_rcv_core(), which normally clears = IPCB before IPv4 interprets skb->cb. The skb instead retains IP6CB data fro=
m the outer packet. IP6CB and IPCB use the same skb->cb storage, so IP6CB(s= kb)->lastopt overlaps IPCB(skb)->opt.optlen and srr, while IP6CB(skb)->nhof=
f overlaps rr and ts. The sender can make the stale optlen byte nonzero wit=
h a valid outer extension-header chain. The reproducers put an eight-byte D= estination Options header immediately after the 40-byte IPv6 header and bef= ore the Segment Routing Header. ipv6_destopt_rcv() records the sender-contr= olled Destination Options offset in both lastopt and nhoff, setting them to=
40. On the reproduced little-endian x86-64 kernel, IPv4 therefore sees opt= len =3D 40 and rr =3D 40. Both tcp_v4_save_options() and __ip_options_echo(=
) skip option copying when optlen is zero. Here optlen is 40, so the TCP SY=
N path allocates room for 40 bytes of option data and calls __ip_options_ec= ho(). The stale rr value makes that function read inner packet byte 41 as t=
he Record Route option length. The reproducers set that sender-controlled b= yte to 255, so __ip_options_echo() copies 255 bytes into the 40-byte option= -data area. Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-= rc5 kernel both produced: BUG: KASAN: slab-out-of-bounds in __ip_options_ec= ho() Write of size 255 The relevant End.DX4 call path is: __ip_options_echo=
tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_proces=
s tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish = ip_local_deliver input_action_end_dx4_finish input_action_end_dx4 The relev= ant End.DT4 call path is: __ip_options_echo tcp_v4_route_req tcp_conn_reque=
st tcp_v4_conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_pr= otocol_deliver_rcu ip_local_deliver_finish ip_local_deliver input_action_en= d_dt4 tcp_v4_save_options() is inlined into the tcp_v4_route_req() path, so=
it does not appear as a separate frame. When decap_and_validate() handles = IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restor=
e the saved value. Doing this in the common decapsulation path covers End.D= X4, End.DT4, and End.DT46's IPv4 arm. Use IP6CB(skb)->iif rather than skb->= skb_iif. These actions run after l3mdev processing, which can replace skb_i=
if with the L3 master; IP6CB iif still records the receiving interface set =
at IPv6 ingress. 2026-09-04 not yet calculated CVE-2026-80840 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-80840 ] Linux--Linux In the Linux kernel, = the following vulnerability has been resolved: net/packet: defer vmalloc TX= _RING free until skbs finish AF_PACKET TX_RING skbs keep a raw pointer to t= heir ring frame. The skb page references preserve page-backed ring blocks a= fter pg_vec is freed, but they do not preserve a vmalloc mapping. tpacket_d= estruct_skb() currently drops the pending reference before writing the time= stamp and TP_STATUS_AVAILABLE to the frame. Move the decrement after those = stores. The smp_wmb() in __packet_set_status() orders the frame stores befo=
re the decrement. Also recheck pending TX frames under pg_vec_lock before n= on-closing ring replacement, so a racing send cannot add a pending skb betw= een the initial check and the ring swap. Ring allocation can produce a mixt= ure of page-backed and vmalloc-backed blocks. Allocate deferred-work storag=
e during TX ring setup when the first vmalloc-backed block is encountered, = and keep its pointer in the pg_vec allocation header. If allocation fails, = return -ENOMEM from ring setup. On socket close, a non-NULL pointer identif= ies a vmalloc-backed vector without a scan. If TX skbs remain, defer the wh= ole vector to system_long_wq. After pg_vec is detached, a late destructor c=
an skip the pending decrement. Use socket write-memory accounting as the de= ferred lifetime gate instead: an skb remains charged through its final sock= _wfree(), after all ring-frame accesses. The delayed work retains a socket = reference and reschedules itself until no TX skbs remain. Move pending_refc=
nt release to packet_sock_destruct() so late skb destructors and deferred c= leanup can safely use it after packet_release(). Page-backed teardown remai=
ns synchronous, and no lock is added to the TX completion hot path. 2026-09= -04 not yet calculated CVE-2026-80841 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-80841 ] Linux--Linux In the Linux kernel, the following vulnerabil= ity has been resolved: net: bridge: mcast: fix use-after-free of a master V= LAN's multicast context br_multicast_toggle_one_vlan() clears BR_VLFLAG_MCA= ST_ENABLED under br->multicast_lock before stopping a VLAN's multicast cont= ext. That is the teardown handshake: lockless readers gate on the flag thro= ugh br_multicast_ctx_should_use() -> br_multicast_ctx_vlan_disabled(), so o= nce it is cleared under the lock no reader can arm the context again. For a=
master VLAN the handshake never runs. __vlan_del() clears BRIDGE_VLAN_INFO= _BRENTRY before calling br_vlan_put_master(), so br_multicast_toggle_one_vl= an(masterv, false) returns early on !br_vlan_is_brentry(vlan): the flag sta=
ys set and br->multicast_lock is never taken. br_vlan_put_master() then dra= ins the context in br_multicast_ctx_deinit() and frees the VLAN through cal= l_rcu(), while a reader still inside rcu_read_lock() sees the context as en= abled and re-arms it. The port and port-VLAN branch of the function has no = br_vlan_is_brentry() test and flips the flag under br->multicast_lock, so i=
t is not affected. The reader is the bridge transmit path. For a master VLA=
N br_multicast_rcv() selects brmctx =3D &vlan->br_mcast_ctx with pmctx =3D = NULL, so IGMP sent to the bridge device re-arms the context's timers after = br_multicast_ctx_deinit() has already stopped them. BUG: KASAN: slab-use-af= ter-free in detach_if_pending+0x412/0x4a0 Write of size 8 at addr ffff88810= ac39918 by task brmc/601 __mod_timer+0x51a/0xc50 br_multicast_host_join+0x2= 5b/0x390 __br_multicast_add_group+0x468/0x530 br_ip4_multicast_add_group+0x= 1a0/0x260 br_multicast_rcv+0x2cda/0x61e0 br_dev_xmit+0x6c4/0x1540 Allocated=
by task 610: br_vlan_add+0x111/0xb40 br_vlan_info+0x370/0x3e0 Freed by tas=
k 0: kfree+0x1a7/0x4f0 rcu_core+0x7dc/0x10a0 Only test br_vlan_is_brentry()=
when enabling, like the br_multicast_ctx_vlan_global_disabled() test next =
to it. Disabling then always clears BR_VLFLAG_MCAST_ENABLED under br->multi= cast_lock before br_multicast_ctx_deinit() drains the context. 2026-09-04 n=
ot yet calculated CVE-2026-80842 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-80842 ] Linux--Linux In the Linux kernel, the following vulnerability h=
as been resolved: xfrm: fix xfrm_state_construct() auth-trunc leak attach_a= uth_trunc() can allocate x->aalg while leaving x->props.aalgo at zero when = the selected auth algorithm has no sadb_alg_id. One real case is cmac(aes).=
xfrm_state_construct() then treats !x->props.aalgo as "no auth algorithm a= ttached yet" and calls attach_auth(). That overwrites x->aalg and loses the=
first allocation. Any later failure or teardown only frees the replacement=
pointer. Check whether x->aalg is already attached instead of inferring th=
at state from x->props.aalgo. 2026-09-04 not yet calculated CVE-2026-80843 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-80843 ] Linux--Linux In the L= inux kernel, the following vulnerability has been resolved: xfrm: ah6: vali= date routing header segments_left AH6 rearranges routing-header addresses b= efore computing or verifying the ICV. ipv6_rearrange_rthdr() assumes that s= egments_left is not larger than the number of addresses described by the ro= uting header's hdrlen field. That assumption does not hold for raw IPv6 HDR= INCL packets. A packet with hdrlen equal to 2 describes one address, but ca=
n carry an arbitrary segments_left value. With segments_left equal to 255, = the function moves its address pointer 4,064 bytes backwards and passes a 4= ,064-byte length to memmove(), resulting in an out-of-bounds access. Valida=
te the invariant locally before modifying the routing header or performing = any address-pointer arithmetic, and propagate malformed-header errors to th=
e existing AH6 input and output error paths. 2026-09-04 not yet calculated = CVE-2026-80844 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80844 ] Linux-= -Linux In the Linux kernel, the following vulnerability has been resolved: = xfrm: avoid lock inversion in nat keepalive work nat_keepalive_work() walks=
the state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. I=
ts callback then acquires x->lock, which conflicts with the delete path tak= ing the same locks in reverse order via xfrm_state_delete() and __xfrm_stat= e_delete(). This creates an AB-BA deadlock that is reported by lockdep when=
a NAT keepalive worker races with SA deletion. Fix this by splitting the k= eepalive walk into two phases. First, collect the candidate states while th=
e walk holds xfrm_state_lock and take a reference on each state. Then, afte=
r the walk completes, process each collected state and acquire x->lock with= out nesting it under xfrm_state_lock. 2026-09-04 not yet calculated CVE-202= 6-80845 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80845 ] Linux--Linux =
In the Linux kernel, the following vulnerability has been resolved: xfrm: d= rop ESP-in-TCP packets with no ingress device ESP-in-TCP receives records t= hrough the TCP strparser. handle_esp() restores skb->dev from the saved skb= _iif before passing the packet into the XFRM input path. Queued TCP data ca=
n be processed after the original ingress device has been removed, for exam= ple during veth or net namespace teardown. In that case dev_get_by_index_rc= u() returns NULL. The XFRM IPv4 and IPv6 input paths both expect skb->dev t=
o be valid while building the route lookup, so queued ESP-in-TCP data can d= ereference a NULL device. Drop the packet if the saved ingress device can n=
o longer be resolved. Such a packet can no longer be routed through the nor= mal XFRM receive path, and this preserves the existing behaviour for packet=
s whose ingress device still exists. 2026-09-04 not yet calculated CVE-2026= -80846 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80846 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: tcp: cla=
mp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes that cal= lers never pass an MSS smaller than 1, but route-derived advmss values can = violate that assumption. A too-small explicit RTAX_ADVMSS is one way to get=
there, but it is not the only one. The same divide-by-zero can also be rea= ched through the "default advmss" path when RTAX_ADVMSS is left at 0 and th=
e effective advmss is later driven down by route MTU and min_adv_mss. Intro= duce a tcp_dst_advmss() helper that clamps route advmss to TCP_MIN_MSS befo=
re TCP consumes it, and use it in the TCP paths that derive advmss from dst=
metrics. This keeps the effective MSS from dropping to zero before tcp_sel= ect_initial_window() rounds the receive window. 2026-09-04 not yet calculat=
ed CVE-2026-80847 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80847 ] Lin= ux--Linux In the Linux kernel, the following vulnerability has been resolve=
d: xfrm: espintcp: fix UAF during close ZDI reported and analyzed a race co= ndition during close for espintcp sockets: espintcp_close() frees emsg->skb=
via kfree_skb() without holding any socket lock. Concurrently, the xfrm_tr= ans_reinject work queue invokes esp_output_tcp_finish() -> espintcp_push_sk= b() -> espintcp_push_msgs() -> skb_send_sock_locked(), which reads the same=
skb as a data source. Fix this by adding a synchronize_rcu() call after re= setting sk_prot, since esp_output_tcp_finish() runs under RCU and won't use=
a socket with sk_prot =3D=3D &tcp_prot. Simply taking the socket lock in e= spintcp_close() could lead to leaks, if esp_output_tcp_finish() re-adds an = skb in the slot we just freed. After this, the existing barrier() is no lon= ger needed. 2026-09-04 not yet calculated CVE-2026-80848 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-80848 ] Linux--Linux In the Linux kernel, the f= ollowing vulnerability has been resolved: net/tcp-ao: fix use-after-free of=
current_key on reconnect to another peer tcp_inbound_ao_hash() is called b= efore bh_lock_sock_nested() is taken, with only rcu_read_lock() held. On th=
e fast path for established sockets, if the rnext_keyid sent by the peer di= ffers from current_key->sndid, the key the peer asked for is looked up and = stored in current_key. The lookup is inside the RCU read side, but current_= key outlives it. When the socket is disconnected and connect() is called ag= ain for another peer, tcp_ao_connect_init() unlinks every key that does not=
match the new peer and frees it with call_rcu(). If current_key points at = such a key, it is cleared to NULL. The fast path reads sk_state only once o=
n entry, so a softirq that got into it while the socket was still establish=
ed can update current_key after that loop has already run. The update is in= side the RCU read side, so it comes before the call_rcu() callback, and onc=
e the callback frees the key, current_key is left pointing at freed memory.=
The next transmission picks that pointer up in tcp_get_current_key(). tcp_= ao_transmit_skb() then reads the traffic key from the freed object, which i=
s the use-after-free. Wait for one grace period before unlinking, and only =
if a key is going to be removed. By the time tcp_connect() runs the socket =
is already in TCP_SYN_SENT, and TCP_AO_ESTABLISHED does not contain TCPF_SY= N_SENT, so a softirq entering after the wait cannot reach the fast path, an=
d the ones already in it have finished. The existing NULL handling in the l= oop is then enough. 2026-09-04 not yet calculated CVE-2026-80849 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-80849 ] Linux--Linux In the Linux kerne=
l, the following vulnerability has been resolved: tcp: fix AO info use-afte= r-free in tcp_ao_connect_init() tcp_v4_connect() adds a SYN-SENT socket to = the ehash before calling tcp_connect(). If TCP-AO is configured, tcp_connec= t() first verifies that a key matches the peer and the bound device's curre=
nt L3 master. tcp_ao_connect_init() later resolves the L3 master again and = removes keys which do not match it. The socket lock does not stabilize the = bound device's VRF membership. Detaching the device from its VRF between th=
e initial validation and the L3-master calculation in tcp_ao_connect_init()=
can therefore make the validation succeed while initialization observes th=
e default L3 domain and removes the only key. The subsequent AO lookup then=
fails, so the no-key path clears tp->ao_info and frees it directly. The re= ceive path can find the socket in the ehash and load tp->ao_info under RCU = before acquiring the socket lock. A reader which loaded the old pointer can=
thus continue into tcp_inbound_ao_hash() after the direct free. The issue = was found during a static audit of TCP-AO object lifetime. An unprivileged = reproducer in self-created user and network namespaces raced connect() with=
detaching a veth from its VRF while sending TCP-AO segments. It triggered = the same KASAN report on two fresh boots: BUG: KASAN: slab-use-after-free i=
n tcp_inbound_ao_hash+0x585/0x19f0 Write of size 8 at addr ffff88800bf88128=
by task tcp_ao_vrf_race/232 Call Trace: tcp_inbound_ao_hash+0x585/0x19f0 t= cp_inbound_hash+0x677/0xa80 tcp_v4_rcv+0x1c3e/0x3ab0 Allocated by task 235:=
tcp_ao_alloc_info+0x43/0xf0 tcp_ao_add_cmd+0xdf7/0x13b0 do_tcp_setsockopt+= 0x168c/0x2640 Freed by task 235: kfree+0x1b8/0x550 tcp_connect+0x252/0x4f00=
tcp_v4_connect+0x1114/0x1720 The bad address is 40 bytes inside the freed = 128-byte object, matching the tcp_ao_info counters.key_not_found field. The=
two runs used 1000 attempts each, reached the no-key path 366 and 411 time=
s, and produced one and two KASAN reports respectively. With this change, t=
he same reproducer reached the no-key path 366 times in 1000 attempts witho=
ut a KASAN report or oops. Use tcp_ao_destroy_sock() for the no-key path. I=
t unpublishes the AO info, updates the socket memory and static-key account= ing, and defers the free until after an RCU grace period. Also drop the WAR= N_ON_ONCE() and its stale comment. The VRF detach race makes the no-key sta=
te reachable during normal operation, so it is a handled condition rather t= han an impossible assertion. On panic_on_warn kernels the WARN would turn t= his handled race into a kernel panic. 2026-09-04 not yet calculated CVE-202= 6-80850 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80850 ] Linux--Linux =
In the Linux kernel, the following vulnerability has been resolved: gtp: se= rialize PDP context updates PDP contexts can be deleted through GTP_CMD_DEL= PDP or while the GTP network device is being unregistered. The latter is se= rialized by RTNL, but the generic-netlink delete path only holds RCU. Runni=
ng both paths concurrently can therefore make both paths delete the same PD=
P context. The issue was found through static analysis and reproduced on a = KASAN-enabled kernel by a simple two-thread program racing GTP_CMD_DELPDP a= gainst RTM_DELLINK: Oops: general protection fault, probably for non-canoni= cal address KASAN: maybe wild-memory-access in range [0xdead000000000120-0x= dead000000000127] RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp] RBP: dead00000000= 0122 The second deletion dereferenced the poisoned hlist pprev pointer. Ser= ialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a shared m= utex. Keep the mutex held until the final use of a PDP context in the NEWPD=
P path, and keep the RCU read-side section around the complete PDP context = use in the DELPDP path. 2026-09-04 not yet calculated CVE-2026-80851 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-80851 ] Linux--Linux In the Linux k= ernel, the following vulnerability has been resolved: tls: device: fix out-= of-bounds write in tls_append_frag() Found with syzkaller and a local syzbo=
t instance running on top of a netdevsim TLS offload emulation; tls_device.=
c is otherwise only reachable on a machine with a NIC that implements the o= ffload. tls_push_data() only checks whether the open record still has room = for another frag at the bottom of its loop, and the MSG_MORE early break sk= ips that check. The record survives to the next syscall with the frag count=
it already had, and tls_append_frag() does not check either, so with TLS_T= X_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds a non-coale= scing pipe page and num_frags walks off the end of tls_record_info.frags[MA= X_SKB_FRAGS]. Once the record is pushed, tls_push_record() runs the same in= dex over sg_tx_data[MAX_SKB_FRAGS] and the sg_set_page() writes land on the=
destruct_work that follows it, which the workqueue then calls. The byte li= mit is fine because copy drops to 0 and the loop falls through to the same = check; the frag count has no such feedback. Push the record rather than kee=
p a full one open, which is what a plain TCP socket does - tcp_sendmsg_lock= ed() uses tcp_mark_push() and new_segment in both the copy and the MSG_SPLI= CE_PAGES paths, and tls_sw already sets full_record when the sk_msg ring fi= lls up, MSG_MORE or not. BUG: KASAN: slab-out-of-bounds in tls_append_frag =
( net/tls/tls_device.c:269) Write of size 8 at addr ffff8881104d1530 by tas=
k tls_oob/450 CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #= 329 PREEMPT Call Trace: <TASK> dump_stack_lvl (lib/dump_stack.c:94 lib/dump= _stack.c:120) print_report (mm/kasan/report.c:378 mm/kasan/report.c:482) ka= san_report (mm/kasan/report.c:595) tls_append_frag (net/tls/tls_device.c:26=
9) tls_push_data (net/tls/tls_device.c:518) tls_device_sendmsg (net/tls/tls= _device.c:583) inet_sendmsg (net/ipv4/af_inet.c:865) sock_sendmsg (net/sock= et.c:775 net/socket.c:790 net/socket.c:813) splice_to_socket (fs/splice.c:8= 84) do_splice (fs/splice.c:936 fs/splice.c:1349) __do_splice (fs/splice.c:1= 431) __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616) do_syscall_64 (ar= ch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_= 64_after_hwframe (arch/x86/entry/entry_64.S:121) </TASK> and, once the reco=
rd is pushed: UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:=
24 index 18 is out of range for type 'skb_frag_t [17]' UBSAN: array-index-o= ut-of-bounds in net/tls/tls_device.c:301:41 index 18 is out of range for ty=
pe 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_devic= e.c:302:39 index 18 is out of range for type 'scatterlist [17]' UBSAN: arra= y-index-out-of-bounds in net/tls/tls_device.c:307:38 index 26 is out of ran=
ge for type 'scatterlist [17]' kernel tried to execute NX-protected page - = exploit attempt? (uid: 0) BUG: unable to handle page fault for address: fff= fea000411a680 #PF: supervisor instruction fetch in kernel mode #PF: error_c= ode(0x0011) - permissions violation Oops: Oops: 0011 [#1] SMP KASAN PTI Wor= kqueue: ktls_device_destruct 0xffffea000411a680 RIP: 0010:0xffffea000411a68=
0 Call Trace: <TASK> worker_thread (kernel/workqueue.c:3405 kernel/workqueu= e.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/pro= cess.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) </TASK> 2026-= 09-04 not yet calculated CVE-2026-80852 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80852 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: KVM: SEV: Allocate full pages for {DE,EN}CRYPT op=
s on SNP-enabled hosts When {de,en}crypting memory of an SEV or SEV-ES gues=
t on an SNP-enabled host via a temporary buffer, allocate a full 4KiB page = for the buffer to ensure the page containing the buffer is wholly owned by = KVM, i.e. won't be concurrently allocated and accessed by other kernel code=
while KVM is using the buffer to {de,en}crypt memory. On SNP-enabled platf= orms, when sending SEV/SEV-ES commands that trigger firmware writes to memo= ry, the to-be-written page(s) must be (temporarily) assigned to Firmware (a=
s required by the SNP architecture, to guard against using such commands as=
gadgets to attack SNP guests). See snp_map_cmd_buf_desc() and friends. Unf= ortunately, transferring ownership of a page to Firmware makes the page ina= ccessible to software, and thus writes generate RMP #PF violations. If KVM = uses a sub-page allocation for its temporary buffer, some other actor in th=
e kernel can allocate and use the other portions of the page, and thus trig= ger unexpected (and seemingly spurious) RMP #PF violations due to software = attempting to access a Firmware-owned page. BUG: unable to handle page faul=
t for address: ffff906ae30f0300 #PF: supervisor write access in kernel mode=
#PF: error_code(0x80000003) - RMP violation PGD 6b1b80d067 P4D 6b1b80d067 = PUD 100231e2063 PMD 10055a88063 PTE 80000100630f0163 SEV-SNP: PFN 0x100630f=
0 unassigned, dumping non-zero entries in 2M PFN region: [0x10063000 - 0x10= 063200] Oops: Oops: 0003 [#1] SMP CPU: 70 UID: 0 PID: 10658 Comm: svw_Waite= rThrea Tainted: G U W O 7.1.0-smp--c22293789940-seanjc-next #1 PREEMPTLAZY = Tainted: [U]=3DUSER, [W]=3DWARN, [O]=3DOOT_MODULE Hardware name: Google, In=
c. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026 RIP: 0010:memse= t+0xf/0x20 Call Trace: <TASK> __kvmalloc_node_noprof+0x2a4/0x710 do_getxatt= r+0x4e/0x130 path_getxattrat+0x125/0x1b0 do_syscall_64+0x10a/0x480 entry_SY= SCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f3a22cb6daa </TASK> Modules l= inked in: kvm_amd kvm irqbypass vfat fat ccp k10temp sha3 libsha3 i2c_piix4=
gq(O) cdc_acm xhci_pci xhci_hcd gsmi: Log Shutdown Reason 0x03 CR2: ffff90= 6ae30f0300 ---[ end trace 0000000000000000 ]--- RIP: 0010:memset+0xf/0x20 K= ernel panic - not syncing: Fatal exception Kernel Offset: 0x39e00000 from 0= xffffffff81000000 (relocation range: 0xffffffff80000000-0xffffffffbfffffff)=
gsmi: Log Shutdown Reason 0x02 2026-09-04 not yet calculated CVE-2026-8085=
3 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80853 ] Linux--Linux In the=
Linux kernel, the following vulnerability has been resolved: usb: gadget: = f_tcm: keep port count until LUN teardown completes tcm_usbg_drop_nexus() p= ermits session removal once tpg_port_count reaches zero. However, usbg_port= _unlink() currently decrements that count from the fabric_pre_unlink() call= back, before core_dev_del_lun() waits for active se_lun references to drain=
. If removal of the last LUN races a nexus removal, the latter can observe =
a zero port count and call target_remove_session(). This frees sess_cmd_map=
while an in-flight struct usbg_cmd, including its work item, can still be = accessed. Overlapping the last-LUN unlink with nexus removal reproduces thi=
s lifetime violation as a DEBUG_OBJECTS "free active" warning for usbg_cmd_= work, followed by a target-core BUG/Oops. The generic target-core unlink pa=
th has no callback after core_dev_del_lun() completes. Add an optional fabr= ic_post_unlink() callback and use it for the f_tcm port count. The count no=
w remains nonzero until core_dev_del_lun() has finished draining active LUN=
references, preventing nexus removal from freeing the session during comma=
nd completion. 2026-09-04 not yet calculated CVE-2026-80854 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-80854 ] Linux--Linux In the Linux kernel, th=
e following vulnerability has been resolved: fuse: fix invalidate lock leak=
on open O_TRUNC DAX failure fuse_open() takes filemap_invalidate_lock() fo=
r a DAX truncate (dax_truncate =3D true) and releases it before the out_ino= de_unlock label. But when fuse_dax_break_layouts() fails, the goto out_inod= e_unlock skips the unlock and leaks the rwsem, so any later fault or trunca=
te on the file stalls on the stale lock. fuse_dax_break_layouts() can fail = with -ERESTARTSYS when a signal interrupts the wait for busy DAX pages to d= rain: open("file", O_RDWR | O_TRUNC) =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80= =9D=E2=82=AC fuse_open() =C3=A2=E2=80=9D=C5=93=C3=A2=E2=80=9D=E2=82=AC file= map_invalidate_lock() # dax_truncate =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80= =9D=E2=82=AC fuse_dax_break_layouts() =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80= =9D=E2=82=AC dax_break_layout() =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2= =82=AC wait_page_idle() # TASK_INTERRUPTIBLE =C3=A2=E2=80=9D=E2=80=9D=C3=A2= =E2=80=9D=E2=82=AC fuse_wait_dax_page() # unlock, schedule, re-lock =C3=A2= =E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC signal =C3=A2=E2=80=A0=E2=80=99 = -ERESTARTSYS goto out_inode_unlock # <- lock leaked Fix this by moving file= map_invalidate_unlock() below the label so that all error paths release the=
lock, and rename the label to out_unlock as it now covers more than just t=
he inode lock. 2026-09-04 not yet calculated CVE-2026-80855 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-80855 ] Linux--Linux In the Linux kernel, th=
e following vulnerability has been resolved: fuse: fix invalidate lock leak=
on setattr writeback failure fuse_do_setattr() takes filemap_invalidate_lo= ck() for a DAX truncate (fault_blocked =3D true) and releases it at the out= :/error: labels. But when a writeback flush is also needed, a write_inode_n= ow() failure returns directly and leaks the lock, so any later fault or tru= ncate on the file stalls on the stale rwsem. For example, truncate(2) on a = setuid file reaches fuse_do_setattr() with both ATTR_SIZE and ATTR_MODE set=
: truncate(2) =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC do_truncate(=
) =C3=A2=E2=80=9D=C5=93=C3=A2=E2=80=9D=E2=82=AC dentry_needs_remove_privs()=
# S_ISUID =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC notify_change()=
# KILL_SUID -> ATTR_MODE =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC = fuse_setattr() # no killpriv: =C3=A2=E2=80=9D=E2=80=9A # ia_valid |=3D ATTR= _MODE =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC fuse_do_setattr() = =C3=A2=E2=80=9D=C5=93=C3=A2=E2=80=9D=E2=82=AC filemap_invalidate_lock() # I= S_DAX && is_truncate =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC write= _inode_now() # is_wb && ATTR_MODE =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D= =E2=82=AC if (err) # e.g. daemon -> -EIO return err # <- lock leaked Fix th=
is by adding an unlock label that releases the lock before returning the er= ror, and use it for the fuse_dax_break_layouts() failure path as well. 2026= -09-04 not yet calculated CVE-2026-80856 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80856 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: fuse: wait for FR_FINISHED on abort_on_kill to pr= event use-after-free The abort_on_kill path in request_wait_answer() calls = fuse_abort_conn() and returns without waiting for FR_FINISHED. If fuse_dev_= do_write() is concurrently processing the same request (FR_LOCKED set), the=
caller frees req->args while it is still being accessed, causing a use-aft= er-free. Fix this by jumping to the existing wait_event(FR_FINISHED) instea=
d of returning early. The wait will not hang because fuse_abort_conn() ensu= res all requests are ended. 2026-09-04 not yet calculated CVE-2026-80857 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-80857 ] Linux--Linux In the Lin=
ux kernel, the following vulnerability has been resolved: fuse: publish io-= uring queues with release semantics fuse_uring_create_queue() initializes a=
fuse_ring_queue and then publishes the pointer into ring->queues[qid] with=
WRITE_ONCE() under the fch->lock. There are several readers that may concu= rrently be fetching that pointer locklessly and then deferencing it. WRITE_= ONCE() doesn't ensure ordering of the queue's field initialization before t=
he ring->queues[qid] pointer assignment. The queue must be published with s= mp_store_release() so the field initialization is guaranteed to happen befo= re. Readers in paths where the read may happen concurrently with the store = need to use READ_ONCE() because any race involving a plain access is undefi= ned. 2026-09-04 not yet calculated CVE-2026-80858 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-80858 ] Linux--Linux In the Linux kernel, the followin=
g vulnerability has been resolved: fuse: fix missing barrier when checking = io-uring readiness fuse_block_alloc() reads fch->initialized and then fch->= io_uring. fch->io_uring is set before fch->initialized, ordered by the smp_= wmb() in fuse_chan_set_intialized(), but fuse_block_alloc() has no matching=
read barrier between the two loads. This may lead a CPU to observe fch->in= itialized=3D1 but fch->io_uring=3D0, and skip the check that blocks request=
allocation until the io-uring queues are ready. This can reintroduce the l= ock-order inversion deadlock that commit 3393ff964e0f prevents. Add an smp_= rmb() barrier to pair with the smp_wmb() in fuse_chan_set_initialized() to = prevent this. 2026-09-04 not yet calculated CVE-2026-80859 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-80859 ] Linux--Linux In the Linux kernel, the=
following vulnerability has been resolved: fuse: fix race between interrup=
t and resend After commit f8fce75fedf7 ("fuse: clear intr_entry in fuse_res= end and fuse_remove_pending_req") the WARN_ON(!list_empty(&req->intr_entry)=
) in fuse_request_free() still triggers due to the following race: In reque= st_wait_answer() if (test_bit(FR_SENT, &req->flags)) -> returns true In fus= e_chan_resend() clear_bit(FR_SENT, &req->flags) In request_wait_answer() qu= eue_interrupt(req) Fix by: - move clearing FR_SENT inside fpq->lock - move = setting FR_PENDING inside fiq->lock - recheck FR_SENT after acquiring fiq->= lock in fuse_dev_queue_interrupt() 2026-09-04 not yet calculated CVE-2026-8= 0860 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80860 ] Linux--Linux In = the Linux kernel, the following vulnerability has been resolved: usb: xhci:=
bail out of setup if the controller is inaccessible xhci_gen_setup() locat=
es the operational registers using the capability length read from the very=
first register: xhci->op_regs =3D hcd->regs + HC_LENGTH(readl(&xhci->cap_r= egs->hc_capbase)); If the controller is dead or has dropped off the bus, th=
at read returns ~0, HC_LENGTH() truncates it to 0xff, and op_regs ends up 0= xff bytes past the page-aligned MMIO base, i.e. unaligned. The first access=
through it, xhci_halt() -> xhci_handshake() reading op_regs->status, is th=
en an unaligned readl() on device memory. arm64 faults on unaligned device = accesses, so instead of xhci_handshake() catching the all-ones value and re= turning -ENODEV, setup oopses: xhci-pci-renesas 0005:08:00.0: Unable to cha= nge power state from D3cold to D0, device inaccessible xhci-pci-renesas 000= 5:08:00.0: xHCI Host Controller xhci-pci-renesas 0005:08:00.0: new USB bus = registered, assigned bus number 1 Unable to handle kernel paging request at=
virtual address ffff80030a770103 ESR =3D 0x0000000096000021 FSC =3D 0x21: = alignment fault Internal error: Oops: 0000000096000021 [#1] SMP pc : xhci_h= alt [xhci_hcd] Call trace: xhci_halt xhci_gen_setup xhci_pci_setup usb_add_= hcd usb_hcd_pci_probe xhci_pci_common_probe xhci_pci_renesas_probe This was=
hit with a Renesas uPD720201 that failed to power up ("Unable to change po= wer state from D3cold to D0, device inaccessible") yet still reached the HC=
D probe path. Read the capability register once, and if it reads back the a= ll-ones value (as xhci_handshake() and xhci_reset() already test for), abor=
t setup with -ENODEV before op_regs is derived from it. Reading it once als=
o avoids re-reading a register that may change under a concurrent hot-remov= al. 2026-09-04 not yet calculated CVE-2026-80861 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-80861 ] Linux--Linux In the Linux kernel, the following=
vulnerability has been resolved: nvme-tcp: fix usage of page_frag_cache nv=
me uses page_frag_cache to preallocate PDU for each preallocated request of=
block device. Block devices are created in parallel threads, consequently = page_frag_cache is used in not thread-safe manner. That leads to incorrect = refcounting of backstore pages and premature free. That can be catched by != sendpage_ok inside network stack: WARNING: CPU: 7 PID: 467 at ../net/core/s= kbuff.c:6931 skb_splice_from_iter+0xfa/0x310. tcp_sendmsg_locked+0x782/0xce=
0 tcp_sendmsg+0x27/0x40 sock_sendmsg+0x8b/0xa0 nvme_tcp_try_send_cmd_pdu+0x= 149/0x2a0 Then random panic may occur. Fix that by serializing the usage of=
page_frag_cache. 2026-09-04 not yet calculated CVE-2026-80862 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-80862 ] Linux--Linux In the Linux kernel,=
the following vulnerability has been resolved: RDMA/rxe: Fix OOB in free_r= d_atomic_resources() free_rd_atomic_resources() iterates using qp->attr.max= _dest_rd_atomic. Updating max_dest_rd_atomic before freeing the old array c=
an make the free path walk past the old allocation and trigger a slab out-o= f-bounds write catched by KASAN: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D BUG: KASAN: slab-out-of-bounds in free_rd_atomic_resource drivers/in= finiband/sw/rxe/rxe_qp.c:180 [inline] BUG: KASAN: slab-out-of-bounds in fre= e_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline] BUG: = KASAN: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw= /rxe/rxe_qp.c:163 [inline] BUG: KASAN: slab-out-of-bounds in rxe_qp_from_at= tr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712 Write of size 4 at = addr ffff88802b8dddb8 by task syz.3.451/11063 CPU: 0 UID: 0 PID: 11063 Comm=
: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full) Hardware name: QEMU Ubuntu 2= 4.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-=
2 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] d= ump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c:120 print_address_description mm= /kasan/report.c:378 [inline] print_report+0xf7/0x600 mm/kasan/report.c:482 = kasan_report+0xe4/0x120 mm/kasan/report.c:595 free_rd_atomic_resource drive= rs/infiniband/sw/rxe/rxe_qp.c:180 [inline] free_rd_atomic_resources drivers= /infiniband/sw/rxe/rxe_qp.c:171 [inline] free_rd_atomic_resources drivers/i= nfiniband/sw/rxe/rxe_qp.c:163 [inline] rxe_qp_from_attr+0x1e88/0x2150 drive= rs/infiniband/sw/rxe/rxe_qp.c:712 rxe_modify_qp+0x1e2/0x530 drivers/infinib= and/sw/rxe/rxe_verbs.c:623 ib_security_modify_qp+0x223/0xfa0 drivers/infini= band/core/security.c:625 _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/= verbs.c:1915 modify_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1= 932 ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:195=
8 ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_main.c:680 vf= s_write+0x2aa/0x1070 fs/read_write.c:686 ksys_write+0x1f8/0x250 fs/read_wri= te.c:740 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_= 64+0x116/0x800 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwfram= e+0x77/0x7f RIP: 0033:0x7fefc75a70cd Code: ff c3 66 2e 0f 1f 84 00 00 00 00=
00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c=
8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 =
64 89 01 48 RSP: 002b:00007fefc8495018 EFLAGS: 00000246 ORIG_RAX: 000000000= 0000001 RAX: ffffffffffffffda RBX: 00007fefc7835fa0 RCX: 00007fefc75a70cd R= DX: 0000000000000078 RSI: 0000200000000240 RDI: 0000000000000007 RBP: 00007= fefc764f10f R08: 0000000000000000 R09: 0000000000000000 R10: 00000000000000=
00 R11: 0000000000000246 R12: 0000000000000000 R13: 00007fefc7836038 R14: 0= 0007fefc7835fa0 R15: 00007ffcf0586aa0 </TASK> Allocated by task 11063: kasa= n_save_stack+0x33/0x60 mm/kasan/common.c:57 kasan_save_track+0x14/0x30 mm/k= asan/common.c:78 poison_kmalloc_redzone mm/kasan/common.c:398 [inline] __ka= san_kmalloc+0xaa/0xb0 mm/kasan/common.c:415 kasan_kmalloc include/linux/kas= an.h:263 [inline] __do_kmalloc_node mm/slub.c:5296 [inline] __kmalloc_nopro= f+0x32a/0x850 mm/slub.c:5308 kmalloc_noprof include/linux/slab.h:954 [inlin=
e] kzalloc_noprof include/linux/slab.h:1188 [inline] alloc_rd_atomic_resour= ces drivers/infiniband/sw/rxe/rxe_qp.c:155 [inline] rxe_qp_from_attr+0x3f8/= 0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:714 rxe_modify_qp+0x1e2/0x530 dri= vers/infiniband/sw/rxe/rxe_verbs.c:623 ib_security_modify_qp+0x223/0xfa0 dr= ivers/infiniband/core/security.c:625 _ib_modify_qp+0x333/0xec0 drivers/infi= niband/core/verbs.c:1915 modify_qp+0x13ca/0x1940 drivers/infiniband/core/uv= erbs_cmd.c:1932 ib_uverbs_modify_qp+0xcb/0x120 drivers/infiniband/core/uver= bs_cmd.c:1958 ib_uverbs_write+0xb86/0x1030 drivers/infiniband/core/uverbs_m=
a ---truncated--- 2026-09-04 not yet calculated CVE-2026-80863 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-80863 ] Linux--Linux In the Linux kernel,=
the following vulnerability has been resolved: RDMA/rxe: Fix responder UAF=
on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_attr() handles IB_QP_MAX= _DEST_RD_ATOMIC outside the IB_QP_STATE path, so it holds no state_lock and=
runs while the responder task rxe_receiver() (recv_task on rxe_wq) is live=
. A modify_qp() setting only that attribute calls free_rd_atomic_resources(=
) then alloc_rd_atomic_resources(), swapping qp->resp.resources[] while rxe= _prepare_res()/find_resource() walk it; free_rd_atomic_resources() also lea= ves the cached pointer qp->resp.res dangling. A local unprivileged user can=
race the free/realloc into a use-after-free in rxe_receiver() (local DoS).=
Drain recv_task around the swap with rxe_disable_task()/rxe_enable_task(),=
as rxe_qp_reset() already does when tearing this array down, re-enabling o= nly after alloc_rd_atomic_resources() succeeds so the responder never resum=
es against a NULL qp->resp.resources on the ENOMEM path. Also clear qp->res= p.res in free_rd_atomic_resources(), like the rxe_resp.c completion paths. = Reproduced under KASAN; the slab-use-after-free in rxe_receiver() is gone. = 2026-09-04 not yet calculated CVE-2026-80864 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-80864 ] Linux--Linux In the Linux kernel, the following vul= nerability has been resolved: bpf: Add missing access_ok call to copy_user_= syms As reported by sashiko we use __get_user without prior access_ok call =
on the user space pointer. Adding the missing call for the whole pointer ar= ray. Plus removing the err check in the error path, because it's not needed=
and also we can return -ENOMEM directly from the first kvmalloc_array fail=
path. [1]
https://lore.kernel.org/bpf/20260611115503.AC16D1F00893@smtp.ker= nel.org/ 2026-09-04 not yet calculated CVE-2026-80865 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80865 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: tipc: avoid busy looping in tipc_exi= t_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wai=
t for pending UDP bearer cleanup works to complete: while (atomic_read(&tn-= >wq_count)) cond_resched(); This loop can busy-wait for a long time if cond= _resched() is a NOP. This typically happens if the netns exit is executed b=
y a high priority task, or under kernels configured without preemption (CON= FIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft=
lockups. Fix this by replacing the busy loop with wait_var_event(), allowi=
ng the thread to sleep properly until the work queue count reaches zero. Ac= cordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up= _var() to wake up the waiter when the count drops to zero. This uses the gl= obal wait queue hash table, avoiding the need to bloat struct tipc_net with=
a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memo=
ry barrier to ensure the wakeup is not missed. 2026-09-04 not yet calculate=
d CVE-2026-80866 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80866 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Curren= tly, Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDO= WN_PCI_ACCESS) before allowing userspace to mmap PCI BARs. The generic vers= ion has had this check since commit eb627e17727e ("PCI: Lock down BAR acces=
s when the kernel is locked down") to prevent DMA attacks when the kernel i=
s locked down. Add the same check to Alpha's pci_mmap_resource(). 2026-09-0=
4 not yet calculated CVE-2026-80867 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-80867 ] Linux--Linux In the Linux kernel, the following vulnerabilit=
y has been resolved: ntfs3: Allocate iomap inline_data using alloc_page Thi=
s fixes a BUG reported in iomap_write_end_inline: iomap_inline_data_valid c= hecks that the inline_data fits within a page. If the inline_data is alloca= ted with kmemdup there's no guarantee that it's page-aligned, so the check = sometimes fails. Allocate it with alloc_page to ensure it's page-aligned. 2= 026-09-04 not yet calculated CVE-2026-80868 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-80868 ] Linux--Linux In the Linux kernel, the following vuln= erability has been resolved: ntfs: bound the attribute-list entry in ntfs_r= ead_inode_mount() The $MFT attribute-list walk in ntfs_read_inode_mount() v= alidates each entry only with "(u8 *)al_entry + 6 > al_end" and "(u8 *)al_e= ntry + le16_to_cpu(al_entry->length) > al_end", but then reads al_entry->lo= west_vcn (an __le64 at offset 8) and al_entry->mft_reference (offset 16) --=
fields beyond the 6 bytes proven in range. al_entry->length is attacker-co= ntrolled and only required non-zero, so a short entry (e.g. length 8) place=
d at the tail passes both checks while the lowest_vcn / mft_reference reads=
fall past al_end. al_end is ni->attr_list + attr_list_size (the on-disk si= ze); the buffer is kvzalloc(round_up(attr_list_size, SECTOR_SIZE)), so the = sector rounding usually absorbs the over-read -- but when attr_list_size is=
a multiple of SECTOR_SIZE there is no slack and a crafted $MFT attribute l= ist produces an out-of-bounds read at mount time. Validate the entry with n= tfs_attr_list_entry_is_valid() (added in patch 1/3) before dereferencing it=
, matching the bound the other attribute-list walks now use. The validator = already requires the length to cover the fixed header, which makes the sepa= rate "!al_entry->length" check redundant, so drop it too. 2026-09-04 not ye=
t calculated CVE-2026-80869 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 0869 ] Linux--Linux In the Linux kernel, the following vulnerability has be=
en resolved: drm/amdkfd: Validate CRIU-restored IDs before idr_alloc The KF=
D CRIU restore flow restores previously saved object IDs from userspace. Fo=
r event restore: kfd_criu_restore_event() -> create_signal_event() / create= _other_event() -> allocate_event_notification_slot() -> idr_alloc(..., *res= tore_id, *restore_id + 1, ...) For BO restore: criu_restore_memory_of_gpu()=
idr_alloc(..., bo_priv->idr_handle, ...) In both cases, the restored ID=
comes from userspace-provided CRIU data. idr_alloc() expects the ID range = values to fit within signed int limits. If a restored ID is larger than INT= _MAX, it can trigger a WARN in the IDR layer. A kernel WARN is undesirable = because it prints a warning trace and may cause a panic or reboot on system=
s with panic_on_warn enabled. Smatch reported these paths as allowing unche= cked userspace values to reach idr_alloc(). Add INT_MAX validation before u= sing restored IDs in: - kfd_criu_restore_event() - criu_restore_memory_of_g= pu() If the restored ID is invalid, return -EINVAL. This prevents invalid r= estore data from reaching the IDR layer and avoids WARN-triggering paths, w= hile keeping valid restore behavior unchanged. 2026-09-04 not yet calculate=
d CVE-2026-80870 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80870 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: crypto: xilinx-trng - Remove crypto_rng interface Implementing the crypto= _rng interface has no purpose, as it isn't used in practice. It's being rem= oved from other drivers too. Just remove it. This leaves hwrng, which is ac= tually used. Tagging with 'Cc stable' due to the bugs that this removes: - = xtrng_trng_generate() sometimes returned success even when it didn't fill i=
n all the bytes. - It was possible for xtrng_trng_generate() and xtrng_hwrn= g_trng_read() to run concurrently and interfere with each other, as the loc= king code in xtrng_hwrng_trng_read() was broken. 2026-09-04 not yet calcula= ted CVE-2026-80871 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80871 ] Li= nux--Linux In the Linux kernel, the following vulnerability has been resolv= ed: ALSA: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA = I2C and SPI queue RCA firmware loading from component bind with request_fir= mware_nowait(). The firmware loader keeps the callback module pinned and ho= lds a device reference, but the callback still uses driver-private HDA stat=
e. Component unbind removes controls and DSP state immediately. Later devic=
e removal tears down the TAS2781 private data, including codec_lock. If the=
async firmware callback runs after unbind has started, it can operate on s= tate that is being torn down. Cancel or synchronize the async firmware requ= est before removing controls and DSP state. A queued callback is cancelled,=
and an already-running callback is allowed to finish before unbind continu= es. 2026-09-04 not yet calculated CVE-2026-80872 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-80872 ] Linux--Linux In the Linux kernel, the following=
vulnerability has been resolved: KVM: arm64: nv: Write ESR_EL2 for injecte=
d nested SError exceptions kvm_inject_el2_exception() writes ESR_EL2 for sy= nchronous exceptions but not for SError. enter_exception64() does not write=
ESR_ELx for any exception type, so the constructed syndrome is dropped. A = guest L2 hypervisor taking a nested SError observes stale ESR_EL2. This aff= ects both kvm_inject_nested_serror() and the EASE path in kvm_inject_nested= _sea(). Write ESR_EL2 for except_type_serror, matching except_type_sync. 20= 26-09-04 not yet calculated CVE-2026-80873 [
https://www.cve.org/CVERecord?= id=3DCVE-2026-80873 ] Linux--Linux In the Linux kernel, the following vulne= rability has been resolved: arm64: dts: renesas: ironhide: Describe inline = ECC carveouts The DBSC5 DRAM controller protects DRAM content using inline = ECC. The inline ECC utilizes areas of DRAM for its operation, which are in = the DRAM address range, but must not be accessed or modified. Describe the = inline ECC carveout areas used by the DBSC5 controller on this hardware as = reserved-memory, which must not be accessed. Include DRAM areas which are u= nprotected by ECC as well, those are parts of the DRAM which directly prece=
de the ECC carveout. In case of high DRAM utilization, unless the inline EC=
C carveouts are properly reserved, Linux may use and corrupt the memory use=
d by the DBSC5 DRAM controller for inline ECC, which would lead to the syst=
em becoming unstable. 2026-09-04 not yet calculated CVE-2026-80874 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-80874 ] Linux--Linux In the Linux ker= nel, the following vulnerability has been resolved: ipvs: use parsed transp= ort offset in TCP state lookup TCP state handling reparses the skb to find = the TCP header. For IPv6 it uses sizeof(struct ipv6hdr), while the surround= ing IPVS code already parsed the packet with ip_vs_fill_iph_skb() and has t=
he real transport-header offset in iph.len. This makes TCP state handling l= ook at the wrong bytes when an IPv6 packet carries extension headers. Use t=
he parsed transport offset passed down from ip_vs_set_state() when reading = the TCP header. For IPv4 and for IPv6 packets without extension headers, th=
e passed offset matches the previous value. 2026-09-04 not yet calculated C= VE-2026-80875 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80875 ] Linux--= Linux In the Linux kernel, the following vulnerability has been resolved: r= ing-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BY= TE_ALIGNMENT is true, rb_calculate_event_length() reserves the space of eve= nt->array[0] for placing the data length and rb_update_event() stores the d= ata length in event->array[0] accordingly. As a result the whole event leng=
th will add extra 4 bytes for sizeof(event.array[0]) unconditionally. But r= ing_buffer_event_length() only subtracts the sizeof(event->array[0]) for ev= ents larger than RB_MAX_SMALL_DATA + sizeof(event->array[0]). As a result, = small events on architectures with RB_FORCE_8BYTE_ALIGNMENT=3Dtrue report a=
data length that is 4 bytes larger than expected. To fix it, add the RB_FO= RCE_8BYTE_ALIGNMENT as a condition to subtract the size of that length fiel=
d whenever RB_FORCE_8BYTE_ALIGNMENT is true. This issue is observed in a ri= scv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when we run ft= race selftest trace_marker_raw.tc, we get the weird log: for cases where th=
e id is 1..100, the number of data field is 8*N, but once id exceeds 100, t=
he number of data field becomes 8*N+4: # 1 buf: 58 00 00 00 80 5e d1 63 (nu= mber of data field is 8*1) ... # a buf: 58 ... (number of data field is 8*2=
) ... # 64 buf: 58 ... (number of data field is 8*13) # 65 buf: 58 ... (num= ber of data field is 8*13+4) After applying this change, the number of data=
field keeps being 8*N+4 consistently. 2026-09-04 not yet calculated CVE-20= 26-80876 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80876 ] Linux--Linux=
In the Linux kernel, the following vulnerability has been resolved: afs: F=
ix vllist leak Fix a leak of the new vllist in afs_update_cell() in the eve=
nt that it is an empty list (nr_servers =3D=3D 0), in which case the old li=
st isn't displaced unless the old list is also empty. 2026-09-04 not yet ca= lculated CVE-2026-80877 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80877=
] Linux--Linux In the Linux kernel, the following vulnerability has been r= esolved: afs: Fix leak of ungot volume Fix afs_lookup_volume_rcu() so that =
it doesn't leak a dying volume if afs_try_get_volume() fails. 2026-09-04 no=
t yet calculated CVE-2026-80878 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-80878 ] Linux--Linux In the Linux kernel, the following vulnerability ha=
s been resolved: ocfs2: fix circular locking dependency in ocfs2_dio_end_io= _write A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE, EXT= ENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE. 1. ocfs2_mknod() acqui= res INODE_ALLOC then EXTENT_ALLOC. 2. ocfs2_dio_end_io_write() acquires EXT= ENT_ALLOC for unwritten extents, then ORPHAN_DIR via ocfs2_del_inode_from_o= rphan() while still holding EXTENT_ALLOC. 3. ocfs2_wipe_inode() acquires OR= PHAN_DIR then INODE_ALLOC via ocfs2_remove_inode. Break the cycle in ocfs2_= dio_end_io_write() by freeing the allocation contexts (releasing EXTENT_ALL= OC) before acquiring ORPHAN_DIR. WARNING: possible circular locking depende= ncy detected ------------------------------------------------------ is tryi=
ng to acquire lock: ffff8881e78b33a0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_S= YSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/ino= de.c:1299 but task is already holding lock: ffff8881e78b4fa0 (&ocfs2_sysfil= e_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0xe= 97/0x43b0 fs/ocfs2/inode.c:1299 the existing dependency chain (in reverse o= rder) is: -> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4= :4}: inode_lock include/linux/fs.h:1029 [inline] ocfs2_del_inode_from_orpha= n+0x12e/0x7a0 fs/ocfs2/namei.c:2728 ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/= aops.c:2418 dio_complete+0x25b/0x790 fs/direct-io.c:281 -> #1 (&ocfs2_sysfi= le_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: inode_lock include/lin= ux/fs.h:1029 [inline] ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/sub= alloc.c:882 ocfs2_reserve_new_metadata_blocks+0x415/0x9a0 fs/ocfs2/suballoc= .c:1078 ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351 -> #0 (&ocfs2_sysfil= e_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: __lock_acquire+0x15a5/0x= 2cf0 kernel/locking/lockdep.c:5237 lock_acquire+0x106/0x350 kernel/locking/= lockdep.c:5868 down_write+0x96/0x200 kernel/locking/rwsem.c:1625 inode_lock=
include/linux/fs.h:1029 [inline] ocfs2_remove_inode fs/ocfs2/inode.c:733 [= inline] ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline] ocfs2_delete_inode f= s/ocfs2/inode.c:1157 [inline] ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inod= e.c:1299 Chain exists of: &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]=
&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] --> &ocfs2_sysfile_=
lock_key[ORPHAN_DIR_SYSTEM_INODE] Possible unsafe locking scenario: CPU0 CP=
U1 ---- ---- lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]); lock(&= ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]); lock(&ocfs2_sysfile_loc= k_key[ORPHAN_DIR_SYSTEM_INODE]); lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_S= YSTEM_INODE]); *** DEADLOCK *** 2026-09-04 not yet calculated CVE-2026-8087=
9 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80879 ] Linux--Linux In the=
Linux kernel, the following vulnerability has been resolved: IB/mlx5: Prop= erly support implicit ODP rereg_mr Due to all the child mkeys in the implic=
it ODP configuration we cannot change anything in place for the parent mkey=
. Instead the whole thing needs to be rebuilt if any change is requested. I=
f the user does not specify a translation then force the implicit values wh= ich will then fall through the logic into mlx5_ib_reg_user_mr() to allocate=
a completely new MR. Since implicit children were also touching the mr->pd=
, this removes another case where the access was racy. 2026-09-04 not yet c= alculated CVE-2026-80880 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8088=
0 ] Linux--Linux In the Linux kernel, the following vulnerability has been = resolved: ocfs2: fix buffer head management in ocfs2_read_blocks() In ocfs2= _read_blocks(), caller should't assume that buffer head returned by 'sb_get= blk()' is exclusively owned and so 'put_bh()' always drops b_count from 1 t=
o 0. If it is not so, buffer head remains on hold and likely to be returned=
by the next call to 'sb_getblk()' unchanged - that is, with BH_Uptodate bi=
t set even if it has failed validation previously, thus allowing to insert = that buffer head into OCFS2 metadata cache and submit it to upper layers. T=
o avoid such a scenario, BH_Uptodate should be cleared immediately after 'v= alidate()' callback has detected some data inconsistency. 2026-09-04 not ye=
t calculated CVE-2026-80881 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 0881 ] Linux--Linux In the Linux kernel, the following vulnerability has be=
en resolved: crypto: tegra - Return ENOMEM when input buffer allocation fai=
ls for ccm Ensure the ENOMEM error value is set when the input buffer alloc= ation fails in tegra_ccm_do_one_req. 2026-09-04 not yet calculated CVE-2026= -80882 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80882 ] Linux--Linux I=
n the Linux kernel, the following vulnerability has been resolved: drm/tegr=
a: gr2d/gr3d: Initialize address register map before HOST1X client is regis= tered The host1x_client_register() function is called just prior to registe=
r map initialization loop, making the device available to userspace. This m=
ay result in userspace attempting to submits a job before the register map =
is initialized. Address this by moving register initialization before host1=
x client registration. 2026-09-04 not yet calculated CVE-2026-80883 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-80883 ] Linux--Linux In the Linux ke= rnel, the following vulnerability has been resolved: ntb: Store original DM=
A address for future release The DMA API requires that dma_free_attrs recei=
ve the exact dma_handle originally returned by the allocation function. Do = not modify it. 2026-09-04 not yet calculated CVE-2026-80884 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-80884 ] Linux--Linux In the Linux kernel, th=
e following vulnerability has been resolved: afs: Fix uncancelled rxrpc OOB=
message handler Fix AFS to cancel its OOB message processing (typically to=
respond to security challenges). Also move OOB message processing to afs_w=
q so that it's also waited for and make the OOB handler just return if the = net namespace is no longer live. 2026-09-04 not yet calculated CVE-2026-808=
85 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80885 ] Linux--Linux In th=
e Linux kernel, the following vulnerability has been resolved: serial: msm:=
Disable DMA for kernel console UART At the moment, concurrent writes from = userspace and the kernel to the console can trigger a race condition that r= esults in an infinite loop of the same messages printed over and over again=
. This is most likely to happen during system startup or shutdown when the = init system starts/stops a large number of system services that interact wi=
th various kernel code. When userspace writes to the TTY device, the driver=
initiates an asynchronous DMA transfer and releases the port lock. At the = same moment, the kernel printk path might grab the port lock and re-configu=
re the UART controller for PIO, without waiting for the DMA operation to co= mplete. It seems like this collision results in zero progress being reporte=
d for the DMA engine, so the same text is printed to the console over and o= ver again. For the kernel console, we want a reliable output path that will=
be functional even during crashes etc. So rather than implementing complex=
code to synchronize the kernel console write routines with the userspace D=
MA write routines, simply disable DMA for the console UART instance. Simila=
r checks exist in many other serial drivers, e.g. 8250_port.c, imx.c, sh-sc= i.c etc. 2026-09-04 not yet calculated CVE-2026-80886 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80886 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: drm/vmwgfx: use check_add_overflow f=
or shader size+offset bound vmw_shader_define() validates the user-supplied=
shader window against its backing buffer with (u64)buffer->tbo.base.size <=
(u64)size + (u64)offset drm_vmw_shader_create_arg::offset is __u64 in the = uapi; when it is near U64_MAX the unsigned addition wraps and the resulting=
tiny value passes the check. The unbounded offset is then stored in res->g= uest_memory_offset and forwarded to host SVGA shader-create commands. Use c= heck_add_overflow() to detect the wrap and compare the resulting endpoint a= gainst the buffer size. 2026-09-04 not yet calculated CVE-2026-80887 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-80887 ] Linux--Linux In the Linux k= ernel, the following vulnerability has been resolved: drm/vmwgfx: drop dma_= buf reference on foreign-fd prime import ttm_prime_fd_to_handle() returns -= ENOSYS when the imported fd's dma_buf->ops do not match the ttm_object_devi= ce's ops, but does so without releasing the reference acquired by dma_buf_g= et(). Any unprivileged renderD client passing a non-vmwgfx prime fd through=
the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_buf reference per cal=
l and indefinitely pins the foreign exporter's GEM resources. Funnel the er= ror path through the existing dma_buf_put() so the reference is always drop= ped. 2026-09-04 not yet calculated CVE-2026-80888 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-80888 ] Linux--Linux In the Linux kernel, the followin=
g vulnerability has been resolved: can: isotp: fix timer drain order, wakeu=
p handling and tx_gen ordering This patch is a follow-up to commit cf070fe3= 3bfb ("can: isotp: serialize TX state transitions under so->rx_lock") which=
addresses following sashiko-bot findings: - isotp_sendmsg(): drain so->txf= rtimer first so a stale callback can't re-arm echotimer after the claim - i= sotp_release(): wake so->wait after forcing ISOTP_SHUTDOWN so a sleeping se= ndmsg() claim isn't stranded - isotp_sendmsg(): have both wait_event_interr= uptible() calls in isotp_sendmsg() also wake on ISOTP_SHUTDOWN and do not r= eturn claim to IDLE to avoid corrupting a concurrent isotp_release() proces=
s. - isotp_sendmsg(): handle potential claim of a new transfer when the wai= t_event_interruptible() call returns in CAN_ISOTP_WAIT_TX_DONE mode. Don't = touch timers and states of the new transfer if a new thread incremented so-= >tx_gen before getting the lock at err_event_drop. - isotp_sendmsg(): handl=
e a stuck can_send() and omit timer and state changes if a new transfer was=
claimed. wait_tx_done() returns the error recorded in so->tx_result[], tag= ged with the caller's own generation. - isotp_tx_timeout(): on a claimed ti= meout, record the ECOMM error for the timed-out transfer's own generation i=
n so->tx_result[]; sk->sk_err is raised unconditionally, same as every othe=
r error path here. - isotp_tx_gen_done()/isotp_tx_timeout(): always read tx= .state (acquire) before tx_gen - the reverse order let a weakly ordered CPU=
pair a fresh tx.state with a stale tx_gen/tx_result slot. - isotp_sendmsg(=
): wait_tx_done: drain sk_err via sock_error() once we have read the result=
from so->tx_result[], so an already-reported error doesn't stay latched fo=
r a later poll()/SO_ERROR. Also align the remaining lock-free so->tx.state/= rx.state/cfecho accesses and use skb->hash as unique loopback echo frame in= dicator. 2026-09-04 not yet calculated CVE-2026-80889 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80889 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: sctp: reject stale cookies with mism= atched verification tags sctp_unpack_cookie() skips cookie expiration check=
s whenever an association already exists. This is broader than the exceptio=
n in RFC 9260 Section 5.2.4. For an existing association, Section 5.2.4 per= mits an expired State Cookie only when both Verification Tags in the cookie=
match the current association. Otherwise, the packet SHOULD be discarded a=
nd a Stale Cookie ERROR MUST be sent. The broad check lets an expired Actio=
n A restart cookie reach sctp_sf_do_dupcook_a(). In a runtime test with the=
default 60 second cookie lifetime, replaying such a cookie after 65 second=
s returned a COOKIE-ACK and restarted the association. Check cookie expirat= ion unless both Verification Tags match. This preserves the Action D except= ion for a lost COOKIE ACK while rejecting expired cookies in all other case=
s. 2026-09-04 not yet calculated CVE-2026-80890 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-80890 ] Linux--Linux In the Linux kernel, the following = vulnerability has been resolved: KVM: s390: pci: Validate AIBV and AISB bef= ore pinning guest pages The AIBV holds one bit per MSI-X vector for a given=
function. The size of the bit vector is derived from the NOI and the AIBVO=
. If the size of the AIBV exceeds a single page boundary, then reject the r= equest as we cannot safely pin the guest AIBV. Similarly reject the request=
if the AISB address is not 8-byte aligned as the architecture requires dou= bleword alignment for the summary bit address. Since the AISBO can address =
up to 64 bits, the size of the AISB can only be 8 bytes for the function. T= his also ensures the AISB doesn't exceed a single page boundary. 2026-09-04=
not yet calculated CVE-2026-80891 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-80891 ] Linux--Linux In the Linux kernel, the following vulnerability=
has been resolved: erofs: cap LZMA stream pool size fs/erofs/decompressor_= lzma.c sizes the module-global MicroLZMA stream pool from num_possible_cpus=
() when the lzma_streams module parameter is unset, then z_erofs_load_lzma_= config() preallocates one image-supplied dictionary per stream, accepting d= ictionaries up to 8 MiB. On high-CPU systems, a small EROFS image can pin h= undreds of MiB of vmalloc-backed decoder state until the erofs module is un= loaded. Impact: An EROFS image mounted by the system can pin up to 8 MiB of=
vmalloc memory per LZMA stream, either as intended or unexpectedly. Bound = the default stream count by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STRE= AMS option, default 16, so the worst-case default preallocation is 128 MiB =
if the number of CPUs is no less than 16 while preserving the existing per-= image dictionary limit. An explicit lzma_streams module parameter is still = honoured as-is, so administrators who deliberately size the pool are not af= fected. 2026-09-04 not yet calculated CVE-2026-80892 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-80892 ] Linux--Linux In the Linux kernel, the follo= wing vulnerability has been resolved: mm/hugetlb: fix swap entry corruption=
when clearing uffd-wp at fork() copy_hugetlb_page_range() clears the uffd-=
wp bit of migration and hwpoison entries with huge_pte_clear_uffd_wp(), whi=
ch operates on the present-PTE bit position. Swap entries keep the uffd-wp = state elsewhere -- the migration branch reads and sets it with pte_swp_uffd= _wp() and pte_swp_mkuffd_wp() -- and the present-PTE position falls into th=
e swap payload. On x86-64 it lands in the inverted swap offset, where a nat= urally-aligned hugetlb PFN always has the affected bit set, so the clear ad= vances the encoded PFN by two pages. No userfaultfd needs to be involved: t=
he clear is guarded only by the child VMA not being uffd-wp registered, so =
a plain fork() with an in-flight hugetlb migration entry (or a poisoned hug= etlb page) corrupts the entry copied into the child. Instrumenting the clea=
r and forking after MADV_HWPOISON on a 2MB anon hugetlb page shows: offset = before=3D120e00 offset after =3D120e02 The fallout is mostly latent: rmap w= alks match migration entries by folio range and remove_migration_pte() rebu= ilds the PTE from the folio, so a within-folio PFN skew heals once migratio=
n completes. But any path that re-encodes the corrupted offset -- e.g. huge= tlb_change_protection() rewriting a writable migration entry via make_reada= ble_migration_entry(swp_offset(entry)) -- propagates it. Migration entries = legitimately carry uffd-wp, so clear it with pte_swp_clear_uffd_wp(), match= ing copy_nonpresent_pte() and move_huge_pte(). A hwpoison entry, on the oth=
er hand, never carries the uffd-wp bit: it is installed fresh by make_hwpoi= son_entry() (try_to_unmap_one() does not preserve uffd-wp on the hwpoison p= ath) and hugetlb_change_protection() leaves hwpoison entries untouched. The=
re was nothing to clear there, only the corruption, so drop the clear entir= ely. 2026-09-04 not yet calculated CVE-2026-80893 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-80893 ] Linux--Linux In the Linux kernel, the followin=
g vulnerability has been resolved: iommufd: Fix wrong hwpt passed to iommuf= d_auto_response_faults on replace iommufd_hwpt_replace_device() calls: iomm= ufd_auto_response_faults(hwpt, old_handle); passing the *new* hwpt together=
with the handle of the device's *old* domain. This should be a parameter m= ismatch: 1. Semantically, iommufd_auto_response_faults(x, handle) scans x->= fault's deliver list and response xarray for groups matching "handle". A gr= oup is queued under the hwpt that was attached at fault-delivery time. old_= handle is fetched *before* the domain switch, so its group lives on old->fa= ult, not on the new hwpt->fault. 2. Historically, the first argument was "o= ld". The routine was introduced by commit b7d8833677ba ("iommufd: Fault-cap= able hwpt attach/detach/replace") as __fault_domain_replace_dev() in fault.=
c, correctly calling iommufd_auto_response_faults(old, curr). Commit fb21b1= 568ada ("iommufd: Make attach_handle generic than fault specific") moved th=
is into iommufd_hwpt_replace_device() in device.c and swapped it to "hwpt".=
This should be a refactor regression, not an intentional change. Fix this =
by passing "old" instead. 2026-09-04 not yet calculated CVE-2026-80894 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-80894 ] Linux--Linux In the Linux=
kernel, the following vulnerability has been resolved: mshv: Order pt_vp_a= rray publish against irqfd assertion path mshv_partition_ioctl_create_vp() = initialises a VP struct (allocations, mutex_init, init_waitqueue_head, page=
mappings) and then publishes the pointer into partition->pt_vp_array. Seve= ral ISR paths read this array locklessly: the intercept ISR, the two schedu= ler ISRs, and mshv_try_assert_irq_fast() on the irqfd fast path. Of these, = only mshv_try_assert_irq_fast() can structurally race the publish. It runs = from an eventfd waker without holding pt_mutex, and MSHV_IRQFD does not req= uire the target lapic_apic_id (=3D=3D vp_index) to refer to an existing VP =
at registration time. A user can therefore register an irqfd targeting a ye= t-to-be-created VP, then trigger mshv_try_assert_irq_fast() concurrently wi=
th MSHV_CREATE_VP for the same index. On weakly-ordered architectures the r= eader can observe a non-NULL pointer in pt_vp_array before the initialising=
stores to the VP struct become visible, leading to use of partially-initia= lised fields (e.g. vp_register_page). The other ISR readers cannot reach th=
is race: the hypervisor will not generate intercept or scheduler messages f=
or a VP that has never been told to run, and the user can only call MSHV_RU= N_VP on the VP fd returned by MSHV_CREATE_VP, which by construction is retu= rned after the publish. Leave those readers as plain loads. Use smp_store_r= elease() in mshv_partition_ioctl_create_vp() to publish the pointer, and pa=
ir it with smp_load_acquire() in mshv_try_assert_irq_fast(). On x86 these c= ompile to plain accesses under TSO; on ARM64 they emit one-instruction acqu= ire/release barriers, acceptable on this fast path. The destroy-side path (= destroy_partition() clearing pt_vp_array[i] to NULL after kfree(vp)) has a = separate ordering and lifetime concern that is out of scope here. 2026-09-0=
4 not yet calculated CVE-2026-80895 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-80895 ] Linux--Linux In the Linux kernel, the following vulnerabilit=
y has been resolved: mshv: Fix race in mshv_irqfd_deassign mshv_irqfd_deact= ivate() and the hlist traversal of pt_irqfds_list require pt->pt_irqfds_loc=
k to be held, but mshv_irqfd_deassign() omits it. This races with the EPOLL= HUP path in mshv_irqfd_wakeup(), which does take the lock before calling ms= hv_irqfd_deactivate(). Additionally, mshv_irqfd_deactivate() uses hlist_del=
() which poisons the node pointers rather than resetting them. Since mshv_i= rqfd_is_active() relies on hlist_unhashed() (checks pprev =3D=3D NULL), a p= oisoned node still appears active. If a concurrent path calls mshv_irqfd_de= activate() again on the same irqfd, the guard fails to prevent a double hli= st_del() on poisoned pointers. Fix both issues: - Add the missing spin_lock= _irq/spin_unlock_irq around the list traversal in mshv_irqfd_deassign(), ma= tching mshv_irqfd_release(). - Use hlist_del_init() instead of hlist_del() =
so the node is properly marked as unhashed after removal, making the is_act= ive guard reliable. 2026-09-04 not yet calculated CVE-2026-80896 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-80896 ] Linux--Linux In the Linux kerne=
l, the following vulnerability has been resolved: netfs: release readahead = folios on iterator preparation failure netfs_prepare_read_iterator() batche=
s readahead folios in put_batch so that the folio references can be dropped=
after the I/O iterator has been prepared. If rolling_buffer_load_from_ra()=
fails after earlier folios have been batched, the function returns immedia= tely and leaves those references held. Release the batch before returning t=
he error. 2026-09-04 not yet calculated CVE-2026-80897 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-80897 ] Linux--Linux In the Linux kernel, the fol= lowing vulnerability has been resolved: netfs: clear PG_private_2 on copy-t= o-cache append failure netfs_pgpriv2_copy_to_cache() marks the folio with P= G_private_2 before netfs_pgpriv2_copy_folio() appends it to the copy-to-cac=
he rolling buffer. If the append fails, the folio is not queued for cache w= riteback, so the PG_private_2 state and its reference must be released imme= diately. 2026-09-04 not yet calculated CVE-2026-80898 [
https://www.cve.org= /CVERecord?id=3DCVE-2026-80898 ] Linux--Linux In the Linux kernel, the foll= owing vulnerability has been resolved: erofs: remove fscache backend entire=
ly EROFS over fscache was introduced to provide image lazy pulling function= ality. After the feature landed, the fscache subsystem made netfs a new har=
d dependency, which is unexpected for a local filesystem and has an kernel-= defined caching hierarchy which could be inflexible compared to the fanotif=
y pre-content hooks. Therefore, this feature has been deprecated for almost=
two years. As EROFS file-backed mounts and fanotify pre-content hooks both=
upstream for a while and already providing equivalent functionality (erofs= -utils has supported fanotify pre-content hooks), let's remove the fscache = backend now. The main application of this feature is Nydus [1], and they pl=
an to move to use fanotify pre-content hooks in the near future too. I hope=
this patch can be merged into Linux 7.2, which is also motivated by newly = found implementation issues [2][3] that are not worth investigating given t=
he deprecation and limited development resources. The associated fscache/ca= chefiles cleanup patch will follow separately through the vfs tree (netfs) = later: it seems fine since the codebase is isolated by CONFIG_CACHEFILES_ON= DEMAND. [1]
https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fs= cache.md [2]
https://github.com/dragonflyoss/nydus/pull/1824 [3]
https://lo= re.kernel.org/r/
20260619135800.1594811-1-michael.bommarito@gmail.com 2026-0= 9-04 not yet calculated CVE-2026-80899 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-80899 ] Linux--Linux In the Linux kernel, the following vulnera= bility has been resolved: ASoC: SDCA: Make UMP message size check more robu=
st If message offset was larger than the buffer length the size check will = pass incorrectly. Refactor the check such that it is more robust to invalid=
sizes. 2026-09-04 not yet calculated CVE-2026-80900 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-80900 ] Linux--Linux In the Linux kernel, the follo= wing vulnerability has been resolved: ipvs: fix the checksum validations ip= _vs_in_icmp_v6() is missing checksum validation for ICMPv6 packets from cli= ents. In fact, as for TCP/UDP we should validate the checksum for ICMP pack= ets only when we mangle the packets on MASQ or on reply for tunnel. Also, S= ashiko points out that handle_response_icmp() being common for IPv4 and IPv=
6 is missing the pseudo-header calculation while validating ICMPv6 messages=
from real servers which is a problem if checksum is not validated by the h= ardware. Fix the problems by creating ip_vs_checksum_common_check() helper = and use it for TCP/UDP/ICMP both for IPv4 and IPv6. Rely on the nf_checksum=
() for validating the ICMP messages but use it also for TCP and UDP. Use co= rrect IP offset for IP_VS_DBG_RL_PKT for TCP/UDP/SCTP. IPVS packets (TCP/UD= P/SCTP/ICMP) do not need checksum validation on LOCAL_OUT (local clients or=
local real servers) and on FORWARD (traffic from servers on LAN). Do it on=
ly on LOCAL_IN, in case nf_checksum() is not called on PRE_ROUTING. Also, i= p_vs_checksum_complete() can be marked static. 2026-09-04 not yet calculate=
d CVE-2026-80901 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80901 ] Linu= x--Linux In the Linux kernel, the following vulnerability has been resolved=
: dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA When = terminating DMA transfers, active descriptors are not properly reclaimed. O= nly cyclic descriptors were handled, leaving non-cyclic descriptors and the=
ir LLI chains to be permanently leaked. Fix by using vchan_terminate_vdesc(=
) which handles both cyclic and non-cyclic descriptors by adding them to de= sc_terminated queue for proper cleanup. Add pchan->desc !=3D pchan->done ch= eck to prevent double-adding completed descriptors, which would corrupt the=
list. 2026-09-04 not yet calculated CVE-2026-80902 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-80902 ] Linux--Linux In the Linux kernel, the follow= ing vulnerability has been resolved: drm/xe/oa: Fix sync entry leak on OA c= onfig emit failure xe_oa_emit_oa_config() releases the sync entries and the=
syncs array only on its success path. When it fails before the point of no=
return (fence allocation, config buffer allocation or batch submission), i=
t returns without touching stream->syncs. The stream open path handles such=
failures in the caller, but xe_oa_config_locked() propagates the error wit= hout any cleanup, so the syncs array and the fence references held by the p= arsed entries are leaked. The next config ioctl overwrites stream->syncs, m= aking the memory unreachable for good. Clean up the parsed syncs when xe_oa= _emit_oa_config() fails, matching the cleanup done by the stream open error=
path. (cherry picked from commit 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)=
2026-09-04 not yet calculated CVE-2026-80903 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-80903 ] Linux--Linux In the Linux kernel, the following vu= lnerability has been resolved: net/tls: Fail tls_sw_splice_read() after a f= ailed async decrypt When an async decrypt fails, tls_decrypt_done() records=
the error in ctx->async_wait.err and calls tls_err_abort(), which stores i=
t in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.e=
rr once they hold the reader lock and fail the call: a record that did not = authenticate breaks the connection. tls_sw_splice_read() has no such check,=
and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only = inside the loop it skips whenever a record is already parsed, and the first=
reader to reach sock_error() clears it, while async_wait.err persists. A s= plice therefore keeps delivering records on a connection that recvmsg() and=
read_sock() refuse to read. Read async_wait.err in tls_sw_splice_read() as=
the other two readers do. 2026-09-04 not yet calculated CVE-2026-80904 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-80904 ] Linux--Linux In the Linu=
x kernel, the following vulnerability has been resolved: net: tap: fix wron=
g transport_header when sending VLAN-tagged frame In tap_get_user_xdp(), wh=
en processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_set_network_heade= r() is called first to advance network_header past the VLAN tag to the inne=
r protocol header. skb_probe_transport_header() is then called with skb->pr= otocol still set to ETH_P_8021Q, while nhoff (derived from skb_network_offs= et()) already points past the VLAN tag to the inner protocol header. In __s= kb_flow_dissect(), proto is initialized to ETH_P_8021Q and nhoff points pas=
t the VLAN tag. When the dissector hits case ETH_P_8021Q, it reads a struct=
vlan_hdr at the current nhoff via __skb_header_pointer(), but that offset = contains the inner protocol header (e.g. an IP header). The bytes are misin= terpreted as a VLAN header, yielding a garbage encapsulated EtherType that = matches no known protocol. The dissector returns false, so skb_probe_transp= ort_header() never calls skb_set_transport_header(), leaving transport_head=
er at its uninitialized sentinel value (~0U). Move skb_set_network_header()=
to after skb_probe_transport_header(). At the time skb_probe_transport_hea= der() is called, network_header still points to the VLAN header (offset ETH= _HLEN), so nhoff is correct and the flow dissector can parse the VLAN heade=
r, extract the inner EtherType, and advance nhoff to the inner protocol hea= der, allowing transport_header to be set correctly. 2026-09-04 not yet calc= ulated CVE-2026-80905 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80905 ]=
Linux--Linux In the Linux kernel, the following vulnerability has been res= olved: net: packet: fix wrong transport_header when sending VLAN-tagged fra=
me In packet_parse_headers(), when processing a VLAN-tagged frame, skb_set_= network_header() is called to advance network_header past the VLAN tag to t=
he inner protocol header. skb_probe_transport_header() is then called with = skb->protocol still set to the outer VLAN EtherType (e.g. ETH_P_8021Q), whi=
le nhoff (derived from skb_network_offset()) already points past the VLAN t=
ag to the inner protocol header. In __skb_flow_dissect(), proto is initiali= zed to ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector h= its case ETH_P_8021Q, it reads a struct vlan_hdr at nhoff via __skb_header_= pointer(), but that offset contains the inner protocol header (e.g. an IP h= eader). The bytes are misinterpreted as a VLAN header, yielding a garbage e= ncapsulated EtherType that matches no known protocol. The dissector returns=
false, so skb_probe_transport_header() never calls skb_set_transport_heade= r(), leaving transport_header at its uninitialized sentinel value (~0U). Mo=
ve skb_probe_transport_header() to before skb_set_network_header(). At the = time skb_probe_transport_header() is called, network_header still points to=
the VLAN header, so nhoff correctly points to the VLAN header. The flow di= ssector can then parse the VLAN header, extract the inner EtherType, and ad= vance nhoff to the inner protocol header, allowing transport_header to be s=
et correctly. 2026-09-04 not yet calculated CVE-2026-80906 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-80906 ] Linux--Linux In the Linux kernel, the=
following vulnerability has been resolved: drm/amdgpu: Fix UVD dpb min siz=
e calculation for H264 This should use actual number of references from the=
decode message, instead of maximum derived from level. (cherry picked from=
commit 64b525edb7e7bdfcdc77883c5e413804e2396856) 2026-09-04 not yet calcul= ated CVE-2026-80907 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80907 ] L= inux--Linux In the Linux kernel, the following vulnerability has been resol= ved: drm/amdgpu: Reject UVD message with dimensions above 4096 Fixes potent= ial overflow in DPB size calculations. (cherry picked from commit 05e1387d1= 51f71569fbe122d2c89f9db0c21dc10) 2026-09-04 not yet calculated CVE-2026-809=
08 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80908 ] Linux--Linux In th=
e Linux kernel, the following vulnerability has been resolved: drm/amdgpu: = Reject UVD message with invalid number of h265 refs Same change as for h264=
, avoids overflow later when calculating min dpb size. (cherry picked from = commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5) 2026-09-04 not yet calcula= ted CVE-2026-80909 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80909 ] Li= nux--Linux In the Linux kernel, the following vulnerability has been resolv= ed: ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses EAR SPKR PA G= ain" and the four "WSA RX* Mux" controls are enumerated, but their get and = put callbacks access the value through ucontrol->value.integer.value[0] (a = long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This=
same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASo=
C: codecs: rx-macro: fix accessing array out of bounds for enum type") and = commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bo= unds for enum type"), but wsa-macro was missed. On 64-bit kernels with CONF= IG_SND_CTL_DEBUG this trips the elem value sanity check and every read of t= hese controls fails with -EINVAL. 2026-09-04 not yet calculated CVE-2026-80= 910 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80910 ] Linux--Linux In t=
he Linux kernel, the following vulnerability has been resolved: ASoC: SOF: = sof-audio: Fix error path in sof_widget_setup_unlocked() If either tplg_ops= ->dai_config or widget_kcontrol_setup fail during widget setup we would dou= ble decrement the use_count of the widget because the sof_widget_free_unloc= ked() would be called twice, similarly the core_put would be invoked twice =
as well. Since the use_count and core_put() is handled within the widget_fr=
ee function we need to return without falling through the pipe_widget_free = label. The fixes tag is picked to the last change around this part of the c= ode which is adequately old enough for backporting purposes. 2026-09-04 not=
yet calculated CVE-2026-80911 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-80911 ] Linux--Linux In the Linux kernel, the following vulnerability has=
been resolved: selinux: reject an unclaimed class value in security_get_cl= asses() security_get_classes() sizes an array by p_classes.nprim and fills =
it at value - 1, so a class value the policy never defines leaves a NULL. s= el_make_classes() passes every entry to sel_make_dir(), reaching the same d= _alloc_name() dereference as the permission array. The class symbol table i=
s allowed to be sparse (policydb_class_isvalid() exists to absorb that), bu=
t this getter builds its own array straight from the hash table and has no = such predicate. Fail the lookup when a value went unclaimed instead of hand= ing out the NULL. Conforming policies define every class they declare and a=
re unaffected. 2026-09-04 not yet calculated CVE-2026-80912 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-80912 ] Linux--Linux In the Linux kernel, th=
e following vulnerability has been resolved: selinux: require every boolean=
value to be defined p_bools.nprim comes from the policy image independentl=
y of how many booleans follow it, and cond_index_bool() fills bool_val_to_s= truct[] at value - 1, so a count larger than the values present leaves NULL=
entries. Every user of that array then walks it by index and dereferences = each entry: cond_evaluate_expr() on the access-vector path, security_get_bo= ols() and security_get_bool_value() behind selinuxfs, and security_set_bool= s(). A sparse class value is absorbed by policydb_class_isvalid() and its s= iblings; booleans have no such predicate, and no consumer that could use on=
e. Reject a boolean value that no boolean defines, once, where the array is=
built. Conforming policies define every boolean they declare and are unaff= ected. 2026-09-04 not yet calculated CVE-2026-80913 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-80913 ] livewire--livewire Livewire is a full-stack = framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-not= ated query-string parser in js/plugins/history/index.js, including fromQuer= yString() and insertDotNotatedValueIntoData(), accepts the __proto__, const= ructor, and prototype path segments and creates inherited objects. Client-s= ide state handlers then access effects.html, effects.js, effects.xjs, and e= ffects.scripts without Object.prototype.hasOwnProperty.call(), allowing inh= erited attacker-controlled state to be treated as trusted effects. An unaut= henticated attacker can craft a URL that, when opened by a user, executes a= rbitrary JavaScript in the affected application's origin. Exploitation requ= ires user interaction and does not bypass server-side authorization or gran=
t privileges beyond the affected user. This issue is fixed in versions 3.8.=
3 and 4.3.4. 2026-08-31 not yet calculated CVE-2026-81887 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-81887 ] Lookyloo--PlaywrightCapture Playwright= Capture contains a server-side request forgery (SSRF) vulnerability in its = favicon retrieval functionality. When only_global_lookup is enabled, the ap= plication validates the initial favicon URL to prevent requests to localhos=
t, loopback, or other non-public network addresses. However, redirects foll= owed by aiohttp were not subjected to the same validation. An attacker able=
to influence the content of a page processed by PlaywrightCapture could sp= ecify a publicly reachable favicon URL that responds with an HTTP redirect =
to a local or otherwise restricted address, such as 127.0.0.1, localhost, o=
r an internal network service. Because aiohttp automatically followed the r= edirect, the resulting request could bypass the application's local-address=
restrictions and cause the PlaywrightCapture host to issue HTTP requests t=
o resources that should not be externally reachable. Depending on the servi= ces reachable from the PlaywrightCapture host and how retrieved favicon dat=
a is subsequently exposed or processed, this could be used to probe interna=
l HTTP services or potentially obtain information from otherwise inaccessib=
le endpoints. The patch introduces an aiohttp request middleware that appli=
es the existing local-URL validation to every request in the redirect chain=
. Requests resolving to restricted/local destinations are rejected before t= hey are issued. 2026-09-03 not yet calculated CVE-2026-85242 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-85242 ] Lutece--Lutece Core A vulnerability=
in the Lutece Core XSL export management module up to version 7.1.7, which=
allows authenticated administrators to execute code remotely. The XML/XSLT=
processing configuration does not enable secure processing mode (FEATURE_S= ECURE_PROCESSING), allowing Java extension functions to be executed from ma= licious XSL stylesheets. An attacker with administrator privileges can uplo=
ad a manipulated XSL transformation file and trigger its execution during u= ser export operations, resulting in the execution of arbitrary code on the = server. 2026-09-01 not yet calculated CVE-2026-4813 [
https://www.cve.org/C= VERecord?id=3DCVE-2026-4813 ] malach-it--boruta-server Boruta is a standalo=
ne authorization server that aims to implement OAuth 2.0 and Openid Connect=
up to decentralized identity specifications. Prior to version 0.10.0, Boru= taIdentityWeb.UserSettingsController.update/2 atomizes every key of the use= r-supplied request body via String.to_atom/1 before any validation. Because=
String.to_atom interns atoms permanently in the BEAM atom table (default c=
ap 1,048,576 atoms; ERL_MAX_ATOMS), any authenticated end user can send PUT=
/users/settings with a user[<fresh-key>]=3D... body containing fresh keys = per request and exhaust the global VM atom table. Once the table is full, t=
he BEAM aborts with no more index entries in atom_tab and the entire OIDC s= erver (auth, admin, gateway apps in the umbrella) crashes. The route is pro= tected only by require_authenticated_user and a per-IP rate limit of 10 req= uests/second; a logged-in end user can hit it. The keys are atomized uncond= itionally before the downstream Accounts.update_user/6 call, so even failin=
g updates contribute to exhaustion. This issue has been patched in version = 0.10.0. 2026-09-02 not yet calculated CVE-2026-49249 [
https://www.cve.org/= CVERecord?id=3DCVE-2026-49249 ] Manacle Technologies--Multi-tenant ERP Syst=
em This vulnerability exists in the ERP system due to improper authenticati=
on controls and inadequate file type validation at the API endpoint. An una= uthenticated remote attacker could exploit this vulnerability by uploading = arbitrary files to a web accessible directory on the targeted system Succes= sful exploitation of this vulnerability could allow the attacker to execute=
arbitrary code and compromise the targeted system. 2026-09-01 not yet calc= ulated CVE-2026-84147 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84147 ]=
Manacle Technologies--Multi-tenant ERP System This vulnerability exists in=
the ERP system due to improper authentication and authorization controls i=
n the API endpoint. An unauthenticated remote attacker could exploit this v= ulnerability by manipulating parameter which could lead to exposure of sens= itive information belonging to other users on the targeted system. 2026-09-=
01 not yet calculated CVE-2026-84148 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-84148 ] Manacle Technologies--Multi-tenant ERP System This vulnerab= ility exists in the ERP system due to exposure of repository information th= rough a publicly accessible .git directory. An unauthenticated remote attac= ker could exploit this vulnerability by accessing the exposed .git director=
y and retrieving repository metadata and associated files, which could allo=
w reconstruction of the application's source code. 2026-09-01 not yet calcu= lated CVE-2026-84149 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84149 ] = MBS-Solutions --X-Series Gateway An issue in the ugw-restart method of /cgi= -bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a=
remote authenticated user with the low-privileged Standard role to inject = arbitrary code into the dpcheck system utility executed as root. 2026-09-04=
not yet calculated CVE-2026-75161 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-75161 ] MBS-Solutions --X-Series Gateway An information disclosure vu= lnerability in the opcua-configuration method of /cgi-bin/wwwugw.cgi in MBS= -Solutions X-Serie Gateway firmware V6_00_05 allows any remote authenticate=
d user, including users with the low-privileged Standard role, to retrieve = the configured OPC-UA authentication credentials in cleartext via the JSON = API response. 2026-09-04 not yet calculated CVE-2026-75162 [
https://www.cv= e.org/CVERecord?id=3DCVE-2026-75162 ] MBS-Solutions --X-Series Gateway An i= ssue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmware V6_00= _05 allows a remote authenticated user with the low-privileged Standard rol=
e to invoke hidden network diagnostic methods (ugw-ping, ugw-traceroute) th=
at are not exposed in the web UI, allowing attackers to obtain sensitive in= formation. 2026-09-04 not yet calculated CVE-2026-75165 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-75165 ] MBS-Solutions --X-Series Gateway Insecur=
e Permission vulnerability in MBS-Solutions X-Serie Gateway firmware V6_00_=
05 allows the low-privileged service user to execute /usr/bin/tcpdump as ro=
ot without a password. By leveraging the tcpdump -z option, an authenticate=
d attacker can achieve arbitrary command execution. 2026-09-04 not yet calc= ulated CVE-2026-75166 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75166 ]=
MBS-Solutions --X-Series Gateway A broken access control vulnerability in = the ugw-usr-edit method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gat= eway firmware V6_00_05 allows a remote authenticated user with the low-priv= ileged Standard role to change the password of arbitrary accounts. 2026-09-=
04 not yet calculated CVE-2026-75167 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-75167 ] MBS-Solutions --X-Series Gateway An arbitrary file upload v= ulnerability in /cgi-bin/ugwupload.cgi of MBS-Solutions X-Serie Gateway fir= mware V6_00_05 allows a remote authenticated user with Admin role to upload=
files with arbitrary content to hardcoded paths. 2026-09-04 not yet calcul= ated CVE-2026-75169 [
https://www.cve.org/CVERecord?id=3DCVE-2026-75169 ] m= icrosoft--winml-cli Windows ML CLI is a command line tool for building port= able, performant, and high-quality AI models for Windows ML. Prior to 0.4.0=
, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI comma= nds through a localhost HTTP API without authentication and configures the = allow_origins setting as a wildcard in both src/winml/modelkit/serve/cli_ap= i.py and src/winml/modelkit/serve/app.py. A malicious website loaded by a u= ser can send cross-origin requests to /v1/cli/build or /v1/cli/config and s=
et the trust_remote_code parameter to true, which is converted to the --tru= st-remote-code command-line flag without validation. This reaches AutoConfi= g.from_pretrained with trust_remote_code=3DTrue in src/winml/modelkit/loade= r/_autoconfig.py and imports Python code from an attacker-controlled model = repository, resulting in arbitrary code execution as the server user. This = issue is fixed in version 0.4.0. 2026-09-02 not yet calculated CVE-2026-844=
52 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84452 ] MikroTik--RouterOS=
RouterOS WebFig contains an unauthenticated file-read vulnerability in the=
/jsproxy path where a newly allocated session retains a stale uninitialize=
d principal pointer used for file authorization. An unauthenticated attacke=
r can prepare the allocator so that the file-serving path dereferences this=
pointer with sufficient rights, then supply parent-directory components in=
an encrypted URI to escape the WebFig file namespace and disclose root-own=
ed files, including configuration stores containing credentials.This issue = affects only 7.x branch was fixed in versions: 7.23.4 (Long-term)=C2=A0and= =C2=A07.24.2 (Stable) 2026-09-05 not yet calculated CVE-2026-67281 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-67281 ] MikroTik--RouterOS=C2=A0 Rout= erOS accepts a "related" btest connection before the corresponding primary = session has completed authentication. An unauthenticated client can use thi=
s state to start an IPv4 UDP test. With "random-data=3Dfalse", the sender t= ransmits an uninitialized tail from a kernel packet buffer. A separate unch= ecked, inverted packet-size interval causes unsigned integer underflow, ano= malously large fragmented output, and can restart the RouterOS kernel. This=
issue was fixed in versions:=C2=A06.49.21 (Long-term),=C2=A07.23.4 (Long-t= erm)=C2=A0and=C2=A07.24.2 (Stable) 2026-09-05 not yet calculated CVE-2026-6= 7277 [
https://www.cve.org/CVERecord?id=3DCVE-2026-67277 ] MikroTik--Router= OS=C2=A0 RouterOS SSH enters the connection protocol after a client-request=
ed rekey even though user authentication was never attempted, allowing an u= nauthenticated client to open a session channel and send an exec request. O=
n affected builds the server dispatches the command, enabling unauthenticat=
ed creation, overwrite, and reconstruction of files in the RouterOS managed=
file namespace, including support files containing configuration and diagn= ostic data.This issue was fixed in versions:=C2=A06.49.21 (Long-term),=C2= =A07.23.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable) 2026-09-05 not yet calc= ulated CVE-2026-67279 [
https://www.cve.org/CVERecord?id=3DCVE-2026-67279 ]=
MikroTik--RouterOS
=C2=A0 RouterOS contains an argument-handling flaw in the SSH login path in= volving usernames that begin with a prohibited character, allowing for the = trusted RouterOS policy mask=C2=A0to be changed, leading to privilege escal= ation. Exploitation requires an unauthenticated SSH session to reach the Ro= uterOS login helper.This issue was fixed in versions:=C2=A06.49.21 (Long-te= rm),=C2=A07.23.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable) 2026-09-05 not y=
et calculated CVE-2026-86060 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 86060 ] MikroTik--RouterOS=C2=A0
=C2=A0 RouterOS does not compare the complete RSA public key when matching =
an SSH authentication request to an authorized user key, checking the key t= ype and modulus but omitting the exponent. Because signature verification u= ses the client-supplied key, an attacker knowing an authorized RSA modulus = can supply a key with exponent one, forge a valid signature, and open an SS=
H command channel as the target user without the private key.This issue aff= ects only 7.x branch was fixed in versions: 7.23.4 (Long-term)=C2=A0and=C2= =A07.24.2 (Stable) 2026-09-05 not yet calculated CVE-2026-67276 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-67276 ] MikroTik--RouterOS=C2=A0
=C2=A0 MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures durin=
g X.509 validation. Because its trust store includes an e=3D3 root CA, an a= ttacker controlling or redirecting an outbound RouterOS TLS connection can = use the root's public certificate - without its private key - to forge a tr= usted intermediate and issue certificates for arbitrary hostnames, enabling=
TLS server impersonation. This issue affects only 7.x branch was fixed in = versions: 7.23.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable) 2026-09-05 not y=
et calculated CVE-2026-67278 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 67278 ] miniorgange.com--miniOrange Oauth Client (free) extension for Jooml=
a Joomla Extension - miniorgange.com - Unauthenticated arbitrary extension = deinstallation via various miniOrange extensions - a missing authentication=
check allows unauthenticated actors to delete arbitrary installed extensio= ns. Only the free versions of the miniOrange plugins are affected. 2026-08-=
31 not yet calculated CVE-2026-78074 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-78074 ] misp--misp MISP contains an authentication bypass vulnerabi= lity in its LDAP and LinOTP authentication components due to insufficient v= alidation of user-supplied credentials. The custom LdapAuthenticate and Lin= OTPAuthenticate components replace CakePHP's FormAuthenticate implementatio=
n but did not replicate its credential validation checks. As a result, empt=
y or non-string values could reach the underlying authentication mechanisms=
. In the LDAP authentication path, an attacker able to identify a valid dir= ectory user's email address could submit an empty password. The empty crede= ntial could be passed to ldap_bind(), where an LDAP server accepting unauth= enticated binds may return a successful result for a valid distinguished na=
me combined with an empty password. MISP could consequently treat the attac= ker as the corresponding authenticated directory user without verification =
of the user's password. The issue also affected the LinOTP authentication c= omponent. Invalid credential types were not rejected before being processed=
, and when mixed authentication was enabled, an empty password could be che= cked against a locally stored MISP password hash. LDAP-provisioned MISP acc= ounts could additionally be created with an empty local password because ac= count creation skipped normal validation, resulting in a hash corresponding=
to an empty password. This could permit authentication through the local f= allback mechanism when such an account was no longer resolved through LDAP.=
Successful exploitation could allow a remote unauthenticated attacker to i= mpersonate an existing MISP user. If the targeted account has administrativ=
e or other privileged permissions, the attacker could gain corresponding ac= cess to sensitive threat-intelligence data, modify or delete information, a= lter configuration, or perform other privileged operations. The patch resol= ves the vulnerability by requiring authentication identifiers and passwords=
to be valid strings, rejecting empty passwords where they are not explicit=
ly permitted, and assigning a randomly generated local password to LDAP-pro= visioned accounts instead of storing a hash derived from an empty password.=
2026-09-03 not yet calculated CVE-2026-85216 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85216 ] misp--misp MISP contains an improper TLS certifica=
te validation vulnerability in CurlClient. The CurlClient::$verifyPeer prop= erty was not explicitly initialized and therefore defaulted to null. When p= assed to cURL, this value effectively disabled TLS peer verification unless=
the calling code explicitly enabled it. As a result, HTTPS connections mad=
e through affected CurlClient instances could accept certificates that were=
not issued by a trusted certificate authority. An attacker capable of inte= rcepting or manipulating network traffic between a MISP instance and a remo=
te HTTPS service could impersonate the remote endpoint and perform a man-in= -the-middle attack. Successful exploitation could allow an attacker to obse= rve sensitive information transmitted by MISP, including authentication mat= erial or exchanged threat intelligence, and to modify responses returned to=
the MISP instance. The impact depends on the functionality using CurlClien=
t and the data exchanged with the remote service. The patch enables TLS pee=
r verification by default while preserving explicit support for configured = self-signed certificates. It also corrects the self-signed certificate hand= ling in SyncTool so that peer verification is disabled only when no pinned =
CA certificate is configured. 2026-09-03 not yet calculated CVE-2026-85221 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85221 ] misp--misp MISP conta= ins an authorization flaw in the OnDemand correlation engine where correlat= ions were calculated solely from matching attribute values without applying=
the distribution, sharing group, organization, or other access-control res= trictions associated with the correlated attributes and events. As a result=
, an authenticated user could receive correlation results referring to attr= ibutes or events that the user was not authorized to access. The vulnerable=
correlation collection path did not take the requesting user into account.=
The patch changes the correlation collector to accept the current user and=
filters the resulting attribute identifiers through MISP's existing fetchA= ttributesSimple() authorization logic, which evaluates event-, attribute-, = object-, distribution-, and sharing-group-level restrictions against the li=
ve data. The issue also affected paths relying on previously stored correla= tion data. Because the OnDemand engine does not maintain the stored correla= tion table, its denormalized access-control information could be stale. The=
patch therefore validates correlated attribute identifiers against the cur= rent ACLs before returning them and additionally applies normal event visib= ility conditions when retrieving related events. An authenticated low-privi= leged user could exploit this issue by querying or creating attributes that=
correlate with restricted MISP content, potentially learning information a= bout otherwise inaccessible events or attributes. 2026-09-03 not yet calcul= ated CVE-2026-85226 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85226 ] m= isp--misp MISP contains a reflected Cross-Site Scripting (XSS) vulnerabilit=
y in the event attribute filtering query builder. The taggedAttributes and = galaxyAttachedAttributes URL parameters were inserted into the query-builde=
r rules without HTML escaping before being serialized as JSON and embedded = inside a <script> element. Because JsonTool::encode() uses JSON_UNESCAPED_S= LASHES, an attacker-controlled value containing a closing </script> sequenc=
e could terminate the surrounding script element and inject arbitrary HTML =
or JavaScript. For example, a specially crafted viewEventAttributes URL cou=
ld contain malicious content in one of the affected filter parameters. An a= ttacker could exploit the vulnerability by convincing an authenticated MISP=
user to follow a crafted URL. Successful exploitation would execute attack= er-controlled JavaScript in the security context of the MISP instance and w= ith the privileges of the victim's authenticated browser session. This coul=
d allow access to information available to the victim, modification of data=
through authenticated requests, or other actions permitted by the victim's=
MISP permissions. The vulnerability is addressed by applying HTML escaping=
with h() to both scalar and array values before they are inserted into the=
DOM. 2026-09-03 not yet calculated CVE-2026-85227 [
https://www.cve.org/CV= ERecord?id=3DCVE-2026-85227 ] misp--misp A persistent unsafe URL injection = vulnerability exists in the MISP dashboard ButtonWidget configuration. Dash= board widget URLs were validated only when the widget was rendered and were=
not validated when the configuration was saved. As a result, an authentica= ted user able to modify dashboard widget settings could persist arbitrary U=
RL values, including URLs using the javascript: scheme, through either of t=
he dashboard settings persistence paths. A malicious javascript: URL stored=
in a dashboard button could potentially result in client-side script execu= tion in the MISP security context if the value reached a rendering or navig= ation path without the existing runtime validation. Such execution could al= low an attacker to perform actions with the privileges of the affected user=
or access information available to their MISP session. The practical explo= itability of this issue is reduced by the fact that MISP already applied UR=
L validation at render time, which neutralized known malicious values befor=
e they were presented to the user. The vulnerability therefore represents a=
persistence-layer validation gap and a defense-in-depth weakness rather th=
an evidence of a direct bypass of the existing rendering protection. The pa= tch introduces a canonical url schema type and validates dashboard widget c= onfiguration before it is persisted through either settings save mechanism.=
ButtonWidget URLs must now be strings resolving to an absolute path on the=
current MISP instance or a full URL with the same origin. Values using jav= ascript:, external origins, malformed URL forms, and non-string values are = rejected at save time. 2026-09-03 not yet calculated CVE-2026-85230 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-85230 ] misp--misp A cross-site requ= est forgery (CSRF) vulnerability existed in the cullEmptyEvents action of M= ISP. The endpoint performed a state-changing and irreversible operation whi=
le accepting HTTP GET requests. Because bodyless GET requests are not subje=
ct to CakePHP's CSRF validation, an attacker could cause an authenticated M= ISP user with sufficient privileges to invoke the endpoint simply by causin=
g their browser to load a crafted URL, for example through an embedded imag=
e or other automatically requested resource. Successful exploitation trigge=
rs the deletion of published empty events. The deletion is particularly sig= nificant because the operation uses skipBlocklist, meaning the removed even=
ts do not leave blocklist entries that could prevent or track their subsequ= ent synchronization. This can result in unintended and potentially irrevers= ible deletion of MISP event records without explicit user interaction. The = vulnerability was addressed by restricting cullEmptyEvents to HTTP POST req= uests, ensuring that CakePHP's normal CSRF protections are applied to the o= peration. 2026-09-03 not yet calculated CVE-2026-85236 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-85236 ] misp--misp A vulnerability in MISP's emai= l-based one-time password (OTP) authentication flow allowed an attacker to = perform an unrestricted number of OTP verification attempts. The email_otp(=
) endpoint did not apply brute-force protection when validating submitted O=
TP values. An attacker who had reached the OTP verification stage, for exam= ple after successfully providing a user's primary authentication credential=
s, could repeatedly submit candidate OTP values while the same OTP remained=
valid. This significantly increased the feasibility of guessing the OTP an=
d bypassing the additional authentication factor, potentially resulting in = unauthorized access to the affected user's account. The issue was exacerbat=
ed by the fact that the OTP is associated with the user rather than with an=
individual pending login session, allowing multiple concurrent sessions to=
attempt guesses against the same valid OTP. The patch integrates the exist= ing MISP brute-force protection mechanism into the email OTP flow. Failed O=
TP attempts are now counted against the user, further attempts are rejected=
once the configured threshold is reached, and the active OTP is invalidate=
d when the attempt budget is exhausted. Blocklisted users are also prevente=
d from requesting the generation of a fresh OTP. In addition, OTP compariso=
n now uses hash_equals() and validates that the submitted value is a string=
. 2026-09-03 not yet calculated CVE-2026-85237 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-85237 ] misp--misp MISP contains a session fixation vulne= rability in the CustomAuth authentication (a custom configuration) flow. Wh=
en a user was successfully authenticated through CustomAuth, MISP stored th=
e authenticated user identity in the existing session without first rotatin=
g the session identifier. As a result, if an attacker can cause a victim to=
use a session identifier known to the attacker before authentication, that=
same session identifier remains valid after the victim successfully authen= ticates. The attacker could subsequently reuse the fixed session identifier=
to access the victim's authenticated MISP session, potentially gaining the=
privileges associated with the victim's account. The issue occurs because = __customAuthentication() wrote the authenticated user into the existing Cak= ePHP session while the call to Session->renew() had previously been disable=
d. The patch restores session identifier rotation when a new authentication=
occurs or when the authenticated user changes, while avoiding unnecessary = session renewal on every request. 2026-09-03 not yet calculated CVE-2026-85= 238 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85238 ] misp--misp A vuln= erability in MISP's event template handling allowed an authenticated user w= ith permission to create or modify event templates to bypass validation of = the template definition field. The EventTemplate::beforeValidate() method o= nly performed semantic validation when the supplied definition was already = represented as an array. If a caller instead supplied a pre-encoded string,=
including malformed JSON or JSON representing an unexpected data type, the=
value bypassed validateDefinition() and only needed to satisfy the generic=
notBlank validation rule. As a result, an invalid event template definitio=
n could be stored persistently in the database. When event templates were s= ubsequently retrieved, EventTemplate::afterFind() attempted to decode the s= tored definition using JsonTool::decode() without handling decoding failure=
s. A definition containing invalid JSON could therefore trigger an exceptio=
n during retrieval. Because the event template index is available to all au= thenticated users, a single malicious or malformed template could make the = event template listing and other functionality relying on EventTemplate que= ries return HTTP 500 errors until the offending database row was manually r= epaired. Valid JSON representing an unexpected type, rather than the expect=
ed JSON object, could similarly result in invalid data reaching downstream = consumers. The vulnerability can therefore be exploited by a user capable o=
f saving event templates to persist malformed template data and cause a per= sistent denial of service against event-template functionality for other us= ers. The patch enforces that event template definitions must be supplied as=
structured objects before saving and always applies semantic validation. O=
n retrieval, malformed JSON and definitions that do not decode to the expec= ted structure are caught, logged, and replaced with an empty definition, pr= eventing a malformed database entry from breaking all event template querie=
s. =C2=A0Poisoning doesn't seem reachable according to the lead developer. = 2026-09-03 not yet calculated CVE-2026-85239 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-85239 ] misp--misp An authorization flaw in MISP allowed an=
authenticated user to submit a sharing_group_id without verifying that the=
user was authorized to use the referenced Sharing Group. In several attrib= ute and Galaxy Cluster creation and editing workflows, validation of the su= bmitted Sharing Group was performed only when the request explicitly set th=
e distribution field to 4 ("Sharing Group"). An attacker could therefore cr= aft a request containing a sharing_group_id while omitting the distribution=
parameter, or otherwise avoiding the distribution =3D=3D 4 condition, caus= ing the Sharing Group authorization check to be skipped. This could allow a=
user with permission to create or modify the affected MISP objects to asso= ciate data with a Sharing Group that they are not authorized to use. Depend= ing on the affected object's existing distribution settings and subsequent = processing, this could bypass intended information-sharing boundaries and r= esult in unauthorized placement or distribution of data to members of anoth=
er Sharing Group. The issue affected attribute attachment and editing opera= tions as well as Galaxy Cluster creation and editing. The fix ensures that = authorization is performed whenever a non-empty sharing_group_id is submitt= ed, independently of the distribution parameter. It also centralizes the au= thorization decision in SharingGroup::canUse() and explicitly rejects empty=
Sharing Group identifiers rather than allowing them to be interpreted as a=
n unrestricted query. 2026-09-04 not yet calculated CVE-2026-85533 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-85533 ] misp--misp An incorrect autho= rization vulnerability in MISP allowed authenticated users to delete attrib= utes from events despite lacking the required perm_modify or perm_modify_or=
g permissions. The affected attribute deletion paths relied on organization=
membership checks performed by MispAttribute::deleteAttribute() but did no=
t consistently enforce MISP's event modification authorization rules. Conse= quently, a user belonging to the organization associated with an event coul=
d potentially delete individual attributes or perform bulk attribute deleti=
on even when their assigned role was not authorized to modify the event. Th=
is created an inconsistency between attribute editing and deletion: editing=
an attribute correctly used MISP's ACL::canModifyEvent() authorization log= ic, whereas the affected deletion operations could bypass these permission = checks. An authenticated attacker with access to an affected MISP instance = and membership in the organization owning an event could exploit this flaw =
to remove attributes from that event, potentially causing unauthorized modi= fication or loss of threat intelligence data. The patch introduces a common=
authorization check for all affected deletion paths. Before deletion, MISP=
now resolves the associated events and verifies that the current user is a= uthorized to modify each event using the same authorization mechanism used =
by normal event and attribute modification operations. 2026-09-04 not yet c= alculated CVE-2026-85538 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8553=
8 ] misp--misp MISP contains a cross-site request forgery (CSRF) vulnerabil= ity in the sharing group quick-edit functionality. The addOrg, removeOrg, a= ddServer, and removeServer actions share the __initialiseSGQuickEdit() help= er, where the HTTP method validation intended to restrict these operations =
to POST requests was commented out. As a result, these state-changing actio=
ns could be invoked using GET requests. An attacker could craft a URL targe= ting one of the affected actions and cause an authenticated MISP user with = sufficient privileges to request it, for example through a malicious link o=
r embedded web resource. Successful exploitation could modify the membershi=
p of a MISP sharing group without the victim intentionally performing the o= peration. Depending on the action performed, an attacker could add or remov=
e organisations or servers from a sharing group, potentially granting unint= ended access to information distributed through that sharing group or disru= pting legitimate information sharing. The patch restores HTTP method enforc= ement centrally in __initialiseSGQuickEdit() by calling allowMethod(['post'= ]), ensuring that all four affected quick-edit operations require POST requ= ests and are therefore subject to the application's normal protections for = state-changing requests. 2026-09-04 not yet calculated CVE-2026-85546 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-85546 ] misp--misp A cross-site re= quest forgery (CSRF) vulnerability exists in MISP due to form-security and = CSRF protections being disabled based on whether an incoming request was id= entified as a REST request. MISP's REST detection can be influenced by requ= est properties such as the URL suffix or the HTTP Accept header. Because Ac= cept: application/json can be supplied by a cross-origin page without requi= ring a CORS preflight, an attacker could cause a request originating from a= nother website to be treated as REST traffic. MISP would consequently disab=
le its normal form-security and CSRF validation even though the request was=
authenticated using the victim's existing browser session. An unauthentica= ted remote attacker could exploit this behavior by convincing an authentica= ted MISP user to visit or interact with a malicious web page. The attacker'=
s page could then issue crafted requests to susceptible state-changing MISP=
endpoints using the victim's privileges. Depending on the permissions of t=
he victim and the targeted endpoint, this could allow unauthorized modifica= tion, creation, publication, or removal of data and other state changes. Th=
e vulnerability originates from granting the form-security exemption based =
on _isRest() rather than on the authentication mechanism used by the reques=
t. The patch changes this behavior so that CSRF and form-security exemption=
s are granted only when the request actually carries a MISP API key. Sessio= n-authenticated REST-style requests remain subject to CSRF protection. The = fix also introduces support for transmitting CSRF tokens through the X-CSRF= -Token header for legitimate same-origin AJAX requests. Such a header canno=
t normally be attached by a cross-origin page without triggering a CORS pre= flight, preventing it from being used to reproduce the original attack. 202= 6-09-04 not yet calculated CVE-2026-85547 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85547 ] MISP--UiBeta
=C2=A0 MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collecti= ons/view.ctp) performed a secondary query of member events by UUID without = applying the caller's access control list (ACL). The CollectionsController:= :view() action correctly resolved collection element UUIDs through Event::f= etchSimpleEvents($user, ...), which enforces per-user event ACL. However, t=
he view template independently re-queried the same UUIDs using only an Even= t.uuid IN (...) condition, omitting the createEventConditions() authorizati=
on filter. Because collection element UUIDs are stored without server-side = authorization against the referenced event (CollectionElementsController::a= dd() accepts whatever UUID the collection owner posts), an authenticated us=
er with view access to a collection could retrieve full details of events t= hey are not permitted to read. The exposed data included event identifiers,=
info, dates, timestamps, creator organization, all event tags, and galaxy = clusters (the latter attached via a cluster-scoped rather than event-scoped=
ACL check). This constitutes an authorization bypass at the presentation l= ayer, allowing horizontal privilege escalation across event boundaries with=
in the MISP instance. 2026-09-06 not yet calculated CVE-2026-86283 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-86283 ] MojoX--MojoX
=C2=A0 MojoX::Authentication versions before 0.006 for Perl allow SAML auth= entication bypass because parse_assertion builds Net::SAML2::Binding::POST = without a trust anchor. parse_assertion in MojoX::Authentication::Model::SA= ML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or ancho=
rs argument, then passes the returned XML to Net::SAML2::Protocol::Assertio= n->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 b= efore 0.86 that certificate guards only encrypted assertions, so the signat= ure on an unencrypted assertion is checked against the certificate the resp= onse itself carries. An attacker starts a SAML login, then posts a response=
signed with a certificate of their own. The audience, InResponseTo and tim= estamp checks that follow are all satisfiable by the attacker, so the respo= nse authenticates any NameID it carries. 2026-09-06 not yet calculated CVE-= 2026-86304 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86304 ] N-central = --N-central
=C2=A0 A vulnerability in the N-central internal API access control filter = allows unauthorised access to internal APIs. This is fixed in N-central 202= 6.3 HF3 and 2026.4 2026-09-05 not yet calculated CVE-2026-86206 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2026-86206 ] N-central --N-central
=C2=A0 An authentication bypass in N-central < 2026.3 HF 3 leads to authent= ication bypass in internal only APIs 2026-09-05 not yet calculated CVE-2026= -86207 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86207 ] N-central --N-= central
=C2=A0 N-central is vulnerable to a pre-auth remote code execution This iss=
ue affects N-central: before 2026.3.1.14. 2026-09-06 not yet calculated CVE= -2026-86218 [
https://www.cve.org/CVERecord?id=3DCVE-2026-86218 ] n8n-io--n=
8n n8n versions before 2.36.2 contain an expression sandbox bypass vulnerab= ility where free identifiers in spread, computed-key, switch-case, or class= -extension positions resolve against process globals. Authenticated users w= ith workflow-edit permission can mutate host objects through expression eva= luation, with changes persisting process-wide until restart. 2026-09-03 not=
yet calculated CVE-2026-85165 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-85165 ] n8n-io--n8n n8n before 2.35.4 and 2.36.x before 2.36.2 does not v= alidate credential references in the inline workflow JSON of nodes that exe= cute an inline sub-workflow (e.g., the Workflow Tool node). A shared-workfl=
ow editor, or any user creating/updating a workflow via the REST API, Publi=
c API, or MCP, can persist a node referencing a credential they do not own.=
When the workflow is later executed under an identity that holds the crede= ntial, the inline sub-workflow resolves the secret and can send it to an at= tacker-controlled endpoint, resulting in credential exfiltration. 2026-09-0=
3 not yet calculated CVE-2026-85166 [
https://www.cve.org/CVERecord?id=3DCV= E-2026-85166 ] n8n-io--n8n n8n before 2.35.4 and 2.36.x before 2.36.2 conta=
in a query injection vulnerability in the Elasticsearch Document Get All an=
d Google Cloud Firestore Document Query operations, which build their JSON = query by interpolating expression values directly into the query string bef= ore parsing. A value containing quote and brace characters can close the in= tended field and introduce new query operators, turning an intended single-= document lookup into a full-collection read. 2026-09-03 not yet calculated = CVE-2026-85167 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85167 ] n8n-io= --n8n n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote cod=
e execution vulnerability in the Git node. The node reset a fixed list of c= ommand-bearing configuration keys before each operation, but that list did = not cover the content-filter and merge-driver key families. A repository wi=
th local configuration setting one of those keys together with a matching a= ttribute pattern causes git to execute the configured command during an ord= inary Add, Commit, Checkout, or Pull operation. The command runs as the n8n=
process user. 2026-09-03 not yet calculated CVE-2026-85168 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-85168 ] n8n-io--n8n n8n versions before 1.12= 3.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromA=
I handler. $fromAI resolved a caller-supplied placeholder name without requ= iring it to be an own property and admitted reserved keys; against a primit= ive input value it returned a live host-prototype reference. An attacker wi=
th workflow-build privilege can walk the prototype chain to the Function co= nstructor and compile/execute arbitrary code in the main n8n process, leadi=
ng to remote code execution. 2026-09-03 not yet calculated CVE-2026-85169 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-85169 ] n8n-io--n8n n8n versio=
ns before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v=
1) and Brevo nodes to the mail composer without verifying it is a string. A=
n authenticated user able to run a workflow can supply an expression that r= esolves to an object carrying a path or href property, causing the composer=
to read a local file accessible to the n8n process or fetch an internal UR=
L (SSRF) and attach the result to the outgoing message. 2026-09-03 not yet = calculated CVE-2026-85170 [
https://www.cve.org/CVERecord?id=3DCVE-2026-851=
70 ] n8n-io--n8n n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credent= ial exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. Th= ese nodes send their decrypted credentials to the authentication endpoint v=
ia the raw legacy HTTP helper outside any error handling, causing the plain= text secret to be persisted in execution error data. Any authenticated user=
can read the plaintext secret from their own execution through the REST AP=
I, bypassing the blank-value redaction enforced by the credentials API. 202= 6-09-03 not yet calculated CVE-2026-85171 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-85171 ] n8n-io--n8n n8n versions before 2.34.1 contain a serve= r-side request forgery vulnerability in the legacy request helper function = exposed to Code and Function nodes. The validation logic checks the uri pro= perty for SSRF safety while the underlying HTTP client uses the url propert=
y when both are present, allowing attackers to bypass validation by supplyi=
ng a safe uri alongside a malicious url to access internal addresses. 2026-= 09-03 not yet calculated CVE-2026-85172 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-85172 ] n8n-io--n8n n8n versions before 2.36.2 contain a missin=
g per-project authorization vulnerability in the Insights API routes that a= llows authenticated users with insights scopes to access workflow names and=
execution statistics across projects. Attackers can supply arbitrary proje= ctId parameters to retrieve sensitive project and workflow information from=
projects they have no membership in. 2026-09-03 not yet calculated CVE-202= 6-85173 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85173 ] Netgate--Pfse= nse Plus/CE Cross-Site Scripting (XSS) vulnerability in the RSS Widget of N= etgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1=
) allows remote authenticated attackers to inject arbitrary JavaScript via = malicious content in an RSS feed title. The injected script executes in the=
browser of any authenticated user who views the dashboard, due to insuffic= ient sanitization of feed title data before rendering in the widget. 2026-0= 9-04 not yet calculated CVE-2026-38961 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-38961 ] Netgate--pfSense Plus/CE Cross Site Scripting vulnerabi= lity in Netgate pfSense Plus software versions <=3D 26.03 pfSense CE softwa=
re versions <=3D 2.8.1 allows a remote attacker to execute arbitrary code v=
ia the captive_portal_status.widget.php file 2026-09-04 not yet calculated = CVE-2026-78849 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78849 ] nodejs= --node A flaw in Node.js HTTP client can cause a request desynchronization = for Node.js-based forwarding proxies that rebuild outbound headers from the=
visible `IncomingMessage` headers while piping the original body to a reus=
ed backend connection. Node.js can omit headers beyond `maxHeadersCount` / = `maxHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDist= inct`, while still using those omitted headers internally for HTTP message = framing. In particular, `Content-Length` can be hidden from userland while = the request body is still delivered. This vulnerability affects all support=
ed release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. 2026-= 09-01 not yet calculated CVE-2026-48932 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-48932 ] nuclio--nuclio Nuclio is a "Serverless" framework for R= eal-Time Events and Data Processing. From version 1.6.19 to before version = 1.17.2, Nuclio's Dashboard build pipeline does not sanitize the spec.build.= tempDir field before using it to construct a shell command. When the Kaniko=
container builder is enabled, a user with function-create permission can i= nject shell metacharacters into this field and achieve arbitrary command ex= ecution inside the Dashboard container, which runs with a Kubernetes servic=
e account holding wildcard access to Secrets, Pods, Jobs, and Deployments i=
n its namespace. This issue has been patched in version 1.17.2. 2026-09-02 = not yet calculated CVE-2026-79754 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-79754 ] nuclio--nuclio Nuclio is a "Serverless" framework for Real-Tim=
e Events and Data Processing. Prior to version 1.17.4, the fix for unauthen= ticated OS command injection in the nuclio dashboard on the local/Docker pl= atform is incomplete. The fix added validateFunctionName for function names=
and common.Quote() for the named-resource shell command path, but the list= -all resource path (triggered when no specific resource name is provided) s= till interpolates the resourceNamespace parameter unquoted into a /bin/sh -=
c command string. An unauthenticated attacker can inject shell metacharacte=
rs via the X-Nuclio-Function-Namespace, X-Nuclio-Project-Namespace, or X-Nu= clio-Function-Event-Namespace HTTP headers to achieve arbitrary command exe= cution inside the dashboard container. This issue has been patched in versi=
on 1.17.4. 2026-09-02 not yet calculated CVE-2026-79756 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-79756 ] oasdiff--oasdiff oasdiff is a command-li=
ne and Go package that compares and detects breaking changes in OpenAPI spe= cs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --a= llow-external-refs=3Dfalse (library: openapi3.Loader.IsExternalRefsAllowed = =3D false) when loading a spec from a git revision (the rev:path form, e.g.=
main:openapi.yaml). External $refs were resolved on that load path even wh=
en external refs were explicitly disabled, so the mitigation silently did n=
ot apply there. This issue has been patched in version 1.18.1. 2026-08-31 n=
ot yet calculated CVE-2026-53508 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-53508 ] oasdiff--oasdiff-action oasdiff-action is a GitHub Action that = detects breaking changes in OpenAPI specs and post a review on every pull r= equest. Before version 0.0.51, the oasdiff actions resolved external $refs =
in the OpenAPI spec by default (allow-external-refs: true). When an action = runs on a pull request whose spec is attacker-controlled - most importantly=
fork pull requests on public repositories - a $ref in that spec is fetched= /read on the runner with no interaction required, enabling SSRF and disclos= ure of structured files on the runner. This issue has been patched in versi=
on 0.0.51. 2026-08-31 not yet calculated CVE-2026-53507 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-53507 ] oasys sysoa --oasys sysoa
=C2=A0 SQL Injection vulnerability in oasys sysoa version 1.0 allows a remo=
te attacker to execute arbitrary code via the outtype parameter in the /out= addresspaging path 2026-09-04 not yet calculated CVE-2025-67066 [
https://w= ww.cve.org/CVERecord?id=3DCVE-2025-67066 ] OCS Inventory NG--Ocsreports Unr= estricted file upload vulnerability in the CSV file upload functionality of=
the Ocsreports admin_info endpoint. The application validates files solely=
based on the name provided by the client, without properly checking their = content or securely restricting the permitted file types. This allows a use=
r with administrator privileges to upload PHP files to a directory accessib=
le via the web interface. If the file is subsequently processed by the serv= er, an attacker could execute arbitrary code with the privileges of the acc= ount used by the web service. 2026-09-03 not yet calculated CVE-2026-76174 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-76174 ] OCS Inventory NG--Ocs= reports SQL injection vulnerability in the del_check parameter of the /ocsr= eports/?function=3Dsave_query_list endpoint. Input provided by an authentic= ated user with operator privileges is incorporated into an SQL query withou=
t proper parameterisation or validation, allowing the query to be manipulat=
ed and information to be extracted from the database using SQL injection te= chniques. 2026-09-03 not yet calculated CVE-2026-76175 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-76175 ] OCS Inventory NG--Ocsreports SQL injectio=
n vulnerability in the endpoint /ocsreports/index.php?function=3Dadmin_doub=
le due to improper processing of the values in the ID field included in the=
selected_grp_dupli[] parameter. An authenticated user with operator privil= eges can manipulate these values to alter the SQL queries executed by the a= pplication and retrieve information stored in the database. 2026-09-03 not = yet calculated CVE-2026-76176 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -76176 ] OCS Inventory NG--Ocsreports Server-Side Request Forgery (SSRF) vu= lnerability in the /ocsreports/?function=3Dtele_activate endpoint due to in= sufficient validation of the HTTPS_SERV and FILE_SERV parameters. An authen= ticated user with operator privileges can provide arbitrary values for thes=
e parameters, causing the OCS Inventory server to make HTTP/HTTPS requests =
to external systems or internal resources, which could allow access to inte= rnal network services or metadata resources of cloud services. 2026-09-03 n=
ot yet calculated CVE-2026-76177 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-76177 ] OCS Inventory NG--Ocsreports A stored Cross-Site Scripting (XSS=
) vulnerability in the notification template functionality of the endpoint = /ocsreports/?function=3Dnotification. A user with administrator privileges = can input malicious HTML content which is subsequently stored and displayed=
without proper sanitisation when other administrators access the template = customisation view, allowing JavaScript code to be executed within the appl= ication's security context and potentially compromising the sessions of oth=
er users with administrative privileges. 2026-09-03 not yet calculated CVE-= 2026-76178 [
https://www.cve.org/CVERecord?id=3DCVE-2026-76178 ] omgovich--= colord Colord is a tiny yet powerful tool for high-performance color manipu= lations and conversions. Prior to 2.9.4, synchronous CSS color string match= ers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colo= rModels/hwbString.ts, src/colorModels/lchString.ts, and src/colorModels/cmy= kString.ts use the ambiguous numeric regular expression ([+-]?\d*.?\d+), al= lowing the same digits to be divided between overlapping quantifiers in qua= dratically many ways when malformed input is rejected. An attacker who can = supply an unbounded color string to colord(), getFormat(), isEqual(), mix()=
, or contrast(), including through a request body, JSON field, or uploaded = stylesheet, can block the processing thread with a multi-kilobyte payload. = The affected matchers are parseRgbaString, parseHslaString, parseHwbaString=
, parseLchaString, and parseCmykaString. This issue is fixed in version 2.9= .4. 2026-09-03 not yet calculated CVE-2026-85062 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-85062 ] Open5GS --Open5GS v2.7.7
=C2=A0 Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote atta= cker to cause a denial of service via the ogs_sbi_time_parse() function 202= 6-09-04 not yet calculated CVE-2026-75438 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-75438 ] OpenNebula Systems--OpenNebula A vulnerability relatin=
g to incorrect access control in OpenNebula by OpenNebula Systems, affectin=
g all versions prior to 7.4. This vulnerability could allow an authenticate=
d user with basic permissions to execute commands on virtual machines belon= ging to other users via the `one.vm.exec` function, without proper verifica= tion of access permissions. To exploit the vulnerability, it is only necess= ary to know the virtual machine's identifier and for qemu-agent to be enabl=
ed on that machine. Exploitation could allow commands to be executed and co= mpromise the confidentiality, integrity and availability of the affected vi= rtual machines. 2026-09-01 not yet calculated CVE-2026-84165 [
https://www.= cve.org/CVERecord?id=3DCVE-2026-84165 ] OptimiDoc--OptimiDoc Server OptimiD=
oc Server (On-Premise) stores credentials for external services in cleartex=
t. An authenticated administrator can view previously configured service pa= sswords, including SMTP, FTP (for scan delivery), Active Directory (for use=
r list import), and SharePoint credentials, in cleartext via the web admini= stration panel page source, allowing exposure of sensitive third-party auth= entication data. This issue was fixed in version=C2=A026.08 2026-09-03 not = yet calculated CVE-2026-15933 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -15933 ] Parrot-- AR.Drone
=C2=A0 Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service=
. The Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication atta= ck, allowing remote and unauthenticated attackers to disconnect drone from = controller during mid-flight. 2026-09-04 not yet calculated CVE-2021-44319 =
[
https://www.cve.org/CVERecord?id=3DCVE-2021-44319 ] pjsip--pjproject PJSI=
P is a free and open source multimedia communication library written in C. = Prior to commit 673b978, a remote out-of-bounds read and write can occur in=
the SDP negotiator when the remote payload-type map maintenance feature is=
enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses = payload-type numbers taken from a remote SDP offer or answer to index fixed= -size internal tables without sufficient bounds validation, so a crafted re= mote SDP can cause memory access outside those tables. The practical impact=
is memory corruption and denial of service; code execution is not demonstr= ated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP=
is enabled. The default is disabled, so default builds are not affected; t=
he feature is an interoperability option that integrating products may enab= le. This issue has been patched via commit 673b978. 2026-09-04 not yet calc= ulated CVE-2026-57159 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57159 ]=
pjsip--pjproject PJSIP is a free and open source multimedia communication = library written in C. Prior to commit d6a0e7f, a buffer overflow can occur =
in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the functi=
on that serializes generic array headers (such as Allow, Require, Supported=
, and Unsupported). Under certain output-buffer boundary conditions the fun= ction can write one byte past the end of the buffer. This is reachable main=
ly in applications that parse and re-serialize incoming SIP requests - for = example a proxy, SBC, or B2BUA - where a remote peer can influence the seri= alized message. The out-of-bounds write is a single fixed byte; code execut= ion and information disclosure are not demonstrated, and in typical pool-ba= sed allocations the byte falls within allocation slack. This issue has been=
patched via commit d6a0e7f. 2026-09-04 not yet calculated CVE-2026-57160 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-57160 ] pjsip--pjproject PJSIP=
is a free and open source multimedia communication library written in C. P= rior to commit acc03b5, a stack buffer overflow exists in PJSUA when proces= sing Service-Route headers in a registration response (update_service_route=
() in pjsua_acc.c). This affects applications that register using the PJSUA= /PJSUA2 account API (the default registration path). The Service-Route URIs=
from a 2xx response to REGISTER are stored into a fixed-size array without=
bounding the number of headers; a registrar that returns an excessive numb=
er of Service-Route headers can write past the end of the array on the stac=
k. The values written are internal pointers rather than arbitrary data, so = the most likely impact is unexpected application termination (denial of ser= vice), though memory corruption cannot be excluded. The malicious response = may come from a compromised or malicious registrar, or - over unprotected t= ransports - a spoofed response. This issue has been patched via commit acc0= 3b5. 2026-09-04 not yet calculated CVE-2026-57161 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-57161 ] pjsip--pjproject PJSIP is a free and open sour=
ce multimedia communication library written in C. Prior to commit a1b707c, =
a stack buffer overflow exists in the SRTP/SDES media transport when proces= sing a=3Dcrypto attributes during SDP offer/answer (sdes_encode_sdp() in tr= ansport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp=
optional or mandatory, using SDES keying). During media negotiation, the c= rypto attributes from the remote SDP are collected into a fixed-size array = without bounding their number; a remote peer that includes an excessive num= ber of a=3Dcrypto attributes in a single media description can write past t=
he end of that array on the stack. This is reachable from an incoming SIP I= NVITE during offer/answer, before application-level authentication. Impact = may range from unexpected application termination to control flow hijack/me= mory corruption. Applications that do not enable SRTP are not affected. Thi=
s issue has been patched via commit a1b707c. 2026-09-04 not yet calculated = CVE-2026-57162 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57162 ] pjsip-= -pjproject PJSIP is a free and open source multimedia communication library=
written in C. Prior to commit c4a151a, a stack buffer overflow exists in t=
he GnuTLS TLS backend when parsing the Subject Alternative Name extension o=
f a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS = builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Netw= ork.framework builds are not affected. While extracting certificate informa= tion after a TLS handshake, an incorrect buffer-size value can cause an ove= rsized SubjectAltName entry to be written past the end of a fixed-size stac=
k buffer. A network-positioned attacker presenting a crafted certificate - =
a malicious server to a connecting client, or a malicious client to a serve=
r that requests certificates - can trigger this during the TLS handshake, b= efore any SIP-level authentication. Impact may range from unexpected applic= ation termination to control flow hijack/memory corruption. This issue has = been patched via commit c4a151a. 2026-09-04 not yet calculated CVE-2026-571=
63 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57163 ] pjsip--pjproject P= JSIP is a free and open source multimedia communication library written in =
C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL=
HTTP client (http_client.c) when buffering an HTTP response body. This aff= ects applications that use the PJLIB-UTIL HTTP client to receive a whole re= sponse body at once (a completion callback with no incremental on_data_read=
callback). When growing the response buffer, an incorrect size calculation=
based on the server-supplied Content-Length can leave the buffer too small=
, causing response data to be written past the end of the allocation. A mal= icious or man-in-the-middle HTTP server can trigger this with a crafted res= ponse; impact may range from unexpected application termination to memory c= orruption. Applications that consume the response incrementally (via on_dat= a_read), or that only connect to trusted servers, are not affected. This is= sue has been patched via commit 8d5956a. 2026-09-04 not yet calculated CVE-= 2026-57164 [
https://www.cve.org/CVERecord?id=3DCVE-2026-57164 ] pjsip--pjp= roject PJSIP is a free and open source multimedia communication library wri= tten in C. Prior to commit 628b716, a stack buffer overflow exists in the P= JLIB-UTIL telnet CLI front-end when redrawing the command line during histo=
ry recall (handle_up_down() in cli_telnet.c). This affects only application=
s that enable the telnet CLI front-end (same gating as the related CLI issu= e). The line-redraw sequence for a recalled history entry can accumulate mo=
re data than a fixed-size stack buffer holds, which may lead to application=
termination. Exploitation requires access to the unauthenticated telnet CL=
I, which already permits arbitrary CLI commands, so the additional impact i=
s limited. Applications that do not enable the telnet CLI front-end are not=
affected. This issue has been patched via commit 628b716. 2026-09-04 not y=
et calculated CVE-2026-57165 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 57165 ] pjsip--pjproject PJSIP is a free and open source multimedia communi= cation library written in C. Prior to commit 4472a31, a stack buffer overfl=
ow exists in the PJLIB-UTIL telnet CLI front-end when rendering feedback fo=
r an entered command line. Several command-line handling paths write an att= acker-influenced amount of data into fixed-size buffers without sufficient = bounds checking, so a long command line can overflow them. This affects onl=
y applications that enable the telnet CLI front-end (e.g. pj_cli_telnet_cre= ate() / --cli-telnet-port). The telnet CLI is an interactive administration=
interface with no authentication, so any client able to reach it can alrea=
dy issue arbitrary CLI commands. A malformed or overly long command line ca=
n overflow a fixed-size stack buffer while rendering command-line feedback,=
which may lead to application termination. Because reaching this code alre= ady requires access to the unauthenticated CLI, the impact beyond that exis= ting access is limited. Applications that do not enable the telnet CLI fron= t-end are not affected. This issue has been patched via commit 4472a31. 202= 6-09-04 not yet calculated CVE-2026-57166 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-57166 ] Power Job--PowerJob PowerJob versions 4.x through 5.1.=
2 contain an unauthenticated remote code execution vulnerability in the /fr= iend/process endpoint of the Server-Worker transport layer 2026-09-04 not y=
et calculated CVE-2026-75429 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 75429 ] pretix--venueless The default docker image shipped for Venueless di=
d not properly ensure that uploaded SVG files could not be delivered with e= xecutable JavaScript content. A valid Content Security Policy is now set. 2= 026-08-31 not yet calculated CVE-2026-82838 [
https://www.cve.org/CVERecord= ?id=3DCVE-2026-82838 ] py-pdf--pypdf pypdf is a free and open-source pure-p= ython PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes=
long runtimes when the pypdf/_utils.py function read_until_whitespace read=
s a stream containing a long run of bytes without whitespace. The function = repeatedly performs immutable bytes concatenation in a one-byte loop, causi=
ng quadratic processing cost for the long non-whitespace input. This issue =
is fixed in version 6.15.0. 2026-08-31 not yet calculated CVE-2026-82398 [ =
https://www.cve.org/CVERecord?id=3DCVE-2026-82398 ] py-pdf--pypdf pypdf is =
a free and open-source pure-python PDF library. Prior to 6.16.0, an attacke=
r can craft a PDF whose cyclic tree structure causes pypdf/generic/_data_st= ructures.py TreeObject.insert_child to follow /Next links indefinitely when=
a writing code path inserts a child, producing an infinite loop. This issu=
e is fixed in version 6.16.0. 2026-09-01 not yet calculated CVE-2026-84309 =
[
https://www.cve.org/CVERecord?id=3DCVE-2026-84309 ] py-pdf--pypdf pypdf i=
s a free and open-source pure-python PDF library. Prior to 6.16.1, an attac= ker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consum=
e long runtimes and large amounts of memory when retrieving document outlin=
es with large numbers of entries or deeply nested reused paths because the = traversal lacked global entry-count and nesting-depth limits. This issue is=
fixed in version 6.16.1. 2026-09-01 not yet calculated CVE-2026-84310 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-84310 ] py-pdf--pypdf pypdf is a = free and open-source pure-python PDF library. Prior to 6.16.1, an attacker = can craft a PDF that causes pypdf/_page.py PageObject._extract_text and Pag= eObject.extract_xform_text to traverse a directed acyclic graph of reused f= orm XObjects in which each form invokes a child multiple times, creating ex= ponentially many traversal paths and causing long runtimes and large memory=
consumption. This issue is fixed in version 6.16.1. 2026-09-01 not yet cal= culated CVE-2026-84311 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84311 =
] Robots--Robots Robots::Validate versions from 0.3.2 before 0.3.11 for Per=
l allow unbounded outbound DNS queries per validation via a forward-confirm= ation loop that does not bound the names it queries. _check_dns issues one = PTR query for the client address, keeps the returned names matching the rul= e's domain, and issues a forward query for each until one resolves back to = that address. Nothing bounds that list, and a client controls the reverse z= one for its own address, so it chooses how many names the PTR answer holds.=
Net::DNS refetches a truncated answer over TCP by default, so the 512-byte=
UDP payload does not cap it either. Any client whose User-Agent matches a = rule with a domain reaches _check_dns. Each forward name is distinct and cl= ient-chosen, so every query misses the local cache and is resolved against = the authoritative servers for that domain. The queries are synchronous, so = the caller is held until all of them answer or time out. 2026-09-04 not yet=
calculated CVE-2026-82309 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82= 309 ] Rockwell Automation--1756-ENBT Module A denial-of-service security is= sue exists in the affected product. The security issue stems from a crafted=
CIP packet being sent crashing the module. The device requires a restart t=
o recover. 2026-09-01 not yet calculated CVE-2026-84235 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-84235 ] Rockwell Automation--Arena A remote code=
execution security issue exists in the affected products when parsing DOE = files that could allow a remote attacker to write past the end of an alloca= ted object and execute code within the context of the current process. To e= xploit this vulnerability, a legitimate user must visit a malicious page or=
open a malicious file. 2026-09-03 not yet calculated CVE-2026-6071 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-6071 ] Rockwell Automation--ArmorSta=
rt LT Multiple stored cross-site scripting security issues exist within Arm= orStart=C3=82=C2=AE LT. Stored XSS occurs when user input is not properly s= anitized and is stored on the server, allowing an attacker to inject malici= ous scripts that will be executed when other users access the affected page=
. 2026-09-01 not yet calculated CVE-2026-19471 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-19471 ] Rockwell Automation--ArmorStart LT A denial-of-se= rvice security issue exists within ArmorStart=C3=82=C2=AE LT. The security = issue stems from improper handling of a crafted HTTP PUT request sent to th=
e embedded web server. This can result in a loss of web server availability=
2026-09-01 not yet calculated CVE-2026-19472 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-19472 ] Rockwell Automation--CompactLogix 5380 / ControlLo= gix 5580 A denial-of-service security issue exists in the affected Logix pl= atforms listed in the table above. The security issue stems from improper v= alidation of input length during CIP message processing. This can result in=
a major nonrecoverable fault (MNRF), requiring a power cycle to recover 20= 26-09-01 not yet calculated CVE-2026-9637 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-9637 ] Rockwell Automation--ControlFLASH A security issue exis=
ts within ControlFLASH=C3=A2=E2=80=9E=C2=A2, where the installer grants wri=
te permissions to the "Everyone" group on a product installation directory.=
This could allow arbitrary code execution, resulting in an attacker being = given the ability to run any commands or code of the attacker's choice on a=
target machine at the logged-in user's permission level. 2026-09-01 not ye=
t calculated CVE-2026-12663 [
https://www.cve.org/CVERecord?id=3DCVE-2026-1= 2663 ] Rockwell Automation--DataEdgePlatform DataMosaix Private Cloud A dat=
a exposure vulnerability exists in the affected product. There are hardcode=
d links in the source code that lead to JSON files that can be reached with= out authentication. If exploited, a threat actor could view customer data. = 2026-09-01 not yet calculated CVE-2024-7952 [
https://www.cve.org/CVERecord= ?id=3DCVE-2024-7952 ] Rockwell Automation--DataEdgePlatform DataMosaix Priv= ate Cloud A vulnerability exists in the affected products that allows a thr= eat actor to create a project and become the administrator for it. If explo= ited, a threat actor could create, modify, and delete their own project. 20= 26-09-01 not yet calculated CVE-2024-7953 [
https://www.cve.org/CVERecord?i= d=3DCVE-2024-7953 ] Rockwell Automation--DataMosaix Private Cloud A vulnera= bility exists in the affected products that allows a threat actor to gain a= ccess to user's projects. To exploit this vulnerability the threat actor mu=
st have basic user privileges. If exploited, the threat actor can modify an=
d delete the project. 2026-09-02 not yet calculated CVE-2024-7956 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2024-7956 ] Rockwell Automation--FactoryTal=
k Activation Manager A privilege escalation security issue exists within Fa= ctoryTalk=C3=82=C2=AE Activation Manager. The security issue stems from cus= tom actions in the installer that spawn visible console windows running wit=
h SYSTEM privileges during installation or repair operations. An authentica= ted attacker with Windows credentials could hijack these console windows to=
obtain a SYSTEM-level command prompt, allowing full access to all files, p= rocesses, and system resources. 2026-09-01 not yet calculated CVE-2026-1667=
5 [
https://www.cve.org/CVERecord?id=3DCVE-2026-16675 ] Rockwell Automation= --FactoryTalk Historian Machine Edition A security issue exists within Fact= oryTalk=C3=82=C2=AE Historian Machine Edition. An attacker with low-level a= uthentication could exploit this vulnerability to achieve remote code execu= tion on the affected device. 2026-09-01 not yet calculated CVE-2025-12768 [=
https://www.cve.org/CVERecord?id=3DCVE-2025-12768 ] Rockwell Automation--F= actoryTalk Historian Machine Edition A denial-of-service security issue exi= sts within FactoryTalk=C3=82=C2=AE Historian Machine Edition.=C2=A0 A netwo=
rk adjacent attacker who is authenticated could send crafted requests to th=
e web interface, resulting in buffer overflow conditions that may cause the=
device to crash and become unresponsive. 2026-09-01 not yet calculated CVE= -2026-12661 [
https://www.cve.org/CVERecord?id=3DCVE-2026-12661 ] Rockwell = Automation--Redundancy Module Configuration Tool A security issue exists wi= thin the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary=
searches directories in the system path for a required DLL, and one or mor=
e of these directories may be writable by standard (non-administrator) user=
s due to incorrect default permissions. If a local attacker places a malici= ous DLL in such a directory and an administrator subsequently runs the tool=
, the malicious DLL is loaded into the elevated process and executes with A= dministrator/SYSTEM privileges. 2026-09-01 not yet calculated CVE-2026-9633=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-9633 ] Rockwell Automation--= Redundancy Module Configuration Tool A security issue exists within the Red= undancy Module Configuration Tool. The RMConfigTool.exe binary searches dir= ectories in the system path for a required DLL, and one or more of these di= rectories may be writable by standard (non-administrator) users due to inco= rrect default permissions. If a local attacker places a malicious DLL in su=
ch a directory and an administrator subsequently runs the tool, the malicio=
us DLL is loaded into the elevated process and executes with Administrator/= SYSTEM privileges. 2026-09-01 not yet calculated CVE-2026-9634 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-9634 ] Rockwell Automation--RSLinx Classi=
c A denial-of-service security issue exists within RSLinx=C3=82=C2=AE Class= ic. The security issue stems from improper handling of a malformed packet. =
A crafted CIP packet can cause the RSLinx=C3=82=C2=AE Classic service to cr= ash, requiring a restart of the service to recover 2026-09-01 not yet calcu= lated CVE-2026-9621 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9621 ] Ro= ckwell Automation--RSLinx Classic A denial-of-service security issue exists=
within RSLinx=C3=82=C2=AE Classic. A crafted CIP packet targeting the Forw= ard Close service can cause the RSLinx=C3=82=C2=AE Classic service to crash=
, requiring a restart of the service to recover. 2026-09-01 not yet calcula= ted CVE-2026-9622 [
https://www.cve.org/CVERecord?id=3DCVE-2026-9622 ] Rock= well Automation--RSLinx Classic A denial-of-service security issue exists w= ithin RSLinx=C3=82=C2=AE Classic. A crafted CIP packet can cause the RSLinx= =C3=82=C2=AE Classic service to crash due to insufficient data length valid= ation, requiring a=C2=A0 restart of the service to recover. 2026-09-01 not = yet calculated CVE-2026-9624 [
https://www.cve.org/CVERecord?id=3DCVE-2026-= 9624 ] Rockwell Automation--RSLinx Classic A denial-of-service security iss=
ue exists within RSLinx=C3=82=C2=AE Classic. A crafted CIP packet with an o= versized embedded message request can cause the RSLinx=C3=82=C2=AE Classic = service to crash, requiring a restart of the service to recover. 2026-09-01=
not yet calculated CVE-2026-9625 [
https://www.cve.org/CVERecord?id=3DCVE-= 2026-9625 ] Roskus--Prospero Flow CRM Cross-Site Request Forgery (CSRF) in = the OrderConfirmController at GET /order/confirm/{order_number} in Roskus P= rospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confi=
rm any order on behalf of an authenticated user by directing them to a craf= ted page. Laravel's VerifyCsrfToken middleware enforces CSRF tokens only on=
POST, PUT, PATCH, and DELETE requests; the Route::get declaration leaves t= his state-changing action unprotected. Session cookies configured with Same= Site=3DLax are automatically included in top-level cross-site navigation, s=
o a single link click triggers OrderConfirmController::confirm() and transi= tions the target order from pending to confirmed without user authorization=
. Because order numbers are sequential integers, an attacker can enumerate = and confirm all existing orders in a single automated sweep. 2026-09-04 not=
yet calculated CVE-2026-82911 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-82911 ] Sage--Employee Self Service A path traversal vulnerability exists=
in Sage Employee Self Service's custom logo functionality due to improper = validation of file path parameters. By leveraging directory traversal seque= nces and their encoded variants, an attacker may bypass directory restricti= ons and access files outside the application's intended file system scope. = Successful exploitation would require knowledge of valid file names and pat= hs. Depending on the privileges of the affected component, exploitation cou=
ld result in the disclosure of sensitive information, including configurati=
on files, environment settings, application assets, and log data. The vulne= rability has been remediated through enhanced path validation and secure pa=
th resolution controls that prevent access to unauthorised locations. 2026-= 09-01 not yet calculated CVE-2026-67395 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-67395 ] samanhappy--mcphub MCPHub is a unified hub for centrall=
y managing and dynamically orchestrating multiple MCP servers/APIs into sep= arate endpoints with flexible routing strategies. Prior to version 0.12.13,=
MCPB File Upload Handler extracts a ZIP file and reads manifest.json from = it. The name field in the manifest is directly concatenated into a file pat=
h (line 107) without any sanitization or path traversal character validatio=
n. An attacker can craft a malicious MCPB file where manifest.name is set t=
o something like ../../../etc/malicious, causing the file to be extracted t=
o an arbitrary location on the file system. The cleanupOldMcpbServer functi=
on (line 110) also uses the unsanitized name, potentially allowing deletion=
of arbitrary directories. This issue has been patched in version 0.12.13. = 2026-08-31 not yet calculated CVE-2026-79743 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-79743 ] samanhappy--mcphub MCPHub is a unified hub for cent= rally managing and dynamically orchestrating multiple MCP servers/APIs into=
separate endpoints with flexible routing strategies. Prior to version 1.0.= 32, MCPHub's SSRF guard in src/utils/ssrf.ts uses a custom isBlockedIpv6 fu= nction that only checks for loopback, link-local, unique-local, IPv4-mapped=
, and IPv4-compatible IPv6 addresses. IPv6 transition address families -- N= AT64 (64:ff9b::/96), 6to4 (2002::/16), and Teredo (2001::/32) -- are not ch= ecked. An attacker who can specify a URL for an MCP server connection can e= ncode a private IPv4 address inside one of these IPv6 forms to bypass the S= SRF guard and reach internal infrastructure. This issue has been patched in=
version 1.0.32. 2026-08-31 not yet calculated CVE-2026-79749 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-79749 ] Sauter--modu680-AS A service runni=
ng on the affected products contains a potential Time-of-Check Time-of-Use = (TOCTOU) race condition. An unauthenticated remote attacker could exploit t= his race condition to bypass intended security controls. This may result in=
the execution of unauthorized code. 2026-09-01 not yet calculated CVE-2026= -78319 [
https://www.cve.org/CVERecord?id=3DCVE-2026-78319 ] Schneider Elec= tric--EcoStruxure OPC UA Server Expert CWE-770: Allocation of Resources Wit= hout Limits or Throttling vulnerability exists that could cause denial of s= ervice of the OPC UA communication platform when a large number of OPC UA r= equests are sent to the platform. 2026-09-01 not yet calculated CVE-2024-10= 085 [
https://www.cve.org/CVERecord?id=3DCVE-2024-10085 ] Schneider Electri= c--NetBotz 5 - 750/755 CWE-78: Improper Neutralization of Special Elements = used in an OS Command ('OS Command Injection') vulnerability exists that co= uld cause execution of Linux Operating system commands when a system back u=
p is restored that has been maliciously modified. 2026-09-01 not yet calcul= ated CVE-2026-13336 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13336 ] S= chneider Electric--NetBotz 5 - 750/755 CWE-564: SQL Injection: Hibernate vu= lnerability exists that could allow the injection of a malicious HQL query =
in the NetBotz database when a malicious user is logged into the NetBotz vi=
a the web-service interface or webui. 2026-09-01 not yet calculated CVE-202= 6-13337 [
https://www.cve.org/CVERecord?id=3DCVE-2026-13337 ] Schneider Ele= ctric--PowerChute Serial Shutdown CWE-307: Improper Restriction of Excessiv=
e Authentication Attempts vulnerability exists that could allow an attacker=
to gain unauthorized access to a user account by performing an arbitrary n= umber of authentication attempts when redirect handling is disabled. 2026-0= 9-01 not yet calculated CVE-2026-13348 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-13348 ] seacms --seacms v13.6
=C2=A0 An authenticated remote code execution (RCE) vulnerability in the ad= min_config.php component of seacms v13.6 allows attackers to execute arbitr= ary code via a crafted POST request. 2026-09-04 not yet calculated CVE-2026= -79423 [
https://www.cve.org/CVERecord?id=3DCVE-2026-79423 ] SEPPmail AG--S= ecure Email Gateway SEPPmail Secure Email Gateway before 15.0.7 contains a = command injection vulnerability that allows authenticated administrators to=
execute commands with elevated privileges. 2026-09-03 not yet calculated C= VE-2026-84830 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84830 ] SEPPmai=
l AG--SEPPmail Secure Email Gateway (SEG) SEPPmail Secure Email Gateway bef= ore 15.0.7 creates a fully privileged session before required multi-factor = authentication enrollment is completed. An attacker with the password for a=
n MFA-required but unenrolled account can access protected functionality wi= thout providing a second factor. 2026-09-03 not yet calculated CVE-2026-848=
31 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84831 ] SEPPmail AG--SEPPm= ail Secure Email Gateway (SEG) SEPPmail Secure Email Gateway before 15.0.6 = deserializes attacker-controlled data in a privileged REST import workflow = without adequate validation. An attacker with a privileged API token can ex= ecute arbitrary commands with "nobody" privileges. 2026-09-03 not yet calcu= lated CVE-2026-84832 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84832 ] = Shizen Connect Inc.--ShizenBox2 (dev-conf) An improper physical access cont= rol issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with p= hysical access to the product may execute bootloader commands without authe= ntication. 2026-09-03 not yet calculated CVE-2026-80253 [
https://www.cve.o= rg/CVERecord?id=3DCVE-2026-80253 ] Shizen Connect Inc.--ShizenBox2 (edge-ap=
p) Authorization bypass through user-controlled key issue exists in ShizenB= ox2 (edge-app). If exploited, an attacker who can log in to the product may=
change the other user's password. 2026-09-03 not yet calculated CVE-2026-8= 0254 [
https://www.cve.org/CVERecord?id=3DCVE-2026-80254 ] Slack--Nebula me=
sh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. Prior to version 0.3.7, two related authorization gaps let a host that sh= ould no longer be trusted obtain a fresh, valid Nebula certificate, because=
nebula-mgmt does not re-evaluate revocation/authorization state at certifi= cate issuance time - only at poll time. Firstly, the blocklist is not enfor= ced at sign / re-enroll time. internal/api/enroll.go:128 calls caMgr.Sign(.= ..) without consulting the blocklist. The blocklist is only checked in the = poll path (internal/api/updates.go:57, fingerprintInBlocklist). The blockli=
st is keyed by certificate fingerprint (internal/store/sqlite.go), so a re-= enrollment produces a new fingerprint that is not in the blocklist. Secondl=
y, renewal does not re-validate operator / CA status. Auto-renewal at poll = time (internal/api/updates.go:285-319, signHostCert) reads host.Name, host.= Groups, host.NebulaIPs from the DB and re-signs without checking whether th=
e owning operator is still active or the CA still valid. DisableOperator (i= nternal/store/sqlite_operators.go) revokes sessions and API keys but does n=
ot retire the operator's CAs, and pki/signer.go checks only CA cert time-ex= piry, not operator/CA status. This issue has been patched in version 0.3.7.=
2026-09-04 not yet calculated CVE-2026-53602 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-53602 ] Slack--Nebula mesh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. Prior to version 0.3.8, Operator session tokens are stored in plaintext i=
n the operator_sessions table (the token column is the PRIMARY KEY). The se= ssion token is a 32-byte random hex value sent directly in a cookie and val=
id for 24 hours. Anyone who can read the database (backup, snapshot, file c= opy, or SQL-level disclosure) obtains every active session token and can hi= jack operator sessions directly, with no further authentication. This issue=
has been patched in version 0.3.8. 2026-09-04 not yet calculated CVE-2026-= 53603 [
https://www.cve.org/CVERecord?id=3DCVE-2026-53603 ] Slack--Nebula m= esh VPN
=C2=A0 nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN=
. Prior to version 0.3.8, the web handler renderMobileBundle passes the rea=
l *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.= LoadByID decrypts the CA's ed25519 private key into a *pki.CAManager, but B= uild never calls CAManager.Wipe() on any return path. As a result, when a m= obile-bundle request goes through the web UI and Build returns - especially=
on error (missing network, invalid prefix, DB error, signing failure) - th=
e plaintext CA private key remains on the Go heap, unwiped, until garbage c= ollection. An attacker able to read process memory (core dump, swap, memory= -scraping) can recover the CA signing key, which would allow minting arbitr= ary host certificates for the mesh. The API handler already does this corre= ctly: it loads the CAManager, defer caMgr.Wipe(), and wraps it in caManager= Resolver. Only the web path is affected. This issue has been patched in ver= sion 0.3.8. 2026-09-04 not yet calculated CVE-2026-53604 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-53604 ] smarty-php--smarty Smarty is a template=
engine for PHP, facilitating the separation of presentation (HTML/CSS) fro=
m application logic. Prior to 4.5.7 and 5.8.2, depending on the release lin=
e, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/Fun= ctionHandler/Fetch.php used Security::isTrustedUri() to validate only the i= nitial remote URL against trusted_uri when a security policy was active. Fo=
r resources handled by file_get_contents(), including HTTPS URLs, PHP follo= wed HTTP redirects by default. An attacker who could supply or influence a = fetch target and had an open redirect on a trusted host could redirect the = request to an attacker-chosen internal endpoint, bypass the trusted_uri all= owlist, and perform server-side request forgery. This issue is fixed in ver= sions 4.5.7 and 5.8.2. 2026-08-31 not yet calculated CVE-2026-62993 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-62993 ] Softing--smartLink HW-PN Mis= sing release of memory after effective lifetime vulnerability in Softing sm= artLink allows resource leak exposure. This issue affects smartLink HW-PN: = from 1.04 before 1.10. 2026-09-04 not yet calculated CVE-2026-13148 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-13148 ] Sonatype--Nexus Repository 3=
A user account with permission to deploy artifacts to a hosted Maven repos= itory could upload a POM file containing an oversized metadata field. This = causes future attempts to list or browse that repository's components to pe= rmanently fail until an administrator repairs the underlying data. Only the=
targeted repository is affected; other repositories and overall server hea= lth remain unaffected. 2026-09-02 not yet calculated CVE-2026-77121 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-77121 ] Sonatype--Nexus Repository 3=
An authorization flaw in the REST API repository details endpoint (GET /se= rvice/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3=
allowed an account holding read or browse permission on a group repository=
to retrieve metadata for member repositories on which it held no direct pe= rmission, by requesting the endpoint directly for the member repository nam=
e. For proxy repositories, the disclosed metadata includes the configured r= emote URL, which may reveal internal upstream hostnames. This includes the = anonymous user if it has been granted this permission; whether the anonymou=
s user holds this permission depends on the role and permission configurati=
on of the specific installation. 2026-09-02 not yet calculated CVE-2026-771=
22 [
https://www.cve.org/CVERecord?id=3DCVE-2026-77122 ] Sonatype--Nexus Re= pository 3 Nexus Repository 3 contains a sensitive information disclosure v= ulnerability in the capability read API. An account holding the nexus:capab= ilities:read privilege can retrieve the plaintext shared secret configured =
on a webhook capability, which is intended to be masked from all API respon= ses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, a=
nd is fixed in version 3.96.0. 2026-09-02 not yet calculated CVE-2026-77123=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-77123 ] Sonatype--Nexus Repo= sitory 3 In affected versions of Nexus Repository 3, the script execution e= ndpoint (POST /service/rest/v1/script/{name}/run) did not verify whether sc= ript execution had been administratively disabled. An account holding scrip= t-execution permission could continue to run previously-created scripts eve=
n after an administrator set nexus.scripts.allowCreation=3Dfalse, undermini=
ng the expectation that this setting fully blocks script execution. 2026-09= -02 not yet calculated CVE-2026-77124 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-77124 ] Sonatype--Nexus Repository 3 A vulnerability was identifie=
d in Sonatype Nexus Repository 3 in which two blobstore group management RE=
ST API endpoints did not correctly enforce the intended authorization check=
. A user granted only the nexus:blobstores:create permission could invoke t= hese endpoints to convert an existing blobstore into a group blobstore, an = action that should require the nexus:blobstores:update permission instead. = This could result in unauthorized modification of blobstore configuration w= ithout administrator approval. The nexus:blobstores:create permission is a = named permission that must be explicitly granted by an administrator; it is=
not held by default. 2026-09-02 not yet calculated CVE-2026-77125 [ https:= //www.cve.org/CVERecord?id=3DCVE-2026-77125 ] squirrelchat--smol-toml smol-= toml is a small, fast, and correct TOML parser and serializer. Prior to 1.7= .1, parse() can enter an infinite loop when a value inside an array or inli=
ne table is followed by a comment with no trailing newline. In src/util.ts,=
skipUntil() calls indexOfNewline(), receives -1 at the end of input, and r= esets the cursor to the beginning of the string instead of leaving the stru= cture scan. The parser then hangs indefinitely and can consume a service's = processing capacity when an application parses attacker-controlled TOML. Th=
is issue is fixed in version 1.7.1. 2026-09-04 not yet calculated CVE-2026-= 85730 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85730 ] sulu--sulu Sulu=
is an open-source PHP content management system based on the Symfony frame= work. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src= /Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do no=
t enforce VIEW permission for the target resource in PreviewLinkManager::ge= nerate() or PreviewLinkManager::revoke(). An authenticated administration u= ser who knows a target resource identifier can create or revoke a preview l= ink for any page, article, or snippet, including content in a webspace or a= rea the user cannot view. A generated preview URL is public and resolves co= ntent by an opaque token, allowing the user or anyone receiving the link to=
read restricted content without authentication. This issue is fixed in ver= sions 2.6.25 and 3.0.8. 2026-08-31 not yet calculated CVE-2026-82394 [ http= s://www.cve.org/CVERecord?id=3DCVE-2026-82394 ] sulu--sulu Sulu is an open-= source PHP content management system based on the Symfony framework. Prior =
to versions 2.6.25 and 3.0.8, the media move endpoint derives its permissio=
n check from the client-supplied collection value instead of the media item=
's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/= MediaManager.php allows MediaManager::move() to reassign the item without c= hecking that source. An authenticated backend user with edit permission on = one collection and knowledge of a target media identifier can name the allo= wed collection in the request, move an item out of a restricted collection,=
and then view or download content the user was not permitted to access. Th=
is issue is fixed in versions 2.6.25 and 3.0.8. 2026-08-31 not yet calculat=
ed CVE-2026-82395 [
https://www.cve.org/CVERecord?id=3DCVE-2026-82395 ] SUS= E--Fleet A security vulnerability was discovered in Fleet's Helm template p= reprocessing where templates evaluated by the Fleet controller could reach = network resources outside the management cluster. A user who can supply bun= dle content to a repository referenced by a `GitRepo` resource can cause th=
e Fleet controller to: - Disclose cluster metadata available to the templat= ing context. - Reveal information about hosts reachable from the controller=
's network position. Because the disclosure channel is name resolution, it = may remain effective in environments where outbound traffic is otherwise re= stricted. The disclosed information is limited to values exposed to the Fle=
et templating context and to name resolution results. Integrity and availab= ility of managed clusters are not affected. This issue affects Fleet: from = 0.12.0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.= 10, from 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1. 2026-09-03 no=
t yet calculated CVE-2026-75036 [
https://www.cve.org/CVERecord?id=3DCVE-20= 26-75036 ] ThinkSNS+ --ThinkSNS+ v2.4
=C2=A0 An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to=
escalate privileges via the ResetPasswordController.php component 2026-09-=
04 not yet calculated CVE-2026-71625 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-71625 ] thorsten--phpMyFAQ phpMyFAQ versions before 4.1.8 fail to v= alidate CAPTCHA when the store parameter is set to 'now' in question submis= sion requests. Unauthenticated attackers can bypass CAPTCHA protection and = submit unlimited questions directly, causing database pollution and trigger= ing outgoing mail notifications. 2026-09-04 not yet calculated CVE-2026-855=
86 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85586 ] thorsten--phpMyFAQ=
phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin conten=
t pages, allowing lesser-privileged editors to read draft and inactive cont= ent. Attackers with only add permissions can access news edit and FAQ trans= late endpoints to view unpublished content invisible to the public. 2026-09= -04 not yet calculated CVE-2026-85587 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-85587 ] thorsten--phpMyFAQ phpMyFAQ versions before 4.1.8 include = live TOTP shared secrets in plaintext within user data export ZIP files. At= tackers obtaining exported archives can extract the TOTP seed and generate = valid one-time codes to bypass two-factor authentication. 2026-09-04 not ye=
t calculated CVE-2026-85588 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 5588 ] thorsten--phpMyFAQ phpMyFAQ before 4.2.0-alpha.2 contains a missing = authorization vulnerability in the admin dashboard API endpoints searches a=
nd content-health that enforce only authentication without permission check=
s. Any authenticated user can access these endpoints to read site-wide sear=
ch statistics and content-health counters regardless of their privilege lev= el. 2026-09-04 not yet calculated CVE-2026-85589 [
https://www.cve.org/CVER= ecord?id=3DCVE-2026-85589 ] thorsten--phpMyFAQ phpMyFAQ before 4.1.8 contai=
ns an authentication bypass vulnerability in its two-factor authentication = (TOTP) disable functionality. The removeTwofactorConfig() handler (reachabl=
e via POST /api/user/remove-twofactor) verifies only that the user is logge=
d in and that a valid CSRF token is supplied, then disables TOTP without re= quiring password re-entry or a current TOTP code. The same downgrade is als=
o reachable inline via PUT /api/user/data/update, which accepts a plain two= factor_enabled form field under the same session+CSRF-only guard. An attack=
er who has hijacked a user's session can silently strip two-factor protecti=
on from any account, including administrator accounts, after which password= -only authentication succeeds. 2026-09-04 not yet calculated CVE-2026-85590=
[
https://www.cve.org/CVERecord?id=3DCVE-2026-85590 ] thorsten--phpMyFAQ p= hpMyFAQ versions before 4.1.8 contain an authentication bypass vulnerabilit=
y in the user control panel API endpoint that allows authenticated attacker=
s to change account passwords without verifying the current password. Attac= kers with session access can submit a PUT request to the user data update e= ndpoint with only a CSRF token to silently change any user's password, incl= uding administrators, causing irreversible account takeover and victim lock= out. 2026-09-04 not yet calculated CVE-2026-85591 [
https://www.cve.org/CVE= Record?id=3DCVE-2026-85591 ] TP-Link Systems Inc.--Archer AX55 v4 A stack-b= ased buffer overflow vulnerability exists in the EasyMesh module of TP-Link=
Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit craft=
ed input that causes the easymesh daemon to crash and may potentially achie=
ve remote code execution on the device. Successful exploitation may cause t=
he EasyMesh daemon to crash and may potentially allow remote code execution=
when Mesh mode is enabled. This may result in high impact to the confident= iality, integrity, and availability of the affected device. 2026-09-03 not = yet calculated CVE-2026-18167 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -18167 ] TP-Link Systems Inc.--Archer AX55 v4 A hard-coded cryptographic ke=
y vulnerability exists in the=C2=A0web module of TP-Link Archer AX55 v4. A = LAN attacker who captures an HTTP login session may use the known shared RS=
A private key to decrypt the=C2=A0administrator=C2=A0password; the weakened=
AES session key further reduces the effort=C2=A0required=C2=A0to compromis=
e session confidentiality. Successful exploitation may disclose the adminis= trator password captured from an HTTP login session and compromise session = confidentiality. 2026-09-03 not yet calculated CVE-2026-18330 [
https://www= .cve.org/CVERecord?id=3DCVE-2026-18330 ] traefik--traefik Traefik versions = from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the tra= efik.ingress.kubernetes.io/service.middlewares Service annotation in the Ku= bernetes Ingress provider. A namespace-limited tenant excluded from the all= owlist can attach an operator-owned middleware to its Service, and if that = middleware injects backend credentials, recover them at a controlled backen=
d. 2026-09-04 not yet calculated CVE-2026-85594 [
https://www.cve.org/CVERe= cord?id=3DCVE-2026-85594 ] traefik--traefik Traefik versions before v2.11.5=
5 and versions v3.0.0 through v3.7.10 contain an authentication bypass vuln= erability in the digestAuth middleware where unknown usernames receive an e= mpty secret instead of rejection. Attackers can compute a valid digest resp= onse using the empty secret and arbitrary credentials to bypass authenticat= ion on any digestAuth-protected route without a valid username or password.=
2026-09-04 not yet calculated CVE-2026-85595 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-85595 ] traefik--traefik Traefik versions >=3D v3.7.0 and = <=3D v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGI=
NX provider. The TLS option generated for an Ingress carrying the nginx.ing= ress.kubernetes.io/auth-tls-secret annotation was named after the Ingress n= amespace and name. As a result, two Ingress objects sharing the same host, = the same client CA secret, and the same client-authentication mode produced=
two distinct TLS option names for that host. Traefik treats this as a TLS = options conflict and falls back to the entry point's default TLS configurat= ion, which does not request a client certificate, so a route configured wit=
h nginx.ingress.kubernetes.io/auth-tls-verify-client: "on" becomes reachabl=
e without a client certificate. Only the v3.7 line is affected; the issue i=
s fixed in v3.7.11. 2026-09-04 not yet calculated CVE-2026-85596 [
https://= www.cve.org/CVERecord?id=3DCVE-2026-85596 ] traefik--traefik Traefik before=
v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resoluti=
on vulnerability that allows unauthenticated attackers to bypass client-cer= tificate authentication by creating conflicting TLS options on multi-host r= outers. Attackers can reach protected backends by exploiting shared TLS res= olution across multiple hostnames in a single router rule, causing the stri=
ct mTLS requirement to fall back to default options for all hosts. 2026-09-=
04 not yet calculated CVE-2026-85597 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-85597 ] Trimble --TM4WEB In Trimble TM4WEB 21.4.0.4 due to security=
misconfiguration with session identifiers, it is possible to recover valid=
session cookies via reflected cross-site scripting affecting the external = document viewer endpoint. 2026-09-04 not yet calculated CVE-2022-35497 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2022-35497 ] Trueview --Trueview 6.0.2= 3.4
=C2=A0 No authentication exists in the MQTT service of Trueview 6.0.23.4. T=
he MQTT broker accepts client connections on TCP port 1883 without requirin=
g authentication, allowing a remote attacker with network access to establi=
sh an MQTT session and perform unauthorized publish or subscribe operations=
. 2026-09-04 not yet calculated CVE-2026-79391 [
https://www.cve.org/CVERec= ord?id=3DCVE-2026-79391 ] Trueview--T18161 S 6.0.23.4
=C2=A0 Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT=
command processing. An attacker with network access can replay or modify c= aptured MQTT messages, including security-related nonce, timestamp, and sig= nature fields, and the device accepts the modified messages and executes th=
e associated commands. 2026-09-04 not yet calculated CVE-2026-79389 [ https= ://www.cve.org/CVERecord?id=3DCVE-2026-79389 ] Trueview--T18161 S 6.0.23.4 =C2=A0 Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due=
to the transmission of MQTT communications in plaintext over TCP port 1883=
. An unauthenticated attacker with access to the same network segment can i= ntercept MQTT traffic and obtain sensitive device information and operation=
al data, including device identifiers, message metadata, and control-relate=
d information. 2026-09-04 not yet calculated CVE-2026-79390 [
https://www.c= ve.org/CVERecord?id=3DCVE-2026-79390 ] Twig--Twig=C2=A0
=C2=A0 Twig is a template language for PHP. From version 1.0.0 to before ve= rsion 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelis=
ts all method calls on instances of Twig\Markup. Twig\Markup is not final, =
so subclasses inherit the bypass. An application that passes an object of a=
Markup-derived class into a sandboxed template (typically to mark a chunk =
of HTML as safe) inadvertently exposes every public method of that subclass=
to template authors, regardless of the configured allowedMethods list. Thi=
s issue has been patched in version 3.27.0. 2026-09-04 not yet calculated C= VE-2026-46636 [
https://www.cve.org/CVERecord?id=3DCVE-2026-46636 ] vbpf--p= revail PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Inte= rpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, Ebp= fTransformer::add() silently skips offset-variable updates when the destina= tion register carries a non-singleton typeset (two or more simultaneously p= ossible pointer types). Subsequent bounds checks use the stale offset and a= ccept out-of-bounds memory accesses, so a crafted BPF program passes verifi= cation even though it would corrupt memory at runtime. This issue has been = patched in version 0.2.4. 2026-09-02 not yet calculated CVE-2026-53670 [ ht= tps://www.cve.org/CVERecord?id=3DCVE-2026-53670 ] vbpf--prevail PREVAIL is =
a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. = Prior to version 0.2.4, the abstract transformer in prevail treats writes t= hrough a T_CTX-typed base register as a silent no-op: do_mem_store in src/c= rab/ebpf_transformer.cpp only models T_STACK stores, and the checker's T_CT=
X bounds arm never tests AccessType::write. An attacker can craft an eBPF p= rogram that overwrites a context field (e.g., ctx->data), reload that field=
typed as T_PACKET, and dereference an attacker-controlled address - and pr= evail will report the program as safe. This issue has been patched in versi=
on 0.2.4. 2026-09-02 not yet calculated CVE-2026-53671 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-53671 ] vbpf--prevail PREVAIL is a Polynomial-Run= time EBPF Verifier using an Abstract Interpretation Layer. Prior to version=
0.2.4, the prevail eBPF verifier accepts ALU32 ADD and SUB instructions th=
at operate on pointer-typed registers without checking the is64 flag. Becau=
se ALU32 arithmetic zero-extends the 32-bit result, the upper half of any p= ointer is silently destroyed at runtime, yet prevail marks the program as v= erified safe. Any caller that can submit an eBPF program for verification -=
including unprivileged users on kernels that permit BPF program loading - = can produce a program that passes verification but faults or misbehaves at = runtime. This issue has been patched in version 0.2.4. 2026-09-02 not yet c= alculated CVE-2026-53706 [
https://www.cve.org/CVERecord?id=3DCVE-2026-5370=
6 ] WebPros--ConfigServer Security & Firewall An insecure Apache configurat= ion in ConfigServer Security & Firewall maps /usr/bin as CGI programs throu=
gh the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker w= hose address is blocked can request a mapped executable and run arbitrary c= ommands as the Apache user. The vulnerability affects installations where C=
SF Messenger v3 and its HTTPS mode are enabled. WebPros addressed the vulne= rability in version 16.31. 2026-09-04 not yet calculated CVE-2026-67402 [ h= ttps://www.cve.org/CVERecord?id=3DCVE-2026-67402 ] WebPros--Plesk A critica=
l local privilege escalation via OS command injection vulnerability has bee=
n discovered in Plesk for Linux, affecting all versions from 18.0.34 before=
18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller w= ith shell access (or allowed to change their own shell access) to elevate p= rivileges to the root account on the hosting server. 2026-09-01 not yet cal= culated CVE-2026-67394 [
https://www.cve.org/CVERecord?id=3DCVE-2026-67394 =
] WebPros--Plesk Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 = through 18.0.80.5 allows local users to execute arbitrary code as root. 202= 6-09-04 not yet calculated CVE-2026-67397 [
https://www.cve.org/CVERecord?i= d=3DCVE-2026-67397 ] WebPros--WHMCS Missing authorization vulnerability has=
been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8= .13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vuln= erability allows an unauthenticated user to get WHMCS customer's data via 2= Checkout payment gateway's endpoint under specific conditions. 2026-09-04 n=
ot yet calculated CVE-2026-67398 [
https://www.cve.org/CVERecord?id=3DCVE-2= 026-67398 ] withastro--astro Astro is a web framework for content-driven we= bsites. Prior to 7.2.4, Astro stripped a configured non-root base path from=
request pathnames using a string-prefix check without verifying a path-seg= ment boundary. With base "/app", a request to "/appX/admin" resolved intern= ally to the protected "/admin" route while middleware observed "/appX/admin=
" in context.url.pathname. In applications that authorize base-prefixed rou= tes by inspecting context.url.pathname, an unauthenticated remote attacker = could bypass pathname-based middleware authorization and reach protected ro= utes. This issue is fixed in version 7.2.4. 2026-09-02 not yet calculated C= VE-2026-84376 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84376 ] wolfSSL= --wolfSSL
=C2=A0 With the wolfSSL backend, when CA caching is enabled and an `CURLOPT= _SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently = reinstall the cached store after the callback returns. A certificate truste=
d by the cached store but rejected by the callback-selected store is then i= ncorrectly accepted. 2026-09-06 not yet calculated CVE-2026-82208 [ https:/= /www.cve.org/CVERecord?id=3DCVE-2026-82208 ] WWBN--AVideo WWBN AVideo throu=
gh 30.0 contains an information disclosure vulnerability in the MobileManag=
er plugin getConfiguration endpoint that returns sensitive configuration da=
ta to unauthenticated visitors. Attackers can send an unauthenticated GET r= equest to plugin/MobileManager/getConfiguration.json.php to obtain TLS priv= ate key file paths, socket configuration details, platform version, and deb=
ug flags enabling further targeted attacks. 2026-09-01 not yet calculated C= VE-2026-84481 [
https://www.cve.org/CVERecord?id=3DCVE-2026-84481 ] Xing In= c.--XING CPTrans-ME-X XING CPTrans-ME-X contains an OS Command Injection (C= WE-78). Unauthenticated OS command may be injected. 2026-09-04 not yet calc= ulated CVE-2026-62928 [
https://www.cve.org/CVERecord?id=3DCVE-2026-62928 ]=
Xing Inc.--XING CPTrans-ME-X XING CPTrans-ME-X contains an Exposure of Sen= sitive System Information to an Unauthorized Control Sphere (CWE-497). Sens= itive system information may be leaked. 2026-09-04 not yet calculated CVE-2= 026-66840 [
https://www.cve.org/CVERecord?id=3DCVE-2026-66840 ] Xing Inc.--= XING CPTrans-ME-X XING CPTrans-ME-X contains a Use of Default Password (CWE= -1393). Anyone with the knowledge of the credential may log in to the affec= ted device. 2026-09-04 not yet calculated CVE-2026-69657 [
https://www.cve.= org/CVERecord?id=3DCVE-2026-69657 ] Xing Inc.--XING CPTrans-ME-X XING CPTra= ns-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the kn= owledge of the credential may log in to the affected device. 2026-09-04 not=
yet calculated CVE-2026-70403 [
https://www.cve.org/CVERecord?id=3DCVE-202= 6-70403 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XM=
L DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xm= ldom versions 0.8.14 and 0.9.11, and in xmldom version 0.6.0 and earlier, E= lement.setAttribute() calls the private _createAttribute(name) path without=
validating the attribute name, while Document.createAttribute(name) valida= tes against QName. XMLSerializer.serializeToString() emits attribute names = verbatim, and requireWellFormed: true did not validate them, so a crafted n= ame can terminate the intended attribute and inject additional attributes, = including event handlers, into browser-consumed output; synthesized xmlns:P= REFIX declarations expose the same unchecked-name boundary. This issue is f= ixed in @xmldom/xmldom versions 0.8.14 and 0.9.11; no fixed version is avai= lable for xmldom. 2026-09-01 not yet calculated CVE-2026-83605 [
https://ww= w.cve.org/CVERecord?id=3DCVE-2026-83605 ] xmldom--xmldom xmldom is a pure J= avaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerial= izer module. From 0.9.0-beta.9 until 0.9.11, the processing-instruction pro= duction in lib/grammar.js lets the greedy S+ separator and lazy Char*? data=
group repeatedly repartition a long whitespace tail when the required clos= ing ?> is absent. Both parsePI and parseProcessingInstruction apply the exp= ression to the entire remaining source, causing quadratic backtracking duri=
ng DOMParser.parseFromString() under default options and allowing a small u= nauthenticated XML input to stall the Node.js event loop. This issue is fix=
ed in @xmldom/xmldom version 0.9.11. 2026-09-01 not yet calculated CVE-2026= -83606 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83606 ] xmldom--xmldom=
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMP= arser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 and=
0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement(ta= gName) stores an unvalidated element name and XMLSerializer.serializeToStri= ng() emits that name verbatim. The requireWellFormed: true path did not val= idate the element qualified name or synthesized xmlns:PREFIX declaration, s=
o attacker-controlled tag names could inject attributes, elements, or proce= ssing instructions into serialized XML or HTML and could cause cross-site s= cripting when browser-consumed. The unchecked values violate the XML QName = constraint, and default serialization and creation-time createElement() beh= avior remain permissive. This issue is fixed in @xmldom/xmldom versions 0.8= .14 and 0.9.11; no fixed version is available for xmldom. 2026-09-01 not ye=
t calculated CVE-2026-83607 [
https://www.cve.org/CVERecord?id=3DCVE-2026-8= 3607 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XML D=
OM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldo=
m versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, the = DOCUMENT_TYPE_NODE branch in lib/dom.js validates publicId, systemId, and i= nternalSubset under requireWellFormed: true but emits DocumentType.name ver= batim. A name containing > or whitespace can terminate the <!DOCTYPE ...> d= eclaration and inject sibling markup; the value can be supplied through cre= ateDocumentType() on the 0.8.x and unscoped lines or through a direct Docum= entType.name property write on every affected line. The default path and le= gacy creation-time behavior remain permissive, while the vulnerable strict = path fails to enforce an XML Name. This issue is fixed in @xmldom/xmldom ve= rsions 0.8.15 and 0.9.12; no fixed version is available for xmldom. 2026-09= -01 not yet calculated CVE-2026-83608 [
https://www.cve.org/CVERecord?id=3D= CVE-2026-83608 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-ba= sed (XML DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.0 u= ntil 0.9.12, the shared reg() builder in lib/grammar.js compiles the anchor=
ed QName_exact validator with the multiline flag, so ^ and $ validate only = one line instead of the complete name. createElementNS, createAttributeNS, = createDocumentType, and createAttribute consequently accept a malformed XML=
name whose first line is valid and whose later text injects markup when se= rialized through either the default path or requireWellFormed: true. The tr= iggering ECMAScript line terminators are U+000A, U+000D, U+2028, and U+2029=
. This issue is fixed in @xmldom/xmldom version 0.9.12. 2026-09-01 not yet = calculated CVE-2026-83609 [
https://www.cve.org/CVERecord?id=3DCVE-2026-836=
09 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XML DOM=
Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom = versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, Docume= nt.createEntityReference(name) accepts an invalid name and the ENTITY_REFER= ENCE_NODE serializer emits the resulting nodeName directly in &name; form. = Directly serializing the node or fragment with XMLSerializer.serializeToStr= ing() and requireWellFormed: true can therefore break the entity-reference = boundary and produce attacker-controlled XML markup when reparsed. The pars=
er does not ordinarily create these nodes, and element-child insertion is r= ejected, so exploitation requires an application to create and directly ser= ialize an EntityReference. This issue is fixed in @xmldom/xmldom versions 0= .8.15 and 0.9.12; no fixed version is available for xmldom. 2026-09-01 not = yet calculated CVE-2026-83610 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -83610 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XML=
DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xml= dom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 and earlier, DO= MParser.parseFromString() can silently accept an end tag such as </a\njunk>=
, close the element, and discard the trailing content. On 0.9.x, the lib/sa= x.js end-tag validator inherits the multiline flag from reg(), allowing the=
first line to satisfy the anchored XML ETag production; older lines have n=
o equivalent residue validation. This parser differential can bypass a pars= e-before-trust well-formedness gate, although it does not inject the discar= ded content; onError on 0.9.x and errorHandler on 0.8.x are the relevant re= porting interfaces. This issue is fixed in @xmldom/xmldom versions 0.8.15 a=
nd 0.9.12; no fixed version is available for xmldom. 2026-09-01 not yet cal= culated CVE-2026-83611 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83611 =
] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XML DOM Le= vel 2 Core) DOMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9= .12, HTML-mode parsing through DOMParser.parseFromString() mishandles a mix= ed-case closing tag for the script, style, textarea, or title raw-text elem= ents. parseHtmlSpecialContent, selected by isHTMLRawTextElement or isHTMLEs= capableRawTextElement, uses a case-sensitive indexOf() and then calls subst= ring() with a missing-close result of negative one, causing unstable parser=
progression and quadratic output amplification. A small untrusted text/htm=
l document can consequently consume disproportionate CPU and memory when pa= rsed and serialized. This issue is fixed in @xmldom/xmldom version 0.9.12. = 2026-09-01 not yet calculated CVE-2026-83612 [
https://www.cve.org/CVERecor= d?id=3DCVE-2026-83612 ] xmldom--xmldom xmldom is a pure JavaScript W3C stan= dard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior=
to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom version 0.6.0 = and earlier, DOMHandler.startElement in lib/dom-parser.js inserts every par= sed attribute through setAttributeNode, while NamedNodeMap.setNamedItem in = lib/dom.js calls the linear getNamedItem or getNamedItemNS lookup for each = insertion. A well-formed element with many distinct attributes therefore re= quires quadratic comparisons during DOMParser.parseFromString() and can sta=
ll a Node.js event loop before application validation. This issue is fixed =
in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available=
for xmldom. 2026-09-01 not yet calculated CVE-2026-83613 [
https://www.cve= .org/CVERecord?id=3DCVE-2026-83613 ] xmldom--xmldom xmldom is a pure JavaSc= ript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer = module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12, and in xmldom v= ersions 0.3.0 through 0.6.0, two independent quadratic paths can cause deni=
al of service. In lib/sax.js, parseElementStartPart repeatedly rescans a ma= lformed tag name to the next > during single-character recovery; in lib/dom= .js, normalize() repeatedly removes and appends adjacent text nodes, causin=
g quadratic reindexing and string rebuilding. The first path is reachable t= hrough default DOMParser.parseFromString() processing, while the second is = also reachable through a direct normalize() call on a programmatically cons= tructed DOM, and endDocument invokes that normalization after parsing. This=
issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed vers= ion is available for xmldom. 2026-09-01 not yet calculated CVE-2026-83614 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-83614 ] xmldom--xmldom xmldom =
is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser an=
d XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 and 0.9.12,=
and in xmldom versions 0.1.5 through 0.6.0, appendElement in lib/sax.js us=
es _copy to clone the complete currentNSMap for each nested element that de= clares a new namespace prefix. Keeping every ancestor map live on the parse=
stack creates quadratic peak namespace-map storage, so a small highly comp= ressible XML document can exhaust the process heap before application valid= ation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no=
fixed version is available for xmldom. 2026-09-01 not yet calculated CVE-2= 026-83615 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83615 ] xmldom--xml= dom xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcess= ingInstruction(target, data) in lib/dom.js accepts an unvalidated target, w= hile the requireWellFormed: true serializer checks only for a colon and the=
reserved case-insensitive xml name on 0.9.x and performs no target check o=
n 0.8.x. Because serialization emits <?target data?>, a target containing >=
, ?, whitespace, or another invalid XML-name character can break the proces= sing-instruction boundary and inject XML structure. This issue is fixed in = @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is available fo=
r xmldom. 2026-09-01 not yet calculated CVE-2026-83616 [
https://www.cve.or= g/CVERecord?id=3DCVE-2026-83616 ] xmldom--xmldom xmldom is a pure JavaScrip=
t W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer mod= ule. From 0.9.11 until 0.9.12, the requireWellFormed: true element and attr= ibute name checks use the anchored QName_exact expression produced by reg()=
in lib/grammar.js, which inherits the multiline flag. A name with a valid = first line followed by U+000A, U+000D, U+2028, or U+2029 and breakout marku=
p therefore passes validation and is emitted verbatim in element start and = end tags or attribute names. This bypasses the strict-serialization checks = introduced for the earlier element-name and attribute-name injection adviso= ries, while the default serialization path remains outside the strict guara= ntee. This issue is fixed in @xmldom/xmldom version 0.9.12. 2026-09-01 not = yet calculated CVE-2026-83617 [
https://www.cve.org/CVERecord?id=3DCVE-2026= -83617 ] xmldom--xmldom xmldom is a pure JavaScript W3C standard-based (XML=
DOM Level 2 Core) DOMParser and XMLSerializer module. From 0.9.10 until 0.= 9.12, the requireWellFormed: true serializer validates DocumentType.publicI=
d and DocumentType.systemId with PubidLiteral_match and SystemLiteral_match=
expressions produced by reg() in lib/grammar.js, which inherit the multili=
ne flag. A complete valid literal on the first line can therefore satisfy t=
he matcher while U+000A, U+000D, U+2028, or U+2029 and breakout markup rema=
in in the emitted <!DOCTYPE ...> declaration. This bypasses the strict-seri= alization mitigation for the earlier DocumentType injection advisory; creat= ion and direct property assignment remain unvalidated by design. This issue=
is fixed in @xmldom/xmldom version 0.9.12. 2026-09-01 not yet calculated C= VE-2026-83618 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83618 ] xmldom-= -xmldom xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Cor=
e) DOMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release= -0.8.x parser in lib/sax.js trims captured end-tag names with the unanchore=
d global expression /[ \t\n\r]+$/g. For an end tag containing a long whites= pace run followed by a non-whitespace character, the expression retries fro=
m each possible starting position and backtracks quadratically before faili=
ng its end anchor. DOMParser.parseFromString() reaches the path under defau=
lt options, allowing a small unauthenticated XML input to stall the Node.js=
event loop; the 0.9.x and unscoped npm lines do not contain this expressio=
n. This issue is fixed in @xmldom/xmldom version 0.8.15. 2026-09-01 not yet=
calculated CVE-2026-83619 [
https://www.cve.org/CVERecord?id=3DCVE-2026-83= 619 ] Xpdf--Xpdf Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in=
a Type 3 font has a zero height. 2026-09-03 not yet calculated CVE-2026-85= 458 [
https://www.cve.org/CVERecord?id=3DCVE-2026-85458 ] YesWiki -- YesWiki =C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Yes= Wiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerab= ility in the semantic template feature that can be escalated to confirmed R= emote Code Execution (RCE). An authenticated administrator can place arbitr= ary Twig expressions into the Semantic template (Twig) field (bn_sem_templa= te), and that content is later executed server-side when public semantic en= dpoints are requested. This issue has been patched in version 4.6.6. 2026-0= 9-05 not yet calculated CVE-2026-52762 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-52762 ] YesWiki--YesWiki
=C2=A0 YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the=
re is an authenticated PHP object injection vulnerability in BazarImportAct= ion via unserialize. This issue has been patched in version 4.6.6. 2026-09-=
05 not yet calculated CVE-2026-52777 [
https://www.cve.org/CVERecord?id=3DC= VE-2026-52777 ] z-galaxy--zbus_polkit Subject::new_for_owner() in the zbus_= polkit crate encodes the uid entry of a unix-process polkit subject as an u= nsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKi= t1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Be= cause of this type mismatch, polkit silently discards the caller-supplied U=
ID and instead determines the subject's owner itself by looking up the PID =
in /proc, a lookup that is inherently subject to a time-of-check/time-of-us=
e race. Consequently, an application that passes a UID obtained from a trus= tworthy source - for example SO_PEERCRED Unix socket peer credentials - in = order to defend against PID reuse receives no protection, and the supplied = UID has no effect on the authorization decision. A local unprivileged attac= ker who can cause an authorized process to terminate and then win the race =
to have their own process assigned the same PID can be authorized under the=
identity of the terminated process, bypassing the polkit authorization che=
ck and performing actions the attacker is not entitled to. This issue affec=
ts zbus_polkit before 5.1.0. 2026-08-31 not yet calculated CVE-2026-78422 [=
https://www.cve.org/CVERecord?id=3DCVE-2026-78422 ] ZenHive--ZenHive mpp I= mproper Validation of Specified Quantity in Input in ZenHive mpp allows an = unauthenticated remote client to inflate the fee-payer's gas cost per spons= ored payment by a large multiplier and to have the sponsor pay for provisio= ning an access key on the client's own account. When the server sponsors Te= mpo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods= /tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the valid= ity window and the access list of the client-signed 0x76 envelope, but does=
not check whether the envelope carries the optional key_authorization fiel=
d. A client can attach a fully signed key authorization, provisioning a new=
access key with token spending limits on its own account, alongside the no= rmal payment call. The key and each limit entry are persistent storage writ=
es billed as intrinsic gas to the sponsor, bounded only by the gas_limit ce= iling. At the reporter's default of one key with three token limits the spo= nsored cost rises from about 46,587 gas to about 1,808,700 gas, and the cli= ent keeps a valid access key it paid nothing for. This issue affects mpp: f= rom 0.2.0 before 0.16.1. 2026-09-06 not yet calculated CVE-2026-82751 [ htt= ps://www.cve.org/CVERecord?id=3DCVE-2026-82751 ] ZenHive--ZenHive mpp
=C2=A0 Improper Validation of Specified Quantity in Input in ZenHive mpp al= lows an unauthenticated remote client to inflate the fee-payer's gas cost p=
er sponsored payment by a large multiplier and to have the sponsor pay for = EIP-7702 account delegations of the client's choosing. When the server spon= sors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/= methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, th=
e validity window and the access list of the client-signed 0x76 envelope, b=
ut never reads its aa_authorization_list field. Every signed delegation in = that list is charged as intrinsic gas before the payment call runs, so a cl= ient attaching delegations from throwaway authority keys makes the sponsor = pay for them within the default gas_limit ceiling. At the reporter's defaul=
t of seven entries the sponsored cost rises from about 46,575 gas to about = 1,884,087 gas. Because each entry is applied as a persistent set-code deleg= ation, a client can also upgrade its own accounts to delegated code at the = sponsor's expense. This issue affects mpp: from 0.2.0 before 0.16.1. 2026-0= 9-06 not yet calculated CVE-2026-82750 [
https://www.cve.org/CVERecord?id= =3DCVE-2026-82750 ] Zhao-github--ApiAdmin v.5.0.1
=C2=A0 File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a r= emote attacker to execute arbitrary code via a crafted .php file 2026-09-04=
not yet calculated CVE-2026-71620 [
https://www.cve.org/CVERecord?id=3DCVE= -2026-71620 ] Zhao-github--ApiAdmin v.5.0.1
=C2=A0 SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a=
remote attacker to obtain sensitive information via the User.php component=
2026-09-04 not yet calculated CVE-2026-71622 [
https://www.cve.org/CVEReco= rd?id=3DCVE-2026-71622 ] =C2=A0Invoice Ninja-- Invoice Ninja v5.13.24
=C2=A0 An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtai=
n sensitive information via the StoreWebhookRequest.php, UpdateWebhookReque= st.php, and WebhookSingle.php components 2026-09-04 not yet calculated CVE-= 2026-71626 [
https://www.cve.org/CVERecord?id=3DCVE-2026-71626 ]=20
Back to top [ #top ]
body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight=
: normal; font-style: normal; color: #333333; }=20
Having trouble viewing this message?=C2=A0View it as a webpage [
https://co= ntent.govdelivery.com/accounts/USDHSCISA/bulletins/428f9a0 ].=C2=A0 [ https= ://content.govdelivery.com/accounts/USDHS/bulletins/292141e ]
You are subscribed to updates from the Cybersecurity and Infrastructure Sec= urity Agency [
https://www.cisa.gov ] (CISA)
Manage Subscriptions [
https://public.govdelivery.com/accounts/USDHSCISA/su= bscriber/edit?preferences=3Dtrue#tab1 ]=C2=A0=C2=A0|=C2=A0=C2=A0Privacy Pol= icy [
https://www.cisa.gov/privacy-policy ]=C2=A0=C2=A0|=C2=A0 Help [ https= ://subscriberhelp.granicus.com/s/article/Subscriber-Help-Center ] [ https:/= /insights.govdelivery.com/Communications/Subscriber_Help_Center ]
Connect with CISA:=20
Facebook [
https://www.facebook.com/CISA ]=C2=A0 |=C2=A0 Twitter [
https://= twitter.com/CISAgov ]=C2=A0 |=C2=A0 Instagram [
https://Instagram.com/cisag=
ov ]=C2=A0 |=C2=A0 LinkedIn [
https://www.linkedin.com/company/cybersecurit= y-and-infrastructure-security-agency ]=C2=A0 |=C2=A0=C2=A0 YouTube [ https:= //www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A ]
________________________________________________________________________
This email was sent to
cisa@toolazy.synchro.net using Granicus Communicatio=
ns Cloud, on behalf of: Cybersecurity and Infrastructure Security Agency = =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202 Granicus Communicati= ons logo [
https://granicus.com/solution/digital-communication-engagement/ = ]=20
body .abe-column-block { min-height: 5px; } table.gd_combo_table img {margi= n-left:10px; margin-right:10px;} table.gd_combo_table div.govd_image_displa=
y img, table.gd_combo_table td.gd_combo_image_cell img {margin-left:0px; ma= rgin-right:0px;}
--===============0436581685986125891==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns=3D"
http://www.w3.org/1999/xhtml" xml:lang=3D"en" lang=3D"en"> <head>
<title> Vulnerability Summary for the Week of August 31, 2026
</title>
</head>
<body style=3D"">
<table width=3D"700" border=3D"0" cellspacing=3D"0" cellpadding=3D"0"=
align=3D"center">
<tr>
<td>
<!--[if (gte mso 9)|(IE)]>
<table style=3D"display:none"><tr><td><a name=3D"gd_top" id=3D"gd_top"></= a></td></tr></table>
<![endif]-->
<a name=3D"gd_top" id=3D"gd_top"></a>
=20
<p><img src=3D"
https://content.govdelivery.com/attachments/fancy_images/U= SDHSCISA/2020/06/3486054/05152023-gov-delivery-banner-copy_original.png" al= t=3D"Cybersecurity and Infrastructure Security Agency (CISA)" title=3D"" wi= dth=3D"600" height=3D"100"></p>
<p>You are subscribed to Vulnerability Bulletins for Cybersecurity and In= frastructure Security Agency. This information has recently been updated an=
d is now available.</p>
<p>The CISA Vulnerability Bulletin provides a summary of new vulnerabilitie=
s that have been recorded in the past week. In some cases, the vulnerabilit= ies in the bulletin may not yet have assigned CVSS scores.</p> <p>Vulnerabilities are based on the=C2=A0<a href=3D"
https://www.cve.org/" t= arget=3D"_blank" class=3D"ext" data-extlink=3D"" rel=3D"noopener">Common Vu= lnerabilities and Exposures</a>=C2=A0(CVE) vulnerability naming standard an=
d are organized according to severity, determined by the=C2=A0<a href=3D"ht= tps://www.cve.org/about/relatedefforts" target=3D"_blank" rel=3D"noopener">= Common Vulnerability Scoring System</a>=C2=A0(CVSS) standard. The division =
of high, medium, and low severities correspond to the following scores:</p>
<strong>High</strong>: vulnerabilities with a CVSS base score of 7.0=E2=80= =9310.0</li>
<strong>Medium</strong>: vulnerabilities with a CVSS base score of 4.0=E2= =80=936.9</li>
<strong>Low</strong>: vulnerabilities with a CVSS base score of 0.0=E2=80= =933.9</li>
</ul>
<p>Entries may include additional information provided by organizations and=
efforts sponsored by CISA. This information may include identifying inform= ation, values, definitions, and related links. Patch information is provide=
d when available. Please note that some of the information in the bulletin =
is compiled from external, open-source reports and is not a direct result o=
f CISA analysis.</p>
<p>=C2=A0</p>
<div class=3D"rss_item" style=3D"margin-bottom: 2em;">
<div class=3D"rss_title" style=3D"font-weight: bold; font-size: 120%; margi=
n: 0 0 0.3em; padding: 0;"><a href=3D"
https://www.cisa.gov/news-events/bull= etins/sb26-250" target=3D"_blank" title=3D"Vulnerability Summary for the We=
ek of August 31, 2026" rel=3D"noopener">Vulnerability Summary for the Week =
of August 31, 2026</a></div>
<div class=3D"rss_pub_date" style=3D"font-size: 90%; font-style: italic; co= lor: #666666; margin: 0 0 0.3em; padding: 0;">09/08/2026 03:40 PM EDT</div>
<div class=3D"rss_description" style=3D"margin: 0 0 0.3em; padding: 0;">
<div id=3D"high_v">
<h2 id=3D"high_v_title">High Vulnerabilities</h2>
<table class=3D"table table-style-align-center no-tablesaw" style=3D"table-= layout: fixed; width: 100%;" border=3D"1" summary=3D"High Vulnerabilities"> <thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">1Hive--gardens-v2</td>
<td>Gardens v2 is a modular governance framework that enables communities t=
o create and manage multiple governance pools with customizable parameters = and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is f= unded, the cluster of streaming contracts moves real pool funds into the pr= oposal's StreamingEscrow to back the Superfluid constant flow agreement (th=
e CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the e= scrow's GDA member units but never reclaims that parked balance, and the pe= rmissionless claim() forwards the escrow's entire balance, including the po=
ol funded buffer, to the beneficiary. The beneficiary is chosen by the prop= osal submitter and defaults to the submitter. The only path that returns es= crow funds to the pool is drainToStrategy, which is onlyStrategy and is rea= ched solely from the dispute reject ruling, never from cancel or natural co= mpletion. At time of publication, there are no publicly known patches.</td> <td>2026-09-03</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55658" target=3D= "_blank" rel=3D"noopener">CVE-2026-55658</a></td>
</tr>
<td class=3D"vendor-product">: Shane Bishop--EWWW Image Optimizer</td>
<td>Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= =3D 8.7.6 versions.</td>
<td>2026-09-03</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84773" target=3D= "_blank" rel=3D"noopener">CVE-2026-84773</a></td>
</tr>
<td class=3D"vendor-product">@fastify/http-proxy--@fastify/http-proxy</td> <td>@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP=
request paths for backslash based dot-segments before forwarding them to t=
he configured upstream. The plain HTTP request handler skips the destinatio=
n validation that the WebSocket path performs, and the underlying reply-fro=
m library only rejects forward-slash traversal, so a request containing bac= kslash dot-segments can escape the boundary set by the prefix and rewritePr= efix options. An unauthenticated network attacker can use this to reach ups= tream paths that were meant to stay hidden behind the proxy, resulting in d= isclosure of internal endpoints. This is a path traversal issue (CWE-22). U= sers should upgrade to @fastify/http-proxy 11.6.2 or later.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85124" target=3D= "_blank" rel=3D"noopener">CVE-2026-85124</a></td>
</tr>
<td class=3D"vendor-product">@fastify/middie--@fastify/middie</td> <td>@fastify/middie versions >=3D 9.1.0 and before 9.3.4 decide whether =
to run path-scoped middleware by matching against the raw request target, w= hile the Fastify router resolves an absolute-form request target to its pat=
h before dispatching. Because the two layers evaluate different strings, a = request using an absolute-form target reaches the route handler while the p= ath-scoped middleware, such as authentication or authorization, is skipped.=
An unauthenticated network attacker can use this to bypass path-based acce=
ss controls in a Fastify application that relies on middie for those contro= ls. Users should upgrade to @fastify/middie 9.3.4 or later.</td> <td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85184" target=3D= "_blank" rel=3D"noopener">CVE-2026-85184</a></td>
</tr>
<td class=3D"vendor-product">aaif-goose--goose</td>
<td>goose 1.37.0 executes arbitrary commands from recipe stdio extensions a=
nd retry.checks without security inspection. Attackers can distribute malic= ious recipes that execute shell commands as the user running goose, bypassi=
ng the recipe security scan which does not inspect extensions or retry conf= igurations.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85623" target=3D= "_blank" rel=3D"noopener">CVE-2026-85623</a></td>
</tr>
<td class=3D"vendor-product">Acato--Email Essentials</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Email Essentials <=3D = 6.0.6 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81764" target=3D= "_blank" rel=3D"noopener">CVE-2026-81764</a></td>
</tr>
<td class=3D"vendor-product">Adobe--Adobe Substance 3D Sampler</td> <td>Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulne= rability that could result in arbitrary code execution in the context of th=
e current user. Exploitation of this issue requires user interaction in tha=
t a victim must open a malicious file.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83959" target=3D= "_blank" rel=3D"noopener">CVE-2026-83959</a></td>
</tr>
<td class=3D"vendor-product">Adobe--ColdFusion 2025</td>
<td>ColdFusion is affected by an Improper Authentication vulnerability that=
could result in privilege escalation. An attacker could leverage this vuln= erability to gain limited read and write access. The vulnerable component i=
s restricted to an administrative network zone by default. Exploitation of = this issue does not require user interaction. Scope is changed.</td> <td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83961" target=3D= "_blank" rel=3D"noopener">CVE-2026-83961</a></td>
</tr>
<td class=3D"vendor-product">Advanced Custom Fields: Extended--Advanced Cus= tom Fields: Extended</td>
<td>The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 do=
es not verify that the requester is authorized to edit the targeted user ac= count in the update-user action of its front-end Forms module; it only chec=
ks a capability when the submitted role is administrator or super_admin. On=
a site that exposes a publicly reachable front-end form whose user-update = action targets an existing administrator (a fixed target, or one mapped to =
a visitor-submitted field) and maps the password to a visitor-submitted fie= ld, an unauthenticated visitor can overwrite that administrator's password = and take over the account. The default target is the submitting user, so ex= ploitation depends on the form being configured to target another account.<=
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12526" target=3D= "_blank" rel=3D"noopener">CVE-2026-12526</a></td>
</tr>
<td class=3D"vendor-product">Advanced Custom Fields: Extended--Advanced Cus= tom Fields: Extended</td>
<td>The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 do=
es not restrict the role submitted through its front-end user forms to the = roles the form actually offers, and its safeguard against privileged roles =
is incomplete, allowing unauthenticated visitors to register an account wit=
h elevated capabilities and then escalate it to administrator.</td> <td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80467" target=3D= "_blank" rel=3D"noopener">CVE-2026-80467</a></td>
</tr>
<td class=3D"vendor-product">advanpix--WP QuickLaTeX</td>
<td>Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <=3D 3.8=
.8 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81776" target=3D= "_blank" rel=3D"noopener">CVE-2026-81776</a></td>
</tr>
<td class=3D"vendor-product">agentscope-ai--agentscope</td>
<td>AgentScope through 2.0.7.post1 contains a path traversal vulnerability =
in LocalWorkspace.add_skill that copies arbitrary server directories into t=
he agent workspace via an unconfined source path parameter. Attackers can s= upply any directory path in the skill_path request parameter to copy files = into the skills directory, making them accessible through the workspace ski=
ll listing.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85685" target=3D= "_blank" rel=3D"noopener">CVE-2026-85685</a></td>
</tr>
<td class=3D"vendor-product">AI Website Builder (GitHub build)--AI Website = Builder (GitHub build)</td>
<td>The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not p= erform any authorisation or nonce check on its REST API routes, allowing un= authenticated attackers to install and activate plugins and themes, import = content from a URL under their control, write a file of their choosing into=
the uploads directory, and delete site content and media. On a host that s= erves PHP from the uploads directory, that file write is remote code execut= ion.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82923" target=3D= "_blank" rel=3D"noopener">CVE-2026-82923</a></td>
</tr>
<td class=3D"vendor-product">Aider-AI--aider</td>
<td>aider (aider-chat) automatically loads a .aider.conf.yml configuration = file from the root of the git repository it is launched in. A crafted repos= itory can set test-cmd (executed at startup) or lint-cmd (executed on the f= irst file edit), which aider runs through a shell (subprocess with shell=3D= True) without any user confirmation, LLM interaction, or API key. Consequen= tly, a user who clones and runs aider inside an attacker-supplied repositor=
y achieves arbitrary command execution on their machine. The behavior is lo= ng-standing and was confirmed on 0.86.3.dev (current main).</td> <td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85674" target=3D= "_blank" rel=3D"noopener">CVE-2026-85674</a></td>
</tr>
<td class=3D"vendor-product">aimhubio--aim</td>
<td>Aim 3.29.1 remote tracking server fails to authenticate requests and di= spatches arbitrary methods through getattr without allowlist validation. Un= authenticated attackers can register clients, instantiate Repo resources, a=
nd invoke arbitrary methods to read experiments or delete runs.</td> <td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85663" target=3D= "_blank" rel=3D"noopener">CVE-2026-85663</a></td>
</tr>
<td class=3D"vendor-product">Amazon-- EFS CSI Driver<br>=C2=A0</td> <td>Unverified ownership of a storage access point in the volume deletion c= omponent of the Amazon EFS CSI Driver before v3.4.1 might allow an authenti= cated Kubernetes user with PersistentVolume creation privileges to cause re= cursive deletion of directories on an EFS filesystem they are not authorize=
d to access, via a crafted PersistentVolume volumeHandle that pairs an acce=
ss point from one filesystem with a different target filesystem. To remedia=
te this issue, users should upgrade to version v3.4.1.</td>
<td>2026-09-04</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85781" target=3D= "_blank" rel=3D"noopener">CVE-2026-85781</a></td>
</tr>
<td class=3D"vendor-product">Amazon--awslabs.dynamodb-mcp-server</td> <td>Improper neutralization of special elements used in a template engine i=
n the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 migh=
t allow a context-dependent actor to execute arbitrary code on the host tha=
t deploys the generated application via crafted table, index, or attribute = names in a data model file.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85654" target=3D= "_blank" rel=3D"noopener">CVE-2026-85654</a></td>
</tr>
<td class=3D"vendor-product">Amazon--ion-c</td>
<td>An uncontrolled recursion issue exists in Amazon Ion-C versions before = 1.1.6 that might allow a remote unauthenticated actor to craft Ion data tha=
t exhausts the native call stack and crashes the application using the libr= ary, resulting in a denial of service.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84851" target=3D= "_blank" rel=3D"noopener">CVE-2026-84851</a></td>
</tr>
<td class=3D"vendor-product">Amazon--ion-java<br>=C2=A0</td>
<td>Improper handling of highly compressed data in Amazon ion-java before 1= .12.1 might allow remote attackers to cause a denial of service via a craft=
ed compressed Ion document that expands to an arbitrarily large size upon d= ecompression due to insufficient coverage of the GZIP auto-decompression op= t-out introduced for CVE-2026-75936. To remediate this issue, users should = upgrade to version 1.12.1.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85786" target=3D= "_blank" rel=3D"noopener">CVE-2026-85786</a></td>
</tr>
<td class=3D"vendor-product">Amazon--log4j-cve-2021-44228-hotpatch</td>
<td>An OS command injection issue in the log4j-cve-2021-44228-hotpatch pack= age in Amazon Linux before 1.3-9 might allow a local user to execute arbitr= ary commands with root privileges via a Java process whose executable path = contains embedded newline characters.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85656" target=3D= "_blank" rel=3D"noopener">CVE-2026-85656</a></td>
</tr>
<td class=3D"vendor-product">AMD--2nd Gen AMD EPYC Processors</td>
<td>A heap overflow in SMM module may allow an attacker with access to a se= cond vulnerability that enables writing to SPI flash, potentially resulting=
in arbitrary code execution.</td>
<td>2026-09-02</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-20577" target=3D= "_blank" rel=3D"noopener">CVE-2023-20577</a></td>
</tr>
<td class=3D"vendor-product">AMD--AMD Ryzen 3000 Series Desktop Processors<=
<td>Insufficient Verification of Data Authenticity in AGESA=C3=A2=E2=80=9E= =C2=A2 may allow an attacker to update SPI ROM data potentially resulting i=
n denial of service or privilege escalation.</td>
<td>2026-09-02</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-20576" target=3D= "_blank" rel=3D"noopener">CVE-2023-20576</a></td>
</tr>
<td class=3D"vendor-product">Ankara Hosting--Site Management Panel</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Ankara Hosting Site Management Panel allows = SQL Injection. This issue affects Site Management Panel: through 15062026.<=
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5956" target=3D"= _blank" rel=3D"noopener">CVE-2026-5956</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Apache Wicket enforces the upload limits configured on a form or upload=
field while parsing a multipart request with Apache Commons FileUpload. If=
the request body has already been consumed by another component, Commons F= ileUpload returns no items and Wicket falls back to reading the upload thro= ugh HttpServletRequest#getParts(). The per-file size limit (for example For= m#setFileMaxSize) and the file count limit (Form#setFileCountMax) are not a= pplied to the parts obtained that way, and no exception is raised, so the u= pload is processed as though those limits had been satisfied. A remote uplo= ader can therefore submit files that are larger, or more numerous, than the=
application permits, up to whatever the component that parsed the request = allows. A part carrying no Content-Type header is additionally read into me= mory in full during parsing, so the size of that allocation is determined b=
y the request and bounded only by those same external limits. The total upl= oad size limit (Form#setMaxSize) is not affected. Commons FileUpload compar=
es the declared Content-Length against it before reading the body, so a req= uest declaring an oversized length is rejected before the fallback is reach= ed. The fallback is reached in deployments where a servlet or filter has al= ready parsed the request body - for example a servlet annotated with @Multi= partConfig, Spring Boot's multipart resolver, or any filter that calls Http= ServletRequest#getParameter() on a multipart request. It applies to the Wic= ket components that accept uploads on that path, including Form with FileUp= loadField, FileUploadToResourceField and AjaxFileDropBehavior. Applications=
that configure neither a per-file nor a file-count limit are not affected,=
as Wicket applies neither by default. This issue affects Apache Wicket: fr=
om 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.= 10.0. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0=
, which fix the issue. Users of Apache Wicket 7.x or older, which are no lo= nger supported, should upgrade to a supported version. As a workaround, con= figure equivalent limits in the component that parses the request - for exa= mple spring.servlet.multipart.max-file-size and max-request-size, or maxFil= eSize and maxRequestSize in @MultipartConfig or in the web.xml <multipar= t-config> element.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71257" target=3D= "_blank" rel=3D"noopener">CVE-2026-71257</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Allura</td> <td>Apache Allura: exposure of non-public information via search. This issu=
e affects Apache Allura: through 1.20.0. Users are recommended to upgrade t=
o version 1.21.0, which fixes the issue.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81270" target=3D= "_blank" rel=3D"noopener">CVE-2026-81270</a></td>
</tr>
<td class=3D"vendor-product">apitable--apitable</td>
<td>APITable through 1.13.0-beta.1 exposes the internal organization loadOr= Search endpoint without authentication, allowing unauthenticated attackers =
to retrieve member names, email addresses, and team hierarchy. Attackers ca=
n query the endpoint with space identifiers obtained from shared links or p= ublic templates to enumerate the complete member directory of any workspace= .</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84485" target=3D= "_blank" rel=3D"noopener">CVE-2026-84485</a></td>
</tr>
<td class=3D"vendor-product">AppFlowy-IO--AppFlowy-Cloud</td> <td>AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects bel= ong to the workspace in authorization checks, allowing attackers to access = documents and database rows across workspaces. Attackers can supply a victi= m's object ID with their own workspace ID to bypass access controls and rea=
d, modify, or delete cross-workspace data.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85619" target=3D= "_blank" rel=3D"noopener">CVE-2026-85619</a></td>
</tr>
<td class=3D"vendor-product">AresIT--WP Compress</td>
<td>Unauthenticated Settings Change in WP Compress <=3D 7.21.28 versions= .</td>
<td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84757" target=3D= "_blank" rel=3D"noopener">CVE-2026-84757</a></td>
</tr>
<td class=3D"vendor-product">argneshu--appium-mcp-server</td> <td>appium-mcp-server through 0.1.61 fails to validate or normalize file pa= ths in the write_file and write_files_batch tools, allowing attackers to wr= ite files outside the intended PROJECT_ROOT directory. Attackers can supply=
absolute paths or relative paths with parent directory segments to overwri=
te arbitrary files with the server user's privileges, including shell profi= les and configuration files in the home directory.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84201" target=3D= "_blank" rel=3D"noopener">CVE-2026-84201</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Vulnerabilities have been identified in the API of HPE Networking Fabri=
c Composer that could potentially allow an unauthenticated remote attacker =
to circumvent existing authentication controls. Successful exploitation cou=
ld allow an attacker to gain administrative privileges leading to complete = compromise of the HPE Networking Fabric Composer host.</td>
<td>2026-09-01</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76657" target=3D= "_blank" rel=3D"noopener">CVE-2026-76657</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability has been identified in the SSH daemon of HPE Networking=
Fabric Composer that could allow an unauthenticated remote attacker to gai=
n administrative access to vulnerable AFC hosts. Successful exploitation co= uld allow an attacker to execute arbitrary commands as a privileged user on=
the underlying operating system leading to complete system compromise.</td=
<td>2026-09-01</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76658" target=3D= "_blank" rel=3D"noopener">CVE-2026-76658</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>An authentication bypass vulnerability exists in the underlying operati=
ng system of HPE Networking Fabric Composer. Successful exploitation could = allow an unauthenticated adjacent attacker to execute arbitrary code as a p= rivileged user on the underlying operating system, leading to complete comp= romise of the AFC host.</td>
<td>2026-09-01</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19766" target=3D= "_blank" rel=3D"noopener">CVE-2026-19766</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an authenticated low privilege operator user t=
o conduct a stored cross-site scripting (XSS) attack against an administrat= ive user of the interface. A successful exploit could allow an attacker to = execute arbitrary script code in a victim's browser in the context of the a= ffected interface.</td>
<td>2026-09-01</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73700" target=3D= "_blank" rel=3D"noopener">CVE-2026-73700</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>An unauthenticated remote code execution vulnerability exists in the un= derlying operating system of HPE Networking Fabric Composer and could be ex= ploited if certain preconditions outside of the attacker's control are met.=
Successful exploitation of this vulnerability could allow an unauthenticat=
ed remote attacker to execute arbitrary code as a privileged user on the un= derlying operating system, leading to complete compromise of the HPE Networ= king Fabric Composer host.</td>
<td>2026-09-01</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73701" target=3D= "_blank" rel=3D"noopener">CVE-2026-73701</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A privilege escalation vulnerability exists in the API of HPE Networkin=
g Fabric Composer. Successful exploitation could allow an authenticated low=
privilege operator user to escalate their permissions to those of an admin= istrative user, leading to complete system compromise.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73702" target=3D= "_blank" rel=3D"noopener">CVE-2026-73702</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated adjacent attacker to conduc=
t a stored cross-site scripting (XSS) attack against a user of the interfac=
e. A successful exploit could allow an attacker to execute arbitrary script=
code in a victim's browser in the context of the affected interface.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73703" target=3D= "_blank" rel=3D"noopener">CVE-2026-73703</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A command sanitization bypass exists in the API of HPE Networking Fabri=
c Composer. Successful exploitation could allow an authenticated low privil= ege operator user to escalate their permissions to those of an administrati=
ve user, leading to complete compromise of the affected system.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73704" target=3D= "_blank" rel=3D"noopener">CVE-2026-73704</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>An arbitrary file write vulnerability in the API of HPE Networking Fabr=
ic Composer could allow an authenticated low privilege operator user to esc= alate privileges. Successful exploitation of this vulnerability may enable = the attacker to execute arbitrary commands on the underlying operating syst= em, leading to complete compromise of the affected system.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73705" target=3D= "_blank" rel=3D"noopener">CVE-2026-73705</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the API of HPE Networking Fabric Composer could allo=
w an unauthenticated remote attacker to obtain limited system information a=
nd to change the state of certain settings of a vulnerable system. Successf=
ul exploitation could allow an attacker to gain insight into internal servi= ces and workflows and to make unauthorized changes that may disrupt the nor= mal operation of the affected service.</td>
<td>2026-09-01</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73706" target=3D= "_blank" rel=3D"noopener">CVE-2026-73706</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Privilege escalation vulnerabilities exist in the API of HPE Networking=
Fabric Composer. Successful exploitation could allow an authenticated low = privilege operator user to complete state-changing actions that should not =
be allowed by their current level of authorization on the platform, includi=
ng changes to the configuration of systems managed by the affected product.= </td>
<td>2026-09-01</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73707" target=3D= "_blank" rel=3D"noopener">CVE-2026-73707</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A business logic vulnerability exists in the API of HPE Networking Fabr=
ic Composer. Successful exploitation could allow an authenticated low privi= lege operator user to obtain elevated privileges and modify settings beyond=
what is authorized by the user's existing privilege level on a vulnerable = system.</td>
<td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73708" target=3D= "_blank" rel=3D"noopener">CVE-2026-73708</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the underlying operating system of HPE Networking Fa= bric Composer could allow an unauthenticated adjacent attacker to run arbit= rary commands on the underlying host if certain preconditions outside of th=
e attacker's control are met. Successful exploitation could allow an attack=
er to execute arbitrary commands on the underlying operating system.</td> <td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73709" target=3D= "_blank" rel=3D"noopener">CVE-2026-73709</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Vulnerabilities in an API endpoint of HPE Networking Fabric Composer co= uld allow an unauthenticated remote attacker to conduct a denial of service=
attack. Successful exploitation could allow an attacker to make limited un= authorized modifications to the underlying operating system and disrupt the=
availability of the affected system, requiring manual intervention to rest= ore functionality.</td>
<td>2026-09-01</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73710" target=3D= "_blank" rel=3D"noopener">CVE-2026-73710</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A privilege escalation vulnerability exists in the API endpoint of HPE = Networking Fabric Composer. Successful exploitation could allow an unauthen= ticated remote attacker to gain administrative privileges leading to comple=
te compromise of the HPE Networking Fabric Composer host.</td> <td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73711" target=3D= "_blank" rel=3D"noopener">CVE-2026-73711</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the API of HPE Networking Fabric Composer could allo=
w an unauthenticated remote attacker to run arbitrary commands on the under= lying host if certain preconditions outside of the attacker's control are m= et. Successful exploitation of this vulnerability could allow an attacker t=
o execute arbitrary commands on the underlying operating system leading to = complete system compromise.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73712" target=3D= "_blank" rel=3D"noopener">CVE-2026-73712</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>Local privilege-escalation vulnerabilities have been discovered in HPE = Networking Fabric Composer. Successful exploitation of these vulnerabilitie=
s could allow a local attacker to achieve arbitrary code execution with roo=
t privileges on the underlying operating system of the affected system.</td=
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73713" target=3D= "_blank" rel=3D"noopener">CVE-2026-73713</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A sensitive information disclosure vulnerability exists in the API of H=
PE Networking Fabric Composer. Successful exploitation could allow an authe= nticated low privilege operator user to access data beyond what is authoriz=
ed by the user's existing privilege level, potentially leading to further u= nauthorized access.</td>
<td>2026-09-01</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73714" target=3D= "_blank" rel=3D"noopener">CVE-2026-73714</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the API of HPE Networking Fabric Composer could allo=
w an unauthenticated remote attacker to conduct a denial of service attack.=
Successful exploitation could allow an attacker to disrupt the availabilit=
y of the affected interface.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73715" target=3D= "_blank" rel=3D"noopener">CVE-2026-73715</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A remote code execution vulnerability exists in the underlying operatin=
g system of HPE Networking Fabric Composer that could allow an unauthentica= ted remote attacker to run arbitrary commands on the underlying host if cer= tain preconditions outside of the attacker's control are met. Successful ex= ploitation could allow an attacker to execute arbitrary commands as a privi= leged user on the underlying operating system, leading to complete compromi=
se of the HPE Networking Fabric Composer host.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73716" target=3D= "_blank" rel=3D"noopener">CVE-2026-73716</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A command injection vulnerability exists in the web-based management in= terface of HPE Networking Fabric Composer that could allow an unauthenticat=
ed remote attacker to run arbitrary commands on the underlying host if cert= ain preconditions outside of the attacker's control are met. Successful exp= loitation could allow an attacker to execute arbitrary commands on the unde= rlying operating system leading to complete system compromise.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73717" target=3D= "_blank" rel=3D"noopener">CVE-2026-73717</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated remote attacker to access s= ensitive information if the attacker can convince an authenticated user of = the interface to interact with a specially crafted URL. Successful exploita= tion could allow an attacker to retrieve information which could be used to=
potentially gain further access to network services supported by HPE Netwo= rking Fabric Composer.</td>
<td>2026-09-01</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73718" target=3D= "_blank" rel=3D"noopener">CVE-2026-73718</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>An arbitrary file write vulnerability exists in the API of HPE Networki=
ng Fabric Composer and could allow an authenticated administrative user to = escalate privileges. Successful exploitation of this vulnerability may enab=
le the attacker to execute arbitrary system commands with root privileges o=
n the underlying operating system.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73719" target=3D= "_blank" rel=3D"noopener">CVE-2026-73719</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>Insecure file operations in the API of HPE Networking Fabric Composer c= ould allow an authenticated remote attacker to achieve remote code executio=
n. Successful exploitation could allow an attacker to execute arbitrary com= mands as a privileged user on the underlying operating system.</td> <td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73720" target=3D= "_blank" rel=3D"noopener">CVE-2026-73720</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Vulnerabilities in the API of HPE Networking Fabric Composer could allo=
w an authenticated remote attacker to conduct SQL injection attacks against=
the HPE Networking Fabric Composer instance. An attacker could exploit the=
se vulnerabilities to obtain and modify sensitive information in the underl= ying database potentially leading to complete compromise of the HPE Network= ing Fabric Composer host.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73721" target=3D= "_blank" rel=3D"noopener">CVE-2026-73721</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>Command injection vulnerabilities in the web-based management interface=
of HPE Networking Fabric Composer could allow an authenticated remote atta= cker to perform command injection against the affected system. Successful e= xploitation could allow an attacker to execute arbitrary commands as a priv= ileged user on the underlying operating system.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73722" target=3D= "_blank" rel=3D"noopener">CVE-2026-73722</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A privilege escalation vulnerability exists in the web-based management=
interface of HPE Networking Fabric Composer. Successful exploitation could=
allow an authenticated low privilege operator user to complete state-chang= ing actions that should not be allowed by their current level of authorizat= ion on the platform.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73723" target=3D= "_blank" rel=3D"noopener">CVE-2026-73723</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Privilege escalation vulnerabilities exist in the API of HPE Networking=
Fabric Composer. Successful exploitation could allow an authenticated low = privilege operator user to change the state of certain settings of a vulner= able system.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73724" target=3D= "_blank" rel=3D"noopener">CVE-2026-73724</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A local privilege-escalation vulnerability has been discovered in HPE N= etworking Fabric Composer. Successful exploitation of this vulnerability co= uld allow a local attacker to achieve arbitrary code execution with root pr= ivileges, leading to a complete compromise of the affected host.</td> <td>2026-09-01</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73725" target=3D= "_blank" rel=3D"noopener">CVE-2026-73725</a></td>
</tr>
<td class=3D"vendor-product">AS203038--looking-glass</td>
<td>Looking Glass is a modern, stateless network-diagnostic platform - a si= ngle self-contained Go binary that fronts a fleet of routers over SSH and e= xposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an = embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, the=
re is an OS Command Injection vulnerability resulting from an unanchored re= gular expression in the input validation layer. This issue has been patched=
in version 1.3.5.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53611" target=3D= "_blank" rel=3D"noopener">CVE-2026-53611</a></td>
</tr>
<td class=3D"vendor-product">Auto x LINE--Auto x LINE</td>
<td>The Auto x LINE WordPress plugin through 1.0.0 does not have authorizat= ion checks in some of its REST endpoints, allowing unauthenticated users to=
call them and update the plugin settings, clear logs etc</td> <td>2026-09-02</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15485" target=3D= "_blank" rel=3D"noopener">CVE-2025-15485</a></td>
</tr>
<td class=3D"vendor-product">AutoAgent --AutoAgent<br>=C2=A0</td>
<td>AutoAgent contains an unauthenticated remote code execution vulnerabili=
ty in the TCP server that binds to all interfaces and executes attacker-sup= plied commands as root. Attackers can connect to the exposed communication = port and execute arbitrary bash commands within the container, gaining acce=
ss to bind-mounted host workspace directories.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86124" target=3D= "_blank" rel=3D"noopener">CVE-2026-86124</a></td>
</tr>
<td class=3D"vendor-product">Automattic--WooCommerce</td>
<td>Improper Neutralization of Special Elements used in an SQL Command ('SQ=
L Injection') vulnerability in Automattic WooCommerce allows Blind SQL Inje= ction. This issue affects WooCommerce: from n/a before 11.0.</td> <td>2026-09-04</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57777" target=3D= "_blank" rel=3D"noopener">CVE-2026-57777</a></td>
</tr>
<td class=3D"vendor-product">Autorius E-goi--Smart Marketing SMS and Newsle= tters Forms</td>
<td>Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Fo= rms <=3D 5.1.24 versions.</td>
<td>2026-08-31</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81756" target=3D= "_blank" rel=3D"noopener">CVE-2026-81756</a></td>
</tr>
<td class=3D"vendor-product">Avaiga--taipy</td>
<td>Taipy configures its socket.io server with wildcard CORS origin and cre= dential flag enabled, allowing any web page to establish credentialed WebSo= cket connections to victim applications. Attackers can open socket.io sessi= ons from arbitrary domains and invoke state variable modifications and acti=
on callbacks without CSRF protection.</td>
<td>2026-09-03</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85183" target=3D= "_blank" rel=3D"noopener">CVE-2026-85183</a></td>
</tr>
<td class=3D"vendor-product">AVideo --AVideo with YPTSocket plugin<br>=C2= =A0</td>
<td>AVideo with YPTSocket plugin enabled contains a cross-site scripting vu= lnerability allowing unauthenticated attackers to execute arbitrary JavaScr= ipt in other users' browsers via the websocket callback mechanism. Attacker=
s can send crafted socket messages with callback names resolving to global = functions like avideoConfirmHTML that accept untrusted data and assign it t=
o innerHTML, achieving script execution in the victim's origin without auth= entication or user interaction.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86188" target=3D= "_blank" rel=3D"noopener">CVE-2026-86188</a></td>
</tr>
<td class=3D"vendor-product">AWS--@amazon-codecatalyst/blueprints.blueprint= </td>
<td>Improper neutralization of special elements used in an OS command (CWE-= 78) in the blueprint resynthesis framework in Amazon Web Services codecatal= yst-blueprints before 0.3.156 might allow a user with permission to commit =
to a repository in the project to execute arbitrary commands in the bluepri=
nt resynthesis environment via shell metacharacters in the owner field of a=
[local] merge strategy entry in a crafted .ownership-file. Version 0.3.156=
removes shell interpretation of the owner field, running the command direc= tly rather than through a shell, and rejects values outside an allowlisted = command form. This eliminates shell metacharacter command injection. To rem= ediate this issue, users should upgrade to version 0.3.156 or later. No act= ion is required for use of the Amazon CodeCatalyst service. Resynthesis run=
s in an isolated per-project environment with scoped credentials, and the s= ervice applies server-side validation there that rejects [local] merge stra= tegy commands outside a restricted allowlisted form, including for blueprin=
t versions published before 0.3.156.</td>
<td>2026-09-03</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85012" target=3D= "_blank" rel=3D"noopener">CVE-2026-85012</a></td>
</tr>
<td class=3D"vendor-product">AWS--aws-fpga</td>
<td>Creation of a temporary file in a directory with insecure permissions i=
n the FPGA management tool installation component in AWS FPGA Development K=
it (aws-fpga) before 2.3.4 might allow local users to execute arbitrary cod=
e with root privileges via crafted shell content placed at a predictable pa=
th in a world-writable temporary directory, which the installation step rea=
ds after elevating its own privileges. To remediate this issue, users shoul=
d upgrade to version 2.3.4.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85028" target=3D= "_blank" rel=3D"noopener">CVE-2026-85028</a></td>
</tr>
<td class=3D"vendor-product">AWS--sagemaker-python-sdk</td>
<td>Cleartext storage of sensitive information in the @step and @remote dec= orator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and=
v2.256.0 might allow an authenticated remote user to extract the HMAC sign= ing key from SageMaker DescribePipeline API responses and forge valid integ= rity signatures for specially crafted function payloads, achieving code exe= cution in another user's pipeline execution context within the same AWS acc= ount.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83551" target=3D= "_blank" rel=3D"noopener">CVE-2026-83551</a></td>
</tr>
<td class=3D"vendor-product">Axolotl--Axolotl=C2=A0<br>=C2=A0</td>
<td>Axolotl through 0.18.0 contains a remote code execution vulnerability i=
n the multipack patch path where trust_remote_code defaults to None instead=
of False, causing the security guard to be bypassed. Attackers can execute=
arbitrary Python code by crafting a malicious Hugging Face model repositor=
y selected as base_model, which is loaded with hardcoded trust_remote_code= =3DTrue during AutoModelForCausalLM.from_pretrained.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86169" target=3D= "_blank" rel=3D"noopener">CVE-2026-86169</a></td>
</tr>
<td class=3D"vendor-product">B&R Industrial Automation GmbH--mapp Servi= ces</td>
<td>Use of Weak Credentials vulnerability in B&R Industrial Automation = GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used i=
n mapp Services: before 6.8.0.</td>
<td>2026-09-03</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79679" target=3D= "_blank" rel=3D"noopener">CVE-2026-79679</a></td>
</tr>
<td class=3D"vendor-product">bdthemes--SigmaForms Pro AI Generated Forms</t=
<td>The SigmaForms Pro - AI Generated Forms plugin for WordPress is vulnera= ble to arbitrary file deletion due to insufficient file path validation in = the delete_submission_files function in all versions up to, and including, = 1.4.11. This makes it possible for unauthenticated attackers to delete arbi= trary files on the server, which can easily lead to remote code execution w= hen the right file is deleted (such as wp-config.php). The malicious path t= raversal URL is submitted via form upload field and stored in the database,=
with deletion triggered when an administrator deletes the submission recor=
d from the admin panel.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78657" target=3D= "_blank" rel=3D"noopener">CVE-2026-78657</a></td>
</tr>
<td class=3D"vendor-product">Bifrost HTTP transport --Bifrost HTTP transpor= t<br>=C2=A0</td>
<td>Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin wh= ose path is an HTTP URL through unauthenticated POST /api/plugins when mana= gement authentication is disabled (the default, governance.auth_config.is_e= nabled=3Dfalse). The shared-object loader treats an http-prefixed path as a=
download URL, writes the body to a temporary .so, and passes it to Go's pl= ugin.Open. After a successful open, optional Init runs immediately with the=
supplied config as the Bifrost process user. On documented dynamically lin= ked builds (DYNAMIC=3D1 / no static-link flags), which the vendor requires = for custom Go plugins, plugin.Open is expected to succeed and this is unaut= henticated remote code execution. On the published statically linked Docker=
image, plugin.Open fails with Dynamic loading not supported, so that build=
class is only server-side request forgery. Attack complexity is High becau=
se the attacker cannot force RCE on the default static image and a loadable=
plugin must match the host Go version, OS, architecture, and linkage. The = 1.6.x HTTP transport line through 1.6.11 does not contain the fix.</td> <td>2026-09-06</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86242" target=3D= "_blank" rel=3D"noopener">CVE-2026-86242</a></td>
</tr>
<td class=3D"vendor-product">Bilibili Desktop--Bilibili Desktop<br>=C2=A0</=
<td>Bilibili Desktop through 1.18.0 disables TLS certificate verification p= rocess-wide and executes unsigned remote JavaScript configuration without i= ntegrity checks. An attacker in an on-path network position can intercept c= onfiguration fetches, inject arbitrary JavaScript executed in the renderer = with access to the privileged IPC bridge, and execute system commands or st= eal login credentials.</td>
<td>2026-09-05</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86185" target=3D= "_blank" rel=3D"noopener">CVE-2026-86185</a></td>
</tr>
<td class=3D"vendor-product">BinaryMuse--toml-node</td>
<td>toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2,=
toml.parse() in lib/compiler.js can be tricked by a table path such as a.b= .y.__proto__.__proto__, allowing traversal from a scalar value into Number.= prototype and Object.prototype. The currentPath tracking value uses both ar= rays and strings, so valueAssignments records a comma-joined path such as a= ,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate= -key guard to miss and attacker-controlled keys to be written to Object.pro= totype. A table-array prefix-clearing path in addTableArray can also erase = guard state before the same __proto__ traversal. Injected properties become=
visible throughout the Node.js process and can cause denial of service, lo= gic or authorization bypass, or code execution when an application contains=
a suitable gadget. This issue is fixed in version 4.1.2.</td> <td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63376" target=3D= "_blank" rel=3D"noopener">CVE-2026-63376</a></td>
</tr>
<td class=3D"vendor-product">BinaryMuse--toml-node</td>
<td>toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0,=
toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/= parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_e= ntry functions recurse through nested arrays and inline tables without a de= pth limit. A remote unauthenticated application parsing an attacker-control= led TOML document containing a few thousand nested arrays or inline tables = can exhaust the Node.js call stack, raise an unexpected RangeError rather t= han the parser's SyntaxError, and terminate an unprotected request worker o=
r process. The corresponding grammar source is src/toml.pegjs, where the ge= nerated parser must be bounded. This issue is fixed in version 4.2.0.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77465" target=3D= "_blank" rel=3D"noopener">CVE-2026-77465</a></td>
</tr>
<td class=3D"vendor-product">BishopFox--joro</td>
<td>Joro is a web exploitation framework. Prior to version 1.1.1, Joro's de= fault proxy mode exposes a local API on 127.0.0.1:9090 that performs no aut= hentication and applies a wildcard CORS policy. Because plugin uploads use = the CORS-safelisted multipart/form-data content type, cross-origin JavaScri=
pt on any page the operator visits can reach privileged endpoints - includi=
ng uploading a native plugin and triggering a restart - directly through th=
e operator's browser, with no preflight or credentials. Since plugins execu=
te on load, this yields unauthenticated remote code execution as the operat= or's user from a single page visit. This issue has been patched in version = 1.1.1.</td>
<td>2026-09-02</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53649" target=3D= "_blank" rel=3D"noopener">CVE-2026-53649</a></td>
</tr>
<td class=3D"vendor-product">blinkospace--blinko</td>
<td>Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in m= ultiple tRPC procedures (message.list, message.update, message.delete, mess= age.clearAfter in server/routerTrpc/message.ts and conversation.clearMessag=
es in server/routerTrpc/conversation.ts). Although these procedures require=
authentication, they query the database by caller-supplied conversation or=
message ID without verifying that the resource belongs to the requesting a= ccount. Any authenticated user can therefore read another user's full AI ch=
at history, modify individual message content, and delete or wipe entire co= nversations by enumerating sequential integer IDs.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85607" target=3D= "_blank" rel=3D"noopener">CVE-2026-85607</a></td>
</tr>
<td class=3D"vendor-product">bluewave-labs--Checkmate</td>
<td>Checkmate through 3.11.0 omits the isAllowed role guard middleware on m= aintenance-window, notification, and check-deletion routes, allowing read-o= nly users to perform administrative actions. Attackers with user-role sessi= ons can create arbitrary maintenance windows to silence alerts, modify noti= fication channels, and delete monitor check history to erase incident evide= nce.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85390" target=3D= "_blank" rel=3D"noopener">CVE-2026-85390</a></td>
</tr>
<td class=3D"vendor-product">bookstackapp--bookstack</td>
<td>BookStack before 26.05.4 contains a stored cross-site scripting vulnera= bility in the drawing upload endpoint that accepts unvalidated base64 conte=
nt and stores it without content inspection. Attackers with editor permissi= ons can upload SVG files containing scripts that execute in administrator b= rowsers when accessed through the image gallery API without content-type va= lidation or CSP headers.</td>
<td>2026-09-02</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84695" target=3D= "_blank" rel=3D"noopener">CVE-2026-84695</a></td>
</tr>
<td class=3D"vendor-product">BPF--BPF=C2=A0<br>=C2=A0</td>
<td>In BPF instructions that load/store a value from/to a scratch memory re= gister the register index is an unsigned 32-bit integer and must not exceed=
15, but libpcap BPF interpreter does not validate the value. In particular=
uncommon use cases a crafted filter program can cause the interpreter to t=
ry reading and writing the OS process memory in the 16GiB starting at the c= urrent stack frame on 64-bit architectures and in the entire address space =
on 32-bit architectures.</td>
<td>2026-09-05</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-0799" target=3D"= _blank" rel=3D"noopener">CVE-2026-0799</a></td>
</tr>
<td class=3D"vendor-product">Bricksforge.--Bricksforge</td>
<td>Subscriber Privilege Escalation in Bricksforge <=3D 3.1.8.8 versions= .</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84814" target=3D= "_blank" rel=3D"noopener">CVE-2026-84814</a></td>
</tr>
<td class=3D"vendor-product">brightvesseldev--Quick Event Manager</td>
<td>Unauthenticated Broken Access Control in Quick Event Manager <=3D 9.=
17 versions.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84847" target=3D= "_blank" rel=3D"noopener">CVE-2026-84847</a></td>
</tr>
<td class=3D"vendor-product">brightvesseldev--Quick Event Manager</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <=
=3D 9.17 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84848" target=3D= "_blank" rel=3D"noopener">CVE-2026-84848</a></td>
</tr>
<td class=3D"vendor-product">c-ares--c-ares</td>
<td>c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.=
7, a use-after-free / double-free in c-ares' query-completion handling. The=
same flaw - a query's callback being invoked while the query is still link=
ed in the channel's internal lookup structures - is present at multiple poi= nts in the resend/finish path (timeout handling, response handling, and que=
ry dispatch). If the query, or for ares_getaddrinfo() the owning host_query=
, is freed as a side effect of that callback, it is then accessed and/or fr= eed a second time. This vulnerability is fixed in ver 1.34.7.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33630" target=3D= "_blank" rel=3D"noopener">CVE-2026-33630</a></td>
</tr>
<td class=3D"vendor-product">camel-ai--owl</td>
<td>OWL's DocumentProcessingToolkit contains a server-side request forgery = vulnerability in the extract_document_content tool that fetches caller-supp= lied URLs with no scheme, host, or IP filtering. Attackers can inject malic= ious URLs through prompt injection to make the server fetch internal resour= ces, with responses returned to the agent context.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85675" target=3D= "_blank" rel=3D"noopener">CVE-2026-85675</a></td>
</tr>
<td class=3D"vendor-product">Canva--Canva</td>
<td>The Canva Android App before 2.376.0 allowed an external origin to be l= oaded in a privileged WebView. A threat actor who controls the page loaded =
by the user is able to communicate with Canva using the user's session.</td=
<td>2026-09-04</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85085" target=3D= "_blank" rel=3D"noopener">CVE-2026-85085</a></td>
</tr>
<td class=3D"vendor-product">Canva--Canva</td>
<td>The Canva Android App before 2.376.0 did not restrict the headers retur= ned to an external origin running in a privileged WebView. A threat actor w= ith control of the WebView could access a user's session.</td> <td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85094" target=3D= "_blank" rel=3D"noopener">CVE-2026-85094</a></td>
</tr>
<td class=3D"vendor-product">Casdoor--Casdoor</td>
<td>A vulnerability has been found in Casdoor up to 4.0.0. This affects an = unknown function of the file controllers/resource.go of the component uploa= d-resource API. Such manipulation leads to missing authentication. It is po= ssible to launch the attack remotely. The exploit has been disclosed to the=
public and may be used. The vendor deleted the GitHub issue for this vulne= rability without any explanation. Afterwards the vendor was contacted early=
about this disclosure via email but did not respond in any way.</td> <td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84423" target=3D= "_blank" rel=3D"noopener">CVE-2026-84423</a></td>
</tr>
<td class=3D"vendor-product">Chanjet--CRM</td>
<td>A flaw has been found in Chanjet CRM up to 20260707. This issue affects=
some unknown processing of the file jxf_dump_table.php. This manipulation =
of the argument gblOrgID causes sql injection. Remote exploitation of the a= ttack is possible. The exploit has been published and may be used. The vend=
or was contacted early about this disclosure but did not respond in any way= .</td>
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84111" target=3D= "_blank" rel=3D"noopener">CVE-2026-84111</a></td>
</tr>
<td class=3D"vendor-product">chewkeanho--software-actualizer</td> <td>(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fai= l-open password validation vulnerability in the Alpha user and root user pa= ssword loops of Shell/debian-minbase-install.sh. The installer invokes mkpa= sswd to generate yescrypt password hashes but does not check the command's = return value and unconditionally accepts the result. If mkpasswd fails to g= enerate a yescrypt hash, for example because an incompatible mkpasswd imple= mentation or an environment without yescrypt support is used, the resulting=
password hash variable can be empty and the build proceeds. The resulting = image can therefore contain empty password fields for the root and alpha ac= counts, potentially permitting passwordless authentication depending on the=
authentication configuration.</td>
<td>2026-09-04</td>
<td>7.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85649" target=3D= "_blank" rel=3D"noopener">CVE-2026-85649</a></td>
</tr>
<td class=3D"vendor-product">chroma-core--chroma</td>
<td>Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters = max_neighbors, ef_construction, and ef_search in collection-create requests=
. Unauthenticated attackers can supply arbitrarily large parameter values t=
o exhaust server memory and cause denial of service during index compaction= .</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85664" target=3D= "_blank" rel=3D"noopener">CVE-2026-85664</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20274 are related to improper resour=
ce control issues that are grouped under the Common Weakness Enumeration (C= WE) CWE-664.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20274" target=3D= "_blank" rel=3D"noopener">CVE-2026-20274</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20279 are related to improper access=
control issues that are grouped under the Common Weakness Enumeration (CWE=
) CWE-284.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20279" target=3D= "_blank" rel=3D"noopener">CVE-2026-20279</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20275 are related to incorrect calcu= lation issues that are grouped under the Common Weakness Enumeration (CWE) = CWE-682.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20275" target=3D= "_blank" rel=3D"noopener">CVE-2026-20275</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20276 are related to insufficient co= ntrol flow management issues that are grouped under the Common Weakness Enu= meration (CWE) CWE-691.</td>
<td>2026-09-02</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20276" target=3D= "_blank" rel=3D"noopener">CVE-2026-20276</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20277 are related to protection mech= anism failure issues that are grouped under the Common Weakness Enumeration=
(CWE) CWE-693.</td>
<td>2026-09-02</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20277" target=3D= "_blank" rel=3D"noopener">CVE-2026-20277</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the Cisco IOS XR Software engineering team has conducted a compre= hensive internal security review. This review resulted in a software harden= ing releases that address multiple internally discovered vulnerabilities. T=
he vulnerabilities tracked by CVE-2026-20278 are related to improper neutra= lization issues that are grouped under the Common Weakness Enumeration (CWE=
) CWE-707.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20278" target=3D= "_blank" rel=3D"noopener">CVE-2026-20278</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco IOS XR Software</td>
<td>As part of Cisco's ongoing commitment to proactive security and product=
quality, the&nbsp;Cisco IOS XR Software engineering team has conducted=
a comprehensive internal security review. This review resulted in a softwa=
re hardening releases that address multiple internally discovered vulnerabi= lities. The vulnerabilities tracked by CVE-2026-20280 are related to improp=
er checking or handling of exceptional condition issues that are grouped un= der the Common Weakness Enumeration (CWE) CWE-703.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20280" target=3D= "_blank" rel=3D"noopener">CVE-2026-20280</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco NX-OS Software</td>
<td>A vulnerability in the Silicon One integration for Cisco Nexus 9000 Ser= ies Switches could allow an unauthenticated, remote attacker to execute cod=
e with&nbsp;root privileges. This vulnerability exists because TCP port=
s 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routin=
g and forwarding (VRF). A successful exploit could allow the attacker to co= nnect to an affected device and send crafted input that could be executed a=
s code with&nbsp;root privileges. The exploitation of this vulnerabilit=
y could also cause the S1HAL process to crash, which could cause the device=
to reload.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20212" target=3D= "_blank" rel=3D"noopener">CVE-2026-20212</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Session Initiation Protocol (SIP)=
Software</td>
<td>A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 an=
d 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session In= itiation Protocol (SIP) Software could allow an unauthenticated, remote att= acker to cause a denial of service (DoS) condition on an affected device. T= his vulnerability is due to improper memory management when an affected dev= ice processes HTTP packets. An attacker could exploit this vulnerability by=
sending a continuous stream of crafted HTTP packets to the device. A succe= ssful exploit could allow the attacker to cause the affected device to cont= inuously consume memory, resulting in a DoS condition.&nbsp;A manual re= boot of the device is required to recover from this condition. Note: For th=
is vulnerability to be exploitable, the phone must be registered to Cisco U= nified Communications Manager (Unified CM) and have Web Access enabled. Web=
Access is disabled by default.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20281" target=3D= "_blank" rel=3D"noopener">CVE-2026-20281</a></td>
</tr>
<td class=3D"vendor-product">Classified Listing--Classified Listing</td>
<td>The Classified Listing WordPress plugin before 6.1.1 does not verify th=
at the caller owns or can edit the target listing before its AI image-editi=
ng AJAX action deletes or attaches media, allowing any authenticated user, = including a subscriber, to permanently delete attachments from, and attach = files to, any listing owned by another user.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16281" target=3D= "_blank" rel=3D"noopener">CVE-2026-16281</a></td>
</tr>
<td class=3D"vendor-product">Cleo--Harmony</td>
<td>A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected = element is an unknown function of the file /api/connections of the componen=
t JWT Refresh Token Handler. Performing a manipulation of the argument Bear=
er results in improper privilege management. The attack is possible to be c= arried out remotely. The exploit has been made public and could be used. Up= grading to version 5.8.1.11 is sufficient to fix this issue. It is recommen= ded to upgrade the affected component.</td>
<td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84115" target=3D= "_blank" rel=3D"noopener">CVE-2026-84115</a></td>
</tr>
<td class=3D"vendor-product">cleverange_auth--cleverange_auth v0.1.10</td> <td>An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause =
a denial of service via the account_verification function and the accounts/= models.py component</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51788" target=3D= "_blank" rel=3D"noopener">CVE-2026-51788</a></td>
</tr>
<td class=3D"vendor-product">Cobham--SATCOM VSAT7090 Maritime Satellite Rou= ter</td>
<td>A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satelli=
te Router up to 20260704. This issue affects the function c_set_reports_dec= ode of the file mail-report.sh of the component JSON Parsing. The manipulat= ion of the argument sender/recipients results in command injection. It is p= ossible to launch the attack remotely. The exploit is now public and may be=
used. The vendor was contacted early about this disclosure but did not res= pond in any way.</td>
<td>2026-09-01</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83772" target=3D= "_blank" rel=3D"noopener">CVE-2026-83772</a></td>
</tr>
<td class=3D"vendor-product">code-projects-- Content Management System 1.0<=
<td>A security flaw has been discovered in code-projects Content Management=
System 1.0. The affected element is an unknown function of the file /login= .php. The manipulation of the argument user_name results in sql injection. = The attack can be executed remotely. The exploit has been released to the p= ublic and may be used for attacks.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86168" target=3D= "_blank" rel=3D"noopener">CVE-2026-86168</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Doctor Appointment System</td> <td>A vulnerability was identified in code-projects Doctor Appointment Syst=
em 1.0. This vulnerability affects unknown code of the file /patient_login.= php. The manipulation of the argument email leads to sql injection. The att= ack may be initiated remotely. The exploit is publicly available and might =
be used.</td>
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85225" target=3D= "_blank" rel=3D"noopener">CVE-2026-85225</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Doctor Appointment System</td> <td>A vulnerability was detected in code-projects Doctor Appointment System=
1.0. This vulnerability affects unknown code of the file /patient/booking.= php. The manipulation of the argument doc_id results in sql injection. The = attack may be launched remotely. The exploit is now public and may be used.= </td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85402" target=3D= "_blank" rel=3D"noopener">CVE-2026-85402</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Doctor Appointment System</td> <td>A flaw has been found in code-projects Doctor Appointment System 1.0. T= his issue affects some unknown processing of the file /contactus.php. This = manipulation of the argument firstname causes sql injection. Remote exploit= ation of the attack is possible. The exploit has been published and may be = used.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85403" target=3D= "_blank" rel=3D"noopener">CVE-2026-85403</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Hospital Information System</td=
<td>A vulnerability was determined in code-projects Hospital Information Sy= stem 1.0. This impacts the function findBySearch of the file addReq.php. Th=
is manipulation of the argument Search causes sql injection. It is possible=
to initiate the attack remotely. The exploit has been publicly disclosed a=
nd may be utilized.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85397" target=3D= "_blank" rel=3D"noopener">CVE-2026-85397</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Hospital Information System</td=
<td>A vulnerability was identified in code-projects Hospital Information Sy= stem 1.0. Affected is the function viewReq of the file viewReq.php. Such ma= nipulation of the argument ID leads to sql injection. It is possible to lau= nch the attack remotely. The exploit is publicly available and might be use= d.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85398" target=3D= "_blank" rel=3D"noopener">CVE-2026-85398</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Hospital Information System</td=
<td>A security flaw has been discovered in code-projects Hospital Informati=
on System 1.0. Affected by this vulnerability is the function getSinglePres=
p of the file includes/presp/PrespController.php. Performing a manipulation=
of the argument ID results in sql injection. The attack can be initiated r= emotely. The exploit has been released to the public and may be used for at= tacks.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85399" target=3D= "_blank" rel=3D"noopener">CVE-2026-85399</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Online Shopping System</td>
<td>A vulnerability was determined in code-projects Online Shopping System = 1.0. Affected by this issue is some unknown functionality of the file /acti= on.php of the component Search Functionality. This manipulation of the argu= ment keyword causes sql injection. It is possible to initiate the attack re= motely. The exploit has been publicly disclosed and may be utilized.</td> <td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82701" target=3D= "_blank" rel=3D"noopener">CVE-2026-82701</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Task Management System<br>=C2= =A0</td>
<td>A vulnerability has been found in code-projects Task Management System =
In PHP 1.0. Affected by this vulnerability is an unknown functionality of t=
he file /index.php of the component Login. The manipulation of the argument=
email leads to sql injection. The attack can be initiated remotely. The ex= ploit has been disclosed to the public and may be used.</td> <td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86180" target=3D= "_blank" rel=3D"noopener">CVE-2026-86180</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Vehicle Management System</td> <td>A vulnerability was detected in code-projects Vehicle Management System=
1.0. The affected element is an unknown function of the file /busprofile.p= hp. Performing a manipulation of the argument busid results in sql injectio=
n. It is possible to initiate the attack remotely. The exploit is now publi=
c and may be used.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85516" target=3D= "_blank" rel=3D"noopener">CVE-2026-85516</a></td>
</tr>
<td class=3D"vendor-product">Colorful--iGameCenter</td>
<td>A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulner= ability affects the function sub_11504 in the library WinRing0x64.sys of th=
e component IOCTL Dispatch. Performing a manipulation of the argument Physi= calAddress/AlignNumer/AlignSize results in improper privilege management. A= ttacking locally is a requirement.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82628" target=3D= "_blank" rel=3D"noopener">CVE-2026-82628</a></td>
</tr>
<td class=3D"vendor-product">Coolify --Coolify=C2=A0<br>=C2=A0</td>
<td>Coolify through 4.3.17 contains an authentication bypass vulnerability =
in the OAuth callback handler that signs users into existing accounts based=
solely on email address without verifying provider assertions or binding O= Auth identities. Attackers can register a victim's email address on any ena= bled OAuth provider to obtain authenticated sessions as that user, bypassin=
g password requirements and two-factor authentication.</td>
<td>2026-09-05</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86117" target=3D= "_blank" rel=3D"noopener">CVE-2026-86117</a></td>
</tr>
<td class=3D"vendor-product">coollabsio--coolify</td>
<td>Coolify before 4.2.0 fails to properly escape environment variable key = names in Docker commands executed over SSH on managed servers. Authenticate=
d attackers can inject shell metacharacters into environment variable keys =
to execute arbitrary commands on the server host outside containers.</td> <td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84694" target=3D= "_blank" rel=3D"noopener">CVE-2026-84694</a></td>
</tr>
<td class=3D"vendor-product">Cozmoslabs--Profile Builder Plugin</td>
<td>A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.= 16.1 on WordPress. The impacted element is the function wppb_ajax_simple_av= atar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Up= load AJAX Handler. Performing a manipulation results in unrestricted upload=
. The attack is possible to be carried out remotely. The exploit has been m= ade public and could be used. Upgrading to version 3.16.2 is sufficient to = resolve this issue. It is suggested to upgrade the affected component.</td> <td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82607" target=3D= "_blank" rel=3D"noopener">CVE-2026-82607</a></td>
</tr>
<td class=3D"vendor-product">cpanel -- cpanel</td>
<td>Eval injection in cPanel 11.138.0.0 and earlier allows remote authentic= ated users to execute arbitrary code as root.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-65643" target=3D= "_blank" rel=3D"noopener">CVE-2026-65643</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS before 5.10.11 fails to validate the admin flag during user r= egistration, allowing it to persist from deactivated admin accounts. Attack= ers can register with a deactivated admin's email address to inherit admini= strator privileges when public registration and disabled email verification=
are configured.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84795" target=3D= "_blank" rel=3D"noopener">CVE-2026-84795</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions before 5.10.11 contain a site scope bypass vulnerabi= lity in GraphQL entry mutation resolvers that fail to validate siteId throu=
gh ArgumentManager::prepareArguments(). Attackers with tokens scoped to one=
site can read, modify, or delete entries across unauthorized sites by pass= ing siteId directly in mutation arguments.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84796" target=3D= "_blank" rel=3D"noopener">CVE-2026-84796</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions before 5.10.11 fail to validate admin status in the = actionGetPasswordResetUrl endpoint, allowing non-admin users with administr= ateUsers permission to mint password reset URLs for administrator accounts.=
Attackers can generate a valid reset URL for any admin user and set a new = password via actionSetPassword, which validates only the verification code = without checking the caller's session, enabling complete control-panel take= over.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84801" target=3D= "_blank" rel=3D"noopener">CVE-2026-84801</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions before 5.10.11 lack authorization checks in the asse= ts/move-asset endpoint when force=3D1 is supplied. Authenticated users with= out peer asset permissions can move their own assets into other users' fold= ers and force deletion of conflicting files, allowing unauthorized asset de= letion and replacement.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84794" target=3D= "_blank" rel=3D"noopener">CVE-2026-84794</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions >=3D 5.0.0-RC1 and < 5.10.11 fail to perform a=
n independent authorization check in ElementsController::actionDeleteForSit= e(). The method loads an element with checkForProvisionalDraft enabled and = runs the deletion authorization check against the user's own provisional dr= aft (which only verifies draft ownership), then propagates the deletion to = the canonical element without re-checking permissions. As a result, an auth= enticated user who has viewEntries, viewPeerEntries, saveEntries, savePeerE= ntries, and editSite permissions but lacks the deleteEntriesForSite permiss= ion can hard-delete a canonical entry's site record (and, for single-site e= ntries, the full element and content), which is irrecoverable via Craft's r= ecycle bin.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84798" target=3D= "_blank" rel=3D"noopener">CVE-2026-84798</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions >=3D 5.0.0-RC1 and < 5.10.11 contain a missing=
authorization vulnerability in AssetsController::actionReplaceFile. When a=
request supplies sourceAssetId and targetFilename but omits assetId, the t= arget asset is resolved by folder and filename after the permission checks = execute, so the replacePeerFiles permission is never enforced. An authentic= ated low-privilege author with only the replaceFiles permission on a shared=
folder can overwrite the content of a peer's asset file (located in the sa=
me folder) with attacker-controlled bytes. Fixed in 5.10.11.</td> <td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84800" target=3D= "_blank" rel=3D"noopener">CVE-2026-84800</a></td>
</tr>
<td class=3D"vendor-product">crcn--sift.js</td>
<td>sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks = the object prototype chain, and dispatches any matched operator key includi=
ng $where. The $where operation compiles a string value into a function usi=
ng new Function unless CSP_ENABLED is set (not set by default). As a result=
, if a prototype-pollution primitive elsewhere in the process sets Object.p= rototype.$where to a malicious string, even benign filter calls such as sif= t({}) execute arbitrary JavaScript. Additionally, passing an untrusted quer=
y object containing a string $where directly to sift results in code execut= ion under the default configuration.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85625" target=3D= "_blank" rel=3D"noopener">CVE-2026-85625</a></td>
</tr>
<td class=3D"vendor-product">crmeb--CRMEB</td>
<td>CRMEB contains an authentication bypass vulnerability in the verifyAuth=
() method of SystemRoleServices.php that returns true from both conditional=
branches. Sub-administrators and accounts with no roles can access restric= ted admin endpoints by exploiting the inert role check that always permits = requests.</td>
<td>2026-09-03</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85212" target=3D= "_blank" rel=3D"noopener">CVE-2026-85212</a></td>
</tr>
<td class=3D"vendor-product">crystaldba--postgres-mcp</td>
<td>Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability = where function-name validation is not applied to RangeFunction nodes in FRO=
M clauses. Attackers can execute file-reading functions like pg_read_file t= hrough FROM-clause syntax to read arbitrary files despite restricted-mode p= rotections.</td>
<td>2026-09-04</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85620" target=3D= "_blank" rel=3D"noopener">CVE-2026-85620</a></td>
</tr>
<td class=3D"vendor-product">cu--silicon</td>
<td>A vulnerability was identified in cu silicon up to 0.1.5. Affected by t= his vulnerability is the function create_app of the file views.py of the co= mponent edit Endpoint. Such manipulation leads to missing authentication. T=
he attack may be performed from remote. The exploit is publicly available a=
nd might be used. The vendor was contacted early about this disclosure but = did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82919" target=3D= "_blank" rel=3D"noopener">CVE-2026-82919</a></td>
</tr>
<td class=3D"vendor-product">Cua computer-server--Cua computer-server=C2=A0= <br>=C2=A0</td>
<td>Cua computer-server versions before 0.3.42 skip authentication when the=
CONTAINER_NAME environment variable is unset and bind to all interfaces by=
default, allowing unauthenticated attackers to execute arbitrary commands.=
Attackers can reach TCP port 8000 to run shell commands via the run_comman=
d endpoint, read and write arbitrary files through file operation endpoints=
, and access interactive PTY shells without authentication.</td> <td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86121" target=3D= "_blank" rel=3D"noopener">CVE-2026-86121</a></td>
</tr>
<td class=3D"vendor-product">cyanheads--git-mcp-server</td>
<td>git-mcp-server 2.15.1 contains an argument injection vulnerability in t=
he ref and object parameters of git_log, git_diff, and git_show tools that = lack leading-dash validation. Attackers can inject git command-line options=
like --output=3D to write files outside the repository to arbitrary paths = accessible by the process.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85626" target=3D= "_blank" rel=3D"noopener">CVE-2026-85626</a></td>
</tr>
<td class=3D"vendor-product">cypht-org--cypht</td>
<td>Cypht before 2.12.2 contains a PHP object injection vulnerability that = allows authenticated attackers to execute arbitrary operating system comman=
ds by supplying a crafted PHP object graph in the back_query GET parameter =
of the logout handler. Attackers can pass a base64-encoded serialized paylo=
ad through this parameter, which is decoded and passed directly to unserial= ize() without an allow-list, signature check, or type restriction, enabling=
gadget-chain exploitation to achieve remote code execution as the web serv=
er process.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71981" target=3D= "_blank" rel=3D"noopener">CVE-2026-71981</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DIR-825M</td>
<td>A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the functi=
on sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the componen=
t LTE Module Firmware Upgrade. This manipulation of the argument fota_url c= auses stack-based buffer overflow. The attack is possible to be carried out=
remotely. The exploit has been published and may be used.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82593" target=3D= "_blank" rel=3D"noopener">CVE-2026-82593</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DIR-825M</td>
<td>A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vu= lnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of th=
e component System Command Execution. Performing a manipulation of the argu= ment sysCmd results in command injection. It is possible to initiate the at= tack remotely. The exploit has been made public and could be used.</td> <td>2026-08-31</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82595" target=3D= "_blank" rel=3D"noopener">CVE-2026-82595</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-320 ShareCenter</td>
<td>A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. T= his affects an unknown part of the file /cgi/file_sharing.cgi of the compon= ent File Sharing. Executing a manipulation of the argument fileurl can lead=
to os command injection. The attack can be launched remotely. The exploit = has been publicly disclosed and may be utilized.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85224" target=3D= "_blank" rel=3D"noopener">CVE-2026-85224</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-320L</td>
<td>A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and=
DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-b= in/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of=
the argument upIsoRootPath results in os command injection. The attack can=
be executed remotely. The exploit is now public and may be used.</td> <td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82689" target=3D= "_blank" rel=3D"noopener">CVE-2026-82689</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-320L</td>
<td>A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L a=
nd DNS-345 up to 20260717. Affected by this issue is some unknown functiona= lity of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such=
manipulation of the argument f_ups_ip leads to os command injection. The a= ttack may be performed from remote. The exploit has been disclosed to the p= ublic and may be used.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82691" target=3D= "_blank" rel=3D"noopener">CVE-2026-82691</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-327L</td>
<td>A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. A= ffected by this vulnerability is an unknown functionality of the file /cgi-= bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command i= njection. The attack is possible to be carried out remotely. The exploit ha=
s been published and may be used.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82690" target=3D= "_blank" rel=3D"noopener">CVE-2026-82690</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-340L</td>
<td>A security vulnerability has been detected in D-Link DNS-340L and DNS-3=
45 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of th=
e file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. Th=
e manipulation of the argument f_sharename/f_target/f_name leads to os comm= and injection. Remote exploitation of the attack is possible. The exploit h=
as been disclosed publicly and may be used.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82688" target=3D= "_blank" rel=3D"noopener">CVE-2026-82688</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-340L</td>
<td>A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717=
. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performi=
ng a manipulation of the argument alias/username/password/volume_location r= esults in os command injection. It is possible to initiate the attack remot= ely. The exploit has been made public and could be used.</td> <td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82692" target=3D= "_blank" rel=3D"noopener">CVE-2026-82692</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-340L</td>
<td>A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by = this vulnerability is an unknown functionality of the file /cgi-bin/addon_c= enter.cgi of the component Add-On Center. Such manipulation of the argument=
f_name/f_url/f_flag/f_login_user leads to os command injection. It is poss= ible to launch the attack remotely. The exploit has been disclosed to the p= ublic and may be used.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85222" target=3D= "_blank" rel=3D"noopener">CVE-2026-85222</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DNS-340L</td>
<td>A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this = issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the=
component CGI Handler. Performing a manipulation of the argument callback_= url/sync_interval results in os command injection. The attack can be initia= ted remotely. The exploit has been made public and could be used.</td> <td>2026-09-03</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85223" target=3D= "_blank" rel=3D"noopener">CVE-2026-85223</a></td>
</tr>
<td class=3D"vendor-product">D-Link--DSM-G600</td>
<td>A weakness has been identified in D-Link DSM-G600 1.01. This affects an=
unknown function of the file /load_file.cgi of the component Multipart Han= dler. Executing a manipulation can lead to out-of-bounds write. The attack = may be launched remotely. The exploit has been made available to the public=
and could be used for attacks.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82680" target=3D= "_blank" rel=3D"noopener">CVE-2026-82680</a></td>
</tr>
<td class=3D"vendor-product">datalab-to--marker</td>
<td>marker through 2.0.0 contains a path traversal vulnerability in the Fas= tAPI /marker/upload handler that fails to sanitize the file.filename parame= ter. Unauthenticated attackers can supply filenames containing directory tr= aversal sequences to write arbitrary files to any location or delete existi=
ng files on the system.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85684" target=3D= "_blank" rel=3D"noopener">CVE-2026-85684</a></td>
</tr>
<td class=3D"vendor-product">datalab-to--surya</td>
<td>surya 0.22.1 screenshot server contains an unauthenticated arbitrary fi=
le read vulnerability in the /info, /page, and /process routes that accept = raw file_path parameters. Attackers can read any image or PDF file on the h= ost by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocumen=
t, obtaining rendered contents as base64 and using /info as an existence or= acle.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85687" target=3D= "_blank" rel=3D"noopener">CVE-2026-85687</a></td>
</tr>
<td class=3D"vendor-product">dbgate--dbgate</td>
<td>DbGate fails to validate jslid parameters in the jsldata controller, al= lowing authenticated users to read and write arbitrary files via file:// sc= heme resolution. Attackers can exploit getJslFileName() to bypass directory=
containment and access sensitive files including encrypted database creden= tials stored in connections configuration.</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85176" target=3D= "_blank" rel=3D"noopener">CVE-2026-85176</a></td>
</tr>
<td class=3D"vendor-product">Delinea--Secret Server (On-Prem)</td>
<td>Under specific conditions, an attacker can register an attacker-control= led FIDO2 credential against a target account and then authenticate as that=
user. This issue affects on-premises deployments only.</td> <td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19117" target=3D= "_blank" rel=3D"noopener">CVE-2026-19117</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Manager</td>
<td>Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a = stack buffer overflow vulnerability in file-level restore agent. A high pri= vileged remote attacker could potentially exploit this vulnerability, leadi=
ng to Information disclosure.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73600" target=3D= "_blank" rel=3D"noopener">CVE-2026-73600</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Missing Authentication for Critical Function=
vulnerability. An unauthenticated attacker with network access to the rest= ricted management interface could potentially exploit this vulnerability to=
read internal system information from the appliance filesystem. This is a = Critical vulnerability as it could expose sensitive information and credent= ials which allow full administrative access to the array.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58574" target=3D= "_blank" rel=3D"noopener">CVE-2026-58574</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore SDNAS contains a Missing Authentication for Critical Fu= nction vulnerability. An unauthenticated attacker with remote access could = potentially exploit this vulnerability, leading to Filesystem access.</td> <td>2026-09-01</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79687" target=3D= "_blank" rel=3D"noopener">CVE-2026-79687</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore, an Incorrect Authorization vulnerability. A low privil= eged attacker with remote access could potentially exploit this vulnerabili= ty, leading to Elevation of privileges.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58566" target=3D= "_blank" rel=3D"noopener">CVE-2026-58566</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an OS Command Injection vulnerability. An auth= enticated user with limited privileges could potentially exploit this vulne= rability to execute arbitrary commands with root privileges.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58567" target=3D= "_blank" rel=3D"noopener">CVE-2026-58567</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an Inclusion of Functionality from Untrusted C= ontrol Sphere vulnerability. An authenticated user with limited privileges = could potentially exploit this vulnerability to execute arbitrary code with=
root privileges..</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58569" target=3D= "_blank" rel=3D"noopener">CVE-2026-58569</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an OS Command Injection vulnerability. An auth= enticated user with limited privileges could potentially exploit this vulne= rability to execute arbitrary commands with root privileges.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58571" target=3D= "_blank" rel=3D"noopener">CVE-2026-58571</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Code Injection vulnerability. An authenticat=
ed user with limited privileges could potentially exploit this vulnerabilit=
y to execute arbitrary code with root privileges.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58572" target=3D= "_blank" rel=3D"noopener">CVE-2026-58572</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an Authentication Bypass by Spoofing vulnerabi= lity. An authenticated attacker could potentially exploit this vulnerabilit=
y to escalate privileges to Administrator.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58575" target=3D= "_blank" rel=3D"noopener">CVE-2026-58575</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an Incorrect Authorization vulnerability. An a= uthenticated attacker with low privileges could potentially exploit this vu= lnerability to invoke administrator-only operations, leading to privilege e= scalation.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76111" target=3D= "_blank" rel=3D"noopener">CVE-2026-76111</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Command Injection vulnerability. An authenti= cated user with limited privileges could potentially exploit this vulnerabi= lity to execute arbitrary commands with root privileges.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79682" target=3D= "_blank" rel=3D"noopener">CVE-2026-79682</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Protection Mechanism Failure vulnerability. =
An authenticated user with limited privileges could potentially exploit thi=
s vulnerability to write attacker-controlled content to arbitrary filesyste=
m paths.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79683" target=3D= "_blank" rel=3D"noopener">CVE-2026-79683</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Protection Mechanism Failure vulnerability. =
An authenticated user with limited privileges could potentially exploit thi=
s vulnerability to bypass access restrictions and gain escalated privileges= .</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79684" target=3D= "_blank" rel=3D"noopener">CVE-2026-79684</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains a Protection Mechanism Failure vulnerability. =
An authenticated user with limited privileges could potentially exploit thi=
s vulnerability to bypass access restrictions and gain escalated privileges= .</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79686" target=3D= "_blank" rel=3D"noopener">CVE-2026-79686</a></td>
</tr>
<td class=3D"vendor-product">Developer Tools--Developer Tools</td>
<td>The Developer Tools WordPress plugin through 1.1.3 contains an unauthen= ticated arbitrary file upload vulnerability in the bundled SWFUpload compon= ent</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-9314" target=3D"= _blank" rel=3D"noopener">CVE-2025-9314</a></td>
</tr>
<td class=3D"vendor-product">devitemsllc--Support Genix Helpdesk, AI Chatbo=
t, Knowledge Base & Customer Support Ticketing System</td>
<td>The Support Genix - Helpdesk, AI Chatbot, Knowledge Base & Customer=
Support Ticketing System plugin for WordPress is vulnerable to Authenticat= ion Bypass leading to Administrator Account Takeover in all versions up to,=
and including, 1.4.52 via the `guest_ticket_login()` function and its `p` = parameter. This is due to the site-wide AES-256-CBC encryption key being de= rived from only three two-digit `wp_rand(10, 99)` values and a Unix timesta=
mp via `md5()` - yielding approximately 19.5 bits of entropy - combined wit=
h a deterministic IV derived from the password, no authentication tag on th=
e ciphertext, and no capability check, nonce, or session validation on the = publicly reachable `/sgnix/?p=3D<token>` endpoint. This makes it poss= ible for authenticated attackers, with subscriber-level access and above, w=
ho can obtain a single legitimate guest ticket token as a known-plaintext o= racle and bound the plugin activation timestamp, to exhaust the ~729,000-ca= ndidate keyspace entirely offline, recover the site-wide encryption key, an=
d forge a self-consistent `{ticket_id, ticket_user}` token targeting any ad= ministrator-owned ticket. Submitting the forged token to the unprotected en= dpoint causes `wp_set_auth_cookie()` to be called for that administrator, g= ranting the attacker full administrative access to the WordPress site.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19806" target=3D= "_blank" rel=3D"noopener">CVE-2026-19806</a></td>
</tr>
<td class=3D"vendor-product">devtron-labs--devtron</td>
<td>Devtron through 2.2.0 fails to enforce authorization checks on the GET = /orchestrator/api-token/webhook endpoint, allowing authenticated users to r= etrieve admin API tokens. Attackers with any authenticated account can quer=
y the endpoint with arbitrary project, environment, and application paramet= ers to retrieve plaintext super-admin JWT tokens for full platform control.= </td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82882" target=3D= "_blank" rel=3D"noopener">CVE-2026-82882</a></td>
</tr>
<td class=3D"vendor-product">dianping--cat</td>
<td>CAT uses Java String.hashCode as the sole integrity check for session c= ookies without server-side keying, allowing attackers to forge valid checks= ums offline. Attackers can set the x-forwarded-for header to bypass IP bind= ing validation and create admin sessions with full configuration access.</t=
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85181" target=3D= "_blank" rel=3D"noopener">CVE-2026-85181</a></td>
</tr>
<td class=3D"vendor-product">digitalbazaar--forge</td>
<td>node-forge through 1.4.0 fails to validate element count in nested Dige= stAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attack= ers can embed garbage bytes inside the DigestAlgorithm sequence to forge va= lid signatures for arbitrary messages using low-exponent RSA keys. This is =
an incomplete fix for CVE-2026-33894.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85393" target=3D= "_blank" rel=3D"noopener">CVE-2026-85393</a></td>
</tr>
<td class=3D"vendor-product">Divi Engine--Divi Ajax Filter</td>
<td>The Divi Ajax Filter plugin for WordPress is vulnerable to Local File I= nclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_t= emplate' parameter parameter. This makes it possible for unauthenticated at= tackers to include and execute arbitrary .php files on the server, allowing=
the execution of any PHP code in those files. This can be used to bypass a= ccess controls, obtain sensitive data, or achieve code execution in cases w= here .php file types can be uploaded and included. This vulnerability is on=
ly exploitable when the loop_templates parameter is set to 'custom-template= '.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11613" target=3D= "_blank" rel=3D"noopener">CVE-2026-11613</a></td>
</tr>
<td class=3D"vendor-product">DocsGPT--DocsGPT</td>
<td>In DocsGPT 0.15.0 and below, the application provides a custom prompt f= eature that allows users to define prompt content used during chatbot inter= actions. This functionality renders user-supplied prompt data using Jinja t= emplates without input sanitization or sandboxing. An unauthenticated attac= ker can inject malicious template expressions, leading to a server-side tem= plate injection (SSTI) vulnerability that can be exploited to achieve full = remote code execution (RCE).</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31020" target=3D= "_blank" rel=3D"noopener">CVE-2026-31020</a></td>
</tr>
<td class=3D"vendor-product">Dokploy--Dokploy</td>
<td>A vulnerability was detected in Dokploy up to 0.29.7. This issue affect=
s the function writeTraefikConfigInPath of the file packages/server/src/uti= ls/traefik/application.ts of the component Settings. The manipulation of th=
e argument path results in path traversal. The attack can be launched remot= ely. The exploit is now public and may be used. The vendor was contacted ea= rly about this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82954" target=3D= "_blank" rel=3D"noopener">CVE-2026-82954</a></td>
</tr>
<td class=3D"vendor-product">domainaware--parsedmarc</td>
<td>parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a sin= gle unbounded read with no limit on decompressed output size. Because parse= dmarc automatically processes incoming DMARC report emails without user int= eraction, an unauthenticated remote attacker can send a crafted email with =
a highly compressed attachment to the monitored mailbox, causing the parsed= marc process to allocate memory proportional to the uncompressed size and e= xhaust available RAM.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82520" target=3D= "_blank" rel=3D"noopener">CVE-2026-82520</a></td>
</tr>
<td class=3D"vendor-product">Dotstore--WooCommerce Product Attachment</td> <td>Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachme=
nt <=3D 2.3.3 versions.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81774" target=3D= "_blank" rel=3D"noopener">CVE-2026-81774</a></td>
</tr>
<td class=3D"vendor-product">dplugins--DevKit Pro</td>
<td>The DevKit Pro plugin for WordPress is vulnerable to Missing Authorizat= ion in versions up to, and including, 2.3.0. This is due to a missing capab= ility check and missing nonce validation in the DPDEV_install_themes_func()=
function registered on the wp_ajax_DPDEV_install_themes action. This makes=
it possible for authenticated attackers, with Subscriber-level access and = above, to install arbitrary theme ZIP packages containing PHP files that ar=
e extracted into the web-accessible wp-content/themes/ directory, which may=
make remote code execution possible.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14357" target=3D= "_blank" rel=3D"noopener">CVE-2026-14357</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Commerce PayPal</td>
<td>Incorrect Authorization vulnerability in Drupal Commerce PayPal allows = Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 =
to 1.12.0, from 2.0.0 to 2.1.3.</td>
<td>2026-09-02</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73475" target=3D= "_blank" rel=3D"noopener">CVE-2026-73475</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Screenshot</td>
<td>Vulnerability in Drupal Screenshot. This issue affects Screenshot versi= ons: *.*.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76759" target=3D= "_blank" rel=3D"noopener">CVE-2026-76759</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Screenshot</td>
<td>Vulnerability in Drupal Screenshot. This issue affects Screenshot versi= ons: *.*.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76782" target=3D= "_blank" rel=3D"noopener">CVE-2026-76782</a></td>
</tr>
<td class=3D"vendor-product">DSpace--DSpace</td>
<td>DSpace open source software is a repository application which provides = durable access to digital resources. From versions 8.0-rc1 to before 8.4, v= ersions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (R= CE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN m= essages. This issue has been patched in versions 8.4, 9.3, and 10.0.</td> <td>2026-09-02</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49832" target=3D= "_blank" rel=3D"noopener">CVE-2026-49832</a></td>
</tr>
<td class=3D"vendor-product">e4jvikwp--VikAppointments Services Booking Cal= endar</td>
<td>Unauthenticated SQL Injection in VikAppointments Services Booking Calen= dar <=3D 1.2.20 versions.</td>
<td>2026-09-03</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84768" target=3D= "_blank" rel=3D"noopener">CVE-2026-84768</a></td>
</tr>
<td class=3D"vendor-product">EASYBYTE Software--Konga</td>
<td>Konga before 2.1.0 contains a privilege escalation vulnerability that a= llows low-privileged local attackers to execute arbitrary code by planting = attacker-controlled OpenSSL configuration or library files in a hardcoded f= ilesystem path absent from default installations. On Windows, the missing d= irectory resides in a location writable by any authenticated local user, en= abling attackers to create the directory and place malicious files that exe= cute at the privilege level of the user or service account that launches Ko= nga, facilitating privilege escalation.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45221" target=3D= "_blank" rel=3D"noopener">CVE-2026-45221</a></td>
</tr>
<td class=3D"vendor-product">EasyCorp--EasyAdminBundle</td>
<td>EasyAdmin is a fast and modern admin generator for Symfony applications=
. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests=
through a single dashboard route and, for custom actions (Action::linkToRo= ute() and MenuItem::linkToRoute()), swaps the executed controller based on = the routeName query parameter on the kernel.controller event. The swap happ= ens after Symfony's security firewall has already evaluated access_control = against the original dashboard URL, and the routeName value was not validat= ed. As a result, a path-based access_control rule protecting the target rou=
te was never evaluated, so a low-privilege backend user who can reach a sin= gle EasyAdmin URL and knows a target route's name can execute that route's = controller, bypassing the path-based rule. Only path-based protections are = bypassed. Routes whose controller enforces its own authorization with #[IsG= ranted] or denyAccessUnlessGranted() remain protected because those checks = are recomputed against the swapped-in controller. This issue is fixed in ve= rsions 4.29.16 and 5.5.1.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81892" target=3D= "_blank" rel=3D"noopener">CVE-2026-81892</a></td>
</tr>
<td class=3D"vendor-product">Ebyte--Ebyte NA111-M Firmware</td>
<td>The affected=C2=A0Ebyte product's vendor configuration utility permits = access to administrative functions without verifying the operator's identit=
y under certain credential conditions. An unauthenticated attacker on the a= djacent network could modify critical settings or change access credentials=
, potentially preventing legitimate administrators from managing the device= .</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73819" target=3D= "_blank" rel=3D"noopener">CVE-2026-73819</a></td>
</tr>
<td class=3D"vendor-product">Ebyte--Ebyte NA111-M Firmware</td>
<td>The affected=C2=A0Ebyte product uses a deprecated hashing algorithm in =
an authentication-related operation. Under conditions where an attacker can=
manipulate or predict the authentication exchange, the weak construction m=
ay reduce the assurance provided by the authentication mechanism and facili= tate unauthorized access.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76133" target=3D= "_blank" rel=3D"noopener">CVE-2026-76133</a></td>
</tr>
<td class=3D"vendor-product">Ebyte--Ebyte NA111-M Firmware</td>
<td>The affected=C2=A0Ebyte product=C2=A0does not provide separation betwee=
n limited and administrative management functions. A low privileged authent= icated attacker could access security sensitive configuration functions and=
modify settings that affect the confidentiality, integrity, or availabilit=
y of the device.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77966" target=3D= "_blank" rel=3D"noopener">CVE-2026-77966</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Theia</td>
<td>In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI=
"Agent Mode" file-change tools (writeFileContent, suggestFileContent, and = the replacement and state helpers) resolved a model-supplied file path with= out a workspace-containment check. A crafted relative path such as ../.bash= rc, an absolute path, or a ~-expanded path could therefore write or delete = files outside the workspace with the privileges of the Theia backend OS use=
r. Because the path argument is influenced by model output, it can be steer=
ed through indirect prompt injection, and in Agent Mode writes are applied = without a confirmation dialog. Writing to a host-executed file such as a sh= ell startup file or ~/.ssh/authorized_keys can escalate to code execution o=
n the backend.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82217" target=3D= "_blank" rel=3D"noopener">CVE-2026-82217</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elastic_agent</td>
<td>Incorrect Permission Assignment for Critical Resource (CWE-732) in Elas= tic Agent can lead to local privilege escalation via Replace Binaries (CAPE= C-642). On Windows systems where Elastic Agent is installed in unprivileged=
mode, resources used by the agent service are created with access controls=
broader than required. A local user could take advantage of this to cause = the service to execute code of their choosing, ultimately obtaining SYSTEM-= level privileges on the host.</td>
<td>2026-09-02</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78604" target=3D= "_blank" rel=3D"noopener">CVE-2026-78604</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elasticsearch</td>
<td>Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machin=
e learning component can lead to remote code execution via Object Injection=
(CAPEC-586). A specially crafted trained model artifact could cause attack= er-controlled logic to execute with a materially broader system-call surfac=
e than intended. Exploitation requires an authenticated user with sufficien=
t privileges to create and deploy trained models.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72649" target=3D= "_blank" rel=3D"noopener">CVE-2026-72649</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to privilege escal= ation via Exploiting Incorrectly Configured Access Control Security Levels = (CAPEC-180). A user holding workflow edit permissions could cause scheduled=
workflow executions to run with the privileges of a different, higher-priv= ileged user, allowing access to and modification of data beyond their own a= uthorization scope.</td>
<td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63137" target=3D= "_blank" rel=3D"noopener">CVE-2026-63137</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized d= eletion of privileged resources via Path Traversal (CAPEC-126). A low-privi= leged user holding Fleet Settings write access could cause a subsequent adm= inistrative action to act on unintended internal resources, resulting in th=
e deletion of privileged resources such as user accounts and other organiza= tional assets. Exploitation requires an administrator to interact with the = affected Fleet interface.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78590" target=3D= "_blank" rel=3D"noopener">CVE-2026-78590</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') (CWE-22) in Kibana can lead to the unauthorized deletion of privile= ged resources via Path Traversal (CAPEC-126). A low-privileged user holding=
tag creation privileges could cause a subsequent administrative action in = the tag management interface to act on an unintended target, resulting in t=
he deletion of privileged resources including administrative accounts and o= ther organizational assets. Exploitation requires an administrator to inter= act with the affected interface.</td>
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78592" target=3D= "_blank" rel=3D"noopener">CVE-2026-78592</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Elastic Security</td>
<td>A local vulnerability in the Winlogbeat Windows installer caused runtim=
e files to be placed in a directory writable by unprivileged users. A low-p= rivileged attacker with existing access to the system could pre-position ma= licious filesystem links, causing a subsequent elevated Winlogbeat operatio=
n to write to or delete arbitrary files. Successful exploitation could resu=
lt in a denial of service.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-14047" target=3D= "_blank" rel=3D"noopener">CVE-2024-14047</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to privilege escal= ation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privil= ege declarations originating from integration packages were not validated b= efore being used to mint credentials for enrolled Elastic Agents. A user ho= lding Fleet management privileges could therefore cause every Elastic Agent=
on a targeted policy to receive a credential carrying arbitrarily elevated=
Elasticsearch cluster privileges, up to and including full cluster adminis= tration.</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78583" target=3D= "_blank" rel=3D"noopener">CVE-2026-78583</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized co= nfiguration modification via Exploiting Incorrectly Configured Access Contr=
ol Security Levels (CAPEC-180).</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82302" target=3D= "_blank" rel=3D"noopener">CVE-2026-82302</a></td>
</tr>
<td class=3D"vendor-product">Elementor--Activity Log</td>
<td>Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <=
=3D 2.13.1 versions.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84759" target=3D= "_blank" rel=3D"noopener">CVE-2026-84759</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an in= coming OIDC identity to an existing local account by matching the email cla=
im alone, without verifying that the IdP marked that email as verified (ema= il_verified). When Wallos is configured against an IdP that lets a user pre= sent an arbitrary or unverified email (multi-tenant IdPs, IdPs with open se= lf-registration, or any IdP the attacker partly controls), an attacker with=
no Wallos account can authenticate with the admin's email and be logged in=
as the admin - full account takeover, no password needed. This issue has b= een patched in version 4.9.6.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61641" target=3D= "_blank" rel=3D"noopener">CVE-2026-61641</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "S= SRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.p=
hp by disabling cURL proxying (CURLOPT_PROXY =3D '' + CURLOPT_NOPROXY =3D '= *'). However, Wallos ships a second, near-identical, unauthenticated logo-i= mage search endpoint - endpoints/payments/search.php - that was not given t=
he same hardening. It still passes the HTTP_PROXY/HTTPS_PROXY environment v= ariable straight into CURLOPT_PROXY. This issue has been patched in version=
5.0.0.</td>
<td>2026-08-31</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77348" target=3D= "_blank" rel=3D"noopener">CVE-2026-77348</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.4, endpoints/db/migrate.php executes database schema m= igrations when called over HTTP with zero authentication. Any unauthenticat=
ed attacker can trigger pending migration files against the live SQLite dat= abase. This issue has been patched in version 4.9.4.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54598" target=3D= "_blank" rel=3D"noopener">CVE-2026-54598</a></td>
</tr>
<td class=3D"vendor-product">Embed HTML5 Game--Embed HTML5 Game</td>
<td>The Embed HTML5 Game WordPress plugin through 1.3 does not properly res= trict who can upload files via the plugin, as well as what can be uploaded,=
making it possible for unauthenticated attackers to upload PHP backdoors o=
n affected sites.</td>
<td>2026-09-02</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4357" target=3D"= _blank" rel=3D"noopener">CVE-2026-4357</a></td>
</tr>
<td class=3D"vendor-product">Estatik--Estatik</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Estatik <=3D 4.3.4 ver= sions.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81775" target=3D= "_blank" rel=3D"noopener">CVE-2026-81775</a></td>
</tr>
<td class=3D"vendor-product">Evil0ctal--Douyin_TikTok_Download_API</td>
<td>Douyin_TikTok_Download_API through 4.1.2 contains a server-side request=
forgery vulnerability in the /api/download and /api/hybrid/video_data endp= oints that allows unauthenticated attackers to fetch arbitrary URLs by supp= lying a url query parameter. Attackers can request internal services includ= ing cloud metadata endpoints and retrieve response bodies containing sensit= ive credentials through error messages.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85608" target=3D= "_blank" rel=3D"noopener">CVE-2026-85608</a></td>
</tr>
<td class=3D"vendor-product">eyecix--JobSearch</td>
<td>Unauthenticated PHP Object Injection in JobSearch <=3D 3.2.0 version= s.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84834" target=3D= "_blank" rel=3D"noopener">CVE-2026-84834</a></td>
</tr>
<td class=3D"vendor-product">F5--BIG-IP</td>
<td>BIG-IP has a vulnerability where an authenticated user of any role may =
be able to create administrative user accounts through an undisclosed reque=
st to Traffic Management User Interface (TMUI). Impact: This vulnerability = may allow an authenticated attacker with network access to the BIG-IP manag= ement interface to escalate privileges by creating administrative accounts =
on the BIG-IP system. There is no data plane exposure; this is a control pl= ane issue only. Note: Software versions which have reached End of Technical=
Support (EoTS) are not evaluated.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66842" target=3D= "_blank" rel=3D"noopener">CVE-2026-66842</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Gateway Fabric</td>
<td>Description: When NGINX Plus is configured as the data plane for NGINX = Gateway Fabric, an injection vulnerability exists in the NGINX configuratio=
n generator component of NGINX Gateway Fabric. User-supplied string values = from the Authentication Filter Custom Resource Definition clientID or cooki= eName fields, or in the clientSecret field of a Secret referenced by an Aut= hentication Filter, are rendered directly into NGINX configuration template=
s without sanitization or escaping. Impact: An authenticated attacker with = permission to create or modify these resources may craft values that inject=
arbitrary NGINX configuration directives. This is a control plane issue; t= here is no data plane exposure.</td>
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66362" target=3D= "_blank" rel=3D"noopener">CVE-2026-66362</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX Ingress Controller</td>
<td>When NGINX Ingress Controller is configured with Ingress annotations, a=
n injection vulnerability exists in the configuration generator of NGINX In= gress Controller. Multiple user-controllable fields are written into the ge= nerated NGINX configuration without sanitization. An authenticated attacker=
with permission to create or modify these annotations may craft values tha=
t inject arbitrary NGINX configuration directives. Impact: An authenticated=
attacker granted write access to NGINX Ingress Controller Ingress annotati= ons through the Kubernetes API may be able to inject arbitrary NGINX config= uration directives, create or delete files, or disable services. There is n=
o data plane exposure; this is a control plane issue only. Note: Software v= ersions which have reached End of Technical Support (EoTS) are not evaluate= d.</td>
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77180" target=3D= "_blank" rel=3D"noopener">CVE-2026-77180</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX JavaScript</td>
<td>Description NGINX JavaScript (njs)=C2=A0and QuickJS (qjs) engines=C2=A0= have a vulnerability when a js_access handler performs asynchronous request=
body processing and an exception is thrown during asynchronous access-cont= rol evaluation before an explicit access denial is returned. An unauthentic= ated attacker can exploit this vulnerability by sending a crafted HTTP requ= est that triggers an error condition in the access validation logic. This m=
ay cause the js_access phase to fail open, allowing the request to proceed = instead of being denied, resulting in an authentication or authorization by= pass and unauthorized access to protected resources. Impact This vulnerabil= ity may allow remote attackers to bypass js_access controls. There is no co= ntrol plane exposure; this is a data plane issue only. Note: Software versi= ons which have reached End of Technical Support (EoTS) are not evaluated.</=
<td>2026-09-02</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18329" target=3D= "_blank" rel=3D"noopener">CVE-2026-18329</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX JavaScript</td>
<td>Description NGINX JavaScript (njs) has a vulnerability in the XML modul= e's namespace prefix list parser, reachable through the xml.exclusiveC14n()=
method. An unauthenticated remote attacker can trigger it when an affected=
NGINX configuration passes an externally controlled XML namespace prefix l= ist to that method. Both the njs and the QuickJS (qjs) engines are affected=
. A crafted prefix list causes an out-of-bounds write past the end of a hea=
p allocation. With the njs engine, which is the engine used when the js_eng= ine directive is absent, this corrupts adjacent objects and crashes the NGI=
NX worker. With the QuickJS engine, the same call additionally leaks the pr= efix list on every invocation, causing worker memory to grow across request=
s. The official nginxinc/nginx-saml reference implementation is affected du= ring SAML signature verification. It reads InclusiveNamespaces/@PrefixList = from an untrusted SAML message and passes it to xml.exclusiveC14n() before = the signature has been verified, so a valid SAML signature is not required.=
A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is su= fficient. Code execution has not been demonstrated and cannot be ruled out = for all platforms, as the effect of the out-of-bounds write depends on cond= itions beyond the attacker's control. =C2=A0 Impact This vulnerability allo=
ws remote attackers to cause a denial of service on the NGINX system, eithe=
r through repeatable worker restarts or through worker memory growth or pos= sibly trigger code execution. There is no control plane exposure; this is a=
data plane issue only. Note: Software versions which have reached End of T= echnical Support (EoTS) are not evaluated.</td>
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78689" target=3D= "_blank" rel=3D"noopener">CVE-2026-78689</a></td>
</tr>
<td class=3D"vendor-product">F5--NGINX JavaScript</td>
<td>A vulnerability exists in NGINX JavaScript where a malformed HTTP respo= nse received by ngx.fetch() can crash an NGINX worker when trusted JavaScri=
pt reads Response.statusText. Exploitation requires control or influence ov=
er the fetched HTTP response. Impact: This vulnerability may allow remote a= ttackers to cause a denial-of-service (DoS) on the NGINX system. There is n=
o control plane exposure; this is a data plane issue only. Note: Software v= ersions which have reached End of Technical Support (EoTS) are not evaluate= d.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78222" target=3D= "_blank" rel=3D"noopener">CVE-2026-78222</a></td>
</tr>
<td class=3D"vendor-product">facefusion--facefusion</td>
<td>facefusion through 3.6.1 fails to normalize job identifiers in get_job_= file_name, allowing attackers to write files outside the jobs directory. At= tackers can supply traversal sequences in the job identifier parameter thro= ugh the unauthenticated HTTP API to create files at arbitrary locations.</t=
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84702" target=3D= "_blank" rel=3D"noopener">CVE-2026-84702</a></td>
</tr>
<td class=3D"vendor-product">Fahad Mahmood--Keep Backup Daily</td>
<td>Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitiv=
e information exposure vulnerability that allows unauthenticated attackers =
to trigger a full MySQL database dump by accessing the publicly exposed `kb= d_cron_process` parameter without authentication. Attackers can predict the=
partially predictable dump filename based on the database name, a limited = random range, and the current Unix timestamp to download the generated back=
up from the publicly accessible uploads directory.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75133" target=3D= "_blank" rel=3D"noopener">CVE-2026-75133</a></td>
</tr>
<td class=3D"vendor-product">FAQ Builder AYS--FAQ Builder AYS</td>
<td>The FAQ Builder AYS WordPress plugin before 1.8.5 does not sanitize or = escape content submitted by unauthenticated visitors before storing it and = outputting it in an admin area page, and the escaping it does apply is undo=
ne by a subsequent decoding step, leading to Stored XSS which will execute =
in the context of a logged in administrator.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81737" target=3D= "_blank" rel=3D"noopener">CVE-2026-81737</a></td>
</tr>
<td class=3D"vendor-product">fast-note-sync-service--fast-note-sync-service= </td>
<td>An issue in fast-note-sync-service <=3D2.13.7 allows a remote attack=
er to escalate privileges via the admin configuration endpoint exposes auth= TokenKey</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52111" target=3D= "_blank" rel=3D"noopener">CVE-2026-52111</a></td>
</tr>
<td class=3D"vendor-product">fastify--fastify</td>
<td>fastify versions before 5.12.2 treat the object resolved by a successfu=
l Ajv async validator as the value result protocol used by custom validator=
compilers. If a request that passes its route schema contains a property n= amed value at the root, fastify replaces the entire request body with that = property's value before the handler runs, so the handler receives a differe=
nt object than the one that satisfied the schema. An authenticated low-priv= ilege caller can use this to make nested data replace the validated body an=
d trigger an operation the route schema did not authorize, leading to unaut= horized state changes and data disclosure. Users should upgrade to fastify = 5.12.2 or later.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84504" target=3D= "_blank" rel=3D"noopener">CVE-2026-84504</a></td>
</tr>
<td class=3D"vendor-product">fastify--fastify</td>
<td>fastify versions >=3D 4.0.0 and before 5.12.2 can route a malformed = URL sent under one plugin prefix to the custom not-found handler of a diffe= rent sibling plugin, and invoke it without the preHandler hook declared for=
that handler. The internal not-found router for encapsulated handlers disp= atches malformed paths through a single shared handler pointer before URL d= ecoding, ignoring the prefix and skipping the selected handler's normal lif= ecycle. An unauthenticated attacker can therefore reach an authentication-p= rotected private fallback through an unrelated public prefix and read its f= ull response, bypassing the authentication hook and breaking prefix encapsu= lation. Users should upgrade to fastify 5.12.2 or later.</td> <td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76169" target=3D= "_blank" rel=3D"noopener">CVE-2026-76169</a></td>
</tr>
<td class=3D"vendor-product">fastify--fastify</td>
<td>fastify versions before 5.12.2 implement the case-insensitive nature of=
HTTP header names by lowercasing names in a route's header schema before c= ompiling it, but the transformation is incomplete: it lowercases the proper= ties keys and the root-level required array, and does not lowercase the tri= gger and dependent names inside the JSON Schema Draft 7 dependencies keywor=
d. Because Node stores request header names in lowercase, a canonical-case = dependency such as requiring an authentication header whenever a privileged= -mode header is present never matches, and the presence assertion is silent=
ly skipped. An unauthenticated remote client can therefore send the header = that activates a privileged branch while omitting the header the dependency=
was meant to require, bypassing the conditional check. Users should upgrad=
e to fastify 5.12.2 or later.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84428" target=3D= "_blank" rel=3D"noopener">CVE-2026-84428</a></td>
</tr>
<td class=3D"vendor-product">fastify--fastify</td>
<td>fastify versions before 5.12.2 decide whether to compile a request sche=
ma based on JavaScript truthiness, but JSON Schema Draft 7 defines the bool= ean false as a valid schema that rejects every instance. When an applicatio=
n assigns false to a route's body, querystring, params, or headers schema t=
o deny all input, fastify treats it as a missing schema, compiles no valida= tor, and runs the route handler on any request. An unauthenticated remote c= lient can therefore reach a handler that a valid deny-all schema was intend=
ed to make unreachable, a complete validation bypass that can lead to unaut= horized state changes or execution of disabled operations. Users should upg= rade to fastify 5.12.2 or later.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84469" target=3D= "_blank" rel=3D"noopener">CVE-2026-84469</a></td>
</tr>
<td class=3D"vendor-product">firecrawl--firecrawl-mcp-server</td> <td>firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulne= rability in the firecrawl_parse tool that accepts unconstrained filePath ar= guments without directory containment validation. Attackers can supply abso= lute paths or directory traversal sequences to read sensitive files like cr= edentials and environment variables, which are then uploaded and returned t=
o the model context.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85606" target=3D= "_blank" rel=3D"noopener">CVE-2026-85606</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_o= em_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujit= su-irmc-common.c via malformed Fujitsu SEL long-text responses.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85504" target=3D= "_blank" rel=3D"noopener">CVE-2026-85504</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in=
_get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info s= ubcommand to dell get-system-info).</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85506" target=3D= "_blank" rel=3D"noopener">CVE-2026-85506</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in=
_output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info su= bcommand to dell get-system-info).</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85507" target=3D= "_blank" rel=3D"noopener">CVE-2026-85507</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in=
_output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ip= v6-info subcommand to dell get-system-info).</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85508" target=3D= "_blank" rel=3D"noopener">CVE-2026-85508</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_d= ata in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than reques= ted.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85509" target=3D= "_blank" rel=3D"noopener">CVE-2026-85509</a></td>
</tr>
<td class=3D"vendor-product">FreeIPMI--FreeIPMI</td>
<td>ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read i=
n ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c w= hen a BMC provides a short response, a different vulnerability than CVE-202= 6-50031 (which has different affected versions).</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85505" target=3D= "_blank" rel=3D"noopener">CVE-2026-85505</a></td>
</tr>
<td class=3D"vendor-product">fs-code--FS Poster - WordPress Social media Au=
to Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest]</td> <td>The FS-Poster plugin for WordPress is vulnerable to Remote Code Executi=
on in versions up to and including 8.0.1. This is due to insufficient input=
sanitization of the FFmpeg path parameter before passing it to the exec() = function, combined with missing authorization checks on the REST API endpoi= nts. This makes it possible for authenticated attackers, with subscriber-le= vel access and above, to execute arbitrary commands on the underlying serve= r.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10195" target=3D= "_blank" rel=3D"noopener">CVE-2026-10195</a></td>
</tr>
<td class=3D"vendor-product">GastroMenum--GastroMenum Web Panel</td> <td>Observable response discrepancy vulnerability in GastroMenum GastroMenu=
m Web Panel allows Account Footprinting. This issue affects GastroMenum Web=
Panel: before 31.08.2026.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19205" target=3D= "_blank" rel=3D"noopener">CVE-2026-19205</a></td>
</tr>
<td class=3D"vendor-product">geonetwork--core-geonetwork</td>
<td>GeoNetwork is a catalog application to manage spatially referenced reso= urces. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used t=
o render formatters is configured without secure processing (`FEATURE_SECUR= E_PROCESSING`) and without disabling Java extension functions (`ALLOW_EXTER= NAL_FUNCTIONS`). Any stylesheet loaded by GeoNetwork can therefore invoke `= java.lang.Runtime.exec()` or `java.lang.ProcessBuilder` directly, achieving=
arbitrary command execution as the GeoNetwork process user. A user with su= fficient privileges to upload a formatter can deliver a `.xsl` file contain= ing Java extension call that execute arbitrary OS commands with the privile= ges of the GeoNetwork process. The issue is patched in GeoNetwork versions = 4.4.12 and 4.2.17.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58400" target=3D= "_blank" rel=3D"noopener">CVE-2026-58400</a></td>
</tr>
<td class=3D"vendor-product">geonetwork--core-geonetwork</td>
<td>GeoNetwork is a catalog application to manage spatially referenced reso= urces. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a=
new formatter via file upload is unprotected and allows the upload of exte= rnal uncontrolled files. An unauthenticated attacker can upload arbitrary `= .xsl` or `.zip` formatter files to the server. An unauthenticated attacker = can write arbitrary files into the GeoNetwork formatter directory. On its o=
wn this constitutes unauthorized write access to server storage. The issue =
is patched in GeoNetwork versions 4.4.12 and 4.2.17.</td>
<td>2026-09-03</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63219" target=3D= "_blank" rel=3D"noopener">CVE-2026-63219</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav before 2.0.18 (affected versions <=3D 2.0.17) contains a remote=
code execution vulnerability in the Twig sort filter. The sortFunc wrapper=
in GravExtension.php hardcodes Twig's isSandboxed argument to false, so un= like |map/|filter/|reduce, |sort accepts a plain function name inside the s= andbox; the remaining denylist misses spl_autoload, which performs a PHP in= clude. An authenticated user with only page-write rights (admin.pages or ap= i.pages.write) can supply a crafted payload (e.g., via form frontmatter ren= dered by the Email plugin) that invokes spl_autoload through the sort filte=
r, resulting in arbitrary PHP execution as the web server user.</td> <td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85604" target=3D= "_blank" rel=3D"noopener">CVE-2026-85604</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav Shortcode Core before 6.2.5 contains stored cross-site scripting v= ulnerabilities in the [lorem] tag parameter and [details] summary parameter=
that are written to rendered pages without escaping. Attackers with page-e= dit access can inject arbitrary HTML and JavaScript that executes in the br= owsers of all page visitors, including administrators.</td>
<td>2026-09-04</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85599" target=3D= "_blank" rel=3D"noopener">CVE-2026-85599</a></td>
</tr>
<td class=3D"vendor-product">getomni-ai--zerox</td>
<td>zerox 1.1.20 contains an OS command injection vulnerability in the file=
download mechanism where the temporary file extension derived from documen=
t URLs is interpolated unsanitized into shell commands executed by poppler = utilities. Attackers can craft document URLs with malicious file extensions=
containing command substitution syntax to execute arbitrary OS commands be= fore document processing occurs.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85672" target=3D= "_blank" rel=3D"noopener">CVE-2026-85672</a></td>
</tr>
<td class=3D"vendor-product">ggml -- llama.cpp</td>
<td>llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in c= ommon/json-schema-to-grammar.cpp, resulting in a denial of service.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52130" target=3D= "_blank" rel=3D"noopener">CVE-2026-52130</a></td>
</tr>
<td class=3D"vendor-product">ggml -- llama.cpp</td>
<td>llama.cpp b5693 and before has a Reachable Assertion via the gguf_reade= r::read function.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52131" target=3D= "_blank" rel=3D"noopener">CVE-2026-52131</a></td>
</tr>
<td class=3D"vendor-product">ggml -- llama.cpp</td>
<td>llama.cpp through commit 97f06e9, when started with the --reranking fla=
g, allows remote attackers to cause a denial of service (std::bad_alloc and=
HTTP 500) via a negative top_n value in a POST request to /rerank.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52132" target=3D= "_blank" rel=3D"noopener">CVE-2026-52132</a></td>
</tr>
<td class=3D"vendor-product">GNOME--gvfs</td>
<td>A flaw was found in the SFTP backend in gvfs. When mounting a share and=
reading a file, a malicious SFTP server can cause read_reply() to process =
a length that exceeds the size requested by the client. The function does n=
ot verify the server-provided length against the allocated buffer size, cau= sing the operation to write past the intended boundaries. This issue allows=
a malicious server to corrupt adjacent heap memory in the gvfsd-sftp proce= ss, resulting in a denial of service as the process aborts upon detecting t=
he heap corruption or potentially allowing arbitrary code execution.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84268" target=3D= "_blank" rel=3D"noopener">CVE-2026-84268</a></td>
</tr>
<td class=3D"vendor-product">golang -- crypto</td>
<td>Previously, after a channel has been established, a malicious peer coul=
d send crafted messages that would deadlock the entire connection. Now, we = handle all RFC 4254 channel messages; global requests are handled explicitl=
y. Then, treat all other messages as a protocol error and tear the connecti=
on down instead of buffering and blocking.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56855" target=3D= "_blank" rel=3D"noopener">CVE-2026-56855</a></td>
</tr>
<td class=3D"vendor-product">golang -- crypto</td>
<td>Previously, a channel registered in the mux's chanList is not usable un= til it is established. A malicious peer was able flood the channel's incomi= ngRequests, deadlocking the entire connection. Now, we add an atomic establ= ished state, set when a channel becomes usable. Until such a time, handlePa= cket drops every packet other than the open confirmation/failure, without b= locking and without tearing down the connection.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78662" target=3D= "_blank" rel=3D"noopener">CVE-2026-78662</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed=
a remote attacker to execute arbitrary code outside the sandbox via crafte=
d network traffic. (Chromium security severity: High)</td>
<td>2026-09-02</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84324" target=3D= "_blank" rel=3D"noopener">CVE-2026-84324</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Improper input validation in DataTransfer in Google Chrome prior to 152= .0.7977.75 allowed a remote attacker leveraging social engineering to bypas=
s system access restrictions via a co-installed app. (Chromium security sev= erity: High)</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84325" target=3D= "_blank" rel=3D"noopener">CVE-2026-84325</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7= 977.75 allowed a remote attacker leveraging social engineering to execute a= rbitrary code outside the sandbox via a crafted HTML page. (Chromium securi=
ty severity: High)</td>
<td>2026-09-02</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84354" target=3D= "_blank" rel=3D"noopener">CVE-2026-84354</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 al= lowed a remote attacker to execute arbitrary code inside the sandbox via a = crafted HTML page. (Chromium security severity: High)</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84326" target=3D= "_blank" rel=3D"noopener">CVE-2026-84326</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in Chromoting in Google Chrome on on Windows pr= ior to 152.0.7977.75 allowed a local attacker to execute arbitrary code out= side the sandbox via a local program. (Chromium security severity: Medium)<=
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84334" target=3D= "_blank" rel=3D"noopener">CVE-2026-84334</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in TabStrip in Google Chrome prior to 152.0.797= 7.75 allowed a remote attacker who had compromised the renderer process and=
leveraged social engineering to potentially execute arbitrary code outside=
the sandbox via a crafted HTML page. (Chromium security severity: Medium)<=
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84335" target=3D= "_blank" rel=3D"noopener">CVE-2026-84335</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowe=
d a remote attacker to execute arbitrary code inside the sandbox via a craf= ted HTML page. (Chromium security severity: Medium)</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84347" target=3D= "_blank" rel=3D"noopener">CVE-2026-84347</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Use after free in Browser in Google Chrome prior to 152.0.7977.75 allow=
ed a remote attacker who had compromised the renderer process to execute ar= bitrary code outside the sandbox via a crafted HTML page. (Chromium securit=
y severity: High)</td>
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84349" target=3D= "_blank" rel=3D"noopener">CVE-2026-84349</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allo= wed a remote attacker leveraging social engineering to execute arbitrary co=
de outside the sandbox via UI Interaction. (Chromium security severity: Low= )</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84350" target=3D= "_blank" rel=3D"noopener">CVE-2026-84350</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.79= 77.75 allowed a remote attacker who had compromised the renderer process to=
execute arbitrary code outside the sandbox via a crafted HTML page. (Chrom= ium security severity: High)</td>
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84351" target=3D= "_blank" rel=3D"noopener">CVE-2026-84351</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a = remote attacker to execute arbitrary code inside the sandbox via a crafted = HTML page. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85046" target=3D= "_blank" rel=3D"noopener">CVE-2026-85046</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Dawn in Google Chrome on on Android prior to 152.0.79= 77.75 allowed a remote attacker to execute arbitrary code outside the sandb=
ox via a crafted HTML page. (Chromium security severity: High)</td>
<td>2026-09-02</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84333" target=3D= "_blank" rel=3D"noopener">CVE-2026-84333</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in WebGL in Google Chrome on on Android prior to 152.0.7= 977.75 allowed a remote attacker to execute arbitrary code outside the sand= box via a crafted HTML page. (Chromium security severity: Critical)</td> <td>2026-09-02</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84352" target=3D= "_blank" rel=3D"noopener">CVE-2026-84352</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Shared Tab Groups in Google Chrome on on Android prio=
r to 152.0.7977.75 allowed a remote attacker leveraging social engineering =
to execute arbitrary code outside the sandbox via a crafted HTML page. (Chr= omium security severity: Critical)</td>
<td>2026-09-02</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84353" target=3D= "_blank" rel=3D"noopener">CVE-2026-84353</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allo= wed a remote attacker to execute arbitrary code outside the sandbox via a c= rafted HTML page. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85042" target=3D= "_blank" rel=3D"noopener">CVE-2026-85042</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 a= llowed a remote attacker to bypass system access restrictions via crafted n= etwork traffic. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85043" target=3D= "_blank" rel=3D"noopener">CVE-2026-85043</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Improper input validation in Transactions Platform in Google Chrome on =
on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially exec= ute arbitrary code outside the sandbox via a crafted HTML page. (Chromium s= ecurity severity: Medium)</td>
<td>2026-09-03</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85047" target=3D= "_blank" rel=3D"noopener">CVE-2026-85047</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Out of bounds write in WebGL in Google Chrome on on Android prior to 15= 2.0.7977.82 allowed a remote attacker to execute arbitrary code outside the=
sandbox via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-09-03</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85050" target=3D= "_blank" rel=3D"noopener">CVE-2026-85050</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Compositing in Google Chrome prior to 152.0.7977.82 a= llowed a remote attacker who had compromised the renderer process to execut=
e arbitrary code outside the sandbox via a crafted HTML page. (Chromium sec= urity severity: High)</td>
<td>2026-09-03</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85048" target=3D= "_blank" rel=3D"noopener">CVE-2026-85048</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed =
a remote attacker to execute arbitrary code inside the sandbox via a crafte=
d HTML page. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85049" target=3D= "_blank" rel=3D"noopener">CVE-2026-85049</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 a= llowed a remote attacker to execute arbitrary code inside the sandbox via a=
crafted HTML page. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85051" target=3D= "_blank" rel=3D"noopener">CVE-2026-85051</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Improper resource exposure in CacheStorage in Google Chrome prior to 15= 2.0.7977.82 allowed a remote attacker to execute arbitrary code inside the = sandbox via a crafted HTML page. (Chromium security severity: High)</td> <td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85053" target=3D= "_blank" rel=3D"noopener">CVE-2026-85053</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a = remote attacker to execute arbitrary code inside the sandbox via a crafted = HTML page. (Chromium security severity: High)</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85045" target=3D= "_blank" rel=3D"noopener">CVE-2026-85045</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana Enterprise</td>
<td>Only self-managed Grafana instances with Auth Proxy authentication and = identity caching enabled (sync_ttl greater than zero) are affected. The Aut=
h Proxy cache key concatenated the username and forwarded identity attribut=
es without a delimiter, so distinct identities could collide on one key. An=
authenticated user who shapes their own attributes to collide with a highe= r-privileged user's, while that user's cache entry is live, is authenticate=
d as that user, up to Administrator (authentication bypass by spoofing).</t=
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14199" target=3D= "_blank" rel=3D"noopener">CVE-2026-14199</a></td>
</tr>
<td class=3D"vendor-product">Grashjs Atlas--CMMS</td>
<td>A Broken Object Level Authorization vulnerability exists in Grashjs Atl=
as CMMS prior to v1.6.0. An authenticated user from one tenant can read and=
modify another tenant's company record by changing only the numeric ID in = the /company/{id} endpoint. The application does not enforce tenant-level o= wnership checks when accessing or updating company objects, allowing cross-= tenant access and modification of company profile data.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51956" target=3D= "_blank" rel=3D"noopener">CVE-2026-51956</a></td>
</tr>
<td class=3D"vendor-product">Gravity Forms--Gravity Forms</td>
<td>The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File = Upload in all versions up to, and including, 3.0.2. This is due to insuffic= ient validation of multi-file upload chunk state in the `GFAsyncUpload::upl= oad()` function, where public form state URL hashes can be reused as chunk = continuation hashes and attacker-controlled temporary filenames are accepte=
d before sanitization. This makes it possible for unauthenticated attackers=
, when a public form contains a File Upload field with Multiple Files enabl= ed, to upload a valid PNG/PDF polyglot to an attacker-selected public `.php=
` or `.html` filename in the Gravity Forms temporary upload directory. This=
can lead to remote code execution on WordPress systems that use NGINX or o= ther non `.htaccess` respecting web servers. NOTE: During installation and = activation, the Gravity Forms plugin places a `.htaccess` file in this dire= ctory, which prevents this vulnerability from being exploited despite the P=
HP file being written to the temporary upload directory. In these cases whe=
re PHP execution is blocked, attacker-written HTML can result in stored sam= e-origin cross-site scripting if a victim visits the generated file URL.</t=
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19513" target=3D= "_blank" rel=3D"noopener">CVE-2026-19513</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerab= ility in checkout-acceptance report actions when Full Multiple Company Supp= ort is enabled. Authenticated users with reports.view permission can enumer= ate sequential acceptance IDs and soft-delete or trigger reminder emails fo=
r acceptances belonging to other companies by exploiting a null check on th=
e legacy users.company_id column.</td>
<td>2026-09-04</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85616" target=3D= "_blank" rel=3D"noopener">CVE-2026-85616</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>snipe-it versions before 8.6.3 contain an authorization bypass vulnerab= ility in the bulk delete functionality that allows restricted users to soft= -delete users outside their authorized scope. Attackers can include unautho= rized user IDs in bulk delete requests to bypass instance-level restriction=
s and modify or disable accounts they should not access.</td> <td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85617" target=3D= "_blank" rel=3D"noopener">CVE-2026-85617</a></td>
</tr>
<td class=3D"vendor-product">h3 --h3=C2=A0<br>=C2=A0</td>
<td>h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed = from user-controlled cookie values in setChunkedCookie() and deleteChunkedC= ookie() functions. Attackers can send a crafted cookie header with an extre= mely large chunk count to trigger an O(n=C3=82=C2=B2) cleanup loop that han=
gs the server process.</td>
<td>2026-09-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86250" target=3D= "_blank" rel=3D"noopener">CVE-2026-86250</a></td>
</tr>
<td class=3D"vendor-product">haris-musa--excel-mcp-server</td> <td>excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode = when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitr= ary files. Attackers can supply unchecked file paths to read and write tool=
s to access any file accessible to the process.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85661" target=3D= "_blank" rel=3D"noopener">CVE-2026-85661</a></td>
</tr>
<td class=3D"vendor-product">hashthemes--Hash Form</td>
<td>Unauthenticated Arbitrary File Upload in Hash Form <=3D 1.4.2 versio= ns.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81780" target=3D= "_blank" rel=3D"noopener">CVE-2026-81780</a></td>
</tr>
<td class=3D"vendor-product">Helicone--helicone</td>
<td>Helicone's VaultManager.getDecryptedProviderKeyById() function in the G=
ET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's=
organization against the vault key's organization identifier. Attackers wi=
th admin or owner privileges in any organization can retrieve decrypted ups= tream provider credentials for other tenants, including plaintext OpenAI, A= nthropic, and Bedrock API keys.</td>
<td>2026-09-03</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85178" target=3D= "_blank" rel=3D"noopener">CVE-2026-85178</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--AOS-CX</td> <td>Vulnerabilities exist in the authentication module that may improperly = process malformed or truncated input. An authenticated remote attacker coul=
d exploit these vulnerabilities by providing specially crafted input from a=
compromised or hostile authentication server. Successful exploitation coul=
d result in a Denial-of-Service or potential remote code execution with ele= vated privileges.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73750" target=3D= "_blank" rel=3D"noopener">CVE-2026-73750</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--AOS-CX</td> <td>An authenticated user with low-privileged access could submit crafted i= nput through the web-based management interface to execute arbitrary comman=
ds on the underlying operating system.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73751" target=3D= "_blank" rel=3D"noopener">CVE-2026-73751</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--AOS-CX</td> <td>Exploitation through affected command-line operations could allow an au= thenticated low-privileged user to execute arbitrary commands as a privileg=
ed user on the underlying operating system.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73753" target=3D= "_blank" rel=3D"noopener">CVE-2026-73753</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--AOS-CX</td> <td>A vulnerability exists in the Credential Manager component that may all=
ow for unauthorized administrative access. An unauthenticated remote attack=
er could exploit this vulnerability on a device in its factory-default or p= ost-ZTP state before any administrator has configured credentials by provid= ing a predictable factory-default password. Successful exploitation could r= esult in full administrative control of the affected device during the init= ial setup process.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73778" target=3D= "_blank" rel=3D"noopener">CVE-2026-73778</a></td>
</tr>
<td class=3D"vendor-product">Hewlett Packard Enterprise (HPE)--AOS-CX</td> <td>A vulnerability exists in a management component that could allow an un= authenticated adjacent attacker to execute arbitrary commands. Successful e= xploitation could result in remote execution of arbitrary commands in the c= ontext of the affected utility.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73763" target=3D= "_blank" rel=3D"noopener">CVE-2026-73763</a></td>
</tr>
<td class=3D"vendor-product">highwarden--Super Store Finder</td> <td>Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <=
=3D 7.10 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81768" target=3D= "_blank" rel=3D"noopener">CVE-2026-81768</a></td>
</tr>
<td class=3D"vendor-product">hiyouga--LlamaFactory</td>
<td>LLaMA-Factory contains a server-side request forgery vulnerability in t=
he OpenAI-compatible API multimodal media URL handler that allows unauthent= icated attackers to bypass SSRF validation. The check_ssrf_url guard valida= tes URLs once but requests.get follows redirects and re-resolves DNS withou=
t re-validation, enabling attackers to use HTTP redirects or DNS rebinding =
to access internal addresses and cloud metadata endpoints.</td> <td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85673" target=3D= "_blank" rel=3D"noopener">CVE-2026-85673</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for=
improper processing of malformed input. An unauthenticated remote attacker=
could exploit these vulnerabilities by sending specially crafted packets t=
o the affected service. Successful exploitation could result in remote code=
execution with elevated privileges.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73749" target=3D= "_blank" rel=3D"noopener">CVE-2026-73749</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An unauthenticated arbitrary file write vulnerability exists in an API = endpoint of AOS-CX. Successful exploitation of this vulnerability allows an=
attacker to write arbitrary files to the underlying operating system, whic=
h could lead to remote code execution.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73752" target=3D= "_blank" rel=3D"noopener">CVE-2026-73752</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Vulnerabilities have been identified in the API endpoint of AOS-CX swit= ches that could potentially allow an unauthenticated remote actor to circum= vent existing authentication controls.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73777" target=3D= "_blank" rel=3D"noopener">CVE-2026-73777</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Vulnerabilities have been identified in the operating system of AOS-CX = switches that could potentially allow an unauthenticated remote actor to ci= rcumvent existing authentication controls. Successful exploitation could co= mpromise system integrity and further expose sensitive information.</td> <td>2026-09-01</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73779" target=3D= "_blank" rel=3D"noopener">CVE-2026-73779</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability in the web-based management interface of AOS-CX switche=
s exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) prot= ection. This could allow a remote unauthenticated attacker to execute arbit= rary input against the affected interface if the attacker can convince an a= uthenticated user of the interface to interact with a specially crafted URL= .</td>
<td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73780" target=3D= "_blank" rel=3D"noopener">CVE-2026-73780</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability in the web-based management interface of AOS-CX could a= llow an authenticated remote attacker to conduct a stored cross-site script= ing (XSS) attack against an administrative user of the interface. A success= ful exploit allows an attacker to execute arbitrary script code in a victim=
's browser in the context of the affected interface.</td>
<td>2026-09-01</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73781" target=3D= "_blank" rel=3D"noopener">CVE-2026-73781</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A format string vulnerability exists in the command line interface of A= OS-CX that could lead to unauthenticated remote code execution. Successful = exploitation of this vulnerability results in the ability to execute arbitr= ary code as a privileged user on the underlying operating system.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73782" target=3D= "_blank" rel=3D"noopener">CVE-2026-73782</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Vulnerabilities have been identified in the operating system of AOS-CX = switches that could potentially allow an unauthenticated remote actor to ci= rcumvent existing authentication controls. In some cases this could enable = unauthorized modification of affected resources and limited disruption of a= ffected services.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73764" target=3D= "_blank" rel=3D"noopener">CVE-2026-73764</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Authenticated path traversal vulnerabilities exist in API endpoints of = AOS-CX. Successful exploitation of these vulnerabilities allows an attacker=
to write arbitrary files to the underlying operating system, which could l= ead to remote code execution.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73765" target=3D= "_blank" rel=3D"noopener">CVE-2026-73765</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Command injection vulnerabilities in the API endpoint of AOS-CX could a= llow an authenticated remote attacker with administrative privileges to inj= ect arbitrary commands. Successful exploitation could allow an attacker to = execute arbitrary commands as a privileged user on the underlying operating=
system.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73766" target=3D= "_blank" rel=3D"noopener">CVE-2026-73766</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Authenticated command injection vulnerabilities exist in the command li=
ne interface of AOS-CX. Successful exploitation of these vulnerabilities re= sults in the ability to execute arbitrary commands as a privileged user on = the underlying operating system.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73767" target=3D= "_blank" rel=3D"noopener">CVE-2026-73767</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability exists in the command line interface of AOS-CX that may=
allow for improper processing of malformed input. Successful exploitation = could result in the execution of arbitrary commands with root privileges.</=
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73768" target=3D= "_blank" rel=3D"noopener">CVE-2026-73768</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An authenticated arbitrary file write vulnerability exists in AOS-CX. S= uccessful exploitation could allow an authenticated malicious actor, under = specific conditions outside the attacker's control and following a required=
action by another user, to create or modify arbitrary files and execute ar= bitrary commands as a privileged user on the underlying operating system.</=
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73770" target=3D= "_blank" rel=3D"noopener">CVE-2026-73770</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An authentication vulnerability exists in the AOS-CX management interfa=
ce and API that may allow improper authentication processing. An unauthenti= cated remote attacker could exploit this vulnerability under specific condi= tions to bypass authentication controls or exhaust system resources. Succes= sful exploitation could result in unauthorized access or denial of service = affecting the management interface.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73771" target=3D= "_blank" rel=3D"noopener">CVE-2026-73771</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An unauthenticated Denial-of-Service (DoS) vulnerability exists in the = API endpoint of AOS-CX. Successful exploitation of this vulnerability resul=
ts in the ability to interrupt the normal operation of the affected service= .</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73773" target=3D= "_blank" rel=3D"noopener">CVE-2026-73773</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A buffer overflow vulnerability exists in the underlying operating syst=
em of AOS-CX that could lead to unauthenticated disclosure of sensitive inf= ormation by sending specially crafted packets to the affected system. Succe= ssful exploitation of this vulnerability could result in limited disclosure=
or modification of information and disruption of the affected system.</td> <td>2026-09-01</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73774" target=3D= "_blank" rel=3D"noopener">CVE-2026-73774</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Vulnerabilities in the API endpoint of AOS-CX could allow a remote atta= cker authenticated with low privileges to access sensitive information. A s= uccessful exploit allows an attacker to retrieve information which could be=
used to potentially gain further access to network services supported by A= OS-CX.</td>
<td>2026-09-01</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73775" target=3D= "_blank" rel=3D"noopener">CVE-2026-73775</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A signature verification bypass vulnerability exists in the command lin=
e interface of AOS-CX. Successful exploitation could allow an authenticated=
malicious actor with administrative privileges to execute arbitrary code o=
n the underlying operating system, when certain pre-conditions outside of t=
he attacker=C3=83=C2=A2=C3=A2=E2=80=9A=C2=AC=C3=A2=E2=80=9E=C2=A2s control = are met.</td>
<td>2026-09-01</td>
<td>7.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73776" target=3D= "_blank" rel=3D"noopener">CVE-2026-73776</a></td>
</tr>
<td class=3D"vendor-product">HTML::FormFu--HTML::FormFu</td>
<td>HTML::FormFu versions through 2.08 for Perl allow resource exhaustion v=
ia an unbounded repeat count from the query string in Repeatable elements. = When a Repeatable element has counter_name set, its process method reads th=
e repeat count from the named query string parameter, checks only that it i=
s a positive integer, and passes it to repeat, which deep-clones the elemen= t's child subtree once per iteration. Nothing caps the value, and no attrib= ute lets an application impose a limit. The count is read on every request,=
before the form decides whether it was submitted, so a plain GET reaches t=
he clone loop with no credentials, no session and no request body. Nesting = multiplies: a Repeatable inside a Repeatable takes a counter at each level,=
so an outer and an inner value of 100 build 10,000 clones. Once the form i=
s submitted, each cloned field's constraints scan the whole element tree in=
_find_field_value, so cost grows faster than linearly with the count. A si= ngle request exhausts memory and CPU. The latest release on CPAN is 2.07, f= rom 2018. Version 2.08 exists only in the git repository.</td> <td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19873" target=3D= "_blank" rel=3D"noopener">CVE-2026-19873</a></td>
</tr>
<td class=3D"vendor-product">Hugging Face--Transformers</td>
<td>A vulnerability in Hugging Face Transformers (versions >=3D 4.49.0 a=
nd <=3D 5.8.1) allows remote Python files to be written to local disk wi= thout user consent when using GenerativePreTrainedModel.load_custom_generat= e(). The function fetches and caches a remote module file before performing=
the required trust_remote_code consent check, inverting the security model=
enforced by other code-loading paths (such as AutoConfig, AutoModel, and A= utoTokenizer). As a result, attacker-controlled Python code from custom_gen= erate/generate.py is copied into the user's ~/.cache/huggingface/modules di= rectory even if the user declines the trust prompt. Although execution is c= orrectly gated, the file write is not reversible and can persist across ses= sions. This can lead to persistent, unauthorized files on disk and stale ca= che collisions where cached attacker code may later be executed during trus= ted model loads. The issue stems from an unconditional file write in dynami= c_module_utils.py prior to any trust verification.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80047" target=3D= "_blank" rel=3D"noopener">CVE-2026-80047</a></td>
</tr>
<td class=3D"vendor-product">hulumi--drift</td>
<td>@hulumi/drift versions before 1.3.2 accept externally supplied execute = plans without sufficient provenance validation, allowing untrusted reconcil= iation input to be treated as trusted. Attackers can supply malicious execu=
te plans that bypass security checks to perform unsafe reconciliation opera= tions.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82858" target=3D= "_blank" rel=3D"noopener">CVE-2026-82858</a></td>
</tr>
<td class=3D"vendor-product">hulumi--policies</td>
<td>@hulumi/policies versions before 1.3.2 contain an evidence validation b= ypass vulnerability in Cloudflare and deployment-governance validators that=
allows attackers to suppress violations by submitting unrelated compliant = evidence. Attackers can use evidence from different zones, hostnames, origi= ns, or repositories to bypass security guardrails for unrelated resources i=
n the same stack.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82855" target=3D= "_blank" rel=3D"noopener">CVE-2026-82855</a></td>
</tr>
<td class=3D"vendor-product">hulumi--policies</td>
<td>@hulumi/policies versions before 1.3.2 fail to properly validate set-qu= alified AWS IAM condition operators in GitHub OIDC trust policies. Attacker=
s can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions = OIDC subject conditions from security guardrails.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82856" target=3D= "_blank" rel=3D"noopener">CVE-2026-82856</a></td>
</tr>
<td class=3D"vendor-product">hulumi--policies</td>
<td>@hulumi/policies versions before 1.3.2 fail to fully inspect inline and=
attached IAM policy evidence for the administrator-policy guardrail. Attac= kers can craft admin-equivalent policy paths that bypass policy evaluation = controls.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82860" target=3D= "_blank" rel=3D"noopener">CVE-2026-82860</a></td>
</tr>
<td class=3D"vendor-product">hulumi--policies</td>
<td>@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vu= lnerability that allows attackers to submit spoofed SecureBucket parent evi= dence during policy evaluation. Attackers can bypass security policy checks=
by providing falsified evidence, causing the validator to miss unsafe buck=
et configurations.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82861" target=3D= "_blank" rel=3D"noopener">CVE-2026-82861</a></td>
</tr>
<td class=3D"vendor-product">HumanSignal--label-studio</td>
<td>Label Studio through 1.23.0 fails to validate webhook URLs, allowing au= thenticated users to dispatch requests to internal services including RFC 1= 918 addresses and cloud metadata endpoints. Attackers can create webhooks t= argeting private networks and exfiltrate annotation data by enabling payloa=
d transmission in outbound requests.</td>
<td>2026-09-03</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85179" target=3D= "_blank" rel=3D"noopener">CVE-2026-85179</a></td>
</tr>
<td class=3D"vendor-product">HumanSignal--label-studio</td>
<td>Label Studio fails to apply organization filters when resolving storage=
URIs for tasks and projects in proxy_api.py endpoints. Attackers can acces=
s other tenants' cloud storage objects by creating a separate organization = and supplying arbitrary file URIs to presign or stream bucket contents.</td=
<td>2026-09-03</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85211" target=3D= "_blank" rel=3D"noopener">CVE-2026-85211</a></td>
</tr>
<td class=3D"vendor-product">Hummingbird Performance--Hummingbird Performan= ce</td>
<td>The Hummingbird Performance WordPress plugin before 3.21.2 does not res= trict a network-wide setting to network administrators, allowing an adminis= trator of any single site on a multisite network to execute arbitrary code = across the entire network.</td>
<td>2026-09-04</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19224" target=3D= "_blank" rel=3D"noopener">CVE-2026-19224</a></td>
</tr>
<td class=3D"vendor-product">hyperledger-firefly--firefly</td>
<td>A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. T=
he impacted element is the function ValidateOptions of the file internal/ev= ents/webhooks/webhooks.go of the component Webhook Subscription. Performing=
a manipulation of the argument url results in server-side request forgery.=
Remote exploitation of the attack is possible. The exploit has been made p= ublic and could be used. The vendor was contacted early about this disclosu=
re but did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82957" target=3D= "_blank" rel=3D"noopener">CVE-2026-82957</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 S=
AP Adapter is vulnerable to an XML external entity (XXE) attack.</td> <td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81832" target=3D= "_blank" rel=3D"noopener">CVE-2026-81832</a></td>
</tr>
<td class=3D"vendor-product">IBM--ContextForge MCP Gateway</td>
<td>IBM ContextForge MCP Gateway <=3D v1.0.7 MCP Context Forge could all=
ow a remote authenticated attacker to obtain sensitive credentials and esca= late privileges due to improper validation of jq filters.</td> <td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18486" target=3D= "_blank" rel=3D"noopener">CVE-2026-18486</a></td>
</tr>
<td class=3D"vendor-product">IBM--ContextForge MCP Gateway</td>
<td>IBM ContextForge MCP Gateway could allow a remote authenticated attacke=
r to obtain sensitive information due to server-side request forgery via DN=
S rebinding.</td>
<td>2026-09-04</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77822" target=3D= "_blank" rel=3D"noopener">CVE-2026-77822</a></td>
</tr>
<td class=3D"vendor-product">IBM--ContextForge MCP Gateway (`mcp-contextfor= ge-gateway`)</td>
<td>IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <=3D v1.0.=
6 MCP Context Forge could allow a remote authenticated attacker to obtain s= ensitive information due to a DNS rebinding vulnerability during tool invoc= ation.</td>
<td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18905" target=3D= "_blank" rel=3D"noopener">CVE-2026-18905</a></td>
</tr>
<td class=3D"vendor-product">IBM--ContextForge MCP Gateway - Translate util= ity</td>
<td>IBM ContextForge MCP Gateway - Translate utility <=3D 1.0.8 MCP Cont= ext Forge could allow a remote attacker to obtain sensitive information fro=
m other sessions due to exposure of data elements to the wrong session.</td=
<td>2026-09-04</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18489" target=3D= "_blank" rel=3D"noopener">CVE-2026-18489</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulat=
e database transactions due to improper authorization in the DDM target dis= patcher.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18175" target=3D= "_blank" rel=3D"noopener">CVE-2026-18175</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unau= thorized access due to improper validation of client-supplied authenticatio=
n parameters.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18221" target=3D= "_blank" rel=3D"noopener">CVE-2026-18221</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to execute arbitrary code due to an authorization bypass in the = flow build process.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19298" target=3D= "_blank" rel=3D"noopener">CVE-2026-19298</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to delete arbitrary local files or directories due to improper l= imitation of a pathname to a restricted directory.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19303" target=3D= "_blank" rel=3D"noopener">CVE-2026-19303</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to = obtain sensitive information due to server-side request forgery.</td>
<td>2026-09-04</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19305" target=3D= "_blank" rel=3D"noopener">CVE-2026-19305</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to = obtain sensitive information due to incomplete scrubbing of sensitive crede= ntial fields.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19300" target=3D= "_blank" rel=3D"noopener">CVE-2026-19300</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to obtain sensitive information from internal services due to a = URL parser discrepancy.</td>
<td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19304" target=3D= "_blank" rel=3D"noopener">CVE-2026-19304</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker =
to read arbitrary files from the server filesystem - including server secre=
t material (secret_key, JWT signing keys, the application database, /proc/s= elf/environ, and other tenants' upload directories) - by supplying absolute=
paths or traversal sequences in the files parameter of an authenticated bu= ild request. The file contents were embedded as text attachments in the lan= guage model prompt and transmitted to the configured model endpoint, result= ing in confidential data exfiltration. This bypassed the LANGFLOW_RESTRICT_= LOCAL_FILE_ACCESS=3Dtrue containment boundary, which was enforced for other=
file-reading components but not for the Chat Input to Message attachment p= ipeline.</td>
<td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19306" target=3D= "_blank" rel=3D"noopener">CVE-2026-19306</a></td>
</tr>
<td class=3D"vendor-product">IBM--Netezza Software</td>
<td>IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials t= hat are hardcoded in the application source code, allowing unauthorized acc= ess to the container registry. The exposed secret enables attackers to pull=
private container images, potentially revealing proprietary code, configur= ation details, and other sensitive information.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8862" target=3D"= _blank" rel=3D"noopener">CVE-2026-8862</a></td>
</tr>
<td class=3D"vendor-product">IBM--Observability with Instana (Agent)</td> <td>IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IB=
M Instana Agent Operator could allow an authenticated Kubernetes tenant to = hijack or permanently destroy another tenant's cluster-level RBAC permissio= ns, caused by cluster-scoped RBAC objects being keyed solely by the bare CR=
name with no namespace disambiguation, allowing a same-named `InstanaAgent=
` CR in an attacker-controlled namespace to silently overwrite the shared `= ClusterRoleBinding` or delete it outright and revoke the victim agent's clu= ster monitoring access.</td>
<td>2026-09-04</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19274" target=3D= "_blank" rel=3D"noopener">CVE-2026-19274</a></td>
</tr>
<td class=3D"vendor-product">IBM--Observability with Instana (Agent)</td> <td>IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IB=
M Instana Agent Operator could allow an authenticated remote attacker to ob= tain sensitive information, caused by missing destination namespace validat= ion when copying etcd mTLS client credentials from the openshift-etcd syste=
m namespace into an attacker-controlled namespace.</td>
<td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19283" target=3D= "_blank" rel=3D"noopener">CVE-2026-19283</a></td>
</tr>
<td class=3D"vendor-product">IBM--Operational Decision Manager</td>
<td>IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, = 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthent= icated attacker can execute arbitrary SQL statements and leverage database = functionality to write a web shell to the application web root, resulting i=
n remote code execution.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18658" target=3D= "_blank" rel=3D"noopener">CVE-2026-18658</a></td>
</tr>
<td class=3D"vendor-product">Icegram--Email Subscribers & Newsletters</=
<td>Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & N= ewsletters <=3D 5.9.33 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81290" target=3D= "_blank" rel=3D"noopener">CVE-2026-81290</a></td>
</tr>
<td class=3D"vendor-product">ICP DAS--UA-2200</td>
<td>A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. Th=
e affected element is the function ArmAngstromInstructionSet of the file /C= GI?RestApi=3DSetHostname. Executing a manipulation of the argument Paramete= rArray can lead to command injection. The attack can be executed remotely. = The exploit has been published and may be used. The vendor was contacted ea= rly about this disclosure but did not respond in any way.</td>
<td>2026-09-01</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84059" target=3D= "_blank" rel=3D"noopener">CVE-2026-84059</a></td>
</tr>
<td class=3D"vendor-product">Ido Kobelkowsky--Simple Payment</td> <td>Unauthenticated Cross Site Scripting (XSS) in Simple Payment <=3D 2.= 5.1 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81292" target=3D= "_blank" rel=3D"noopener">CVE-2026-81292</a></td>
</tr>
<td class=3D"vendor-product">ieungSoft--Ultra RAMDisk Pro</td>
<td>A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. Thi=
s issue affects some unknown processing in the library URDSCSI.sys of the c= omponent Kernel Driver. This manipulation causes improper privilege managem= ent. The attack needs to be launched locally. The exploit has been publicly=
disclosed and may be utilized. The vendor was contacted early about this d= isclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82807" target=3D= "_blank" rel=3D"noopener">CVE-2026-82807</a></td>
</tr>
<td class=3D"vendor-product">Ignition --Ignition =C2=A08.1.5.3<br>=C2=A0</t=
<td>In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" se= tting shipped blank, which permitted any authenticated user to create proje= cts (if they can execute gateway scripts). Ignition 8.1.54 restricts projec=
t creation to Designer sessions and no longer relies on this setting. The 8=
.3 series is not affected.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77393" target=3D= "_blank" rel=3D"noopener">CVE-2026-77393</a></td>
</tr>
<td class=3D"vendor-product">ILIAS-eLearning e.V.--ILIAS</td>
<td>ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vu= lnerability in the repository trash table where the table navigation sort f= ield from HTTP requests is passed directly into the ORDER BY clause of a SQ=
L query without validation against declared sortable columns. Authenticated=
users with write permission on any container can inject arbitrary SQL thro= ugh the sort parameter, and because multi-statement execution is enabled in=
the database layer, stacked queries enable full database read and write ac= cess as well as administrator account takeover.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82538" target=3D= "_blank" rel=3D"noopener">CVE-2026-82538</a></td>
</tr>
<td class=3D"vendor-product">Inbox Foundry--ActiveInbox Extension</td>
<td>A vulnerability was identified in Inbox Foundry ActiveInbox Extension u=
p to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/se= rvice-worker.production-esm.js of the component Google OAuth Client Secret.=
Such manipulation leads to hard-coded credentials. The attack can be execu= ted remotely. The exploit is publicly available and might be used. The vend=
or was informed beforehand about the issue. The support explains, that "[a]=
t the moment, the [bug bounty] programme is on hold while we work through a=
large number of existing reports."</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82808" target=3D= "_blank" rel=3D"noopener">CVE-2026-82808</a></td>
</tr>
<td class=3D"vendor-product">Insyde Software--InsydeH2O</td>
<td>HDD password plaintext is stored in a UEFI variable.</td> <td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-38489" target=3D= "_blank" rel=3D"noopener">CVE-2021-38489</a></td>
</tr>
<td class=3D"vendor-product">Interinfo--DreamMaker</td>
<td>DreamMaker developed by Interinfo has a SQL Injection vulnerability. Au= thenticated remote attackers can inject arbitrary SQL commands to read, mod= ify, and delete database contents.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85540" target=3D= "_blank" rel=3D"noopener">CVE-2026-85540</a></td>
</tr>
<td class=3D"vendor-product">Invicti Security Corp.--Acunetix</td>
<td>Acunetix 25.11.251107123 for Windows contains a local privilege escalat= ion vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that = allows low-privileged local attackers to execute arbitrary code as SYSTEM b=
y exploiting a missing hardcoded directory path for OpenSSL-related files. = Attackers can create the missing directory, place a malicious file at the e= xpected path, and cause the SYSTEM-level wvsc.exe process to load and execu=
te it, resulting in full privilege escalation.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6958" target=3D"= _blank" rel=3D"noopener">CVE-2026-6958</a></td>
</tr>
<td class=3D"vendor-product">iova.mihai--SliceWP</td>
<td>Unauthenticated Cross Site Scripting (XSS) in SliceWP <=3D 1.2.10 ve= rsions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82224" target=3D= "_blank" rel=3D"noopener">CVE-2026-82224</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A security flaw has been discovered in itsourcecode Online Medicine Del= ivery System 1.0. Affected is the function Employee::employeeAuthentication=
of the file /rider/login.php of the component Login Interface. The manipul= ation of the argument emp_email results in sql injection. It is possible to=
launch the attack remotely. The exploit has been released to the public an=
d may be used for attacks.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82610" target=3D= "_blank" rel=3D"noopener">CVE-2026-82610</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A weakness has been identified in itsourcecode Online Medicine Delivery=
System 1.0. Affected by this vulnerability is the function Customer::cusAu= thentication of the file /login.php of the component Customer Login Interfa= ce. This manipulation of the argument U_USERNAME causes sql injection. The = attack can be initiated remotely. The exploit has been made available to th=
e public and could be used for attacks.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82611" target=3D= "_blank" rel=3D"noopener">CVE-2026-82611</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A security vulnerability has been detected in itsourcecode Online Medic= ine Delivery System 1.0. Affected by this issue is the function loadResultL= ist of the file /index.php?q=3Dsingle-item of the component Product Detail = Page. Such manipulation of the argument ID leads to sql injection. The atta=
ck can be launched remotely. The exploit has been disclosed publicly and ma=
y be used.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82612" target=3D= "_blank" rel=3D"noopener">CVE-2026-82612</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A vulnerability was detected in itsourcecode Online Medicine Delivery S= ystem 1.0. This affects the function loadResultList of the file /index.php?= q=3Dproduct of the component Product Search Interface. Performing a manipul= ation of the argument Search results in sql injection. The attack may be in= itiated remotely. The exploit is now public and may be used.</td> <td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82613" target=3D= "_blank" rel=3D"noopener">CVE-2026-82613</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A flaw has been found in itsourcecode Online Medicine Delivery System 1= .0. This vulnerability affects the function loadResultList of the file /ind= ex.php?q=3Dproduct of the component Product Category Filter Interface. Exec= uting a manipulation of the argument Category can lead to sql injection. Th=
e attack may be launched remotely. The exploit has been published and may b=
e used.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82614" target=3D= "_blank" rel=3D"noopener">CVE-2026-82614</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A vulnerability has been found in itsourcecode Online Medicine Delivery=
System 1.0. This issue affects the function Customer::find_phone of the fi=
le /passwordrecover.php of the component Password Recovery Interface. The m= anipulation of the argument phonenumber leads to sql injection. Remote expl= oitation of the attack is possible. The exploit has been disclosed to the p= ublic and may be used.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82615" target=3D= "_blank" rel=3D"noopener">CVE-2026-82615</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A security vulnerability has been detected in itsourcecode Online Medic= ine Delivery System 1.0. Affected by this issue is the function Order::pupd= ate of the file /rider/orders/controller.php?action=3Dedit&actions=3Dco= nfirm of the component Order Status Update. The manipulation of the argumen=
t ID leads to sql injection. It is possible to initiate the attack remotely=
. The exploit has been disclosed publicly and may be used.</td> <td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85187" target=3D= "_blank" rel=3D"noopener">CVE-2026-85187</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A security flaw has been discovered in itsourcecode Online Medicine Del= ivery System 1.0. The affected element is the function doInsert of the file=
/rider/orders/controller.php?action=3Dadd of the component Order Managemen=
t Controller. Performing a manipulation of the argument image results in un= restricted upload. Remote exploitation of the attack is possible. The explo=
it has been released to the public and may be used for attacks.</td> <td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85208" target=3D= "_blank" rel=3D"noopener">CVE-2026-85208</a></td>
</tr>
<td class=3D"vendor-product">IXON--VPN Client<br>=C2=A0</td>
<td>Improper neutralization of CRLF sequences in IXON VPN Client before ver= sion 1.4.7 allows an attacker to execute commands as root or SYSTEM. Config= uration values accepted by the local service are written to a file later co= nsumed by a privileged subprocess, without line-ending sequences being neut= ralized, which allows additional directives to be introduced into that file=
. The configuration interface accepts changes without authenticating or ver= ifying the origin of the requester. The injected configuration persists on = disk across restarts of the client and the operating system, and the VPN co= nnection continues to function normally, so there is no behavioral change v= isible to the user.</td>
<td>2026-09-04</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75925" target=3D= "_blank" rel=3D"noopener">CVE-2026-75925</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types=
marked as storing their configuration in independent top-level configurati=
on files in Jenkins (such as the global configuration and jobs) can appear =
as nested field values in user-submitted `config.xml` documents and subsequ= ently handle HTTP requests via Stapler, resulting in remote code execution.= </td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84645" target=3D= "_blank" rel=3D"noopener">CVE-2026-84645</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e5800= 8a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapl=
er does not restrict the types of objects that can be instantiated via form=
data binding to those compatible with the expected field type, allowing at= tackers with Overall/Read permission to instantiate types related to config= uration for which that field type was not intended.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84647" target=3D= "_blank" rel=3D"noopener">CVE-2026-84647</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log v= iewer does not escape log record metadata (source, level, and timestamp) re= sulting in a stored cross-site scripting (XSS) vulnerability exploitable by=
attackers in control of agent processes.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84648" target=3D= "_blank" rel=3D"noopener">CVE-2026-84648</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both incl= usive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through = 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HT=
TP endpoint serving dynamically generated JavaScript resources embeds the u= ser's cross-site request forgery (CSRF) token (crumb) as a string literal, = allowing attackers with control over a page hosted on the same site as Jenk= ins to obtain a valid crumb for the targeted user's session and perform act= ions on their behalf.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84649" target=3D= "_blank" rel=3D"noopener">CVE-2026-84649</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields=
cannot be excluded from deserialization, allowing attackers able to submit=
configuration updates to specify the values of transient fields that will =
be deserialized, the impact depending on how those fields are used.</td> <td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84650" target=3D= "_blank" rel=3D"noopener">CVE-2026-84650</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not=
rotate the session when a user is authenticated via the "remember me" cook= ie, allowing attackers able to serve content on the same site as Jenkins to=
set a known session cookie in the victim's browser, which after the victim=
authenticates via the "remember me" cookie, grants the attacker access to = Jenkins as that user.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84652" target=3D= "_blank" rel=3D"noopener">CVE-2026-84652</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Allure Plugin</td>
<td>A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earl= ier allows attackers with Item/Read permission on jobs that publish Allure = report results to read arbitrary files on the Jenkins controller's file sys= tem.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84669" target=3D= "_blank" rel=3D"noopener">CVE-2026-84669</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Customizable Header P= lugin</td>
<td>Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier all= ows overwriting the plugin's appearance configuration through Stapler data = binding, allowing attackers to configure a custom SVG icon containing inlin=
e JavaScript, resulting in a stored cross-site scripting (XSS) vulnerabilit= y.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84673" target=3D= "_blank" rel=3D"noopener">CVE-2026-84673</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins File Parameter Plugin= </td>
<td>Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows wr= iting files to arbitrary locations on the Jenkins controller file system th= rough Stapler data binding, which can lead to remote code execution.</td> <td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84671" target=3D= "_blank" rel=3D"noopener">CVE-2026-84671</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Microsoft Entra ID (p= reviously Azure AD) Plugin</td>
<td>Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc= 2d2 and earlier grants Entra group permissions using both the group's uniqu=
e object ID and its display name, allowing attackers who can create an Entr=
a group with a colliding display name to gain the permissions configured fo=
r a privileged group.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84672" target=3D= "_blank" rel=3D"noopener">CVE-2026-84672</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Performance Plugin</t=
<td>Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not re= strict the classes that can be instantiated when deserializing cached perfo= rmance reports stored in the build directory on the Jenkins controller, all= owing attackers with Item/Configure permission to execute arbitrary code on=
the Jenkins controller.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84670" target=3D= "_blank" rel=3D"noopener">CVE-2026-84670</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins SAML Plugin</td>
<td>Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwritin=
g the SAML identity provider metadata file through Stapler data binding, al= lowing attackers to replace it with attacker-controlled content and authent= icate as any user.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84668" target=3D= "_blank" rel=3D"noopener">CVE-2026-84668</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins SonarQube Scanner Plu= gin</td>
<td>Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL = schemes for the dashboard links it creates based on SonarQube scanner resul= ts, allowing the `javascript:` scheme, resulting in a stored cross-site scr= ipting (XSS) vulnerability exploitable by attackers with Item/Configure per= mission.</td>
<td>2026-09-02</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84665" target=3D= "_blank" rel=3D"noopener">CVE-2026-84665</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins ThinBackup Plugin</td=
<td>Jenkins ThinBackup Plugin 2.1.4 and earlier allows overwriting the plug= in's backup configuration through Stapler data binding, allowing attackers =
to redirect backup writes to an attacker-specified directory and to include=
arbitrary files from the Jenkins controller file system in backups.</td> <td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84667" target=3D= "_blank" rel=3D"noopener">CVE-2026-84667</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins TICS Plugin</td>
<td>OS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and = earlier allows attackers able to control build environment variable values =
to execute arbitrary commands on the agent running the build.</td>
<td>2026-09-02</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84675" target=3D= "_blank" rel=3D"noopener">CVE-2026-84675</a></td>
</tr>
<td class=3D"vendor-product">JetBackup--JetBackup</td>
<td>The JetBackup WordPress plugin before 3.1.23.5 does not verify the role=
or capabilities of the account it preserves across a restore or migration = before granting it administrator privileges, allowing a subscriber-level us=
er to gain administrator access after the site owner restores or migrates t=
he site.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19453" target=3D= "_blank" rel=3D"noopener">CVE-2026-19453</a></td>
</tr>
<td class=3D"vendor-product">jina-ai--reader</td>
<td>jina-ai reader contains a server-side request forgery vulnerability whe=
re URL validation is performed only on the initial request but not re-appli=
ed to subsequent redirect hops. Attackers can craft a public URL that redir= ects to internal network addresses or cloud metadata endpoints, allowing th=
e server to fetch and return the target's response body to the attacker.</t=
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85699" target=3D= "_blank" rel=3D"noopener">CVE-2026-85699</a></td>
</tr>
<td class=3D"vendor-product">jofpin trape--jofpin trape 2.0<br>=C2=A0</td> <td>A weakness has been identified in jofpin trape 2.0. This affects an unk= nown part of the file core/user.py. This manipulation of the argument vId/i=
d causes authorization bypass. Remote exploitation of the attack is possibl=
e. The exploit has been made available to the public and could be used for = attacks. The project was informed of the problem early through an issue rep= ort but has not responded yet.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85638" target=3D= "_blank" rel=3D"noopener">CVE-2026-85638</a></td>
</tr>
<td class=3D"vendor-product">John Havlik--Breadcrumb NavXT</td> <td>Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <=3D = 7.5.1 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84765" target=3D= "_blank" rel=3D"noopener">CVE-2026-84765</a></td>
</tr>
<td class=3D"vendor-product">JoomUnited--WP File Download</td>
<td>The WP File Download plugin for WordPress is vulnerable to arbitrary fi=
le deletion due to insufficient file path validation in the delete function=
in all versions. This makes it possible for authenticated attackers, with = subscriber-level access and above, to delete arbitrary files on the server,=
which can easily lead to remote code execution when the right file is dele= ted (such as wp-config.php). The two-stage exploit requires a first request=
to the file.save task to persist the path-traversal string into file metad= ata, followed by a second request to the file.delete task to trigger the un= link call - both endpoints lack capability checks and nonce enforcement.</t=
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14982" target=3D= "_blank" rel=3D"noopener">CVE-2026-14982</a></td>
</tr>
<td class=3D"vendor-product">kamailio -- kamailio</td>
<td>An issue in kamailio v.6.1.1 and before allows a remote attacker to cau=
se a denial of service via the IMS P-CSCF registration handling components<=
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52022" target=3D= "_blank" rel=3D"noopener">CVE-2026-52022</a></td>
</tr>
<td class=3D"vendor-product">Kamailio--Kamailio</td>
<td>A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affe= cts the function get_4bytes of the file src/modules/ims_registrar_scscf/cxd= x_avp.c of the component AVP Handler. Executing a manipulation can lead to = out-of-bounds read. The attack may be performed from remote. The exploit ha=
s been publicly disclosed and may be utilized. This patch is called abb5d60= af6eefbd367bf6588c5589566b090e272. It is advisable to implement a patch to = correct this issue. The vendor points out, that "[v]ersion 5.5.0 is old and=
not maintained anymore."</td>
<td>2026-08-31</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82608" target=3D= "_blank" rel=3D"noopener">CVE-2026-82608</a></td>
</tr>
<td class=3D"vendor-product">kerberosmansour--hulumi</td>
<td>hulumi versions before v1.3.2 contain a privilege escalation vulnerabil= ity in the weekly integration IAM policy that allows role lifecycle operati= ons on af-e2e-* roles without sufficient boundary restrictions. Attackers w= ith the documented principal can create persistent higher-privilege roles i=
n the sandbox account.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82857" target=3D= "_blank" rel=3D"noopener">CVE-2026-82857</a></td>
</tr>
<td class=3D"vendor-product">kerberosmansour--hulumi</td>
<td>hulumi versions before v1.3.2 contain a deployment SCP template that al= lows tag-on-create bypasses for hulumi:iac-role protections. Attackers can = bypass intended IAM boundary restrictions by exploiting the weakened SCP te= mplate in downstream deployments.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82859" target=3D= "_blank" rel=3D"noopener">CVE-2026-82859</a></td>
</tr>
<td class=3D"vendor-product">kerberosmansour--hulumi</td>
<td>Hulumi versions before v1.3.2 resolve the threat-model helper script fr=
om an unsafe root, allowing workspace files to shadow the intended helper s= cript. Attackers can place malicious files in the workspace to execute arbi= trary code during local skill execution.</td>
<td>2026-08-31</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82862" target=3D= "_blank" rel=3D"noopener">CVE-2026-82862</a></td>
</tr>
<td class=3D"vendor-product">killbill--killbill</td>
<td>Kill Bill through 0.24.21 fails to enforce permission annotations on se= veral AdminResource endpoints including getQueueEntries, invalidatesCache, = and putOutOfRotation. Authenticated users with minimal account:read permiss= ions can read internal queues, flush server caches, and disable the server =
by putting the host out of rotation.</td>
<td>2026-09-03</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85213" target=3D= "_blank" rel=3D"noopener">CVE-2026-85213</a></td>
</tr>
<td class=3D"vendor-product">kirillbdev--WC Ukraine Shipping</td> <td>Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipp= ing <=3D 1.22.3 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84836" target=3D= "_blank" rel=3D"noopener">CVE-2026-84836</a></td>
</tr>
<td class=3D"vendor-product">kishan0725--Hospital-Management-System</td>
<td>A security flaw has been discovered in kishan0725 Hospital-Management-S= ystem 1.0. This vulnerability affects unknown code of the file /search.php.=
The manipulation of the argument Contact results in sql injection. It is p= ossible to launch the attack remotely. The exploit has been released to the=
public and may be used for attacks. The vendor was contacted early about t= his disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82914" target=3D= "_blank" rel=3D"noopener">CVE-2026-82914</a></td>
</tr>
<td class=3D"vendor-product">Kitae Park--Mang Board WP</td>
<td>Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= =3D 2.3.8 versions.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84770" target=3D= "_blank" rel=3D"noopener">CVE-2026-84770</a></td>
</tr>
<td class=3D"vendor-product">klaussilveira--GitList</td>
<td>A security vulnerability has been detected in klaussilveira GitList 2.0= .0. Affected by this vulnerability is the function getDefaultBranch of the = file src/SCM/System/Git/CommandLine.php of the component Git Command Line. = Such manipulation leads to os command injection. The attack can be executed=
remotely. The exploit has been disclosed publicly and may be used. Upgradi=
ng to version 3.0.0-beta addresses this issue. The name of the patch is 88c= f2866083d5f7c20d9d565c45f828a7ad1516b. Upgrading the affected component is = advised.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82668" target=3D= "_blank" rel=3D"noopener">CVE-2026-82668</a></td>
</tr>
<td class=3D"vendor-product">Klemsan Electrical Electronics Inc.--KIO (Klem= san Internet Objects)</td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability=
in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allo=
ws Code Injection. This issue affects KIO (Klemsan Internet Objects): befor=
e v1.9.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18808" target=3D= "_blank" rel=3D"noopener">CVE-2026-18808</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno versions v1.9.0 through v1.12.7 contain a policy exception hand= ling flaw. When a policy in enforce mode is combined with two PolicyExcepti= ons, the less restrictive exception takes precedence, allowing an attacker =
to bypass the policy by crafting a resource name that matches the second ex= ception's name pattern (e.g., '*ingress*'). This can be used to circumvent = policies such as one blocking hostPath volumes. Fixed in v1.13.0.</td> <td>2026-09-01</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84200" target=3D= "_blank" rel=3D"noopener">CVE-2026-84200</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno before 1.16.4 automatically attaches the admission controller's=
ServiceAccount token to outbound HTTP requests in apiCall service mode wit= hout explicit authorization headers. Attackers can exfiltrate the token by = directing apiCall requests to external or attacker-controlled endpoints, ga= ining full control over Kyverno policies and cluster resources.</td> <td>2026-09-01</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84195" target=3D= "_blank" rel=3D"noopener">CVE-2026-84195</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno before 1.18.0 contains a server-side request forgery vulnerabil= ity in apiCall.service.url that allows authenticated users to send arbitrar=
y HTTP requests by injecting user-controlled input through variable substit= ution. Attackers can target internal services, cloud metadata endpoints, an=
d loopback addresses, with response data reflected in admission error messa= ges enabling non-blind data exfiltration.</td>
<td>2026-09-01</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84196" target=3D= "_blank" rel=3D"noopener">CVE-2026-84196</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vul= nerability in the APICall feature. The URL field in a Policy's ServiceCall = configuration is not validated, so a user with namespace-level Policy creat= ion permissions can direct Kyverno to make HTTP requests to arbitrary inter= nal resources (e.g., cloud metadata endpoints such as 169.254.169.254 or ot= her tenants' resources). Because Kyverno executes these requests using its = cluster-wide high-privilege ServiceAccount (a Confused Deputy problem), the=
responses-potentially including other tenants' secrets and cloud IAM crede= ntials-are returned in the PolicyReport and can be read by the attacker, br= eaking multi-tenant isolation.</td>
<td>2026-09-01</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84199" target=3D= "_blank" rel=3D"noopener">CVE-2026-84199</a></td>
</tr>
<td class=3D"vendor-product">Lara Dashboard--Lara Dashboard<br>=C2=A0</td> <td>Lara Dashboard before 1.3.0 contains an authentication bypass vulnerabi= lity in the screenshot-login route that allows unauthenticated attackers to=
authenticate as any user by email when APP_ENV is not production. Attacker=
s can request the GET /screenshot-login/{email} endpoint with a registered = email address to receive a fully authenticated session, enabling access to = user administration, settings, database contents, and arbitrary code execut= ion through the module installer.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86184" target=3D= "_blank" rel=3D"noopener">CVE-2026-86184</a></td>
</tr>
<td class=3D"vendor-product">Laravel--Laravel=C2=A0<br>=C2=A0</td>
<td>Laravel is a web application framework. Prior to versions 12.60.0 and 1= 3.10.0, a CRLF injection vulnerability in Laravel's email validation, in co= mbination with how Symfony Mailer and Symfony Mime handle certain character=
sequences, may allow an unauthenticated attacker to interfere with outboun=
d email processing in applications that send mail to user-supplied addresse=
s. This issue has been patched in versions 12.60.0 and 13.10.0.</td> <td>2026-09-04</td>
<td>8.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48019" target=3D= "_blank" rel=3D"noopener">CVE-2026-48019</a></td>
</tr>
<td class=3D"vendor-product">laravel-backup-restore --laravel-backup-restor= e=C2=A0<br>=C2=A0</td>
<td>laravel-backup-restore restores database backups made with spatie/larav= el-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS = command injection during database restore. This issue has been patched in v= ersion 1.9.4.</td>
<td>2026-09-04</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53932" target=3D= "_blank" rel=3D"noopener">CVE-2026-53932</a></td>
</tr>
<td class=3D"vendor-product">lavague-ai--LaVague</td>
<td>LaVague 0.2.35 contains a remote code execution vulnerability in Python= FromMarkdownExtractor.extract_as_object that evaluates untrusted language m= odel output derived from web page content. Attackers can inject malicious P= ython code through web pages using indirect prompt injection to execute arb= itrary code on the operator's host without review.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85694" target=3D= "_blank" rel=3D"noopener">CVE-2026-85694</a></td>
</tr>
<td class=3D"vendor-product">lenve--vhr</td>
<td>vhr fails to validate user authorization in the PUT /hr/info endpoint, = allowing authenticated users to modify arbitrary HR profiles by supplying a=
ny profile ID in the request body. Attackers can overwrite other users' nam= es, addresses, and disable accounts including administrators to cause denia=
l of service.</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85214" target=3D= "_blank" rel=3D"noopener">CVE-2026-85214</a></td>
</tr>
<td class=3D"vendor-product">lenve--vhr</td>
<td>vhr through commit 03abbd3 fails to verify that the account ID in PUT /= hr/pass requests belongs to the authenticated caller. Authenticated attacke=
rs can change arbitrary account passwords by supplying a target account ID = and that account's current password in the request body.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85182" target=3D= "_blank" rel=3D"noopener">CVE-2026-85182</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, c= ommit message) returned by the admin-configurable Oxidized integration URL = (oxidized.url) into the device showconfig page without applying htmlspecial= chars(). An administrator who points the Oxidized URL at an attacker-contro= lled server (SSRF) can cause it to return malicious JSON, resulting in stor= ed/persistent cross-site scripting affecting all users who view any device'=
s showconfig tab. Fixed in 26.7.0.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84189" target=3D= "_blank" rel=3D"noopener">CVE-2026-84189</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS versions before 26.5.0 contain a remote code execution vulnera= bility in the AboutController where the snmpget configuration parameter is = passed to shell_exec() without proper validation. An authenticated administ= rator can modify the snmpget configuration to point to a malicious executab=
le file and trigger code execution by accessing the /about endpoint.</td> <td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84190" target=3D= "_blank" rel=3D"noopener">CVE-2026-84190</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerabi= lity in legacy PHP templates that output SNMP-sourced and syslog-sourced da=
ta without escaping. An attacker who controls a monitored network device ca=
n inject arbitrary JavaScript through SNMP interface descriptions or syslog=
program fields that executes when authenticated users view affected pages.= </td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84192" target=3D= "_blank" rel=3D"noopener">CVE-2026-84192</a></td>
</tr>
<td class=3D"vendor-product">libxml2--libxml2<br>=C2=A0</td>
<td>In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat s= tack-based buffer overflow.</td>
<td>2026-09-05</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86140" target=3D= "_blank" rel=3D"noopener">CVE-2026-86140</a></td>
</tr>
<td class=3D"vendor-product">light0011--cms</td>
<td>A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d= 5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by thi=
s issue is the function AuthController::_initialize of the file App/Admin/C= ontroller/ChapterController.class.php of the component Chapter Controller. = The manipulation leads to authorization bypass. The attack can be initiated=
remotely. The exploit is publicly available and might be used. Continious = delivery with rolling releases is used by this product. Therefore, no versi=
on details of affected nor updated releases are available. The project was = informed of the problem early through an issue report but has not responded=
yet.</td>
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85378" target=3D= "_blank" rel=3D"noopener">CVE-2026-85378</a></td>
</tr>
<td class=3D"vendor-product">light0011--cms</td>
<td>A security flaw has been discovered in light0011 cms c774dce31c6df00555= 68a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affec=
ts the function ChapterModel::searchChapter of the file App/Home/Controller= /ChapterController.class.php of the component Query Builder. The manipulati=
on of the argument content results in sql injection. The attack can be laun= ched remotely. The exploit has been released to the public and may be used = for attacks. This product does not use versioning. This is why information = about affected and unaffected releases are unavailable. The project was inf= ormed of the problem early through an issue report but has not responded ye= t.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85379" target=3D= "_blank" rel=3D"noopener">CVE-2026-85379</a></td>
</tr>
<td class=3D"vendor-product">light0011--cms</td>
<td>A weakness has been identified in light0011 cms c774dce31c6df0055568a8d= 5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerabil= ity affects the function catchimage of the file Public/ueditor/php/controll= er.php of the component UEditor. This manipulation of the argument source[]=
causes server-side request forgery. The attack may be initiated remotely. = The exploit has been made available to the public and could be used for att= acks. This product uses a rolling release model to deliver continuous updat= es. As a result, specific version information for affected or updated relea= ses is not available. The project was informed of the problem early through=
an issue report but has not responded yet.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85380" target=3D= "_blank" rel=3D"noopener">CVE-2026-85380</a></td>
</tr>
<td class=3D"vendor-product">Lightstar--SmartIT Desktop Manager</td> <td>SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded = Credentials vulnerability. Unauthenticated remote attackers can obtain the = SSH service account credentials and passwords for the SmartIT Agent directl=
y from the application source code.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85146" target=3D= "_blank" rel=3D"noopener">CVE-2026-85146</a></td>
</tr>
<td class=3D"vendor-product">Lightstar--SmartIT Desktop Manager</td> <td>SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded = Credentials vulnerability. Unauthenticated remote attackers can exploit a f= ixed password to remotely access user hosts.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85148" target=3D= "_blank" rel=3D"noopener">CVE-2026-85148</a></td>
</tr>
<td class=3D"vendor-product">Lightstar--SmartIT Desktop Manager</td> <td>SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded = Credentials vulnerability. Unauthenticated remote attackers can obtain a sp= ecific password from the source code, which can be used to retrieve the AES=
encryption key used for communication.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85147" target=3D= "_blank" rel=3D"noopener">CVE-2026-85147</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM=
: x86/mmu: WARN and clear role.invalid when creating a child shadow page Ex= plicitly clear role.invalid when deriving a child shadow page's role from i=
ts parent to harden against bugs elsewhere in KVM, as violating KVM's invar= iant that invalid pages are NOT on the list of active MMU pages leads to us= e-after-free due to __kvm_mmu_prepare_zap_page() using list_add() instead o=
f list_move() when processing an invalid shadow page, i.e. makes a bad situ= ation far worse. Yell loudly if the parent is invalid, as it means KVM has = missed a validity check, i.e. KVM is attempting to map memory using an inva= lid/obsolete root, but continue on as the child is otherwise still a valid = shadow page. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D BUG: KASAN:=
slab-use-after-free in __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm] Write=
of size 8 at addr ff11000153dd1368 by task repro/853 CPU: 1 UID: 1000 PID:=
853 Comm: repro Not tainted 7.2.0-rc2-3aec122bdcaf-next-vm #5 PREEMPT Hard= ware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 Call = Trace: <TASK> dump_stack_lvl+0x4b/0x70 print_report+0x153/0x49c kasan= _report+0xbc/0xf0 __kvm_mmu_get_shadow_page+0x1817/0x1860 [kvm] mmu_alloc_r= oot+0x141/0x320 [kvm] kvm_mmu_load+0x612/0x20f0 [kvm] kvm_arch_vcpu_ioctl_r= un+0x3dd5/0x6150 [kvm] kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm] __x64_sys_ioctl+0x= 131/0x1b0 do_syscall_64+0x67/0x5f0 entry_SYSCALL_64_after_hwframe+0x4b/0x53=
</TASK> Allocated by task 853: kasan_save_stack+0x20/0x40 kasan_save= _track+0x14/0x30 __kasan_slab_alloc+0x5f/0x70 kmem_cache_alloc_noprof+0xfe/= 0x2e0 __kvm_mmu_topup_memory_cache+0x135/0x530 [kvm] paging64_page_fault+0x= 318/0x1e30 [kvm] kvm_mmu_do_page_fault+0x21d/0x630 [kvm] kvm_mmu_page_fault= +0x18c/0x17b0 [kvm] kvm_arch_vcpu_ioctl_run+0x1f35/0x6150 [kvm] kvm_vcpu_io= ctl+0x5e4/0x10d0 [kvm] __x64_sys_ioctl+0x131/0x1b0 do_syscall_64+0x67/0x5f0=
entry_SYSCALL_64_after_hwframe+0x4b/0x53 Freed by task 853: kasan_save_sta= ck+0x20/0x40 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 __ka= san_slab_free+0x43/0x70 kmem_cache_free+0xe2/0x400 kvm_mmu_commit_zap_page.= part.0+0x1e2/0x310 [kvm] kvm_mmu_free_roots+0x283/0x560 [kvm] kvm_arch_vcpu= _ioctl_run+0x33c8/0x6150 [kvm] kvm_vcpu_ioctl+0x5e4/0x10d0 [kvm] __x64_sys_= ioctl+0x131/0x1b0 do_syscall_64+0x67/0x5f0 entry_SYSCALL_64_after_hwframe+0= x4b/0x53</td>
<td>2026-09-03</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80726" target=3D= "_blank" rel=3D"noopener">CVE-2026-80726</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: btr= fs: initialize inode mapping flags for cached inodes [BUG] When running gen= eric/795 with 8K block size, 4K page size, the test always fails, triggerin=
g some ASSERT()s related to folio size: 795 (241074): drop_caches: 3 assert= ion failed: IS_ALIGNED(start, blocksize) && IS_ALIGNED(end + 1, blo= cksize), in extent_io.c:1404 (blocksize=3D8192 root=3D262 ino=3D258 start= =3D16826368 end=3D16830463 mapping min order=3D0) ------------[ cut here ]-= ----------- kernel BUG at extent_io.c:1404! Oops: invalid opcode: 0000 [#1]=
SMP CPU: 8 UID: 0 PID: 241105 Comm: fsstress Tainted: G OE 7.2.0-rc5-custo=
m+ #442 PREEMPT(full) f4bfb352566f3949f29c233ce6f735050a03b245 Tainted: [O]= =3DOOT_MODULE, [E]=3DUNSIGNED_MODULE Hardware name: QEMU Standard PC (Q35 +=
ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:assert_folio_range.cold+0x3= d/0x3f [btrfs] Call Trace: <TASK> btrfs_read_folio+0x9e/0x170 [btrfs = 4cd1dd93b341b8ef766643f9512f4a86259567a3] prepare_one_folio.constprop.0+0x1= 04/0x2a0 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3] btrfs_buffered_wr= ite+0x285/0xa50 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3] btrfs_do_w= rite_iter+0x1aa/0x210 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3] iter= _file_splice_write+0x31a/0x540 direct_splice_actor+0x53/0x170 splice_direct= _to_actor+0xe9/0x240 do_splice_direct+0x76/0xb0 vfs_copy_file_range+0x1fd/0= x630 __x64_sys_copy_file_range+0xf9/0x220 do_syscall_64+0xe1/0x790 entry_SY= SCALL_64_after_hwframe+0x4b/0x53 </TASK> ---[ end trace 0000000000000= 000 ]--- The ASSERT() itself is added by a later patch. The crash is trigge= red with that new debug patch, and without this fix. [CAUSE] In the above c= ase, the start 16826368 is properly 8K aligned, but the end (16830463 + 1) =
is not 8K aligned. Furthermore the mapping's minimal folio order is 0, not = the expected 1 for 8K block size with 4K page size. So this means some inod=
es do not have btrfs_set_inode_mapping_order() called on it. The missing bt= rfs_set_inode_mapping_order() call happens for cached inodes, through the f= ollowing events: - btrfs_create_new_inode() called for inode X Which proper=
ly sets minimal folio order for the VFS inode. - btrfs_update_inode() calle=
d for inode X Which calls btrfs_delayed_update_inode() to create a delayed_= node into root->delayed_nodes xarray. - Drop cache/memory pressure, evic= ting in-memory inode X Which evicted the inode X, but delayed_node is still=
in root->delayed_nodes for future reuse. - btrfs_iget() for inode X cal= led again btrfs_iget() |- btrfs_iget_locked() | |- iget5_locked_rcu() | Whi=
ch creates a new vfs_inode for btrfs, whose mapping still | has the minimal=
order as 0. | |- btrfs_read_locked_inode() |- btrfs_fill_inode() | |- btrf= s_get_delayed_node() | Which found out the previous node, and use that dela= yed | node to initialize the new inode. | |- filled =3D true; |- if (filled=
) goto cache_index; Which skips the btrfs_update_inode_mapping_flags() and = btrfs_set_inode_mapping_order() calls. So the inode still has minimal folio=
order set as 0, not the required 1. Thus later page cache read will get a = folio whose size is smaller than block size, as the mapping has its minimal=
folio order set as 0 not 1, then trigger the ASSERT(). [FIX] Move the btrf= s_update_inode_mapping_flags() and btrfs_set_inode_mapping_order() calls un= der cache_index label, so that the mapping flags and minimal folio order is=
always set no matter if we have a cached inode.</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80734" target=3D= "_blank" rel=3D"noopener">CVE-2026-80734</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: reg= ulator: fp9931: Fix VPOS/VNEG voltage selector table The VPOSNEG_table[] ma= pping does not match the FP9931 datasheet. The datasheet defines the VPOS/V= NEG voltage mapping as: 00h-04h -> 7.04V (-7.04V) 05h -> 7.26V (-7.26=
V) 06h -> 7.49V (-7.49V) ... 28h-3Fh -> 15.06V (-15.06V) However, VPO= SNEG_table[] has two issues: 1. Selector 0x00~0x04 should all map to 7.04V =
(5 entries), but the table has 6 entries of 7.04V, causing all subsequent e= ntries to be shifted by one position. 2. Selectors 0x29~0x3F should all cla=
mp to 15.06V (23 entries), but the table has only 41 entries. Any selector = value above 0x28 would result in an out-of-bounds table access. Fix both is= sues by removing the duplicate 7.04V entry and appending the missing 23 cla= mped 15.06V entries, bringing the table to the correct size of 64 entries (= 0x00~0x3F).</td>
<td>2026-09-03</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80745" target=3D= "_blank" rel=3D"noopener">CVE-2026-80745</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /amdkfd: Add bounds check for CRAT subtype length The CRAT parser validates=
that the subtype header fits within the image, but does not verify that th=
e advertised subtype length fits. A malformed CRAT table with an oversized = length field causes out-of-bounds reads when kfd_parse_subtype() casts the = header to specific subtype structures. Add validation that sub_type_hdr + l= ength does not exceed the image boundary before parsing the subtype content=
s. (cherry picked from commit 48e1d1e6e8798aef0312e68d8e586021b5b3cf4d)</td=
<td>2026-09-03</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80747" target=3D= "_blank" rel=3D"noopener">CVE-2026-80747</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: pmd= omain: mediatek: fix remaining %pOF after of_node_put() scpsys_get_bus_prot= ection_legacy() looks up several legacy bus protection regmaps from device-= tree nodes. Two error paths put the device node before checking whether the=
regmap lookup failed, but still pass that node to dev_err_probe() with %pO=
F on failure. If of_node_put() drops the last reference, the later %pOF for= matting can dereference a freed device node. Keep the node reference until = after the error message has been emitted in the infracfg and SMI lookup pat= hs. Also drop the SMI node before returning when the SMI phandle is missing= .</td>
<td>2026-09-03</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80750" target=3D= "_blank" rel=3D"noopener">CVE-2026-80750</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Inp= ut: psxpad-spi - set driver data before use psxpad_spi_suspend() retrieves = the controller state with spi_get_drvdata(), but probe never stores it, so = suspend dereferences a NULL pointer. Store it during probe.</td>
<td>2026-09-03</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80752" target=3D= "_blank" rel=3D"noopener">CVE-2026-80752</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ovp=
n: run deferred work on a module-owned workqueue ovpn queues several work i= tems whose callbacks execute module text. These works currently run on the = global system workqueues, so module exit has no driver-owned drain point th=
at guarantees the callbacks have fully returned before the module text can =
be freed. Object references protect the objects used by the callbacks, but = they do not prove that a workqueue function has returned. In particular, a = worker can drop the final reference that unblocks device teardown while it =
is still executing ovpn code. Add a module-owned workqueue and queue all ov=
pn work items on it. During module exit, unregister rtnl and netlink first,=
flush the workqueue so ordinary ovpn workers finish, run the final RCU bar= rier, and destroy the workqueue last. This keeps the workqueue available fo=
r cleanup work queued from RCU callbacks, while ensuring no ovpn work item = can outlive the module text. The per-device delayed keepalive work remains = explicitly disabled during netdev teardown (disable_delayed_work_sync in nd= o_uninit), since flush_workqueue does not flush delayed work that is still = only pending on its timer.</td>
<td>2026-09-03</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80753" target=3D= "_blank" rel=3D"noopener">CVE-2026-80753</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net=
: remove CAP_SYS_RAWIO zero-padding in dev_validate_header dev_validate_hea= der() reads dev->hard_header_len directly when zero-padding short link l= ayer headers for CAP_SYS_RAWIO holders: if (capable(CAP_SYS_RAWIO)) { memse= t(ll_header + len, 0, dev->hard_header_len - len); return true; } Packet=
send paths call dev_validate_header() on skbs whose headroom was allocated=
from an earlier hard_header_len read. If the device is reconfigured so tha=
t dev->hard_header_len increases before validation, the memset writes pa=
st the reserved buffer, an out-of-bounds write. This out-of-bounds write is=
masked in some SOCK_RAW paths today because the same concurrent increase c=
an first make skb_push() exceed the reserved headroom and trigger skb_under= _panic(). Remove the zero-padding branch before making those hard_header_le=
n reads consistent, so the snapshot fixes do not turn a loud panic into a s= ilent overwrite. This path is only reached for variable length L2 protocols=
, where len < hard_header_len but len >=3D min_header_len. No remaini=
ng in-tree variable length L2 protocol implements header_ops->validate, = and the CAP_SYS_RAWIO bypass that zero-pads and accepts short headers has n=
o real value beyond allowing testing of intentionally malformed input. Drop=
the CAP_SYS_RAWIO branch. The remaining reads of dev->hard_header_len i=
n dev_validate_header() are comparisons only and have no memory safety impa= ct.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80731" target=3D= "_blank" rel=3D"noopener">CVE-2026-80731</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ata=
: pata_sl82c105: fix bridge revision use-after-free pci_get_slot() returns =
a referenced PCI device. Commit 44c10138fd4b ("PCI: Change all drivers to u=
se pci_device->revision") replaced a configuration-space read with direc=
t access to the cached revision field, but left that access after pci_dev_p= ut(). The bridge may therefore be freed before its revision is read. Read t=
he revision before dropping the reference.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80732" target=3D= "_blank" rel=3D"noopener">CVE-2026-80732</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ovp=
n: ensure socket is owned by ovpn before deref sk_user_data Some subsystems=
, like BPF SOCKMAP, set sk_user_data without actually setting the encap_typ=
e. For this reason, we must make sure that the type is the one ovpn expects=
before dereferencing sk_user_data. Failing to do so may lead to out-of-bou= nds reads.</td>
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80735" target=3D= "_blank" rel=3D"noopener">CVE-2026-80735</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: thu= nderbolt: Fix bandwidth group reservation indexing Valid bandwidth group ID=
s range from 1 through MAX_GROUPS, while Group ID 0 is reserved. tb_consume= d_dp_bandwidth() uses the Group ID directly to index its local group_reserv= ed[] array. The array currently has MAX_GROUPS entries, so its valid indice=
s are 0 through MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one = element past the end, and the final group's reserved bandwidth is not inclu= ded when the array is summed. Give group_reserved[] MAX_GROUPS + 1 entries =
so direct Group ID indexing covers the reserved ID 0 and valid IDs 1 throug=
h MAX_GROUPS.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80736" target=3D= "_blank" rel=3D"noopener">CVE-2026-80736</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ser= ial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does no=
t wait for a running callback, so the TX callback can still touch the TX bu= ffer after it is freed. The RX poll timer reads the RX buffers without the = port lock. Switch to dmaengine_terminate_sync() and delete the RX timer bef= ore freeing the buffers.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80737" target=3D= "_blank" rel=3D"noopener">CVE-2026-80737</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf=
: Check sk_state before sk_protocol in bpf_tcp_*_syncookie bpf_tcp_gen_sync= ookie and bpf_tcp_check_syncookie accept a socket pointer 'sk' with argumen=
t type ARG_PTR_TO_BTF_ID_SOCK_COMMON. However, they access sk->sk_protoc=
ol without validating whether 'sk' represents a full socket. Fix this issue=
by checking sk->sk_state !=3D TCP_LISTEN before inspecting sk->sk_pr= otocol in both bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie. Since min= i-sockets are never in the TCP_LISTEN state, the condition short-circuits a=
nd prevents dereferencing fullsock-specific fields.</td>
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80738" target=3D= "_blank" rel=3D"noopener">CVE-2026-80738</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_reco= rd() accesses s[len - 1] to strip the trailing newline, but len is unsigned=
int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bou= nds read. Add an early return when len is 0.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80741" target=3D= "_blank" rel=3D"noopener">CVE-2026-80741</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: mmc=
: loongson2: Fix sg iteration in data reorder functions In ls2k0500_mmc_reo= rder_cmd_data() and ls2k2000_mmc_reorder_cmd_data(), the for_each_sg() macr=
o already iterates over the scatterlist entries, with 'sg' pointing to the = current entry. However, the code incorrectly uses '&sg[i]' and 'sg_dma_= len(&sg[i])' inside the loop, which treats 'sg' as an array base and in= dexes it again, leading to access of wrong sg entries (or out-of-bounds if = the list is not an array).</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80748" target=3D= "_blank" rel=3D"noopener">CVE-2026-80748</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /connector/hdmi: Fix out of bounds memory read A helper function was copyin=
g a given audio infoframe into the connector's copy but using the size of t=
he destination (a generic target, sized to accept many different data block=
s) not the source (a very specific type of data block). Thus, it was copyin=
g 60 bytes of data from a 28 byte allocation. Fix that by using the source = size instead, together with a build bug on the source size actually being s= maller than the destination. I hit this running KUnit tests under KASAN (wh= ile debugging something else entirely). In the real world, it seems unlikel=
y to cause an actual problem. It is a read not a write so it can't corrupt = any memory. However, it could potentially fall off the end of a page and ca= use an accvio bug.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80749" target=3D= "_blank" rel=3D"noopener">CVE-2026-80749</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: pmd= omain: mediatek: mfg: initialize prev_o in mtk_mfg_attach_dev() mtk_mfg_att= ach_dev() reads prev_o on the first iteration of its loop, in "if (prev_o &= amp;& prev_o->freq =3D=3D o->freq)", before prev_o is assigned at=
the end of the loop body. On that first iteration, evaluating prev_o reads=
an indeterminate value. If it is non-NULL, the condition dereferences a st= ale or invalid pointer, potentially faulting or incorrectly skipping the fi= rst OPP. Initialize prev_o to NULL. This matches the intent as well: there =
is no previous OPP to compare against on the first iteration. Found with Cl= ang's -Wconditional-uninitialized.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80751" target=3D= "_blank" rel=3D"noopener">CVE-2026-80751</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Inp= ut: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 se= nsor detection, the transmitter (TX) electrode count was incorrectly assign=
ed the value of the receiver (RX) electrode count due to copy-paste typos. = This incorrect value was then propagated to the driver data and used by F54=
to determine the diagnostics report size. On devices with more RX than TX = electrodes, this inflated the perceived TX count, leading to incorrect repo=
rt size calculations and potential out-of-bounds buffer accesses. Fix the t= ypos by correctly assigning the TX electrode counts.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80754" target=3D= "_blank" rel=3D"noopener">CVE-2026-80754</a></td>
</tr>
<td class=3D"vendor-product">LiquidThemes--Booking Hub</td>
<td>Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hu=
b allows Privilege Escalation. This issue affects Booking Hub: from n/a thr= ough 1.3.1.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81769" target=3D= "_blank" rel=3D"noopener">CVE-2026-81769</a></td>
</tr>
<td class=3D"vendor-product">LiteSpeed Technologies--LiteSpeed Cache</td> <td>Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache &= lt;=3D 7.9 versions.</td>
<td>2026-09-03</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84761" target=3D= "_blank" rel=3D"noopener">CVE-2026-84761</a></td>
</tr>
<td class=3D"vendor-product">lllyasviel Fooocus--lllyasviel Fooocus</td>
<td>An eval() injection vulnerability in the get_list function in modules/m= eta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote att= ackers to execute arbitrary Python code via a crafted styles payload in the=
EXIF metadata of an uploaded image file.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51974" target=3D= "_blank" rel=3D"noopener">CVE-2026-51974</a></td>
</tr>
<td class=3D"vendor-product">lm-sys--FastChat</td>
<td>FastChat contains an authentication bypass vulnerability in the /regist= er_worker endpoint that allows unauthenticated attackers to register arbitr= ary worker addresses and perform server-side request forgery. Attackers can=
register malicious workers under victim model names to intercept user prom= pts, images, and responses, or probe internal network ports across the work=
er mesh.</td>
<td>2026-09-04</td>
<td>9.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85695" target=3D= "_blank" rel=3D"noopener">CVE-2026-85695</a></td>
</tr>
<td class=3D"vendor-product">malcare--MalCare Security</td>
<td>Unauthenticated Denial of Service Attack in MalCare Security <=3D 6.=
69 versions.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84776" target=3D= "_blank" rel=3D"noopener">CVE-2026-84776</a></td>
</tr>
<td class=3D"vendor-product">MapGeo--Interactive Geo Maps</td> <td>Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= =3D 1.6.30 versions.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81770" target=3D= "_blank" rel=3D"noopener">CVE-2026-81770</a></td>
</tr>
<td class=3D"vendor-product">maplibre--maplibre-gl-js</td>
<td>MapLibre GL JS is an interactive vector tile map library for web browse= rs. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attribu= tes as a live NamedNodeMap while removeAttributes() removes attributes from=
the same collection, shifting indexes and skipping an adjacent dangerous a= ttribute. An attacker who controls untrusted third-party style attribution = strings or user-supplied custom attributions can supply consecutive dangero=
us attributes, causing an attribute such as onload or ontoggle to survive s= anitization and execute when the attribution control inserts the content in=
to innerHTML. A victim must render the affected map content for the script =
to execute. This issue is fixed in version 6.4.1.</td>
<td>2026-09-03</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85061" target=3D= "_blank" rel=3D"noopener">CVE-2026-85061</a></td>
</tr>
<td class=3D"vendor-product">Marcus--Login With Ajax</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Marcus Login With Ajax allows Reflected XSS.=
This issue affects Login With Ajax: from n/a through 4.5.1.</td> <td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82883" target=3D= "_blank" rel=3D"noopener">CVE-2026-82883</a></td>
</tr>
<td class=3D"vendor-product">Mauro Cassani--ACPT (Premium)</td>
<td>The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Esca= lation in all versions up to, and including, 2.0.66. This is due to missing=
authorization in the `submit()` function, which allows unauthenticated for=
m submissions to control the target user ID before calling `wp_update_user(= )`. This makes it possible for unauthenticated attackers to overwrite any W= ordPress user's email address and password, including an administrator's, a=
nd take over the account. Successful exploitation requires a public ACPT us=
er form that permits anonymous submissions.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15354" target=3D= "_blank" rel=3D"noopener">CVE-2026-15354</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds write vulnerability in DASYLab due to lack of=
proper validation of user-supplied data. Successful exploitation requires =
an attacker to get a user to open a specially crafted .DSB file.=C2=A0 This=
issue affects all versions before 2026.0.0.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64195" target=3D= "_blank" rel=3D"noopener">CVE-2026-64195</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds write vulnerability in DASYLab=C2=A0due to im= proper validation of user-supplied data, resulting in a write past the end =
of an allocated heap.=C2=A0Successful exploitation requires an attacker to = get a user to open a specially crafted .DSB file.=C2=A0 This issue affects = all versions before 2026.0.0.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64196" target=3D= "_blank" rel=3D"noopener">CVE-2026-64196</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds write vulnerability in DASYLab=C2=A0due to im= proper validation of user-supplied data, resulting in a write past the end =
of an allocated data structure. Successful exploitation requires an attacke=
r to get a user to open a specially crafted .DSB file.=C2=A0 This issue aff= ects all versions before 2026.0.0.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64197" target=3D= "_blank" rel=3D"noopener">CVE-2026-64197</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds read vulnerability in DASYLab due to improper=
validation of user-supplied data. =C2=A0 This results in a read a few byte=
s past the end of an allocated heap buffer during file handling.=C2=A0 Succ= essful exploitation requires an attacker to get a user to open a specially = crafted .DSB file.=C2=A0 This issue affects all versions before 2026.0.0.</=
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64198" target=3D= "_blank" rel=3D"noopener">CVE-2026-64198</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds read vulnerability in DASYLab due to improper=
validation of user-supplied data. =C2=A0 This results in a read outside th=
e bounds of an allocated data structure.=C2=A0 Successful exploitation requ= ires an attacker to get a user to open a specially crafted .DSB file.=C2=A0=
This issue affects all versions before 2026.0.0.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64199" target=3D= "_blank" rel=3D"noopener">CVE-2026-64199</a></td>
</tr>
<td class=3D"vendor-product">measX--DASYLab</td>
<td>There is an out-of-bounds read vulnerability in DASYLab due to improper=
validation of user-supplied data. =C2=A0 This results in a read a past the=
end of an allocated heap buffer during string conversion.=C2=A0 Successful=
exploitation requires an attacker to get a user to open a specially crafte=
d .DSB file.=C2=A0 This issue affects all versions before 2026.0.0.</td> <td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-64200" target=3D= "_blank" rel=3D"noopener">CVE-2026-64200</a></td>
</tr>
<td class=3D"vendor-product">medplum--medplum</td>
<td>Medplum is a developer platform that enables development of healthcare = apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoi=
nt could return the client_secret of preconfigured OAuth clients defined vi=
a the defaultOAuthClients server configuration when a matching redirect_uri=
was provided. This issue has been patched in version 5.1.7.</td> <td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44506" target=3D= "_blank" rel=3D"noopener">CVE-2026-44506</a></td>
</tr>
<td class=3D"vendor-product">medplum--medplum</td>
<td>Medplum is a developer platform that enables development of healthcare = apps. Prior to version 5.1.6, the external identity provider callback at GE=
T /auth/external accepts attacker-controlled redirect URIs that only need t=
o start with a registered client redirect URI, rather than matching exactly=
. After a successful external IdP login, the server appends Medplum login a=
nd code values to that attacker-supplied URL and issues a redirect. Because=
the external login request state is serialized as raw JSON and later trust=
ed by the callback, an attacker who can tamper with state.redirectUri can c= ause Medplum to redirect authorization artifacts to an attacker-controlled = endpoint. When the registered redirect URI is a bare origin or another pref=
ix that can be extended into a different hostname, this becomes a cross-ori= gin authorization code leak. This issue has been patched in version 5.1.6.<=
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53728" target=3D= "_blank" rel=3D"noopener">CVE-2026-53728</a></td>
</tr>
<td class=3D"vendor-product">MegaEase--EaseProbe</td>
<td>A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is th=
e function realIP of the file web/server.go of the component Middleware. Th=
is manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP ca= uses improper access controls. The attack can be initiated remotely. The ex= ploit has been published and may be used. The vendor was contacted early ab= out this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82815" target=3D= "_blank" rel=3D"noopener">CVE-2026-82815</a></td>
</tr>
<td class=3D"vendor-product">melograno--Booking for Appointments and Events=
Calendar Amelia</td>
<td>The Booking for Appointments and Events Calendar - Amelia (Premium) plu= gin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9= .6.2. This is due to insufficient validation of the attacker-controlled 'ty= pe' parameter in the customer update endpoint, which allows customers to se=
t their role to 'manager' and trigger creation of a WordPress user with the=
wpamelia-manager role when the 'externalId' parameter is set to 0. This ma= kes it possible for unauthenticated attackers to escalate their privileges =
to administrator by first elevating to the manager role, then creating a pr= ovider entity linked to an administrator user ID and overwriting that admin= istrator's password.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9055" target=3D"= _blank" rel=3D"noopener">CVE-2026-9055</a></td>
</tr>
<td class=3D"vendor-product">Menulux Software Inc.--Menulux Portal</td>
<td>Plaintext storage of a password vulnerability in Menulux Software Inc. = Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects = Menulux Portal: before 20260903211448.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19051" target=3D= "_blank" rel=3D"noopener">CVE-2026-19051</a></td>
</tr>
<td class=3D"vendor-product">Menulux Software Inc.--Menulux Portal</td>
<td>Observable response discrepancy vulnerability in Menulux Software Inc. = Menulux Portal allows Account Footprinting. This issue affects Menulux Port= al: before 20260903211448.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19080" target=3D= "_blank" rel=3D"noopener">CVE-2026-19080</a></td>
</tr>
<td class=3D"vendor-product">Metagauss--RegistrationMagic</td> <td>Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <=3D=
6.0.9.8 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82221" target=3D= "_blank" rel=3D"noopener">CVE-2026-82221</a></td>
</tr>
<td class=3D"vendor-product">Metagauss--RegistrationMagic</td> <td>Unauthenticated Broken Authentication in RegistrationMagic <=3D 6.0.= 9.8 versions.</td>
<td>2026-08-31</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82225" target=3D= "_blank" rel=3D"noopener">CVE-2026-82225</a></td>
</tr>
<td class=3D"vendor-product">MetaGPT--MetaGPT 0.8.1</td>
<td>An OS command injection vulnerability in MetaGPT 0.8.1 allows an attack=
er to execute arbitrary commands via the path argument of RepoParser.rebuil= d_class_views() in metagpt/repo_parser.py.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79408" target=3D= "_blank" rel=3D"noopener">CVE-2026-79408</a></td>
</tr>
<td class=3D"vendor-product">MetaGPT--MetaGPT 0.8.1</td>
<td>A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 al= lows an attacker to read arbitrary files via the FILE_NAME value used by se= t_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vu= lnerable code joins the attacker-controlled FILE_NAME value with the settin=
gs directory and opens the resulting path without validating that the resol= ved path remains within the intended directory.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79407" target=3D= "_blank" rel=3D"noopener">CVE-2026-79407</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Azure AI Language Authoring</td>
<td>Missing authentication for critical function in Azure AI Language allow=
s an unauthorized attacker to elevate privileges over a network.</td>
<td>2026-09-03</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70352" target=3D= "_blank" rel=3D"noopener">CVE-2026-70352</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Azure Cosmos DB</td>
<td>Authorization bypass through user-controlled key in Azure Cosmos DB all= ows an authorized attacker to perform spoofing over a network.</td> <td>2026-09-03</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-69857" target=3D= "_blank" rel=3D"noopener">CVE-2026-69857</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Entra</td>
<td>Authorization bypass through user-controlled key in Microsoft Azure Act= ive Directory B2C allows an unauthorized attacker to elevate privileges ove=
r a network.</td>
<td>2026-09-03</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83711" target=3D= "_blank" rel=3D"noopener">CVE-2026-83711</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Copilot Studio</td> <td>Improper verification of cryptographic signature in Copilot Studio allo=
ws an unauthorized attacker to elevate privileges over a network.</td>
<td>2026-09-03</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80098" target=3D= "_blank" rel=3D"noopener">CVE-2026-80098</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Discovery Studio</td>
<td>Improper neutralization of special elements in data query logic in Micr= osoft Discovery Studio allows an unauthorized attacker to disclose informat= ion over a network.</td>
<td>2026-09-03</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-62906" target=3D= "_blank" rel=3D"noopener">CVE-2026-62906</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Entra</td>
<td>Authentication bypass using an alternate path or channel in Microsoft E= ntra ID allows an unauthorized attacker to elevate privileges over a networ= k.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-62916" target=3D= "_blank" rel=3D"noopener">CVE-2026-62916</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Fabric</td>
<td>Missing authorization in Microsoft Fabric allows an authorized attacker=
to elevate privileges over a network.</td>
<td>2026-09-03</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70178" target=3D= "_blank" rel=3D"noopener">CVE-2026-70178</a></td>
</tr>
<td class=3D"vendor-product">Microsoft--Microsoft Power Platform</td> <td>Server-side request forgery (ssrf) in Power Automate allows an authoriz=
ed attacker to elevate privileges over a network.</td>
<td>2026-09-03</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-65818" target=3D= "_blank" rel=3D"noopener">CVE-2026-65818</a></td>
</tr>
<td class=3D"vendor-product">migrateguru--Migrate Guru Site Migration &=
Cloning</td>
<td>Unauthenticated Denial of Service Attack in Migrate Guru - Site Migrati=
on &amp; Cloning <=3D 6.65 versions.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84778" target=3D= "_blank" rel=3D"noopener">CVE-2026-84778</a></td>
</tr>
<td class=3D"vendor-product">MindsDB -- MindsDB=C2=A0<br>=C2=A0</td> <td>MindsDB through 26.1.0 contains a server-side request forgery vulnerabi= lity in the web crawler handler that allows unauthenticated attackers to fe= tch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list=
. Attackers can bypass the allowlist control by exploiting the default empt=
y configuration and access internal services and cloud metadata endpoints w= ithout authentication.</td>
<td>2026-09-05</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86173" target=3D= "_blank" rel=3D"noopener">CVE-2026-86173</a></td>
</tr>
<td class=3D"vendor-product">miniOrange--WordPress Social Login and Registe= r</td>
<td>Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login an=
d Register <=3D 7.8.2 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82229" target=3D= "_blank" rel=3D"noopener">CVE-2026-82229</a></td>
</tr>
<td class=3D"vendor-product">Ministry of the Interior (MVR)--eObanka-Identi= fikace</td>
<td>Improper neutralization of special elements used in an OS command ('OS = command injection') vulnerability in Digit=C3=83=C2=A1ln=C3=83=C2=AD a info= rma=C3=84=C2=8Dn=C3=83=C2=AD agentura (DIA) eOb=C3=84=C2=8Danka-Identifikac=
e on MacOS enables an attacker to=C2=A0register a custom URL scheme (czeeop= auth://) for parameterized application execution. Prior to version 3.6.0, i= ncoming URL parameters were passed to the compiled AppleScript wrapper usin=
g concatenation without sufficient sanitization.</td>
<td>2026-08-31</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59111" target=3D= "_blank" rel=3D"noopener">CVE-2026-59111</a></td>
</tr>
<td class=3D"vendor-product">MladenSU--cli-mcp-server</td>
<td>cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability =
in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS=
is enabled. Attackers can use shell command substitution syntax like $(...=
) or backticks to execute non-allowlisted commands that bypass the ALLOWED_= COMMANDS validation check.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85660" target=3D= "_blank" rel=3D"noopener">CVE-2026-85660</a></td>
</tr>
<td class=3D"vendor-product">modelscope--modelscope</td>
<td>ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuratio=
n files, allowing arbitrary code execution through Python object constructi=
on tags. Attackers can craft malicious model repositories with poisoned con= figuration files that execute code when loaded by users.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84202" target=3D= "_blank" rel=3D"noopener">CVE-2026-84202</a></td>
</tr>
<td class=3D"vendor-product">modelscope--ms-swift</td>
<td>ms-swift 4.5.2 contains a server-side request forgery vulnerability in = the swift deploy OpenAI-compatible API that fetches multimodal media URLs w= ithout validation or redirect filtering. Unauthenticated attackers can supp=
ly arbitrary image_url, audio_url, or video_url parameters to make the serv=
er issue requests to internal services and cloud metadata endpoints.</td> <td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85686" target=3D= "_blank" rel=3D"noopener">CVE-2026-85686</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerabi= lity in the SAY_MOOS variable handler that passes unsanitized text to a she=
ll command. Attackers can publish SAY_MOOS messages containing backticks or=
command substitution syntax to execute arbitrary commands as the iSay proc= ess user.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85425" target=3D= "_blank" rel=3D"noopener">CVE-2026-85425</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attack= er-chosen MOOS client names without sanitization. Attackers can inject shel=
l metacharacters into client names to execute arbitrary commands as the uMe= mWatch process user through unquoted redirection targets in system calls.</=
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85426" target=3D= "_blank" rel=3D"noopener">CVE-2026-85426</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authe= nticity before creating outbound bridge routes. Attackers can publish NODE_= BROKER_PING messages with crafted HostRecord data to redirect bridged varia= bles to attacker-controlled addresses.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85434" target=3D= "_blank" rel=3D"noopener">CVE-2026-85434</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of = TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enrol=
l attacker-controlled shore routes. Attackers can publish malicious shore r= oute messages to receive bridged vehicle traffic including sensor data and = control information.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85435" target=3D= "_blank" rel=3D"noopener">CVE-2026-85435</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabiliti=
es in IvP function string decoders that trust attacker-controlled length fi= elds without validation. Attackers can craft malicious encoded strings with=
mismatched declared and actual field lengths to overflow heap and stack bu= ffers, potentially achieving remote code execution through MOOS variables o=
r alog files.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85437" target=3D= "_blank" rel=3D"noopener">CVE-2026-85437</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in Str= ingToIvPFunction() where dimension, piece, and degree counts from encoded B= HV_IPF payloads are used as allocation sizes and loop bounds without valida= tion. Attackers can supply crafted payloads with mismatched dimension value=
s to write attacker-controlled doubles past the end of the IvPBox weight ar= ray, causing memory corruption and potential code execution.</td> <td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85438" target=3D= "_blank" rel=3D"noopener">CVE-2026-85438</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity f= rom the message body rather than validating it from the connection source. = Attackers can craft NODE_MESSAGE packets with spoofed source identities to = impersonate other nodes and post arbitrary variable notifications without v= alidation.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85429" target=3D= "_blank" rel=3D"noopener">CVE-2026-85429</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 contains a remote code execution vulnerability =
in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails t=
o sanitize shell metacharacters in log file pathnames. Attackers can embed = shell syntax in log file names or the --dir parameter to execute arbitrary = commands with the privileges of the operator running alogsplit.</td> <td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85439" target=3D= "_blank" rel=3D"noopener">CVE-2026-85439</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in is= Quoted(), isBraced(), and isChevroned() functions that strip whitespace but=
index using the original string length. Attackers can send NODE_REPORT mes= sages with leading or trailing whitespace to read past buffer bounds and ac= cess adjacent memory.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85444" target=3D= "_blank" rel=3D"noopener">CVE-2026-85444</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 contains a denial of service vulnerability in t=
he Demuxer::addMuxPacket() function that trusts the packet count declared i=
n mux headers without validation. Attackers can declare arbitrarily large p= acket counts to trigger unbounded memory allocation, exhausting system reso= urces and causing service unavailability.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85445" target=3D= "_blank" rel=3D"noopener">CVE-2026-85445</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnera= bility in uFldNodeComms where each new node identity creates a ledger entry=
and triggers all-pairs distribution work. Attackers can supply unbounded d= istinct node names in reports to drive the shoreside broker into quadratic = processing, delaying or preventing distribution of legitimate node reports.= </td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85446" target=3D= "_blank" rel=3D"noopener">CVE-2026-85446</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ = subscriptions without validating duration or variable list limits. Attacker=
s can register long-lived pipeways with many variables to cause pRealm to g= enerate excessive output indefinitely, exhausting system resources.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85447" target=3D= "_blank" rel=3D"noopener">CVE-2026-85447</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of cl= aimed communities stored in parallel vectors within ShoreBroker::handleMail= NodePing(). A single publisher can supply unbounded distinct community name=
s to grow retained state and per-pass work without limit, causing memory ex= haustion and performance degradation.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85448" target=3D= "_blank" rel=3D"noopener">CVE-2026-85448</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of trac= ked node identities from NODE_REPORT messages, allowing attackers to exhaus=
t memory by supplying unbounded distinct node names. Attackers can publish = crafted NODE_REPORT data to cause memory exhaustion and stall the operator = display without authentication.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85449" target=3D= "_blank" rel=3D"noopener">CVE-2026-85449</a></td>
</tr>
<td class=3D"vendor-product">Motorola--Smart Connect Application</td>
<td>The mobile Smart Connect dashboard UI was subject to manipulation by 3r=
d party apps. When paired with a phishing attack, this manipulation could r= esult in escalated privileges of an attacker within the system.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18058" target=3D= "_blank" rel=3D"noopener">CVE-2026-18058</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Sandbox escape due to use-after-free in the DOM: Navigation component. = This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ES=
R 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thund= erbird 153.2.</td>
<td>2026-09-01</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84119" target=3D= "_blank" rel=3D"noopener">CVE-2026-84119</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Sandbox escape due to use-after-free in the DOM: Security component. Th=
is vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR = 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunder= bird 153.2.</td>
<td>2026-09-01</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84121" target=3D= "_blank" rel=3D"noopener">CVE-2026-84121</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Site isolation issue in the DOM: Navigation component. This vulnerabili=
ty was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunde= rbird 153.2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84129" target=3D= "_blank" rel=3D"noopener">CVE-2026-84129</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Site isolation issue in the DOM: Push Subscriptions component. This vul= nerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, an=
d Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84133" target=3D= "_blank" rel=3D"noopener">CVE-2026-84133</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Other issue in the Profile Backup component. This vulnerability was fix=
ed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.= 2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84134" target=3D= "_blank" rel=3D"noopener">CVE-2026-84134</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Site isolation issue in the DOM: Navigation component. This vulnerabili=
ty was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunde= rbird 153.2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84140" target=3D= "_blank" rel=3D"noopener">CVE-2026-84140</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Integer overflow in the Graphics: ImageLib component. This vulnerabilit=
y was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunder= bird 153.2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84141" target=3D= "_blank" rel=3D"noopener">CVE-2026-84141</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Internally found bugs present in Thunderbird 154. Some of these bugs sh= owed evidence of memory corruption or another security-relevant defect and =
we presume that with enough effort some of these could have been exploited.=
This vulnerability was fixed in Firefox 155 and Thunderbird 155.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84142" target=3D= "_blank" rel=3D"noopener">CVE-2026-84142</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1=
and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory c= orruption or another security-relevant defect and we presume that with enou=
gh effort some of these could have been exploited. This vulnerability was f= ixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155=
, Thunderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84143" target=3D= "_blank" rel=3D"noopener">CVE-2026-84143</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Privilege escalation due to use-after-free in the Graphics: WebGPU comp= onent. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thun= derbird 155, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84123" target=3D= "_blank" rel=3D"noopener">CVE-2026-84123</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Privilege escalation in the WebDriver BiDi component. This vulnerabilit=
y was fixed in Firefox 155 and Thunderbird 155.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84128" target=3D= "_blank" rel=3D"noopener">CVE-2026-84128</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Privilege escalation due to invalid pointer in the Graphics component. = This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ES=
R 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thund= erbird 153.2.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84131" target=3D= "_blank" rel=3D"noopener">CVE-2026-84131</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Information disclosure in the Graphics: WebGPU component. This vulnerab= ility was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thu= nderbird 153.2.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84130" target=3D= "_blank" rel=3D"noopener">CVE-2026-84130</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Information disclosure in the Networking: HTTP component. This vulnerab= ility was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thu= nderbird 153.2.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84132" target=3D= "_blank" rel=3D"noopener">CVE-2026-84132</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Internally found bugs present in Thunderbird 154 and Thunderbird ESR 15= 3.1. Some of these bugs showed evidence of memory corruption or another sec= urity-relevant defect and we presume that with enough effort some of these = could have been exploited. This vulnerability was fixed in Firefox 155, Fir= efox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84144" target=3D= "_blank" rel=3D"noopener">CVE-2026-84144</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1=
and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory c= orruption or another security-relevant defect and we presume that with enou=
gh effort some of these could have been exploited. This vulnerability was f= ixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 15= 3.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84145" target=3D= "_blank" rel=3D"noopener">CVE-2026-84145</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox_mobile</td>
<td>Other issue in Firefox Focus for Android. This vulnerability was fixed =
in Firefox 155.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84135" target=3D= "_blank" rel=3D"noopener">CVE-2026-84135</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox_mobile</td>
<td>Privilege escalation in Firefox for Android. This vulnerability was fix=
ed in Firefox 155.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84117" target=3D= "_blank" rel=3D"noopener">CVE-2026-84117</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- thunderbird</td>
<td>Malicious calendar invitations could use file URI attachments to launch=
local or network-hosted executables on Windows, bypassing Thunderbird's no= rmal executable attachment protections. With the new invitation display ena= bled, the attachment could also appear under a misleading filename. This vu= lnerability was fixed in Thunderbird 154 and Thunderbird 153.2.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84637" target=3D= "_blank" rel=3D"noopener">CVE-2026-84637</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- thunderbird</td>
<td>Triggering an error condition in certain MIME bodies would cause uninit= ialized memory to be used. This vulnerability was fixed in Thunderbird 155,=
Thunderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84639" target=3D= "_blank" rel=3D"noopener">CVE-2026-84639</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- thunderbird</td>
<td>A maliciously constructed mail header could lead to a one byte read pas=
t the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thu= nderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84640" target=3D= "_blank" rel=3D"noopener">CVE-2026-84640</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- thunderbird</td>
<td>A malicious IMAP server can trigger use-after-free and heap-memory disc= losure by sending a crafted ID response. Heap contents can ultimately be pe= rsisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thund= erbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84641" target=3D= "_blank" rel=3D"noopener">CVE-2026-84641</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- thunderbird</td>
<td>The values of the mail.allowed_attachment_hostnames advanced config set= ting were used in a regular expression without escaping. For some possible = valid hostnames, this could allow certain unintended hostnames to also matc=
h and serve remote attachments. This vulnerability was fixed in Thunderbird=
155 and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84642" target=3D= "_blank" rel=3D"noopener">CVE-2026-84642</a></td>
</tr>
<td class=3D"vendor-product">mpdavis--python-jose</td>
<td>python-jose through 3.5.0 fails to properly validate asymmetric keys in=
HMAC initialization, accepting DER-encoded public keys that lack PEM armor=
or SSH prefixes. Attackers holding the service's public key can forge HS25=
6 tokens that pass verification when algorithms are not explicitly restrict= ed. This is an incomplete fix for CVE-2024-33663.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85394" target=3D= "_blank" rel=3D"noopener">CVE-2026-85394</a></td>
</tr>
<td class=3D"vendor-product">MSI--Dragon Center</td>
<td>A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affecte=
d by this vulnerability is the function MmioWritePath in the library NTIOLi= b_X64.sys of the component MMIO Write Path Handler. Performing a manipulati=
on of the argument count/elementSize results in integer overflow. The attac=
k requires a local approach. The exploit has been made public and could be = used. The vendor was contacted early about this disclosure but did not resp= ond in any way.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82908" target=3D= "_blank" rel=3D"noopener">CVE-2026-82908</a></td>
</tr>
<td class=3D"vendor-product">Mstfakts-- College-Management-System<br>=C2=A0= </td>
<td>A vulnerability was found in Mstfakts College-Management-System. This i= ssue affects the function mysqli_query of the file Front-end/university.php=
of the component Search Handler. The manipulation of the argument book_nam= e/book_author results in sql injection. The attack may be performed from re= mote. The exploit has been made public and could be used. This product util= izes a rolling release system for continuous delivery, and as such, version=
information for affected or updated releases is not disclosed. The project=
was informed of the problem early through an issue report but has not resp= onded yet.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86213" target=3D= "_blank" rel=3D"noopener">CVE-2026-86213</a></td>
</tr>
<td class=3D"vendor-product">Mstfakts-- College-Management-System<br>=C2=A0= </td>
<td>A vulnerability was determined in Mstfakts College-Management-System. I= mpacted is an unknown function of the file Front-end/login.php. This manipu= lation of the argument email causes improper authentication. It is possible=
to initiate the attack remotely. The exploit has been publicly disclosed a=
nd may be utilized. This product is using a rolling release to provide cont= inious delivery. Therefore, no version details for affected nor updated rel= eases are available. The project was informed of the problem early through =
an issue report but has not responded yet.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86214" target=3D= "_blank" rel=3D"noopener">CVE-2026-86214</a></td>
</tr>
<td class=3D"vendor-product">MythicalLTD--FeatherPanel</td>
<td>FeatherPanel versions before 1.3.7.10 fail to validate permissions in t=
he SubuserController updateSubuser handler, allowing authenticated subusers=
to modify their own permission records. A subuser with minimal permissions=
can send a crafted request to grant themselves full server control, enabli=
ng unauthorized access to sensitive data, backups, and server configuration= .</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84715" target=3D= "_blank" rel=3D"noopener">CVE-2026-84715</a></td>
</tr>
<td class=3D"vendor-product">NangoHQ--nango</td>
<td>Nango before 0.71.6 contains a missing authentication vulnerability in = the runner tRPC server that allows unauthenticated attackers to execute arb= itrary JavaScript code by invoking the exposed start procedure without cred= entials. Attackers with network access to the runner port can send requests=
to the unauthenticated start procedure, bypassing the unenforced RUNNER_SE= CRET_KEY environment variable, to achieve remote code execution within the = runner process.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9317" target=3D"= _blank" rel=3D"noopener">CVE-2026-9317</a></td>
</tr>
<td class=3D"vendor-product">NASA--earthdata-search</td>
<td>A vulnerability was detected in NASA earthdata-search 1.0.0. Affected b=
y this vulnerability is the function scaleImage of the file serverless/src/= scaleImage/handler.js of the component scale Endpoint. Performing a manipul= ation results in server-side request forgery. The attack can be initiated r= emotely. The exploit is now public and may be used. The vendor was contacte=
d early about this disclosure but did not respond in any way.</td> <td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82801" target=3D= "_blank" rel=3D"noopener">CVE-2026-82801</a></td>
</tr>
<td class=3D"vendor-product">nasa-jpl--ION-DTN</td>
<td>ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerabili=
ty in the decodeSdnv function that allows unauthenticated remote attackers =
to read memory by sending truncated SDNV values. Attackers can send a UDP d= atagram to the LTP link service input port with a truncated SDNV to trigger=
reads up to nine bytes past buffer boundaries and underflow byte counters.= </td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84484" target=3D= "_blank" rel=3D"noopener">CVE-2026-84484</a></td>
</tr>
<td class=3D"vendor-product">Net::DNS--Net::DNS</td>
<td>Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbo= unded recursion in sig_data when re-encoding a message with a misplaced TSI=
G record. sig_data signs a message by re-encoding it, and removes TSIG reco= rds only from the additional section. A TSIG decoded into the answer or aut= hority section survives that step and is signed again, so encoding re-enter=
s sig_data with no termination condition. Decoding does not reject such a m= essage: a TSIG that is not the last record on the wire raises "misplaced or=
corrupt TSIG", but the error is caught, reported as a warning, and the rec= ord is left in the packet. RFC 8945 section 5.2 requires the message to be = dropped. The recursion is reached only when the decoded TSIG carries an emp=
ty MAC, since a MAC recovered from the wire short-circuits the signing step=
. It is reached only from code that re-encodes a message it decoded, such a=
s a forwarder or a proxy. A decoded message that is never re-encoded is una= ffected. Message direction does not matter: a query reaches the same path a=
s a response. Each cycle re-encodes the whole message, so fewer than 100 by= tes on the wire exhaust available memory and terminate the process.</td> <td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81928" target=3D= "_blank" rel=3D"noopener">CVE-2026-81928</a></td>
</tr>
<td class=3D"vendor-product">netease-youdao--QAnything</td>
<td>QAnything 2.0.0 contains an authentication bypass vulnerability in the = /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints t= hat allows unauthenticated attackers to access any uploaded file or documen=
t. Attackers can enumerate file identifiers through unauthenticated endpoin=
ts and retrieve base64-encoded files or parsed document chunks without owne= rship verification to disclose cross-tenant knowledge base content.</td> <td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85671" target=3D= "_blank" rel=3D"noopener">CVE-2026-85671</a></td>
</tr>
<td class=3D"vendor-product">nodeca--js-yaml</td>
<td>js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2=
and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js do=
es not count empty mapping sources while processing the merge key <<.=
An attacker can alias a large sequence of empty mappings into many merge t= argets, causing O(N * K) processing while totalMergeKeys remains unchanged = and the configured resource limit is never reached. A relatively small YAML=
document can therefore cause prolonged CPU consumption in applications tha=
t parse untrusted YAML, and merge processing is enabled by default on these=
release lines. This issue is fixed in versions 3.15.2 and 4.3.2.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84375" target=3D= "_blank" rel=3D"noopener">CVE-2026-84375</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>Nodemailer before 8.0.4 is vulnerable to SMTP command injection through=
the unsanitized envelope.size parameter. When an application passes a cust=
om envelope object with a size property containing CRLF characters to sendM= ail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE= =3D...) without sanitization, allowing injection of arbitrary SMTP commands=
such as RCPT TO to silently add attacker-controlled recipients. Exploitati=
on requires the application to expose the envelope size to attacker-control= led input, as Nodemailer does not include size in the default auto-construc= ted envelope.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82854" target=3D= "_blank" rel=3D"noopener">CVE-2026-82854</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrl= Access flags to message-level raw option, allowing authenticated attackers =
to read arbitrary files or perform server-side request forgery by supplying=
path or href properties. Attackers can exploit this by crafting raw messag=
es with file paths or URLs that bypass the intended sandbox, with fetched c= ontent delivered in the outgoing message to attacker-controlled recipients.= </td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82659" target=3D= "_blank" rel=3D"noopener">CVE-2026-82659</a></td>
</tr>
<td class=3D"vendor-product">Nokia--WaveSuite</td>
<td>WaveSuite is affected by an insufficient role-based access control vuln= erability in the CPB Log Files feature. Successful exploitation allows an a= uthenticated low-privilege user to load pages restricted to higher-privileg=
e roles by requesting the corresponding URL directly in the browser.</td> <td>2026-08-31</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40463" target=3D= "_blank" rel=3D"noopener">CVE-2026-40463</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a=
remote code execution vulnerability that allows attackers to execute arbit= rary OS commands by supplying a malicious repository with a crafted .git/co= nfig that sets core.fsmonitor to an attacker-controlled command. When a use=
r opens the malicious repository and sends any message, the agent triggers =
a git status index refresh which executes the injected command in the user'=
s process context, exposing the full environment including configured provi= der API keys.</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71963" target=3D= "_blank" rel=3D"noopener">CVE-2026-71963</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by = this issue is the function _sess_nowait of the file s71.py of the component=
Session Management. This manipulation of the argument session_id causes au= thorization bypass. The attack can be initiated remotely. The vendor was co= ntacted early about this disclosure but did not respond in any way.</td> <td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85105" target=3D= "_blank" rel=3D"noopener">CVE-2026-85105</a></td>
</tr>
<td class=3D"vendor-product">NSquared--Simply Schedule Appointments</td>
<td>Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Ap= pointments <=3D 1.6.12.23 versions.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84764" target=3D= "_blank" rel=3D"noopener">CVE-2026-84764</a></td>
</tr>
<td class=3D"vendor-product">ntop --nDPI=C2=A0<br>=C2=A0</td>
<td>ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabil= ity in the ndpi_json_string_escape function that writes beyond caller-suppl= ied buffer boundaries. Attackers can trigger the overflow by supplying craf= ted network packet data including TLS SNI, HTTP headers, or DNS names that = reach the vulnerable function, causing heap corruption.</td> <td>2026-09-04</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86098" target=3D= "_blank" rel=3D"noopener">CVE-2026-86098</a></td>
</tr>
<td class=3D"vendor-product">ntop--ntopng</td>
<td>ntopng is a web-based network traffic monitoring application. In versio=
ns 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag= /badge feature - `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest= /v2/edit/tag/tag.lua` - perform no authorization check at all. Any authenti= cated user, including a non-administrator ("unprivileged") account, can del= ete or rename any tag in the system, including tags created by an administr= ator. Version 6.7.260718 contains a fix.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84989" target=3D= "_blank" rel=3D"noopener">CVE-2026-84989</a></td>
</tr>
<td class=3D"vendor-product">ntopng--ntopng<br>=C2=A0</td>
<td>ntopng before 6.7.260717 fails to check user privileges in the pools bu= lk-delete endpoint, allowing authenticated non-administrators to delete all=
host pools and member bindings. Attackers can issue POST requests to the d= elete pools endpoint to irreversibly destroy every host pool, removing traf= fic policy bindings and visibility restrictions that may bypass security po= licies.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86091" target=3D= "_blank" rel=3D"noopener">CVE-2026-86091</a></td>
</tr>
<td class=3D"vendor-product">ntopng--ntopng=C2=A0<br>=C2=A0</td>
<td>ntopng before 6.7.260717 fails to perform authorization checks in the d= elete endpoints and recipients REST v2 handlers. Authenticated non-administ= rator users can issue POST requests to irreversibly delete all configured n= otification endpoints and recipients, silencing all alerts.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86090" target=3D= "_blank" rel=3D"noopener">CVE-2026-86090</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard=
's project management API, allowing any authenticated user (without members= hip in the target project) to bypass OPA authorization checks on write path=
s (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any p= roject along with all its associated resources (functions, API gateways, et= c.). This issue has been patched in version 1.16.0.</td>
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45730" target=3D= "_blank" rel=3D"noopener">CVE-2026-45730</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.16.4, the Nuclio controller builds a curl invocati=
on string for each cron trigger and stores it as the args of a Kubernetes C= ronJob container (/bin/sh, -c, <command>). Two fields in the trigger = specification flow into this string without adequate sanitization: event.he= aders keys and event.body. This issue has been patched in version 1.16.4.</=
<td>2026-09-02</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52831" target=3D= "_blank" rel=3D"noopener">CVE-2026-52831</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.grad=
le file during function builds using Go's text/template package. The templa=
te renders runtimeAttributes.repositories[] values with the {{ . }} action,=
which performs no escaping. An attacker can embed a closing brace (}) to b= reak out of the repositories {} block and append arbitrary Groovy statement=
s that execute unconditionally during the Gradle configuration phase. This = issue has been patched in version 1.16.5.</td>
<td>2026-09-02</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52833" target=3D= "_blank" rel=3D"noopener">CVE-2026-52833</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.17.4, on the Nuclio local Docker platform, the fun= ction namespace is interpolated-unvalidated-into a double-quoted docker ps = --filter "label=3Dnuclio.io/namespace=3D<value>" command that is exec= uted via the host shell (/bin/sh -c). Because the default auth kind is nop = (unauthenticated), a remote attacker can inject arbitrary OS commands that = run as root inside the dashboard container, which holds the Docker socket = =C3=A2=E2=80=A0=E2=80=99 host compromise. This issue has been patched in ve= rsion 1.17.4.</td>
<td>2026-09-02</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79755" target=3D= "_blank" rel=3D"noopener">CVE-2026-79755</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61750" target=3D= "_blank" rel=3D"noopener">CVE-2026-61750</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61751" target=3D= "_blank" rel=3D"noopener">CVE-2026-61751</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61752" target=3D= "_blank" rel=3D"noopener">CVE-2026-61752</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61753" target=3D= "_blank" rel=3D"noopener">CVE-2026-61753</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61754" target=3D= "_blank" rel=3D"noopener">CVE-2026-61754</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61755" target=3D= "_blank" rel=3D"noopener">CVE-2026-61755</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61756" target=3D= "_blank" rel=3D"noopener">CVE-2026-61756</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61757" target=3D= "_blank" rel=3D"noopener">CVE-2026-61757</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61758" target=3D= "_blank" rel=3D"noopener">CVE-2026-61758</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61759" target=3D= "_blank" rel=3D"noopener">CVE-2026-61759</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61760" target=3D= "_blank" rel=3D"noopener">CVE-2026-61760</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61761" target=3D= "_blank" rel=3D"noopener">CVE-2026-61761</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61762" target=3D= "_blank" rel=3D"noopener">CVE-2026-61762</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61763" target=3D= "_blank" rel=3D"noopener">CVE-2026-61763</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61764" target=3D= "_blank" rel=3D"noopener">CVE-2026-61764</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61765" target=3D= "_blank" rel=3D"noopener">CVE-2026-61765</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61766" target=3D= "_blank" rel=3D"noopener">CVE-2026-61766</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61767" target=3D= "_blank" rel=3D"noopener">CVE-2026-61767</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61768" target=3D= "_blank" rel=3D"noopener">CVE-2026-61768</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61769" target=3D= "_blank" rel=3D"noopener">CVE-2026-61769</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61770" target=3D= "_blank" rel=3D"noopener">CVE-2026-61770</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61771" target=3D= "_blank" rel=3D"noopener">CVE-2026-61771</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61772" target=3D= "_blank" rel=3D"noopener">CVE-2026-61772</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61773" target=3D= "_blank" rel=3D"noopener">CVE-2026-61773</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61774" target=3D= "_blank" rel=3D"noopener">CVE-2026-61774</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61775" target=3D= "_blank" rel=3D"noopener">CVE-2026-61775</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61776" target=3D= "_blank" rel=3D"noopener">CVE-2026-61776</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61777" target=3D= "_blank" rel=3D"noopener">CVE-2026-61777</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61778" target=3D= "_blank" rel=3D"noopener">CVE-2026-61778</a></td>
</tr>
<td class=3D"vendor-product">nvidia -- nemo_megatron_bridge</td>
<td>NVIDIA Megatron Bridge contains a vulnerability where an attacker could=
cause a deserialization of untrusted data. A successful exploit of this vu= lnerability might lead to code execution, data tampering, and information d= isclosure.</td>
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61779" target=3D= "_blank" rel=3D"noopener">CVE-2026-61779</a></td>
</tr>
<td class=3D"vendor-product">OAuth Single Sign On--OAuth Single Sign On</td=
<td>The OAuth Single Sign On WordPress plugin before 7.0.1 does not verify = the identity assertion returned by its Steam single sign-on flow, allowing = unauthenticated attackers to log in as an arbitrary non-administrator user,=
and to create new accounts.</td>
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82183" target=3D= "_blank" rel=3D"noopener">CVE-2026-82183</a></td>
</tr>
<td class=3D"vendor-product">ogx-ai--ogx</td>
<td>OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unau= thenticated server-side request forgery vulnerability in the OpenAI-compati= ble POST /v1/responses endpoint. MCP tool definitions accept a server_url p= arameter (along with headers and authorization values) that is fetched serv= er-side without destination validation; the existing validate_url_not_priva= te() guard used for other URL inputs is not applied to server_url. On the d= efault starter configuration, which runs without authentication, a remote u= nauthenticated attacker can cause the server to open connections to arbitra=
ry internal addresses (including cloud metadata endpoints such as
http://16= 9.254.169.254/) and forward attacker-supplied headers and bearer tokens to = those destinations.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85666" target=3D= "_blank" rel=3D"noopener">CVE-2026-85666</a></td>
</tr>
<td class=3D"vendor-product">OHF-Voice--wyoming</td>
<td>Wyoming before 1.10.2 contains a server-side request forgery vulnerabil= ity that allows unauthenticated attackers with network access to force outb= ound connections to arbitrary targets by supplying a malicious `uri` query = parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix:/=
/` URIs to affected endpoints including /api/info, /api/speech-to-text, and=
/api/text-to-speech to override the server-configured backend and redirect=
connections to attacker-chosen hosts.</td>
<td>2026-09-01</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8712" target=3D"= _blank" rel=3D"noopener">CVE-2026-8712</a></td>
</tr>
<td class=3D"vendor-product">ollama--ollama</td>
<td>Ollama fails to validate redirect destinations when pulling tensor-laye=
r models, allowing unauthenticated attackers to redirect blob downloads to = arbitrary hosts. An attacker can control a registry, serve a malicious tens= or-layer manifest, and cause the server to issue GET requests to internal h= osts including cloud metadata endpoints.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85180" target=3D= "_blank" rel=3D"noopener">CVE-2026-85180</a></td>
</tr>
<td class=3D"vendor-product">OpenAI--Codex CLI</td>
<td>OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Wi= ndows and macOS misclassified certain PowerShell commands as safe because t= heir command-safety parser interpreted PowerShell's stop-parsing token (--%=
) differently than PowerShell itself. If a user opens an attacker-prepared = repository and Codex follows its instructions, Codex can run a file-writing=
Git command without requesting user approval. On macOS and Linux, exploita= tion additionally requires separately installed PowerShell Core (pwsh) to b=
e invoked. If filesystem protections permit the write, the command can modi=
fy Codex's configuration. If Codex later loads the modified configuration, =
it can launch an attacker-controlled MCP server and execute code with the u= ser's privileges, allowing it to read, change, or delete files accessible t=
o that account. The approval bypass does not disable filesystem sandboxing;=
the default filesystem sandbox on macOS and Linux can prevent writes outsi=
de permitted locations.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19591" target=3D= "_blank" rel=3D"noopener">CVE-2026-19591</a></td>
</tr>
<td class=3D"vendor-product">OpenAI--Codex CLI</td>
<td>OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Wi= ndows and macOS automatically collected Git repository metadata without dis= abling the repository-local core.fsmonitor setting. If a user opens or uses=
an attacker-prepared repository whose preserved .git/config sets core.fsmo= nitor to an attacker-controlled filesystem-monitor helper, Git can execute = that helper while Codex collects repository metadata. The helper runs outsi=
de Codex's command sandbox and without a user-approval prompt, allowing att= acker-controlled code to run with the user's privileges. The code can read,=
change, or delete the user's files and access other resources available to=
the user's account. An ordinary Git clone does not preserve the source rep= ository's local .git/config; exploitation requires a repository delivered o=
r copied with that configuration intact.</td>
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19592" target=3D= "_blank" rel=3D"noopener">CVE-2026-19592</a></td>
</tr>
<td class=3D"vendor-product">OpenAI--Codex Desktop</td>
<td>OpenAI Codex Desktop for Windows and macOS automatically inspected Git = metadata and working-tree status when a user opened a workspace. If the wor= kspace contains a repository with preserved attacker-controlled .git/config=
, the attr.tree setting and a configured clean or process filter can cause = Git to run an attacker-controlled program. The program runs outside Codex's=
command sandbox with the signed-in user's privileges, without a workspace-= trust prompt, command approval, or interaction with a model. The attacker c=
an read, modify, or delete files and access credentials available to that u= ser. Exploitation requires Git to be available on PATH and the user to open=
the attacker-prepared repository with its local Git configuration intact. =
An ordinary Git clone does not copy the source repository's .git/config and=
is not sufficient by itself.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19593" target=3D= "_blank" rel=3D"noopener">CVE-2026-19593</a></td>
</tr>
<td class=3D"vendor-product">OpenAI--Codex Desktop</td>
<td>OpenAI Codex Desktop for Windows and macOS could execute attacker-contr= olled Git hooks because automated Git operations trusted the repository's l= ocal core.hooksPath setting. If a user opens an attacker-prepared repositor=
y whose preserved .git/config points core.hooksPath to an attacker-controll=
ed directory, Codex can run a malicious hook while processing the repositor=
y. The hook executes outside Codex's command sandbox, without user approval=
, and with the user's privileges, allowing it to read, change, or delete th=
e user's files and access other resources available to the user's account. =
An ordinary Git clone does not preserve the attacker-controlled repository-= local configuration required for exploitation.</td>
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19590" target=3D= "_blank" rel=3D"noopener">CVE-2026-19590</a></td>
</tr>
<td class=3D"vendor-product">OpenAtomFoundation--pikiwidb</td>
<td>PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server =
on a port derived from the client port plus 2000 (e.g. 11221 when the defau=
lt client port 9221 is used) that does not authenticate incoming requests. = Although requirepass is intended to gate replication - a slave presents it =
as masterauth inside its MetaSync request - only the MetaSync handler (Hand= leMetaSyncRequest) validates it; the frame dispatcher (DealMessage) does no=
t require a completed or attempted MetaSync before routing other message ty= pes to their handlers. As a result, an unauthenticated remote attacker can = connect directly to the replication port and issue TrySync, DBSync, BinlogS= ync, and RemoveSlaveNode requests, obtaining the full-sync snapshot and liv=
e write stream and removing replica nodes, even when requirepass is configu= red.</td>
<td>2026-09-02</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84700" target=3D= "_blank" rel=3D"noopener">CVE-2026-84700</a></td>
</tr>
<td class=3D"vendor-product">openedx--openedx-platform</td>
<td>Open edX Platform enables the authoring and delivery of online learning=
at any scale. Prior to commit 59bb6d6, the view function set_course_mode_p= rice() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is de= corated only with @login_required and performs no course-level permission c= heck. Any authenticated user - including a learner account with zero course=
roles - can issue a single POST request to overwrite the honor mode price = and currency of any course on the platform. The companion frontend modal wa=
s removed in a prior cleanup, but the URL route and view remain live, makin=
g this an unguarded orphan endpoint. This issue has been patched via commit=
59bb6d6.</td>
<td>2026-09-02</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53635" target=3D= "_blank" rel=3D"noopener">CVE-2026-53635</a></td>
</tr>
<td class=3D"vendor-product">openjsf -- fast-uri</td>
<td>fast-uri serializes the port component of a URI without validating it. = When recomposing the authority, the userinfo and host components are escape=
d but the port is concatenated verbatim, so a port value that is not a sequ= ence of digits can inject authority delimiters, demoting the intended host =
to userinfo and pointing the authority at an attacker-controlled host. Both=
fast-uri and Node's URL read the result back as the attacker's host with n=
o error, so re-validating the built URI does not catch it. This affects app= lications that build URIs from parts and assign untrusted data to the port = component through the serialize, normalize, or equal functions in their obj= ect forms. The issue affects fast-uri versions before 2.4.6, from 3.0.0 bef= ore 3.1.7, and from 4.0.0 before 4.1.4. It is fixed in 2.4.6, 3.1.7, and 4.= 1.4, where recomposeAuthority rejects any port that is not a digit sequence=
per RFC 3986.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84292" target=3D= "_blank" rel=3D"noopener">CVE-2026-84292</a></td>
</tr>
<td class=3D"vendor-product">openjsf -- fast-uri</td>
<td>fast-uri accepts a host that contains an unbalanced or misplaced author= ity bracket without reporting an error. A host that starts with an opening = bracket but does not end with a closing bracket is neither validated as an =
IP literal nor canonicalized as a domain name, so parse() returns it as the=
host with error undefined, while Node's URL and the HTTP clients built on =
it resolve the same string to a different host. An application that reads t=
he parsed host to make a host decision, such as an SSRF denylist, a redirec=
t allowlist, or proxy routing, and then passes the original URL to an HTTP = client evaluates its policy against a string that is not the host the reque=
st reaches. The same host is carried through normalize, equal, and resolve.=
This affects fast-uri versions 2.4.5, 3.1.6, and 4.1.3, and is fixed in 2.= 4.6, 3.1.7, and 4.1.4, where parse() reports a malformed host for any host = that contains a bracket but is not a valid IPv6 literal.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84394" target=3D= "_blank" rel=3D"noopener">CVE-2026-84394</a></td>
</tr>
<td class=3D"vendor-product">OpenMAIC --OpenMAIC=C2=A0<br>=C2=A0</td> <td>OpenMAIC before 1.0.1 skips server-side request forgery validation in n= on-production builds, allowing unauthenticated attackers to reach cloud ins= tance metadata services. Attackers can supply arbitrary provider URLs via t=
he x-base-url header or baseUrl parameter to access sensitive cloud credent= ials and metadata.</td>
<td>2026-09-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86259" target=3D= "_blank" rel=3D"noopener">CVE-2026-86259</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>OpenPanel before 2.3.0 fails to properly validate chart formula express= ions, allowing authenticated project members with read access to execute ar= bitrary code by recovering the native JavaScript Function constructor throu=
gh mathjs matrix objects. Attackers can use the recovered constructor to lo=
ad Node.js built-ins and execute operating system commands with the privile= ges of the API process, bypassing organization authorization boundaries.</t=
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85610" target=3D= "_blank" rel=3D"noopener">CVE-2026-85610</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in=
the unauthenticated favicon proxy endpoint GET /misc/favicon that allows r= emote attackers to execute scripts by supplying an SVG file URL. Attackers = can host malicious SVG files with embedded scripts that execute in the vict= im's browser on the API origin, enabling same-origin credentialed requests =
to authenticated endpoints.</td>
<td>2026-09-04</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85613" target=3D= "_blank" rel=3D"noopener">CVE-2026-85613</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>OpenPanel before 2.3.0 contains an unauthenticated server-side request = forgery vulnerability in the GET /tools/site-checker endpoint that accepts =
a fully client-controlled URL parameter with no private IP filtering or DNS= -rebinding protection. Attackers can make the OpenPanel server issue reques=
ts to internal services, localhost, and cloud metadata endpoints, reading i= nternal HTTP response titles, headers, status codes, and SSL certificate in= formation.</td>
<td>2026-09-04</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85614" target=3D= "_blank" rel=3D"noopener">CVE-2026-85614</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>Openpanel before 2.3.0 contains an unauthenticated full-read server-sid=
e request forgery (SSRF) vulnerability in the GET /tools/site-checker endpo= int (apps/api/src/controllers/tools.controller.ts). The endpoint passes a u= ser-supplied url query parameter to fetchWithRedirects() and performs serve= r-side HTTP requests to arbitrary URLs without any SSRF/IP validation. An u= nauthenticated remote attacker can access cloud instance metadata endpoints=
, probe internal services, scan internal network ports, and read returned c= ontent (status code, page size, timing, and parsed HTML metadata), and leak=
internal IP addresses (via getIPInfo() to a third party).</td> <td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85609" target=3D= "_blank" rel=3D"noopener">CVE-2026-85609</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>OpenPanel before 2.3.0 contains an unauthenticated server-side request = forgery vulnerability in the /misc/favicon and /misc/og endpoints that acce=
pt an attacker-supplied url parameter with insufficient validation. Attacke=
rs can force the API to fetch arbitrary internal hosts and cloud metadata e= ndpoints, with small responses returned verbatim enabling credential theft = and internal service enumeration.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85612" target=3D= "_blank" rel=3D"noopener">CVE-2026-85612</a></td>
</tr>
<td class=3D"vendor-product">OpenSearch--OpenSearch</td>
<td>Unrestricted deserialization of untrusted data in the cursor pagination=
component in the OpenSearch SQL plugin allows a remote authenticated user = with basic read/search permissions to execute arbitrary code on the server =
by sending a crafted cursor parameter to the plugins/sql endpoint.</td> <td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83497" target=3D= "_blank" rel=3D"noopener">CVE-2026-83497</a></td>
</tr>
<td class=3D"vendor-product">OpenTalker--SadTalker</td>
<td>SadTalker contains an OS command injection vulnerability in the video m= uxing process where uploaded audio filenames are interpolated into ffmpeg c= ommands without proper escaping. Attackers can upload audio files with shel=
l metacharacters in the filename to break out of quoted arguments and execu=
te arbitrary system commands when video generation occurs.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85696" target=3D= "_blank" rel=3D"noopener">CVE-2026-85696</a></td>
</tr>
<td class=3D"vendor-product">Oxford Nanopore--MinKNOW</td>
<td>Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP add= ress for authentication.</td>
<td>2026-09-02</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-35585" target=3D= "_blank" rel=3D"noopener">CVE-2024-35585</a></td>
</tr>
<td class=3D"vendor-product">Pangolin--Pangolin</td>
<td>Pangolin before 1.22.0 contains an authentication bypass vulnerability = that allows unauthenticated attackers to access any protected resource by s= upplying an attacker-controlled URL parameter to the share-link authenticat= ion endpoint that omits the expected resource identifier from the token ver= ification call. Attackers holding a single valid share link for any resourc=
e can authenticate against arbitrary resources across different organizatio= ns, bypassing all configured authentication methods including SSO, resource=
passwords, PIN codes, email allowlists, and header authentication.</td> <td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72001" target=3D= "_blank" rel=3D"noopener">CVE-2026-72001</a></td>
</tr>
<td class=3D"vendor-product">Paolo--GeoDirectory</td>
<td>Unauthenticated SQL Injection in GeoDirectory <=3D 2.8.174 versions.= </td>
<td>2026-09-03</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84813" target=3D= "_blank" rel=3D"noopener">CVE-2026-84813</a></td>
</tr>
<td class=3D"vendor-product">Parrot--AR.Drone<br>=C2=A0</td>
<td>Parrot AR.Drone version 1 and 2 does not employ a suitable mechanism to=
prevent denial-of-service (DoS) attacks. An attacker can harm the device a= vailability (i.e., video streaming and control) by using tool to perform an=
IPv4 flood attack. Verified attacks includes SYN flooding and UDP flooding= .</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-44320" target=3D= "_blank" rel=3D"noopener">CVE-2021-44320</a></td>
</tr>
<td class=3D"vendor-product">Passionate Programmer Peter--WP Data Access</t=
<td>Unauthenticated SQL Injection in WP Data Access <=3D 5.5.81 versions= .</td>
<td>2026-08-31</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81293" target=3D= "_blank" rel=3D"noopener">CVE-2026-81293</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain a privilege esc= alation vulnerability in DirectIo64.sys that allows local users to clear ar= bitrary bits at any physical memory address due to missing validation of th=
e physical address parameter in an exposed IOCTL handler. Attackers can obt= ain a device handle and supply an arbitrary 64-bit physical address with a = bit index to invoke MmMapIoSpace and clear bits in kernel code pages or pag=
e table entries, enabling local privilege escalation or system compromise.<=
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80113" target=3D= "_blank" rel=3D"noopener">CVE-2026-80113</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain an improper acc= ess control vulnerability in the DirectIo64.sys kernel driver that allows u= nprivileged local users to perform privileged hardware operations by openin=
g a handle to the device object created without a security descriptor. Atta= ckers can issue IOCTLs through the permissive default Windows ACL applied t=
o the device to access restricted hardware operations regardless of privile=
ge or integrity level.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80112" target=3D= "_blank" rel=3D"noopener">CVE-2026-80112</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded cr= edentials vulnerability in DirectIo64.sys that allows local attackers to pe= rform arbitrary physical memory writes by extracting an 8-byte key embedded=
as a hardcoded literal in the distributed binary and computing valid MD5 a= uthentication tags for arbitrary IOCTL write requests. Attackers can additi= onally bypass a secondary validation gate by using the driver's own bit-cle=
ar IOCTL to clear a single bit in the gating instruction's displacement byt=
e, causing all subsequent write requests to skip MAC verification, size che= cks, and Vendor ID checks entirely.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80114" target=3D= "_blank" rel=3D"noopener">CVE-2026-80114</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain a privilege esc= alation vulnerability in DirectIo64.sys that allows local users to modify h= ardware configuration by exploiting exposed IOCTLs with no validation on de= vice selection, register offset, or value. Attackers can obtain a device ha= ndle and issue arbitrary PCI configuration space read/write operations to e= nable Bus Master DMA on any PCI device, halt storage controller I/O by clea= ring command registers, or remap Base Address Registers to redirect DMA to =
an attacker-chosen physical address.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80116" target=3D= "_blank" rel=3D"noopener">CVE-2026-80116</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain a privilege esc= alation vulnerability in DirectIo64.sys that allows local users to issue ar= bitrary IN and OUT instructions to any x86 I/O port due to missing allowlis=
t or port validation on exposed IOCTLs. Attackers can obtain a device handl=
e and write to sensitive ports including the PS/2 controller port, CPU rese=
t ports, CMOS configuration ports, and interrupt controller ports to cause =
an immediate system reset or other hardware-level manipulation from a stand= ard user account.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80117" target=3D= "_blank" rel=3D"noopener">CVE-2026-80117</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain an unauthentica= ted physical memory disclosure in DirectIo64.sys, reachable by unprivileged=
local users through a single IOCTL with no caller-identity check. The hand= ler writes a crash-dump-format (PAGEDU64) image of all physical memory to a=
caller-supplied file path in the SYSTEM context, allowing a standard user =
to create files in locations they cannot otherwise write and to recover mem= ory belonging to processes of other users. The image is preceded by a heade=
r that exposes the kernel loaded-module list, active-process list and PFN d= atabase pointers, defeating KASLR. The same handler also dereferences the r= eturn value of an internal kernel-structure locator without a NULL check; t= hat locator returns NULL on three distinct failure paths, and a kernel cras=
h results on builds where any of those paths is taken.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80118" target=3D= "_blank" rel=3D"noopener">CVE-2026-80118</a></td>
</tr>
<td class=3D"vendor-product">PassMark --PerformanceTest<br>=C2=A0</td>
<td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain an information = disclosure vulnerability in DirectIo64.sys that allows unauthenticated loca=
l attackers to dump complete physical memory contents by supplying a caller= -controlled file path to an exposed IOCTL. Attackers can issue a single IOC=
TL call to trigger the driver to iterate all physical memory ranges via MmG= etPhysicalMemoryRanges and map each page through ZwMapViewOfSection on the = PhysicalMemory section object, writing a full RAM image to an attacker-spec= ified path in the SYSTEM context, bypassing user-mode ACLs and exposing LSA=
SS working set, process memory, and cryptographic material from all running=
processes.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80119" target=3D= "_blank" rel=3D"noopener">CVE-2026-80119</a></td>
</tr>
<td class=3D"vendor-product">Paul Ryan--Authorizer</td>
<td>Unauthenticated Privilege Escalation in Authorizer <=3D 3.15.1 versi= ons.</td>
<td>2026-09-02</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81294" target=3D= "_blank" rel=3D"noopener">CVE-2026-81294</a></td>
</tr>
<td class=3D"vendor-product">PCRE2 --PCRE2=C2=A0<br>=C2=A0</td>
<td>PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because=
reuse of a cached workspace block, in a recursive DFA matching workspace, = lacks a size check (even though a newly allocated block, for the same purpo= se, does have a size check). This outcome requires an attacker-controlled r= egular expression, or a recursive pattern in conjunction with a small heap = limit (this can be set through the API).</td>
<td>2026-09-05</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86145" target=3D= "_blank" rel=3D"noopener">CVE-2026-86145</a></td>
</tr>
<td class=3D"vendor-product">Peppermint-Lab--peppermint</td>
<td>Peppermint through 0.5.5 contains a hardcoded JWT signing secret in doc= ker-compose.yml that allows unauthenticated attackers to forge session toke=
ns for any account. Attackers can use the published secret to mint valid to= kens for arbitrary user IDs and access protected endpoints without credenti= als.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85391" target=3D= "_blank" rel=3D"noopener">CVE-2026-85391</a></td>
</tr>
<td class=3D"vendor-product">Phison Electronics Corporation--PS3111-S11 Con= troller Firmware</td>
<td>Phison PS3111-S11 controller firmware verifies RSA signatures using a p= ublic modulus embedded within the firmware image itself rather than anchore=
d in immutable storage. Attackers can generate arbitrary RSA key pairs, sig=
n modified firmware with the private key, embed the matching modulus in the=
signature segment, and the controller accepts the tampered firmware as val= id.</td>
<td>2026-08-31</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82876" target=3D= "_blank" rel=3D"noopener">CVE-2026-82876</a></td>
</tr>
<td class=3D"vendor-product">Phison Electronics Corporation--PS3111-S11 Con= troller Firmware</td>
<td>Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose = privileged vendor unique commands over the ATA interface with absent or def= eatable authentication mechanisms. Attackers can bypass the weak CRC-16 bas=
ed unlock handshake or exploit builds with no VUC lock to read and write co= ntroller memory and raw flash, persisting implants across power cycles.</td=
<td>2026-09-02</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84696" target=3D= "_blank" rel=3D"noopener">CVE-2026-84696</a></td>
</tr>
<td class=3D"vendor-product">Photo Gallery by 10Web--Photo Gallery by 10Web= </td>
<td>The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not esca=
pe two request parameters before reflecting them into input-attribute value=
s on its admin pages (one on the Shortcode page, one on the Galleries/Album=
s list page), so an unauthenticated attacker can craft a link that, when op= ened by a logged-in administrator (or, for the first sink, a contributor), = executes arbitrary JavaScript in the victim's authenticated session via an = auto-firing onfocus handler. The Galleries/Albums sink renders only when th=
e site has more than 20 galleries/albums (the normal state of a populated i= nstall).</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12865" target=3D= "_blank" rel=3D"noopener">CVE-2026-12865</a></td>
</tr>
<td class=3D"vendor-product">Piwigo--Piwigo</td>
<td>A security vulnerability has been detected in Piwigo up to 16.3.0. Affe= cted by this issue is some unknown functionality of the file i.php of the c= omponent Image Derivative Handler. The manipulation leads to path traversal=
. Remote exploitation of the attack is possible. The exploit has been discl= osed publicly and may be used.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84441" target=3D= "_blank" rel=3D"noopener">CVE-2026-84441</a></td>
</tr>
<td class=3D"vendor-product">pixarlabs--Master Addons for Elementor Element=
or Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & = Template Kits</td>
<td>The Master Addons for Elementor - Elementor Addons, Widgets, Mega Menu = Builder, Popup Builder, Widget Builder & Template Kits plugin for WordP= ress is vulnerable to Arbitrary File Upload in all versions up to, and incl= uding, 3.1.9 via the upload_template_kit function. This is due to incorrect=
authorization on the upload_template_kit() AJAX handler, which requires on=
ly upload_files capability instead of the manage_options required by all si= bling handlers, combined with missing per-entry file type filtering after Z=
IP extraction. This makes it possible for authenticated attackers, with edi= tor-level access and above, to upload files that may be executable, which m= akes remote code execution possible. Editors can satisfy the nonce requirem= ent because the required nonces are localized on the standard Pages list sc= reen, which is accessible to any user with the edit_pages capability.</td> <td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75921" target=3D= "_blank" rel=3D"noopener">CVE-2026-75921</a></td>
</tr>
<td class=3D"vendor-product">plandex-ai--plandex</td>
<td>Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles=
function that allows attackers to write files outside the project director=
y. Attackers can influence model output through poisoned repository files o=
r attacker-controlled context to write to arbitrary locations like shell rc=
or cron files, achieving code execution.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85690" target=3D= "_blank" rel=3D"noopener">CVE-2026-85690</a></td>
</tr>
<td class=3D"vendor-product">pnpm--pnpm</td>
<td>pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11= .0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml pa= ckages keys with dp.parse(depPath).name and uses it without validation in d= eps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/s= rc/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), sto= reController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowi=
ng package contents to be written outside node_modules when a user runs pnp=
m install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry p= ermits lifecycle scripts, the escaped package can execute code with the use= r's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.</td> <td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82392" target=3D= "_blank" rel=3D"noopener">CVE-2026-82392</a></td>
</tr>
<td class=3D"vendor-product">pnpm--pnpm</td>
<td>pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a=
scoped path traversal in a tarball dependency's package.json manifest name=
because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash cha= racters only for unscoped names. During pnpm install, the unvalidated name = reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.= ts, pnpm11/installing/deps-resolver/src/index.ts, and pnpm11/deps/graph-bui= lder/src/lockfileToDepGraph.ts, causing package extraction outside node_mod= ules and allowing attacker-controlled files to overwrite arbitrary filesyst=
em paths even when --ignore-scripts is used. The overwrite can replace shel=
l startup files, Git hooks, or installed package code and lead to code exec= ution. This issue is fixed in versions 10.34.5, and 11.11.0.</td> <td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82393" target=3D= "_blank" rel=3D"noopener">CVE-2026-82393</a></td>
</tr>
<td class=3D"vendor-product">PocketMine-MP--PocketMine-MP<br>=C2=A0</td>
<td>PocketMine-MP before 4.7.2 fails to properly handle exceptions from the=
adhocore/json-comment library when parsing skin geometry data. Attackers c=
an send login or skin packets with invalid geometry JSON to trigger an unha= ndled RuntimeException, causing server crash.</td>
<td>2026-09-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-51009" target=3D= "_blank" rel=3D"noopener">CVE-2022-51009</a></td>
</tr>
<td class=3D"vendor-product">PostgreSQL-- Anonymizer<br>=C2=A0</td> <td>PostgreSQL Anonymizer contains a vulnerability that allows unprivileged=
masked users to execute arbitrary code by abusing operators, domain casts,=
or view subqueries that carry untrusted expressions. When these objects ar=
e evaluated in the context of the extension's masking mechanisms, the malic= ious code can run with elevated privileges. The issue is fixed in PostgreSQ=
L Anonymizer 3.1.4 and later versions</td>
<td>2026-09-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19633" target=3D= "_blank" rel=3D"noopener">CVE-2026-19633</a></td>
</tr>
<td class=3D"vendor-product">PowerJob--PowerJob</td>
<td>A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the=
function MuConnectionManager.getOrCreateConnection of the file powerjob-se= rver/powerjob-server-starter/src/main/java/tech/powerjob/server/web/control= ler/TestController.java of the component Transport Endpoint. The manipulati=
on leads to server-side request forgery. The attack is possible to be carri=
ed out remotely. The exploit is publicly available and might be used. The p= roject was informed of the problem early through an issue report but has no=
t responded yet.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82630" target=3D= "_blank" rel=3D"noopener">CVE-2026-82630</a></td>
</tr>
<td class=3D"vendor-product">PowerJob--Worker v5.1.2</td>
<td>PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the=
/worker/deployContainer HTTP endpoint without authentication on the defaul=
t transport port. This allows a remote attacker to execute arbitrary code.<=
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75430" target=3D= "_blank" rel=3D"noopener">CVE-2026-75430</a></td>
</tr>
<td class=3D"vendor-product">PowerJob--Worker v5.1.2</td>
<td>PowerJob Server version 5.1.2 (and likely earlier) uses a predictable J=
WT signing key for HS256-based authentication. This allows a remote attacke=
r to execute arbitrary code.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75431" target=3D= "_blank" rel=3D"noopener">CVE-2026-75431</a></td>
</tr>
<td class=3D"vendor-product">predis--predis</td>
<td>Predis is a flexible and feature-complete Redis and Valkey client for P= HP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggreg= ate cluster and replication connections reparses an already serialized RESP=
buffer in AbstractAggregateConnection::write() by splitting it with explod= e("\r\n") instead of honoring RESP length prefixes. Attacker-controlled key=
s or values containing CRLF sequences can therefore be interpreted by Comma= nd::deserializeCommand() as additional commands. On cluster connections, Cl= usterStrategy::getFakeKey() can route injected keyless commands using the l= iteral fake key value "key", permitting operations such as shard-wide cache=
deletion, targeted data modification, data reads, or node disruption. On r= eplication connections, malformed reparsing can throw an uncaught exception=
and repeatedly terminate affected requests. Only pipeline() reaches this v= ulnerable path; transaction() and MULTI are not affected. This issue is fix=
ed in version 3.3.0.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84372" target=3D= "_blank" rel=3D"noopener">CVE-2026-84372</a></td>
</tr>
<td class=3D"vendor-product">Progress Software--Telerik UI for ASP.NET AJAX= </td>
<td>In Progress=C3=82=C2=AE Telerik=C3=82=C2=AE UI for AJAX prior to v2026.= 3.812, insufficient integrity protection of dialog request parameters used =
by the RadEditor file browser may allow an attacker who has obtained certai=
n application encryption key material to alter the folders the file browser=
reads from, writes to, and uploads into, potentially resulting in remote c= ode execution.</td>
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19219" target=3D= "_blank" rel=3D"noopener">CVE-2026-19219</a></td>
</tr>
<td class=3D"vendor-product">Progress Software--Telerik UI for ASP.NET AJAX= </td>
<td>In Progress=C3=82=C2=AE Telerik=C3=82=C2=AE UI for AJAX prior to v2026.= 3.812, insufficient validation of client-supplied state in RadImageEditor m=
ay allow an attacker to influence which file is returned by the control's i= mage cache, potentially exposing file contents outside the intended image d= irectories.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18672" target=3D= "_blank" rel=3D"noopener">CVE-2026-18672</a></td>
</tr>
<td class=3D"vendor-product">Proper Fraction--ProfilePress</td> <td>ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains a=
n unauthenticated remote code execution vulnerability that allows unauthent= icated attackers to install and activate arbitrary plugins by brute-forcing=
a weak 32-bit connect token via the ppress_connect_process AJAX handler. A= ttackers can supply a caller-controlled URL through the file request parame= ter to trigger silent plugin installation and activation, achieving PHP cod=
e execution as the web-server user.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66047" target=3D= "_blank" rel=3D"noopener">CVE-2026-66047</a></td>
</tr>
<td class=3D"vendor-product">Proxmox Server Solutions GmbH--Proxmox Virtual=
Environment (VE)</td>
<td>Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentica= tion bypass vulnerability in libpve-access-control before 8.0.4 that allows=
unauthenticated attackers to authenticate as any existing enabled user wit= hout a configured second factor by supplying an arbitrary tfa-challenge val=
ue in the API login endpoint. Attackers can send a POST request to the acce=
ss ticket API endpoint with any value in the tfa-challenge parameter to com= pletely skip password verification, gaining unauthorized access including t=
o the root@pam account. All affected releases are end of life.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-54391" target=3D= "_blank" rel=3D"noopener">CVE-2023-54391</a></td>
</tr>
<td class=3D"vendor-product">Pterodactyl Panel --Pterodactyl Panel=C2=A0<br= >=C2=A0</td>
<td>Pterodactyl Panel before 1.14.1 fails to validate action-specific permi= ssions in scheduled task creation, allowing subusers with only schedule.upd= ate permission to execute arbitrary console commands. Attackers can create = and immediately trigger scheduled tasks that run game-server console comman= ds, control server power state, or create backups without proper authorizat= ion checks.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86177" target=3D= "_blank" rel=3D"noopener">CVE-2026-86177</a></td>
</tr>
<td class=3D"vendor-product">pydantic--httpx2</td>
<td>HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, ht= tpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py = and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin us=
es wss through a SOCKS5 proxy because the TLS upgrade condition only recogn= izes https. HTTPX2 exposes the flaw through Client.websocket() and AsyncCli= ent.websocket() from 2.6.0 through 2.9.1, so the opening handshake, query p= arameters, Authorization headers, cookies, and subsequent frames can cross = the proxy path in plaintext without certificate verification. An attacker c= ontrolling or observing that path can read or modify traffic and impersonat=
e the WebSocket server. This issue is fixed in httpcore2 2.10.0 and HTTPX2 = 2.10.0.</td>
<td>2026-09-02</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84381" target=3D= "_blank" rel=3D"noopener">CVE-2026-84381</a></td>
</tr>
<td class=3D"vendor-product">pydantic--httpx2</td>
<td>HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, th=
e HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate e= ach gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_b= ytes() yields bounded pieces to the application. A 64 KiB compressed chunk = can expand to approximately 64 MiB in one intermediate allocation, so an at= tacker-controlled or compromised server can cause severe memory pressure or=
out-of-memory process termination even when the application streams the re= sponse. This issue is fixed in version 2.12.0.</td>
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84382" target=3D= "_blank" rel=3D"noopener">CVE-2026-84382</a></td>
</tr>
<td class=3D"vendor-product">Pyramid Solutions--EtherNet/IP Adapter DLL Kit=
(EIPA)</td>
<td>An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a=
large Class 3 explicit-message request to exceed the application-side rece= ive buffer without generating an error or warning. The result could be memo=
ry corruption, a device crash, or a potential remote attack vector without = the originating device receiving a CIP error indicating that the request co= uld not be processed.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78012" target=3D= "_blank" rel=3D"noopener">CVE-2026-78012</a></td>
</tr>
<td class=3D"vendor-product">QD--QD</td>
<td>Server-side request forgery (SSRF) in the /har/test endpoint in QD 2022= 0208 through 20250803. Fetcher.build_request() in libs/fetcher.py construct=
s an httpclient.HTTPRequest from user-supplied JSON without validating URL = scheme, host, or IP range. The /har/test handler does not require authentic= ation, enabling unauthenticated remote attackers to force the QD server to = send arbitrary HTTP requests to internal network resources and cloud metada=
ta endpoints. validate_cert is set to False, disabling TLS verification.</t=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51152" target=3D= "_blank" rel=3D"noopener">CVE-2026-51152</a></td>
</tr>
<td class=3D"vendor-product">Quarkus--quarkus-qute</td>
<td>A flaw was found in the Qute template engine, which is used by Quarkus =
to generate dynamic content like HTML pages or emails. The issue exists in = the component responsible for looking up data values (ReflectionValueResolv= er), which fails to properly block access to sensitive Java internal functi= ons when processing certain data types like Enums. An attacker who can prov= ide or influence the template text can exploit this bypass to take control =
of the server by executing unauthorized commands.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12894" target=3D= "_blank" rel=3D"noopener">CVE-2026-12894</a></td>
</tr>
<td class=3D"vendor-product">QVidium--Opera11</td>
<td>A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11=
. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the compo= nent CGI Script. This manipulation of the argument ipaddr causes command in= jection. The attack may be initiated remotely. The exploit has been publicl=
y disclosed and may be utilized. The vendor explains: "QVidium has now clos=
ed its doors and no longer will be able to sell products or provide support=
." This vulnerability only affects products that are no longer supported by=
the maintainer.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82971" target=3D= "_blank" rel=3D"noopener">CVE-2026-82971</a></td>
</tr>
<td class=3D"vendor-product">rabindralamsal --inventory-management-system 1= .0.0<br>=C2=A0</td>
<td>A flaw has been found in rabindralamsal inventory-management-system 1.0= .0. This affects an unknown part of the file index.php of the component Log= in. Executing a manipulation of the argument username/password can lead to = sql injection. The attack can be executed remotely. The exploit has been pu= blished and may be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86211" target=3D= "_blank" rel=3D"noopener">CVE-2026-86211</a></td>
</tr>
<td class=3D"vendor-product">ramon-victor--freegpt-webui</td>
<td>A security vulnerability has been detected in ramon-victor freegpt-webu=
i up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function = _conversation of the file server/backend.py of the component Backend Conver= sation API. Such manipulation of the argument model leads to missing authen= tication. The attack may be launched remotely. The exploit has been disclos=
ed publicly and may be used. This product operates on a rolling release bas= is, ensuring continuous delivery. Consequently, there are no version detail=
s for either affected or updated releases. This vulnerability only affects = products that are no longer supported by the maintainer.</td> <td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85702" target=3D= "_blank" rel=3D"noopener">CVE-2026-85702</a></td>
</tr>
<td class=3D"vendor-product">Really Simple Plugins--Really Simple SSL</td> <td>Unauthenticated Broken Authentication in Really Simple SSL <=3D 9.8.=
0 versions.</td>
<td>2026-09-03</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84777" target=3D= "_blank" rel=3D"noopener">CVE-2026-84777</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Advanced Cluster Management f=
or Kubernetes 2.17</td>
<td>A flaw was found in submariner. In cert-auth mode, the connection confi= guration is built using free-form strings from the Custom Resource Definiti=
on (CRD) without proper validation. A malicious cluster can exploit this by=
publishing a CableName that includes newlines and ipsec.conf directives. T= his allows an attacker to inject arbitrary configuration parameters or exec= ute commands through leftupdown hooks, leading to remote code execution as = root on the gateway node.</td>
<td>2026-09-02</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66786" target=3D= "_blank" rel=3D"noopener">CVE-2026-66786</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat AMQ Broker 7</td>
<td>A flaw was found in Jolokia's JSR-160 proxy functionality where insuffi= cient validation of client-controlled JMX service URLs allows a bypass of t=
he denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `t= arget.url` value from a Jolokia POST request and passes it to `JMXServiceUR=
L` and `JMXConnectorFactory` for establishing the remote JMX connection. Th=
e existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/lda= p:.*`, which can be bypassed using alternative valid JMX service URL forms,=
including `ldaps://` schemes or LDAP URLs with a non-empty JMX host compon= ent. These URLs are accepted as valid `JMXServiceURL` objects and can cause=
the Jolokia agent JVM to perform a JNDI lookup against an attacker-control= led LDAP endpoint. This can result in server-side request forgery (SSRF), f= orwarding of supplied JMX credentials to the remote endpoint, and potential=
ly remote code execution depending on the classes and configuration availab=
le in the target JVM.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84218" target=3D= "_blank" rel=3D"noopener">CVE-2026-84218</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Build of Apache Camel 3.33 fo=
r Quarkus 3.33.3.SP1</td>
<td>A flaw was found in RESTEasy's SourceProvider. This vulnerability allow=
s an unauthenticated attacker to perform an unauthenticated remote file rea=
d. By sending a specially crafted XML body with a DOCTYPE declaration refer= encing external entities to an endpoint that accepts application/xml and re= turns Source or StreamSource, the server can be tricked into resolving the = entity and including sensitive file contents in the HTTP response. This is = due to the SourceProvider.writeTo() method creating a SAXParser without dis= abling external entity resolution, leading to an XML External Entity (XXE) = vulnerability.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17615" target=3D= "_blank" rel=3D"noopener">CVE-2026-17615</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat build of Apache Camel for Spr= ing Boot 4</td>
<td>Undertow is a flexible performant web server used in JBoss EAP and Wild= Fly. A flaw was found in how Undertow handles WebSocket connections. Specif= ically, certain configuration limits like message buffer sizes and session = timeouts cannot be adjusted and default to being unlimited. This allows a r= emote attacker to send large amounts of data or maintain connections indefi= nitely, potentially crashing the server by exhausting its memory or other r= esources.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81624" target=3D= "_blank" rel=3D"noopener">CVE-2026-81624</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat build of Quarkus</td>
<td>A flaw was found in SmallRye GraphQL. The number scalar coercion for Bi= gInteger does not properly validate the magnitude of float or string inputs=
. An unauthenticated remote attacker can exploit this by sending a GraphQL = query containing a large exponent float literal. This can lead to the alloc= ation of extremely large BigInteger objects, causing CPU exhaustion or an O= utOfMemoryError, resulting in a denial of service.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76763" target=3D= "_blank" rel=3D"noopener">CVE-2026-76763</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in GDB's STABS debug format parser. The read_member_fu= nctions() function in gdb/stabsread.c contains a linked list removal bug in=
the code that separates destructor and non-destructor member functions of = C++ classes. The bug causes the destructor entries to remain in the main fu= nction list while the list length counter is decremented, resulting in an o= ut-of-bounds write when the function list is copied to its final allocated = array. An attacker can craft an ELF binary with malicious .stab and .stabst=
r sections that triggers this out-of-bounds write when a user opens the fil=
e in GDB and performs any symbol-inspection operation such as setting a bre= akpoint. The inferior process does not need to be executed. Under controlle=
d conditions, this was demonstrated to achieve execution of arbitrary comma= nds within the GDB process.</td>
<td>2026-08-31</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13732" target=3D= "_blank" rel=3D"noopener">CVE-2026-13732</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A heap-based buffer overflow was found in Corosync's Totem Process Grou=
p (totempg) message reassembly. When processing fragmented multicast messag= es, the buffer used to reassemble fragments lacks a runtime bounds check in=
release builds. A network-adjacent attacker able to send crafted multicast=
protocol messages to the cluster could cause a heap buffer overflow with a= ttacker-controlled data. This can crash the Corosync daemon, causing a deni=
al of service to the entire cluster, and may potentially allow further expl= oitation given sufficient heap-corruption control.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81665" target=3D= "_blank" rel=3D"noopener">CVE-2026-81665</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in rpm. A local attacker could supply a specially craf= ted `.gem` filename containing RPM macro syntax. When a user or automated w= orkflow invokes `rpmuncompress -x` on this file, the macro expansion occurs=
during command construction. This allows the attacker to execute arbitrary=
commands with the privileges of the invoking account, leading to a comprom= ise of confidentiality, integrity, and availability.</td>
<td>2026-09-01</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84233" target=3D= "_blank" rel=3D"noopener">CVE-2026-84233</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in rpm. An attacker can exploit a command injection vu= lnerability by influencing the path or filename of a tarball processed by `= rpmbuild -t*` to include shell metacharacters. This is particularly relevan=
t in automated build or continuous integration (CI) workflows that ingest e= xternally supplied artifact names. Successful exploitation allows for arbit= rary command execution with the privileges of the build user, which could l= ead to information disclosure or disruption of the build environment.</td> <td>2026-09-02</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84837" target=3D= "_blank" rel=3D"noopener">CVE-2026-84837</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in rpmuncompress. This command injection vulnerability=
allows a local attacker to execute arbitrary commands. This occurs when rp= muncompress processes a specially crafted archive filename containing shell=
metacharacters, which are not properly escaped before being passed to shel=
l command strings. Successful exploitation requires user interaction, where=
a user or automated workflow invokes rpmuncompress on the malicious file, = leading to high impact on the confidentiality, integrity, and availability =
of data accessible to the invoking user.</td>
<td>2026-09-02</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84838" target=3D= "_blank" rel=3D"noopener">CVE-2026-84838</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A NULL pointer dereference flaw was found in GStreamer's RTSP support l= ibrary. The vulnerability occurs while parsing an Authorization or WWW-Auth= enticate header that uses Digest authentication. Specially crafted whitespa=
ce placement around a parameter's terminator can cause an internal length c= alculation to underflow, leading to a crash of the process parsing the head= er. On an RTSP server this can be triggered by a remote, unauthenticated at= tacker sending a single malformed request when the server has authenticatio=
n enabled; the same flaw can also be triggered against an RTSP client by a = malicious or compromised RTSP server. Successful exploitation results in a = denial of service (application crash) and has no confirmed impact on confid= entiality or integrity.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85150" target=3D= "_blank" rel=3D"noopener">CVE-2026-85150</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-= Middle (MITM) attacker can exploit a heap use-after-free vulnerability in t=
he HTTP/2 client implementation. This occurs when a GNOME application uploa=
ds a file using HTTP/2, and the server sends a GOAWAY frame while the file = body is being read asynchronously. This can lead to memory corruption, pote= ntially resulting in information disclosure or arbitrary code execution.</t=
<td>2026-09-04</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85197" target=3D= "_blank" rel=3D"noopener">CVE-2026-85197</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 7</td>
<td>A stack out-of-bounds write vulnerability was found in gfs2-utils. In g= fs2_edit, the di_height field from on-disk inode metadata is used as an arr=
ay index without bounds checking, causing a stack buffer overflow that may = lead to arbitrary code execution when processing crafted GFS2 filesystem im= ages.</td>
<td>2026-09-03</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71220" target=3D= "_blank" rel=3D"noopener">CVE-2026-71220</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 7</td>
<td>A stack out-of-bounds write vulnerability was found in gfs2-utils. In s= avemeta, the height value from on-disk inode metadata is used as a loop bou=
nd without bounds checking, causing a stack buffer overflow that may lead t=
o arbitrary code execution when processing crafted GFS2 filesystem images.<=
<td>2026-09-03</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71221" target=3D= "_blank" rel=3D"noopener">CVE-2026-71221</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
<td>The nsenter --join-cgroup option opens the target cgroup.procs file as = root and leaves that file descriptor open across later namespace and creden= tial changes and across execve(). Because the kernel checks later cgroup mi= grations using the credentials from the original open, a program run in an = attacker-controlled target can inherit root's ability to move host processe=
s between cgroups. After a privileged operator uses --join-cgroup against t= hat target, an unprivileged user can migrate and terminate unrelated root p= rocesses.</td>
<td>2026-09-02</td>
<td>7.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78408" target=3D= "_blank" rel=3D"noopener">CVE-2026-78408</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
<td>The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 = and later and passes the configured subdirectory to open_tree() with AT_SYM= LINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or ke=
ep resolution inside the newly mounted filesystem. A local unprivileged use=
r with an fstab-authorized X-mount.subdir entry can attach a host path at t=
he intended mountpoint.</td>
<td>2026-09-02</td>
<td>7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78409" target=3D= "_blank" rel=3D"noopener">CVE-2026-78409</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Hardened Images</td>
<td>A flaw was found in util-linux. Restricted bind mounts take the source = path from fstab but do not pin that source before the privileged mount. A l= ocal unprivileged user who can replace the authorized source or a writable = ancestor can redirect SUID mount(8) to bind another host directory. If the = fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root t= hen changes ownership or mode on that redirected inode.</td>
<td>2026-09-02</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78410" target=3D= "_blank" rel=3D"noopener">CVE-2026-78410</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat OpenShift Container Platform = 4</td>
<td>A flaw was found in openshift/oauth-server. The OAuth login and error p= age endpoints pass the unauthenticated Accept-Language header to golang.org= /x/text/language.ParseAcceptLanguage() without input validation. A bypass o=
f the CVE-2022-32149 mitigation exists: the upstream guard counts only '-' = characters but the internal BCP 47 scanner aliases '_' to '-' after the gua=
rd check. An unauthenticated attacker can send a crafted Accept-Language he= ader using '_' separators to trigger quadratic-time parsing, consuming exce= ssive CPU and denying authentication to all cluster users.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49329" target=3D= "_blank" rel=3D"noopener">CVE-2026-49329</a></td>
</tr>
<td class=3D"vendor-product">RedPort--Optimizer wXa-203</td>
<td>A security vulnerability has been detected in RedPort Optimizer wXa-203=
, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the = function exec of the file /xgatev1/system/datetime.php of the component Sys= tem Clock. The manipulation leads to command injection. The attack may be i= nitiated remotely. The exploit has been disclosed publicly and may be used.=
The vendor was contacted early about this disclosure but did not respond i=
n any way.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83524" target=3D= "_blank" rel=3D"noopener">CVE-2026-83524</a></td>
</tr>
<td class=3D"vendor-product">RegistrationMagic--RegistrationMagic</td>
<td>The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a=
registration form field value before outputting it in an HTML attribute on=
an administrative page, allowing unauthenticated users to perform Stored C= ross-Site Scripting attacks against high privilege users such as admin.</td=
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77792" target=3D= "_blank" rel=3D"noopener">CVE-2026-77792</a></td>
</tr>
<td class=3D"vendor-product">rometheme--RTMKit</td>
<td>Contributor PHP Object Injection in RTMKit <=3D 2.1.5 versions.</td> <td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84752" target=3D= "_blank" rel=3D"noopener">CVE-2026-84752</a></td>
</tr>
<td class=3D"vendor-product">rometheme--RTMKit</td>
<td>Unauthenticated Cross Site Scripting (XSS) in RTMKit <=3D 2.1.5 vers= ions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84763" target=3D= "_blank" rel=3D"noopener">CVE-2026-84763</a></td>
</tr>
<td class=3D"vendor-product">rubyzip--rubyzip</td>
<td>rubyzip versions before 3.4.0 contain a path traversal vulnerability in=
Zip::Entry#extract that fails to properly validate extraction paths using = prefix comparison without trailing separators. Attackers can craft archive = entries with names like ../upload_backup/owned.sh to write files outside th=
e intended extraction directory into sibling paths sharing the destination = prefix.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85396" target=3D= "_blank" rel=3D"noopener">CVE-2026-85396</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api= /servers/:name endpoints in MCPHub create/update MCP server configurations = and then immediately spawn the configured stdio process via child_process.s= pawn. Authentication is required, but there is no authorization check restr= icting these endpoints to admins, and there is no allowlist/sanitization on=
the command and args fields. As a result, any authenticated non-admin user=
can submit a server configuration with command:"/bin/sh" (or any other bin= ary) and arbitrary args, causing MCPHub to execute the attacker-controlled = process as the MCPHub server's OS user (commonly root in the published Dock=
er image and in npx/systemd deployments). This issue has been patched in ve= rsion 0.12.15.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79748" target=3D= "_blank" rel=3D"noopener">CVE-2026-79748</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config end= point (handler updateSystemConfig) performs no authorization check. It is p= rotected only by the app-wide authentication middleware and a rate limiter =
- it never inspects req.user.isAdmin. This issue has been patched in versio=
n 1.0.29.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79744" target=3D= "_blank" rel=3D"noopener">CVE-2026-79744</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.31, when a bearer key with accessType: = 'servers' (or 'custom') is used against a group route, isBearerKeyAllowedFo= rRequest grants access to the entire group as long as any single server in = that group appears in the key's allowedServers list - not only when every s= erver the key is scoped to matches, and critically, without ever re-checkin=
g allowedServers again once the group-level connection is authorized. A key=
explicitly scoped to one specific server therefore also grants full access=
to every other server that happens to share a group with it, including ser= vers the key was never authorized for. This issue has been patched in versi=
on 1.0.31.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79746" target=3D= "_blank" rel=3D"noopener">CVE-2026-79746</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.32, the built-in prompt and resource co= ntrollers perform no role checking. The mutating POST/PUT /api/prompts* and=
POST/PUT /api/resources* routes are attached to the authenticated router w= ith no admin gate, and the handlers never read req.user. The DAO singletons=
they write are consulted first - ahead of any connected MCP server - for e= very session in handleGetPromptRequest / handleReadResourceRequest. A non-a= dmin can therefore create, overwrite, and shadow global prompt templates an=
d resources that all other users are served. The scored impact is the unaut= horized integrity violation (creation/tampering/shadowing of globally-serve=
d records); stored prompt injection into other users' LLM sessions is a dow= nstream consequence of that tampering. This issue has been patched in versi=
on 1.0.32.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79745" target=3D= "_blank" rel=3D"noopener">CVE-2026-79745</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.32, an authenticated non-admin user can=
register a server pointing at an arbitrary URL and make the hub issue serv= er-side requests to it, with no egress filtering (no block of loopback / RF= C1918 / link-local 169.254.0.0/16). Via the OpenAPI proxy path the response=
body is returned to the caller (full, reflected SSRF); via the SSE/streama= ble-http transport the request is sent blind. This issue has been patched i=
n version 1.0.32.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79747" target=3D= "_blank" rel=3D"noopener">CVE-2026-79747</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to se= rvers they own (list views and config edits enforce ownership), but the too= l-execution API does not. Any authenticated non-admin user can invoke tools=
on MCP servers owned by other users - servers they cannot even see in GET = /api/servers. Because connected MCP servers carry real capability (filesyst= em, HTTP fetch, cloud APIs with the owner's keys), this is cross-tenant com= promise: demonstrated arbitrary host file read (/etc/passwd, another user's=
secrets) and SSRF. This issue has been patched in version 1.0.30.</td> <td>2026-08-31</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79750" target=3D= "_blank" rel=3D"noopener">CVE-2026-79750</a></td>
</tr>
<td class=3D"vendor-product">Saturday Drive--Ninja Forms - Layout & Sty= les</td>
<td>Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styl=
es <=3D 3.0.31 versions.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81772" target=3D= "_blank" rel=3D"noopener">CVE-2026-81772</a></td>
</tr>
<td class=3D"vendor-product">Saturday Drive--Ninja Forms File Uploads Exten= sion</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads = Extension <=3D 3.3.26 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81773" target=3D= "_blank" rel=3D"noopener">CVE-2026-81773</a></td>
</tr>
<td class=3D"vendor-product">SciPhi-AI--R2R</td>
<td>R2R through 3.6.6 contains a stacked SQL injection vulnerability that a= llows unauthenticated attackers to execute arbitrary SQL statements by mani= pulating the index name parameter in the vector index creation endpoint. Th=
e index name is interpolated directly into a CREATE INDEX statement via str= ing formatting without identifier quoting or allowlist validation, enabling=
arbitrary DDL and DML execution through semicolon-separated statements und=
er the PostgreSQL superuser account.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82526" target=3D= "_blank" rel=3D"noopener">CVE-2026-82526</a></td>
</tr>
<td class=3D"vendor-product">SciPhi-AI--R2R</td>
<td>R2R through 3.6.6 contains a SQL injection vulnerability that allows un= authenticated attackers to inject SQL predicates into the chunks search que=
ry by manipulating the filter key parameter in the retrieval search endpoin=
t. Attackers can exploit the direct interpolation of filter keys into the S=
QL WHERE clause without parameterization or escaping to perform time-based = and boolean-based data exfiltration from the application database.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82527" target=3D= "_blank" rel=3D"noopener">CVE-2026-82527</a></td>
</tr>
<td class=3D"vendor-product">scrapy--scrapy</td>
<td>Scrapy is a high-level web crawling and scraping framework for Python. = Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3Downl= oadHandler converts an S3-scheme bucket and key request into a plaintext HT=
TP request to the corresponding S3 endpoint unless request.meta["is_secure"=
] is explicitly enabled, then signs and sends the plaintext request with co= nfigured AWS credentials. A network attacker who can observe traffic betwee=
n Scrapy and S3 can read the bucket and key path, AWS Authorization header,=
X-Amz-Security-Token when temporary credentials are used, S3 object conten= ts, and S3 response headers. An active man-in-the-middle attacker can also = modify the plaintext S3 response body, status code, and headers before Scra=
py processes them, causing scraped-data poisoning, poisoned exports, HTTP c= ache poisoning when caching is enabled, or influence over later crawl targe=
ts through forged redirects or attacker-controlled links. Users making S3-s= cheme requests with AWS credentials are affected. This issue is fixed in ve= rsion 2.17.0.</td>
<td>2026-09-01</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84366" target=3D= "_blank" rel=3D"noopener">CVE-2026-84366</a></td>
</tr>
<td class=3D"vendor-product">scriptsbundle--Nokri Job Board WordPress Theme= </td>
<td>The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Pr= ivilege Escalation via Account Takeover in all versions up to, and includin=
g, 1.6.6. This is due to insufficient reset token validation in the `nokri_= reset_password()` function, which allows empty attacker-supplied reset toke=
ns to match empty or unset `sb_password_forget_token` user meta values. Thi=
s makes it possible for unauthenticated attackers to reset the password of = any user, including administrators, and gain access to their account.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18550" target=3D= "_blank" rel=3D"noopener">CVE-2026-18550</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A vulnerability was determined in SeaCMS up to 13.6. Affected is the fu= nction parseIf of the file search.php of the component Template Engine. Thi=
s manipulation of the argument searchtype causes code injection. It is poss= ible to initiate the attack remotely. The exploit has been publicly disclos=
ed and may be utilized.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82598" target=3D= "_blank" rel=3D"noopener">CVE-2026-82598</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A security flaw has been discovered in SeaCMS up to 13.6. Affected by t= his issue is some unknown functionality of the file /zyapi.php?ac=3Dvideoli= st. Performing a manipulation of the argument ids results in sql injection.=
The attack can be initiated remotely. The exploit has been released to the=
public and may be used for attacks.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82600" target=3D= "_blank" rel=3D"noopener">CVE-2026-82600</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A security vulnerability has been detected in SeaCMS up to 13.6. This i= mpacts the function parseIf of the file seacms_locoy_news.php of the compon= ent Locoy Collector. The manipulation of the argument pwd leads to code inj= ection. The attack may be initiated remotely. The exploit has been disclose=
d publicly and may be used.</td>
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85137" target=3D= "_blank" rel=3D"noopener">CVE-2026-85137</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A vulnerability was detected in SeaCMS up to 13.6. Affected is the func= tion addslashes of the file weixin/index.php of the component WeChat Module=
. The manipulation of the argument Content results in sql injection. The at= tack may be launched remotely. The exploit is now public and may be used.</=
<td>2026-09-03</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85138" target=3D= "_blank" rel=3D"noopener">CVE-2026-85138</a></td>
</tr>
<td class=3D"vendor-product">shabti--Frontend Admin by DynamiApps</td>
<td>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to = arbitrary file deletion due to insufficient file path validation in the mov= e_folders function in all versions up to, and including, 3.29.12. This make=
s it possible for unauthenticated attackers to delete arbitrary files on th=
e server, which can easily lead to remote code execution when the right fil=
e is deleted (such as wp-config.php). This is exploitable without authentic= ation when a form is configured with public visibility (who_can_see=3D'all'=
), as the required nonce is publicly obtainable from the rendered form.</td=
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19952" target=3D= "_blank" rel=3D"noopener">CVE-2026-19952</a></td>
</tr>
<td class=3D"vendor-product">Sheikh Heera--Agentimus AI SEO, llms.txt &=
MCP for AI Agents</td>
<td>Subscriber Broken Access Control in Agentimus - AI SEO, llms.txt &a= mp; MCP for AI Agents <=3D 1.51.0 versions.</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84779" target=3D= "_blank" rel=3D"noopener">CVE-2026-84779</a></td>
</tr>
<td class=3D"vendor-product">Shenzhen Jixiang Tengda Technology Co., Ltd--T= enda A18</td>
<td>Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co.=
, Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrar=
y code via the fromSetCmdlineRun function</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51934" target=3D= "_blank" rel=3D"noopener">CVE-2026-51934</a></td>
</tr>
<td class=3D"vendor-product">ShopEx--ECShop</td>
<td>A weakness has been identified in ShopEx ECShop up to 2.5.1. This affec=
ts the function check_img_type of the file admin/pack.php. Executing a mani= pulation of the argument pack_img can lead to unrestricted upload. It is po= ssible to launch the attack remotely. The exploit has been made available t=
o the public and could be used for attacks. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82921" target=3D= "_blank" rel=3D"noopener">CVE-2026-82921</a></td>
</tr>
<td class=3D"vendor-product">ShopEx--ECShop</td>
<td>A security vulnerability has been detected in ShopEx ECShop up to 2.5.1=
. This vulnerability affects the function flow_update_cart of the file /flo= w.php?step=3Dupdate_cart. The manipulation of the argument rec_id leads to = sql injection. The attack can be initiated remotely. The exploit has been d= isclosed publicly and may be used. The vendor was contacted early about thi=
s disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82922" target=3D= "_blank" rel=3D"noopener">CVE-2026-82922</a></td>
</tr>
<td class=3D"vendor-product">Siemens--Mendix SAML (Mendix 10 compatible)</t=
<td>A vulnerability has been identified in Mendix SAML (Mendix 10 compatibl=
e) (All versions < V4.2.3), Mendix SAML (Mendix 11 compatible) (All vers= ions < V4.2.3), Mendix SAML (Mendix 9.24 compatible) (All versions < = V3.6.27). Affected versions of the module do not properly validate the SAML=
response signature. This could allow unauthenticated remote attackers to h= ijack an account (session) in specific SSO configurations.</td> <td>2026-09-03</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80465" target=3D= "_blank" rel=3D"noopener">CVE-2026-80465</a></td>
</tr>
<td class=3D"vendor-product">signum-network--signum-node</td>
<td>Signum Node is a HDD-mined cryptocurrency using an energy efficient and=
fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.=
9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to = receive an arbitrarily inflated block reward by crafting a block with a neg= ative totalFeeCashBackNqt value. The vulnerability was introduced when the = SMART_FEES hardfork (block ~1,029,000) enabled fee cash-back and burn accou= nting without overflow protection. This issue has been patched in version 3= .9.9.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48486" target=3D= "_blank" rel=3D"noopener">CVE-2026-48486</a></td>
</tr>
<td class=3D"vendor-product">Silk Themes--Newspapers X</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Sil=
k Themes Newspapers X allows Malicious Software Implanted. This issue affec=
ts Newspapers X: from 1.0.46 through 1.0.48.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81779" target=3D= "_blank" rel=3D"noopener">CVE-2026-81779</a></td>
</tr>
<td class=3D"vendor-product">silverplugins217--Calculation For Contact Form=
7</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact F= orm 7 <=3D 1.0 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81300" target=3D= "_blank" rel=3D"noopener">CVE-2026-81300</a></td>
</tr>
<td class=3D"vendor-product">Simple Ajax Chat--Simple Ajax Chat</td>
<td>The Simple Ajax Chat WordPress plugin before 20260827 does not escape c= hat message content before rendering it, allowing unauthenticated users to = inject arbitrary HTML attributes into the page and run scripts in the brows=
er of anyone viewing the chat, including administrators.</td> <td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81807" target=3D= "_blank" rel=3D"noopener">CVE-2026-81807</a></td>
</tr>
<td class=3D"vendor-product">SiteGround--SiteGround Security</td> <td>Unauthenticated Bypass Vulnerability in SiteGround Security <=3D 1.6=
.6 versions.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82228" target=3D= "_blank" rel=3D"noopener">CVE-2026-82228</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan before v3.8.2 contains a stored cross-site scripting vulnerabili=
ty in asset serving due to an incomplete extension blocklist that misses sc= ript-capable file types. Attackers can upload files with extensions like .x= ht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable media types and = execute JavaScript to steal API tokens and compromise workspaces.</td> <td>2026-09-02</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84803" target=3D= "_blank" rel=3D"noopener">CVE-2026-84803</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan before v3.8.2 logs API tokens from query parameters in plaintext=
to an accessible log file when full-text search requests exceed timing thr= esholds. Authenticated attackers can read the log file via the getFile endp= oint to recover admin API tokens and gain permanent administrative access.<=
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85174" target=3D= "_blank" rel=3D"noopener">CVE-2026-85174</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan versions <=3D 3.8.1 (fixed in v3.8.2) contain an incomplete b= locklist in the IsForbiddenAbsPath() function (kernel/util/path_guard.go), = which only blocks conf/conf.json by exact match and does not restrict the T=
LS private key (conf/key.pem) or CA private key (conf/ca.key) stored in the=
same conf/ directory. Because the getFile handler skips the blocklist for = RoleAdministrator and all authenticated users receive RoleAdministrator in = v3.8.1, any user (or any client on a default no-auth-code instance) can ret= rieve these private keys via POST /api/file/getFile. On deployments with TL=
S enabled, this allows decryption of captured HTTPS traffic (key.pem) and f= orging of certificates trusted by clients that imported SiYuan's CA (ca.key= ).</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85175" target=3D= "_blank" rel=3D"noopener">CVE-2026-85175</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan before v3.8.2 contains a denial of service vulnerability in the = unauthenticated /api/system/uiproc endpoint that accepts and retains attack= er-controlled process identifiers without size limits or authentication. At= tackers can send repeated requests with unique identifiers to exhaust proce=
ss memory and degrade service availability.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85581" target=3D= "_blank" rel=3D"noopener">CVE-2026-85581</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan versions before v3.8.2 contain a denial of service vulnerability=
in the publish-service Basic Auth throttle that stores failed-attempt stat=
e using attacker-controlled usernames without enforcing capacity limits or = eviction policies. Unauthenticated attackers can submit repeated authentica= tion requests with unique invalid usernames to exhaust memory and increase = synchronization overhead, degrading service availability.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85584" target=3D= "_blank" rel=3D"noopener">CVE-2026-85584</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan before v3.8.2 contains an unbounded resource consumption vulnera= bility in the request-concurrency middleware that retains mutex entries for=
every unique request path without eviction. Unauthenticated attackers can = send numerous unique request paths to permanently increase process memory a=
nd synchronization overhead, degrading availability.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85585" target=3D= "_blank" rel=3D"noopener">CVE-2026-85585</a></td>
</tr>
<td class=3D"vendor-product">Slack Nebula mesh VPN--Slack Nebula mesh VPN<b= r>=C2=A0</td>
<td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. P= rior to version 0.7.1, revocation is the only in-band mechanism that isolat=
es a compromised/offboarded host from a Nebula mesh. Because the blocklist = never reaches any peer's config.yml, a Blocked host retains full overlay re= achability to every peer under its CA (and internal services on the mesh) f=
or up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.key+= host.crt can run stock slackhq/nebula directly, ignore the agent's 403/410 = poll responses, and stay connected after the operator revokes the host. Ope= rator-visible state (UI shows blocked, audit log records it) is misleading.=
This issue has been patched in version 0.7.1.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61699" target=3D= "_blank" rel=3D"noopener">CVE-2026-61699</a></td>
</tr>
<td class=3D"vendor-product">Slack--Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. F= rom version 0.6.0 to before version 0.7.2, non-admin operators (role user) = can set allow_private: true on their own managed webhook subscription (POST= /PATCH /api/v1/webhook-subscriptions). No admin check exists on this field.=
At delivery time, allow_private switches the dispatcher to an unguarded HT=
TP client, bypassing the private/loopback/link-local SSRF guard - letting a=
low-privilege operator make the server request internal addresses. This is= sue has been patched in version 0.7.2.</td>
<td>2026-09-04</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63464" target=3D= "_blank" rel=3D"noopener">CVE-2026-63464</a></td>
</tr>
<td class=3D"vendor-product">Snowflake--Snowflake Connector for Python</td> <td>Improper OCSP response validation in the Snowflake Python, Go, JDBC, an=
d Node.js drivers allowed a revoked TLS certificate to be accepted as valid=
, because OCSP responses were not reliably bound to the certificate being v= alidated and definitive verification failures were treated as transient. A = man-in-the-middle attacker holding a revoked certificate and its private ke=
y for a Snowflake or stage hostname could cause the driver to establish a T=
LS session to the attacker-controlled endpoint anyway, allowing the attacke=
r to read and modify data transmitted within that connection. Successful ex= ploitation requires that on-path position and the corresponding private key=
, and impact is limited to data carried within the intercepted connection. = The fix is available in the patched versions listed above. Users must manua= lly upgrade.</td>
<td>2026-09-04</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85525" target=3D= "_blank" rel=3D"noopener">CVE-2026-85525</a></td>
</tr>
<td class=3D"vendor-product">Soarkey--StudentManagement</td>
<td>A weakness has been identified in Soarkey StudentManagement and =C3=A5= =C2=AD=C2=A6=C3=A7=E2=80=9D=C5=B8=C3=A4=C2=BF=C2=A1=C3=A6=C2=81=C2=AF=C3=A7= =C2=AE=C2=A1=C3=A7=C2=90=E2=80=A0=C3=A7=C2=B3=C2=BB=C3=A7=C2=BB=C5=B8 up to=
e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminD= ao.doGet of the file code/src/service/AdminDao.java of the component Admini= strative Servlet. Executing a manipulation of the argument action can lead =
to authorization bypass. It is possible to launch the attack remotely. The = exploit has been made available to the public and could be used for attacks=
. The project was informed of the problem early through an issue report but=
has not responded yet.</td>
<td>2026-08-31</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82621" target=3D= "_blank" rel=3D"noopener">CVE-2026-82621</a></td>
</tr>
<td class=3D"vendor-product">Social Media Share Buttons & Social Sharin=
g Icons--Social Media Share Buttons & Social Sharing Icons</td>
<td>The Social Media Share Buttons & Social Sharing Icons WordPress plu= gin before 3.0.1 does not properly escape a value taken from the incoming r= equest before outputting it in an inline JavaScript event handler, leading =
to Reflected Cross-Site Scripting which is triggered when a user interacts = with the affected button. Exploitation requires the Social Media Share Butt= ons & Social Sharing Icons WordPress plugin before 3.0.1 to be running =
a non-default icon display configuration.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19723" target=3D= "_blank" rel=3D"noopener">CVE-2026-19723</a></td>
</tr>
<td class=3D"vendor-product">SolidInvoice--SolidInvoice</td>
<td>SolidInvoice is an open-source invoicing platform. Prior to version 3.0= .1, the `DataGrid` LiveComponent deserializes a `context` prop value using = PHP's `unserialize()` after receiving it from the client. Because the prop =
is marked `writable: true`, an authenticated attacker can supply an arbitra=
ry PHP serialized payload. Version 3.0.1 fixes the issue.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61686" target=3D= "_blank" rel=3D"noopener">CVE-2026-61686</a></td>
</tr>
<td class=3D"vendor-product">sonaar--MP3 Audio Player for Music, Radio &=
; Podcast by Sonaar</td>
<td>Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Musi=
c, Radio & Podcast by Sonaar <=3D 5.13.1 versions.</td> <td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81289" target=3D= "_blank" rel=3D"noopener">CVE-2026-81289</a></td>
</tr>
<td class=3D"vendor-product">sonicwall -- sma8200v</td>
<td>A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance=
Work Place interface due to an unintended alternate access path. A remote = unauthenticated attacker could potentially exploit this vulnerability to ga=
in unauthorized access to sensitive functionality and perform unauthorized = operations.</td>
<td>2026-09-01</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83548" target=3D= "_blank" rel=3D"noopener">CVE-2026-83548</a></td>
</tr>
<td class=3D"vendor-product">sonicwall -- sma8200v</td>
<td>Post-authentication Improper Neutralization of Special Elements used in=
an OS Command ('OS Command Injection') vulnerability has been identified i=
n the SMA1000 Appliance Management Console (AMC) which in specific conditio=
ns could potentially enable a remote authenticated attacker as administrato=
r to execute arbitrary OS commands, resulting in remote code execution.</td=
<td>2026-09-01</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83549" target=3D= "_blank" rel=3D"noopener">CVE-2026-83549</a></td>
</tr>
<td class=3D"vendor-product">SonicWall--Network Security Manager<br>=C2=A0<=
<td>An Improper Neutralization of Special Elements used in an OS Command ('=
OS Command Injection') vulnerability in the SonicWall Network Security Mana= ger (NSM) On-Prem Management interface allows an authenticated attacker wit=
h SuperAdmin privileges to inject arbitrary commands that are executed on t=
he underlying host, resulting in remote code execution.</td> <td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78327" target=3D= "_blank" rel=3D"noopener">CVE-2026-78327</a></td>
</tr>
<td class=3D"vendor-product">SonicWall--Network Security Manager<br>=C2=A0<=
<td>A missing authorization vulnerability in the SonicWall Network Security=
Manager (NSM) On-Prem Management interface allows a lower-privileged Admin=
user to escalate privileges to SuperAdmin.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78328" target=3D= "_blank" rel=3D"noopener">CVE-2026-78328</a></td>
</tr>
<td class=3D"vendor-product">SonicWall--Network Security Manager<br>=C2=A0<=
<td>A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM=
) On-Prem file upload and archive processing functionality allows an attack=
er to extract files outside the intended destination directory using a spec= ially crafted archive.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81939" target=3D= "_blank" rel=3D"noopener">CVE-2026-81939</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem</td>
<td>A security flaw has been discovered in SourceCodester Class and Exam Ti= metabling System 1.0. This vulnerability affects unknown code of the file /= admin/session.php. The manipulation of the argument ID results in missing a= uthorization. The attack can be executed remotely. The exploit has been rel= eased to the public and may be used for attacks.</td>
<td>2026-09-04</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85512" target=3D= "_blank" rel=3D"noopener">CVE-2026-85512</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0</td>
<td>A vulnerability was determined in SourceCodester Class and Exam Timetab= ling System 1.0. Affected is the function mysqli_query of the file /admin/m= odal_add_product.php. Executing a manipulation of the argument fname can le=
ad to sql injection. The attack can be executed remotely. The exploit has b= een publicly disclosed and may be utilized.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86224" target=3D= "_blank" rel=3D"noopener">CVE-2026-86224</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0</td>
<td>A vulnerability was identified in SourceCodester Class and Exam Timetab= ling System 1.0. Affected by this vulnerability is the function mysqli_quer=
y of the file /admin/modal_add_room.php. The manipulation of the argument r= oom_name leads to sql injection. The attack is possible to be carried out r= emotely. The exploit is publicly available and might be used.</td> <td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86225" target=3D= "_blank" rel=3D"noopener">CVE-2026-86225</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0<br>=C2=A0</td>
<td>A vulnerability was detected in SourceCodester Class and Exam Timetabli=
ng System 1.0. The affected element is the function mysqli_query of the fil=
e /admin/modal_add_course.php. The manipulation of the argument course resu= lts in sql injection. The attack can be launched remotely. The exploit is n=
ow public and may be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86220" target=3D= "_blank" rel=3D"noopener">CVE-2026-86220</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0<br>=C2=A0</td>
<td>A flaw has been found in SourceCodester Class and Exam Timetabling Syst=
em 1.0. The impacted element is the function mysqli_query of the file /admi= n/modal_add_course1.php. This manipulation of the argument course causes sq=
l injection. The attack may be initiated remotely. The exploit has been pub= lished and may be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86221" target=3D= "_blank" rel=3D"noopener">CVE-2026-86221</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0<br>=C2=A0</td>
<td>A vulnerability has been found in SourceCodester Class and Exam Timetab= ling System 1.0. This affects the function mysqli_query of the file /admin/= modal_add_course2.php. Such manipulation of the argument course leads to sq=
l injection. The attack may be launched remotely. The exploit has been disc= losed to the public and may be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86222" target=3D= "_blank" rel=3D"noopener">CVE-2026-86222</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Class and Exam Timetabling Sys= tem 1.0<br>=C2=A0</td>
<td>A vulnerability was found in SourceCodester Class and Exam Timetabling = System 1.0. This impacts the function mysqli_query of the file /admin/modal= _add_coursea.php. Performing a manipulation of the argument course results =
in sql injection. Remote exploitation of the attack is possible. The exploi=
t has been made public and could be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86223" target=3D= "_blank" rel=3D"noopener">CVE-2026-86223</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Exam Timetabling System 1.0</t=
<td>A weakness has been identified in SourceCodester Class and Exam Timetab= ling System 1.0. Affected is an unknown function of the file /delete_user.p= hp. This manipulation of the argument ID causes sql injection. The attack m=
ay be initiated remotely. The exploit has been made available to the public=
and could be used for attacks.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86209" target=3D= "_blank" rel=3D"noopener">CVE-2026-86209</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Exam Timetabling System 1.0<br= >=C2=A0</td>
<td>A security flaw has been discovered in SourceCodester Class and Exam Ti= metabling System 1.0. This impacts an unknown function of the file /delete_= teacher.php. The manipulation of the argument ID results in sql injection. = The attack can be launched remotely. The exploit has been released to the p= ublic and may be used for attacks.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86208" target=3D= "_blank" rel=3D"noopener">CVE-2026-86208</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Exam Timetabling System 1.0<br= >=C2=A0</td>
<td>A security vulnerability has been detected in SourceCodester Class and = Exam Timetabling System 1.0. Affected by this vulnerability is an unknown f= unctionality of the file /delete_user_account.php. Such manipulation of the=
argument ID leads to sql injection. The attack may be launched remotely. T=
he exploit has been disclosed publicly and may be used.</td> <td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86210" target=3D= "_blank" rel=3D"noopener">CVE-2026-86210</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Online Voting System 1.0</td> <td>A vulnerability was found in SourceCodester Online Voting System 1.0. T=
he impacted element is an unknown function of the file /ajax.php?action=3Dd= elete_category. Performing a manipulation of the argument ID results in sql=
injection. Remote exploitation of the attack is possible. The exploit has = been made public and could be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86161" target=3D= "_blank" rel=3D"noopener">CVE-2026-86161</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Online Voting System 1.0</td> <td>A vulnerability was determined in SourceCodester Online Voting System 1= .0. This affects an unknown function of the file /ajax.php?action=3Dlogin. = Executing a manipulation of the argument Username can lead to sql injection=
. The attack can be executed remotely. The exploit has been publicly disclo= sed and may be utilized.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86162" target=3D= "_blank" rel=3D"noopener">CVE-2026-86162</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Online Voting System 1.0<br>= =C2=A0</td>
<td>A flaw has been found in SourceCodester Online Voting System 1.0. Impac= ted is an unknown function of the file /ajax.php?action=3Dsave_user. This m= anipulation of the argument ID causes sql injection. The attack may be init= iated remotely. The exploit has been published and may be used.</td> <td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86159" target=3D= "_blank" rel=3D"noopener">CVE-2026-86159</a></td>
</tr>
<td class=3D"vendor-product">SourceCodester--Online Voting System 1.0<br>= =C2=A0</td>
<td>A vulnerability has been found in SourceCodester Online Voting System 1= .0. The affected element is an unknown function of the file /ajax.php?actio= n=3Ddelete_voting. Such manipulation of the argument ID leads to sql inject= ion. The attack may be launched remotely. The exploit has been disclosed to=
the public and may be used.</td>
<td>2026-09-06</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86160" target=3D= "_blank" rel=3D"noopener">CVE-2026-86160</a></td>
</tr>
<td class=3D"vendor-product">SpartnerNL--Laravel-Excel</td>
<td>Laravel Excel provides supercharged Excel exports and imports in Larave=
l. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Fil= es\Disk::copy() method resolves the caller-controlled $destination supplied=
through Excel::store(), $export->store(), or storeExcel() against the p= rocess working directory with realpath() instead of the configured filesyst=
em disk. If the path names an existing writable file, Disk::copy() opens it=
with fopen() in rb+ mode and uses stream_copy_to_stream(), bypassing Flysy= stem path confinement and allowing an attacker whose application input cont= rols the export path to overwrite arbitrary existing files with export cont= ent. The rb+ behavior creates a non-truncating overwrite and trailing bytes=
when the new export is shorter, and overwriting an executable PHP file can=
lead to remote code execution. This issue is fixed in version 3.1.70.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84374" target=3D= "_blank" rel=3D"noopener">CVE-2026-84374</a></td>
</tr>
<td class=3D"vendor-product">SQL Chat--SQL Chat<br>=C2=A0</td>
<td>SQL Chat contains four unauthenticated API endpoints that accept client= -supplied database connection parameters and execute arbitrary SQL queries = against attacker-specified hosts. Attackers can connect to internal databas= es, execute SQL commands, enumerate schemas, and pivot into the server's ne= twork without authentication.</td>
<td>2026-09-05</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86123" target=3D= "_blank" rel=3D"noopener">CVE-2026-86123</a></td>
</tr>
<td class=3D"vendor-product">StellarWP--LearnDash LMS</td>
<td>The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted Fi=
le Type Upload in versions up to and including 5.1.5. This is due to insuff= icient input validation in the 'learndash_fileupload_process' function, whi=
ch iterates through an entire array and validates only the first file. This=
makes it possible for authenticated attackers, with subscriber-level acces=
s and above who are enrolled in a course with assignment uploads enabled, t=
o upload arbitrary disallowed files, including PHP files, to the server's w= p-content/uploads/learndash/assignments/ directory. The uploaded files can = only be used for Remote Code Execution if default server configurations hav=
e been changed to allow for execution.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12483" target=3D= "_blank" rel=3D"noopener">CVE-2026-12483</a></td>
</tr>
<td class=3D"vendor-product">Studio-42--elFinder</td>
<td>elFinder is an open-source file manager for web, written in JavaScript = using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.clas= s.php can bypass server-side request forgery protections when PHP cURL is u= navailable because validate_address() validates $info['ip'], but get_remote= _contents() selects fsock_get_contents(), which connects to $arr['host'] an=
d performs a second DNS resolution. An attacker able to submit a URL upload=
can use DNS rebinding to have the first resolution return a public address=
and the connection resolution return a loopback or private address, causin=
g the internal HTTP response body to be stored as an uploaded file and made=
readable through elFinder. After a successful fetch, get_headers($url, tru=
e) separately requests the original hostname without reusing the validated = and pinned connection, creating an additional blind server-side request for= gery path even when curl_get_contents() is selected. This issue is fixed in=
version 2.1.70.</td>
<td>2026-08-31</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81889" target=3D= "_blank" rel=3D"noopener">CVE-2026-81889</a></td>
</tr>
<td class=3D"vendor-product">Studio-42--elFinder</td>
<td>elFinder is an open-source file manager for web, written in JavaScript = using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolume= Driver.class.php calls mimetypeInternalDetect() without passing the result = through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 ex= tensions are absent from mime.types, the staticMimeMap entries that map the=
m to text/x-php are not applied, and allowPutMime() permits extraction even=
when uploadDeny blocks text/x-php. An attacker with ZIP upload permission = can extract PHP-executable files into a web-accessible files/ directory and=
achieve remote code execution when the server executes those extensions. T= his issue is fixed in version 2.1.70.</td>
<td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81891" target=3D= "_blank" rel=3D"noopener">CVE-2026-81891</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A flaw was found in Rancher Manager. The GlobalRole controller derived = the target ClusterRole name from the user-settable `authz.management.cattle= .io/cr-name` annotation and overwrote that object's rules without verifying=
ownership. A user with delegated GlobalRole create or update permission co= uld point the annotation at any existing ClusterRole, such as `cluster-admi= n`, and revoke the permissions of every principal bound to it. The change p= ersists after the malicious GlobalRole is deleted. This issue affects Ranch= er: before 2.15.1.</td>
<td>2026-09-03</td>
<td>8.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71404" target=3D= "_blank" rel=3D"noopener">CVE-2026-71404</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A flaw was found in Rancher Manager. Project Secrets were propagated in=
to a namespace based only on its `field.cattle.io/projectId` annotation, wi= thout verifying that the referenced project belonged to the same downstream=
cluster. A user able to create namespaces on one cluster could set the ann= otation to a project ID from another cluster and have that project's secret=
s copied into a namespace under their control. This issue affects Rancher: = before 2.15.1.</td>
<td>2026-09-03</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75033" target=3D= "_blank" rel=3D"noopener">CVE-2026-75033</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A flaw was found in Rancher Manager. The SAML assertion replay protecti=
on introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs=
in a per-process cache, so each replica only detected replays that reached=
the same pod. In a high-availability deployment, an attacker holding a cap= tured assertion could replay it once against every other replica to obtain = additional authenticated sessions as the victim. This issue affects Rancher=
: before 2.15.1.</td>
<td>2026-09-03</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75034" target=3D= "_blank" rel=3D"noopener">CVE-2026-75034</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A flaw was found in Rancher Manager. When a non-administrative caller s= upplied a label selector naming a different user, the ext.cattle.io/v1 Toke=
n store dropped its internal owner filter instead of returning an empty res= ult. Any authenticated user could therefore list and watch every other user=
's tokens, disclosing token metadata and the stored salted hash of the bear=
er token. This issue affects Rancher: before 2.15.1.</td>
<td>2026-09-03</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75035" target=3D= "_blank" rel=3D"noopener">CVE-2026-75035</a></td>
</tr>
<td class=3D"vendor-product">SUSE--yast2-auth-client</td>
<td>A OS command injection vulnerability in yast2-auth-client allows an att= acker who controls Active Directory configuration values to execute arbitra=
ry commands as root on the configured host. Auth::AuthConf in src/lib/auth/= authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads=
testjoin invocations by interpolating configuration values into a single c= ommand string and passing that string to Open3.popen2 / Open3.capture2, whi=
ch causes Ruby to run it through /bin/sh. The Organizational Unit (ou), dns= hostname, AD user name and AD domain name values are neither validated nor = shell-quoted.</td>
<td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59681" target=3D= "_blank" rel=3D"noopener">CVE-2026-59681</a></td>
</tr>
<td class=3D"vendor-product">SUSE--yast2-samba-client</td>
<td>Improper neutralization of special elements used in an OS command in ya= st2-samba-client allows an attacker who controls the content of an Active D= irectory directory tree - a rogue domain controller, or a directory user de= legated the right to create objects - to execute arbitrary commands as root=
on a machine being joined to that domain. This issue affects yast2-samba-c= lient through 5.0.4.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-25706" target=3D= "_blank" rel=3D"noopener">CVE-2026-25706</a></td>
</tr>
<td class=3D"vendor-product">SUSE--yast2-users</td>
<td>An OS command injection vulnerability was found in yast2-users. When di= splaying the "Password Settings" tab of a user, get_password_term() in src/= include/users/dialogs.rb read the shadowLastChange and shadowExpire fields = with GetString(), which performs no numeric validation, and passed the resu= lting string to format_days_after_epoch(). That helper interpolated the val=
ue into a shell command executed via Ruby backticks without quoting or esca= ping. Impact: an administrator who manages users against an external/federa= ted LDAP directory via `yast2 users` triggers root command execution the mo= ment they view or edit that particular user's "Password Settings" tab. No "= join domain" or trust setup is required, just browsing/editing one user ent= ry. This issue affects yast2-users through 5.0.8.</td>
<td>2026-09-01</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59680" target=3D= "_blank" rel=3D"noopener">CVE-2026-59680</a></td>
</tr>
<td class=3D"vendor-product">svg--svgo</td>
<td>SVGO, short for SVG Optimizer, is a Node.js library and command-line ap= plication for optimizing SVG files. From version 1.0.0 until versions 2.8.4=
, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElem= ent in versions 2 and 3, incompletely filters executable links in plugins/r= emoveScripts.js and lib/svgo/tools.js. The plugin does not recognize namesp= ace-prefixed SVG anchor elements such as svg:a with href or namespaced *:hr=
ef values, and it does not remove ASCII tab, line-feed, or carriage-return = characters before checking URL schemes. Browsers remove those characters be= fore parsing a scheme, allowing an executable link to pass the plugin's che= ck. When an application processes attacker-controlled SVG input and serves = the result in an active browser context, a victim who activates the survivi=
ng link can execute script in the SVG's origin, expose data, modify content=
, or perform actions as the victim. This issue is fixed in versions 2.8.4, = 3.3.5, and 4.1.0.</td>
<td>2026-09-01</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84370" target=3D= "_blank" rel=3D"noopener">CVE-2026-84370</a></td>
</tr>
<td class=3D"vendor-product">Syed Balkhi--Charitable</td>
<td>Subscriber SQL Injection in Charitable <=3D 1.8.12.1 versions.</td> <td>2026-08-31</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81287" target=3D= "_blank" rel=3D"noopener">CVE-2026-81287</a></td>
</tr>
<td class=3D"vendor-product">TAC Information Services Internal and External=
Trade Inc.--GOLDENHORN ONEIT</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in TAC Information Services Internal and Extern=
al Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affec=
ts GOLDENHORN ONEIT: before G=C3=83=C2=B6beklitepe.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18198" target=3D= "_blank" rel=3D"noopener">CVE-2026-18198</a></td>
</tr>
<td class=3D"vendor-product">Tailored Media--Tailored Tools</td> <td>Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <=3D 3.= 0.2 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81765" target=3D= "_blank" rel=3D"noopener">CVE-2026-81765</a></td>
</tr>
<td class=3D"vendor-product">TBC Technology Inc.--KitLogistic</td>
<td>Missing Authorization vulnerability in TBC Technology Inc. KitLogistic = allows Accessing Functionality Not Properly Constrained by ACLs. This issue=
affects KitLogistic: before v2.2.2.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19616" target=3D= "_blank" rel=3D"noopener">CVE-2026-19616</a></td>
</tr>
<td class=3D"vendor-product">TBTAK BLGEM Software Technologies Research Ins= titute--Pardus Boot Repair</td>
<td>Improper neutralization of special elements used in an OS command ('OS = command injection') vulnerability in T=C3=83=C5=93B=C3=84=C2=B0TAK B=C3=84= =C2=B0LGEM Software Technologies Research Institute Pardus Boot Repair allo=
ws OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 = before 1.0.8.</td>
<td>2026-08-31</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19702" target=3D= "_blank" rel=3D"noopener">CVE-2026-19702</a></td>
</tr>
<td class=3D"vendor-product">Team Password Manager--Team Password Manager</=
<td>Team Password Manager before 14.184.308 fails to enforce authentication=
requirements in the local account password reset flow. Unauthenticated att= ackers can reset local account passwords and authenticate as those users to=
gain unauthorized access.</td>
<td>2026-09-02</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84699" target=3D= "_blank" rel=3D"noopener">CVE-2026-84699</a></td>
</tr>
<td class=3D"vendor-product">TeamWiseFlow--xiaobei</td>
<td>xiaobei through 5.5.2 fails to implement authentication or signature va= lidation on webhook endpoints, allowing unauthenticated attackers to inject=
arbitrary messages into the agent pipeline. Attackers can publish maliciou=
s messages via the /webhook_worktool handler and exploit unvalidated media = URL fetching to perform server-side request forgery against internal servic= es.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85667" target=3D= "_blank" rel=3D"noopener">CVE-2026-85667</a></td>
</tr>
<td class=3D"vendor-product">TEN-framework--ten-framework</td>
<td>TEN Framework 0.11.71 contains unauthenticated arbitrary file read and = write vulnerabilities in the TMAN Designer file-content API endpoints. Atta= ckers can submit POST and PUT requests to the /api/designer/v1/file-content=
endpoints to read arbitrary files or write malicious content to system pat= hs, enabling code execution through authorized_keys, cron files, or executa= ble graph files.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85688" target=3D= "_blank" rel=3D"noopener">CVE-2026-85688</a></td>
</tr>
<td class=3D"vendor-product">Tenda --HG10<br>=C2=A0</td>
<td>A vulnerability was determined in Tenda HG10 300001138. This issue affe= cts the function formWanRedirect of the file /boaform/formWanRedirect of th=
e component Boa Web Server. Executing a manipulation of the argument if can=
lead to buffer overflow. The attack may be launched remotely. The exploit = has been publicly disclosed and may be utilized.</td>
<td>2026-09-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86166" target=3D= "_blank" rel=3D"noopener">CVE-2026-86166</a></td>
</tr>
<td class=3D"vendor-product">Tenda-- CP3</td>
<td>A vulnerability was detected in Tenda CP3 27.5.57.101. The affected ele= ment is the function sub_2F77E8 of the file Apis/system.c of the component = Network Configuration Management. Performing a manipulation results in os c= ommand injection. The attack may be initiated remotely.</td> <td>2026-09-06</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86151" target=3D= "_blank" rel=3D"noopener">CVE-2026-86151</a></td>
</tr>
<td class=3D"vendor-product">Tenda-- CP3<br>=C2=A0</td>
<td>A security flaw has been discovered in Tenda CP3 27.5.57.101. This vuln= erability affects the function SystemAsh of the file Apis/system.c of the c= omponent Kylin. The manipulation of the argument AlarmVoiceURL results in o=
s command injection. It is possible to launch the attack remotely.</td> <td>2026-09-05</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86148" target=3D= "_blank" rel=3D"noopener">CVE-2026-86148</a></td>
</tr>
<td class=3D"vendor-product">Tenda-- CP3<br>=C2=A0</td>
<td>A weakness has been identified in Tenda CP3 27.5.57.101. This issue aff= ects some unknown processing of the file Net/NetCheckPing.cpp. This manipul= ation of the argument interface_name/host causes os command injection. The = attack can be initiated remotely.</td>
<td>2026-09-05</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86149" target=3D= "_blank" rel=3D"noopener">CVE-2026-86149</a></td>
</tr>
<td class=3D"vendor-product">Tenda-- CP3<br>=C2=A0</td>
<td>A vulnerability has been found in Tenda CP3 27.5.57.101. This affects t=
he function CRedirServer::SetRedirectEnable of the file Functions/Redirect.= cpp. The manipulation leads to improper privilege management. Remote exploi= tation of the attack is possible.</td>
<td>2026-09-06</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86153" target=3D= "_blank" rel=3D"noopener">CVE-2026-86153</a></td>
</tr>
<td class=3D"vendor-product">Tenda--AC1206</td>
<td>A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulner= ability affects the function TendaTelnet of the file /goform/telnet of the = component Web UI. Executing a manipulation can lead to missing authenticati= on. It is possible to launch the attack remotely. The exploit has been publ= icly disclosed and may be utilized.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82693" target=3D= "_blank" rel=3D"noopener">CVE-2026-82693</a></td>
</tr>
<td class=3D"vendor-product">Tenda--AC1206</td>
<td>A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue = affects the function R7WebsSecurityHandler of the file /goform/ate of the c= omponent Web UI. The manipulation leads to missing authentication. The atta=
ck can be initiated remotely. The exploit is publicly available and might b=
e used.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82694" target=3D= "_blank" rel=3D"noopener">CVE-2026-82694</a></td>
</tr>
<td class=3D"vendor-product">Tenda--AC18</td>
<td>A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted=
is an unknown function of the file /goform/telnet of the component Telnet = Handler. The manipulation results in missing authentication. The attack can=
be launched remotely. The exploit has been released to the public and may =
be used for attacks.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82695" target=3D= "_blank" rel=3D"noopener">CVE-2026-82695</a></td>
</tr>
<td class=3D"vendor-product">Tenda--CP3 =C2=A027.5.57.101<br>=C2=A0</td>
<td>A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is=
the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cp=
p of the component Kylin. Executing a manipulation can lead to os command i= njection. The attack may be launched remotely.</td>
<td>2026-09-06</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86152" target=3D= "_blank" rel=3D"noopener">CVE-2026-86152</a></td>
</tr>
<td class=3D"vendor-product">Tenda--HG10</td>
<td>A vulnerability was determined in Tenda HG10 300001138. This issue affe= cts the function formLogin of the file /boaform/formLogin of the component = Boa Web Server. Executing a manipulation of the argument Username can lead =
to buffer overflow. The attack may be launched remotely. The exploit has be=
en publicly disclosed and may be utilized.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85109" target=3D= "_blank" rel=3D"noopener">CVE-2026-85109</a></td>
</tr>
<td class=3D"vendor-product">Tenda--HG10</td>
<td>A vulnerability was identified in Tenda HG10 300001138. Impacted is the=
function formWlanSetup of the file /boaform/formWlanSetup of the component=
Boa Web Server. The manipulation of the argument ssid leads to buffer over= flow. Remote exploitation of the attack is possible. The exploit is publicl=
y available and might be used.</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85110" target=3D= "_blank" rel=3D"noopener">CVE-2026-85110</a></td>
</tr>
<td class=3D"vendor-product">Tenda--HG10<br>=C2=A0</td>
<td>A vulnerability was found in Tenda HG10 300001138. This vulnerability a= ffects the function formURL of the file /boaform/admin/formURL. Performing =
a manipulation of the argument Keywd/urlFQDN results in buffer overflow. Th=
e attack may be initiated remotely. The exploit has been made public and co= uld be used.</td>
<td>2026-09-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86165" target=3D= "_blank" rel=3D"noopener">CVE-2026-86165</a></td>
</tr>
<td class=3D"vendor-product">Tenda--HG10<br>=C2=A0</td>
<td>A vulnerability was identified in Tenda HG10 300001138. Impacted is the=
function formgponConf of the file /boaform/admin/formgponConf of the compo= nent Boa. The manipulation of the argument fmgpon_loid leads to os command = injection. Remote exploitation of the attack is possible. The exploit is pu= blicly available and might be used.</td>
<td>2026-09-06</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86167" target=3D= "_blank" rel=3D"noopener">CVE-2026-86167</a></td>
</tr>
<td class=3D"vendor-product">Tenda--HG21</td>
<td>Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.= 0-260302 allows attackers to gain root access.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38577" target=3D= "_blank" rel=3D"noopener">CVE-2026-38577</a></td>
</tr>
<td class=3D"vendor-product">Teracity Software Technologies Inc.--E-OSB</td=
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in Teracity Software Technologies Inc. E-OSB al= lows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18765" target=3D= "_blank" rel=3D"noopener">CVE-2026-18765</a></td>
</tr>
<td class=3D"vendor-product">The Libreswan Project--libreswan</td>
<td>In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_Extrac= tPublicKey() and asserts that the result is not NULL. However, CERT_Extract= PublicKey() returns NULL when public key extraction fails, for example if t=
he RSA exponent is set to 0. A remote attacker can send a malformed X.509 c= ertificate in a CERT payload to trigger the assertion, causing the pluto da= emon to abort and restart. Continued exploitation causes a denial of servic=
e. No remote code execution is possible. Both IKEv1 and IKEv2 are affected.=
The vulnerability is only exploitable when both the OS and libreswan are r= unning in FIPS mode and at least one CA certificate is loaded. The CERT pay= load is processed before peer authentication, so no credentials are needed =
to exploit this. Configurations using only PreSharedKey (PSK) authenticatio=
n with no CA certificates loaded in the NSS database are not vulnerable.</t=
<td>2026-09-02</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14957" target=3D= "_blank" rel=3D"noopener">CVE-2026-14957</a></td>
</tr>
<td class=3D"vendor-product">The-Vibe-Company--megaparse</td>
<td>MegaParse 0.0.55 contains an unauthenticated server-side request forger=
y vulnerability in the POST /v1/url endpoint that fetches caller-supplied U= RLs server-side. Attackers can supply internal service URLs or metadata end= points without authentication to read their responses directly from the JSO=
N response.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85691" target=3D= "_blank" rel=3D"noopener">CVE-2026-85691</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 lacks authentication in the wire protocol=
, allowing unauthenticated clients to connect with full publish, subscribe,=
and database clear privileges. Attackers can bypass the compile-time proto= col string check and connect with arbitrary client names to execute privile= ged operations including DB_CLEAR which resets all variables and clears cli= ent mail queues.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85424" target=3D= "_blank" rel=3D"noopener">CVE-2026-85424</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains an authentication bypass vulnera= bility in the optional MOOSDB HTTP server that allows unauthenticated clien=
ts to write variables. Attackers can send HTTP requests with variable names=
and values to the MOOSDB HTTP server port to modify MOOS variables includi=
ng actuator and override commands without authentication.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85428" target=3D= "_blank" rel=3D"noopener">CVE-2026-85428</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a pre-authentication heap overfl=
ow vulnerability in MOOSCommPkt packet handling that allows remote attacker=
s to write arbitrary data by declaring a negative packet length. Attackers = can exploit the signed integer check in InflateTo() and negative size conve= rsion in recv() to overflow a four-byte heap buffer during the HandShake ph= ase before authentication.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85440" target=3D= "_blank" rel=3D"noopener">CVE-2026-85440</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 fails to validate client identity in MOOS=
DB message processing, allowing authenticated attackers to attribute writes=
to other clients by supplying arbitrary source identifiers in serialized m= essages. Attackers can forge message origins and cancel third-party subscri= ptions by exploiting the disconnect between authenticated connection identi=
ty and wire-supplied source attribution.</td>
<td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85432" target=3D= "_blank" rel=3D"noopener">CVE-2026-85432</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability=
in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory acc= ess during deserialization. Attackers can open a TCP connection to the MOOS=
DB port and send a crafted short packet to read memory before authenticatio= n.</td>
<td>2026-09-03</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85455" target=3D= "_blank" rel=3D"noopener">CVE-2026-85455</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 fails to validate that serialized string = lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated att= ackers can send a crafted message with a negative length value to the MOOSD=
B port, causing an unhandled exception that terminates the database process= .</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85441" target=3D= "_blank" rel=3D"noopener">CVE-2026-85441</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 fails to validate packet length declarati= ons in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers t=
o trigger unbounded buffer allocation by sending crafted wire packets. Atta= ckers can send packets with large declared lengths to exhaust server memory=
and cause denial of service before client authentication completes.</td> <td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85442" target=3D= "_blank" rel=3D"noopener">CVE-2026-85442</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a denial of service vulnerabilit=
y in MOOSCommServer::ListenLoop() where the accept thread performs a blocki=
ng receive without timeout during the wire-protocol handshake. An attacker = can open a TCP connection to the MOOSDB port and send no data, causing the = accept thread to block indefinitely while holding the socket-list lock, pre= venting all subsequent client connections.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85443" target=3D= "_blank" rel=3D"noopener">CVE-2026-85443</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a denial of service vulnerabilit=
y in the MOOSDB HTTP server that creates unbounded connections and threads = without limits. Attackers can open many connections and send endless header=
data to exhaust server threads and memory, causing service unavailability.= </td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85450" target=3D= "_blank" rel=3D"noopener">CVE-2026-85450</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a remote process termination vul= nerability in the SuicidalSleeper component that uses a hard-coded passphra=
se for multicast command authorization. Any multicast-reachable peer can en= umerate MOOS processes and send termination commands to trigger process shu= tdown by exploiting the default multicast group and port with the known pas= sphrase.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85451" target=3D= "_blank" rel=3D"noopener">CVE-2026-85451</a></td>
</tr>
<td class=3D"vendor-product">themoos--essential-moos</td>
<td>MOOS essential-moos through 10.0.1 contains an authentication bypass vu= lnerability in pShare that accepts UDP datagrams from any source and republ= ishes them with the attacker-claimed identity intact. Attackers can send cr= afted UDP datagrams to pShare input routes to inject messages into the loca=
l MOOS community under spoofed identities, or send malformed datagrams to c= rash the pShare process.</td>
<td>2026-09-03</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85430" target=3D= "_blank" rel=3D"noopener">CVE-2026-85430</a></td>
</tr>
<td class=3D"vendor-product">themoos--essential-moos</td>
<td>MOOS essential-moos pShare through 10.0.1 fails to properly authorize P= SHARE_CMD messages, allowing any publisher to reconfigure network routes an=
d listeners at runtime. Attackers can send crafted PSHARE_CMD messages with=
cmd=3Doutput or cmd=3Dinput parameters to open new listeners on arbitrary = addresses and redirect or duplicate bus traffic to attacker-controlled dest= inations.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85433" target=3D= "_blank" rel=3D"noopener">CVE-2026-85433</a></td>
</tr>
<td class=3D"vendor-product">themoos--essential-moos</td>
<td>MOOS essential-moos pAntler through 10.0.1 contains a remote code execu= tion vulnerability that allows unauthenticated attackers to execute arbitra=
ry programs by publishing a crafted MISSION_FILE message to the MOOSDB. Att= ackers can publish a mission file containing malicious Run entries that pAn= tler parses and executes via execvp() without authentication validation.</t=
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85427" target=3D= "_blank" rel=3D"noopener">CVE-2026-85427</a></td>
</tr>
<td class=3D"vendor-product">themoos--essential-moos</td>
<td>MOOS essential-moos through version 10.0.1 contains an unauthenticated = UDP packet injection vulnerability in pMOOSBridge when configured with UDPL= isten. Attackers can send crafted UDP packets to the configured port to inj= ect arbitrary variables into the local MOOS community with spoofed source a=
nd community identifiers.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85431" target=3D= "_blank" rel=3D"noopener">CVE-2026-85431</a></td>
</tr>
<td class=3D"vendor-product">themoos--essential-moos</td>
<td>MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerabi= lity in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to co= rrupt heap memory by sending UDP datagrams with negative declared lengths. = Attackers can send crafted UDP packets to the configured UDPListen port to = trigger an oversized memcpy operation that writes past the destination buff= er, causing heap corruption and denial of service.</td>
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85436" target=3D= "_blank" rel=3D"noopener">CVE-2026-85436</a></td>
</tr>
<td class=3D"vendor-product">themoos--ui-moos</td>
<td>MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability i=
n ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are fo= rmatted into fixed 1024-byte buffers using sprintf without length validatio=
n. Attackers can supply arbitrarily long MOOS identifiers that overflow the=
buffers when an operator selects process list entries or pokes variables, = enabling code execution.</td>
<td>2026-09-03</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85452" target=3D= "_blank" rel=3D"noopener">CVE-2026-85452</a></td>
</tr>
<td class=3D"vendor-product">Throws SPAM Away--Throws SPAM Away</td> <td>Unauthenticated SQL Injection in Throws SPAM Away <=3D 3.8.2 version= s.</td>
<td>2026-08-31</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81763" target=3D= "_blank" rel=3D"noopener">CVE-2026-81763</a></td>
</tr>
<td class=3D"vendor-product">Tickera--Tickera</td>
<td>Unauthenticated PHP Object Injection in Tickera <=3D 3.6.0.2 version= s.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82226" target=3D= "_blank" rel=3D"noopener">CVE-2026-82226</a></td>
</tr>
<td class=3D"vendor-product">TMT Machine Industry and Trade Ltd. Co.--Talas= soft Industrial Management Software</td>
<td>Use of Hard-coded Credentials vulnerability in TMT Machine Industry and=
Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Em= bedded Sensitive Data. This issue affects Talassoft Industrial Management S= oftware: from V.4 before V.16.</td>
<td>2026-09-01</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18931" target=3D= "_blank" rel=3D"noopener">CVE-2026-18931</a></td>
</tr>
<td class=3D"vendor-product">TMT Machine Industry and Trade Ltd. Co.--Talas= soft Industrial Management Software</td>
<td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Tala= ssoft Industrial Management Software allows SQL Injection. This issue affec=
ts Talassoft Industrial Management Software: from V.4 before V.16.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18630" target=3D= "_blank" rel=3D"noopener">CVE-2026-18630</a></td>
</tr>
<td class=3D"vendor-product">TMT Machine Industry and Trade Ltd. Co.--Talas= soft Industrial Management Software</td>
<td>Missing authentication for critical function vulnerability in TMT Machi=
ne Industry and Trade Ltd. Co. Talassoft Industrial Management Software all= ows Authentication Bypass. This issue affects Talassoft Industrial Manageme=
nt Software: from V4 before V.16.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18771" target=3D= "_blank" rel=3D"noopener">CVE-2026-18771</a></td>
</tr>
<td class=3D"vendor-product">TMT Machine Industry and Trade Ltd. Co.--Talas= soft Industrial Management Software</td>
<td>Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry=
and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross S= ite Request Forgery. This issue affects Talassoft Industrial Management Sof= tware: from V.4 before V.16.</td>
<td>2026-09-01</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18780" target=3D= "_blank" rel=3D"noopener">CVE-2026-18780</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet before v3.16.208 fails to validate organizationId ownership in = database write and destroy routes, allowing any builder-role user to create=
, alter, or drop tables in other organizations' databases. Attackers can ex= ploit missing organization-resolving guards to permanently delete tables, i= nsert arbitrary data, and modify schemas across tenant boundaries on shared=
instances.</td>
<td>2026-08-31</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82870" target=3D= "_blank" rel=3D"noopener">CVE-2026-82870</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet before v3.16.208 fails to validate that the path organizationId=
matches the authenticated user's workspace before performing ToolJet DB ta= ble operations. A workspace admin can create, view, and delete database tab= les in another workspace by replacing the organizationId parameter in table= -management API requests.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82872" target=3D= "_blank" rel=3D"noopener">CVE-2026-82872</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet before v3.16.208 fails to validate that authenticated users bel= ong to the organization specified in the organizationId path parameter of t= ooljet-db endpoints, allowing any Builder user to read, modify, and delete = tables across tenant boundaries. Attackers can extract victim organization = IDs from public app endpoints, then exploit schema operation endpoints to d= isclose table schemas, plant malicious tables, corrupt existing schemas, or=
permanently destroy victim data without any relationship to the target org= anization.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82874" target=3D= "_blank" rel=3D"noopener">CVE-2026-82874</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet Database versions before v3.16.44 contain a privilege escalatio=
n vulnerability in the join_tables endpoint that grants JOIN_TABLES ability=
to all authenticated users without role or workspace membership validation=
. Attackers can read arbitrary ToolJet Database tables from any workspace b=
y supplying victim workspace identifiers in the request path while authenti= cating with their own workspace credentials.</td>
<td>2026-08-31</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82869" target=3D= "_blank" rel=3D"noopener">CVE-2026-82869</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet before v3.16.208 fails to validate organization membership in d= atabase read routes, allowing any authenticated user to access other organi= zations' table schemas and row data. Attackers can supply arbitrary organiz= ation IDs in URL parameters to list tables, retrieve column definitions, an=
d execute join queries to read actual stored data from victim organizations= .</td>
<td>2026-08-31</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82871" target=3D= "_blank" rel=3D"noopener">CVE-2026-82871</a></td>
</tr>
<td class=3D"vendor-product">toon-format--toon</td>
<td>TOON is a compact, human-readable serialization of JSON data for LLM pr= ompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, = constructor, or prototype key wrote through the object prototype chain inst= ead of creating an own property, polluting Object.prototype for the runtime=
. In packages/toon/src/decode/expand.ts, the expandPaths: 'safe' path and i= nsertPathSafe function made dotted keys such as a.__proto__.x the strongest=
vector, while plain nested objects, tabular rows, quoted keys, and streami=
ng decode were also affected. The encoder also dropped own __proto__ proper= ties and could invoke an inherited setter during normalization. Services th=
at decode untrusted TOON could experience denial of service or, when a suit= able downstream gadget is present, remote code execution. This issue is fix=
ed in version 2.3.1.</td>
<td>2026-09-02</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82404" target=3D= "_blank" rel=3D"noopener">CVE-2026-82404</a></td>
</tr>
<td class=3D"vendor-product">tornadoweb--tornado</td>
<td>Tornado is a Python web framework and asynchronous networking library. = Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bo= dies with urllib.parse.parse_qs in tornado/escape.py without passing max_nu= m_fields. RequestHandler._execute in tornado/web.py parses the body before = handler dispatch through HTTPServerRequest._parse_body and parse_body_argum= ents in tornado/httputil.py, so an unauthenticated request body containing = millions of separator-delimited fields can synchronously stall the single-t= hreaded event loop and delay every connection. The body is bounded only by = max_buffer_size, which defaults to 104857600 bytes. This issue is fixed in = version 6.5.8.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82397" target=3D= "_blank" rel=3D"noopener">CVE-2026-82397</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--CP450</td>
<td>A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element=
is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a mani= pulation of the argument topicurl results in buffer overflow. Remote exploi= tation of the attack is possible.</td>
<td>2026-09-03</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85031" target=3D= "_blank" rel=3D"noopener">CVE-2026-85031</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--NR1800X</td>
<td>A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Im= pacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. T=
he manipulation of the argument FileName results in stack-based buffer over= flow. The attack can be executed remotely. The exploit has been made public=
and could be used.</td>
<td>2026-08-31</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82616" target=3D= "_blank" rel=3D"noopener">CVE-2026-82616</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--NR1800X</td>
<td>A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B2023070=
3. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The = manipulation of the argument ussd leads to command injection. The attack ca=
n be initiated remotely. The exploit is publicly available and might be use= d.</td>
<td>2026-08-31</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82597" target=3D= "_blank" rel=3D"noopener">CVE-2026-82597</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the getPairCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to obtain pairing and me= sh-slave configuration via sending a crafted POST request to /cgi-bin/cstec= gi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51669" target=3D= "_blank" rel=3D"noopener">CVE-2026-51669</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the getSlaveUpdate function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to query slave upgra=
de status and affect upgrade bookkeeping via sending a crafted POST request=
to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51670" target=3D= "_blank" rel=3D"noopener">CVE-2026-51670</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the getRoamingCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to obtain the roaming=
enablement flag via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51672" target=3D= "_blank" rel=3D"noopener">CVE-2026-51672</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setScheduleCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to configure forced = reboot tasks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51674" target=3D= "_blank" rel=3D"noopener">CVE-2026-51674</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWanIeCfg function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to reconfigure uplink s= ettings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51675" target=3D= "_blank" rel=3D"noopener">CVE-2026-51675</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setAccessDeviceCfg function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter access-= device policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.= </td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51676" target=3D= "_blank" rel=3D"noopener">CVE-2026-51676</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setUPnPCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to change UPnP service s= tate via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51677" target=3D= "_blank" rel=3D"noopener">CVE-2026-51677</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setPasswordCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the admini= strator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi.= </td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51679" target=3D= "_blank" rel=3D"noopener">CVE-2026-51679</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to modify LED behavior vi=
a sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51680" target=3D= "_blank" rel=3D"noopener">CVE-2026-51680</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side adm= inistration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51681" target=3D= "_blank" rel=3D"noopener">CVE-2026-51681</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setStorageCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to alter the storage-= related service state via sending a crafted POST request to /cgi-bin/cstecg= i.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51684" target=3D= "_blank" rel=3D"noopener">CVE-2026-51684</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiEasyCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure or di= sable wireless networks via sending a crafted POST request to /cgi-bin/cste= cgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51686" target=3D= "_blank" rel=3D"noopener">CVE-2026-51686</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiEasyGuestCf function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to create or wea= ken guest wireless access via sending a crafted POST request to /cgi-bin/cs= tecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51687" target=3D= "_blank" rel=3D"noopener">CVE-2026-51687</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setUpgradeFW function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to trigger firmware-up= grade workflow changes via sending a crafted POST request to /cgi-bin/cstec= gi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51689" target=3D= "_blank" rel=3D"noopener">CVE-2026-51689</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to alter upstream provisi= oning and connectivity via sending a crafted POST request to /cgi-bin/cstec= gi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51690" target=3D= "_blank" rel=3D"noopener">CVE-2026-51690</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setUploadSetting function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate the = upload or flash workflow via sending a crafted POST request to /cgi-bin/cst= ecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51691" target=3D= "_blank" rel=3D"noopener">CVE-2026-51691</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiGuestCfg function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to establish or wea= ken guest wireless access via sending a crafted POST request to /cgi-bin/cs= tecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51692" target=3D= "_blank" rel=3D"noopener">CVE-2026-51692</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setVpnPassCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to weaken edge filter= ing via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51693" target=3D= "_blank" rel=3D"noopener">CVE-2026-51693</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setPortForwardRules function of TOTOLIN=
K T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose inter= nal services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51696" target=3D= "_blank" rel=3D"noopener">CVE-2026-51696</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setIptvCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to alter IPTV service co= nfiguration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51697" target=3D= "_blank" rel=3D"noopener">CVE-2026-51697</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setUrlFilterRules function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter browsing=
policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51698" target=3D= "_blank" rel=3D"noopener">CVE-2026-51698</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setDmzCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to expose an internal hos=
t via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51699" target=3D= "_blank" rel=3D"noopener">CVE-2026-51699</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiAdvancedCfg function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade wirel= ess behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51700" target=3D= "_blank" rel=3D"noopener">CVE-2026-51700</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setMacFilterRules function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change device = access control via sending a crafted POST request to /cgi-bin/cstecgi.cgi.<=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51701" target=3D= "_blank" rel=3D"noopener">CVE-2026-51701</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiMeshName function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to rename mesh entr= ies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51705" target=3D= "_blank" rel=3D"noopener">CVE-2026-51705</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiWpsCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to change WPS availab= ility via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51708" target=3D= "_blank" rel=3D"noopener">CVE-2026-51708</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiBasicCfg function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure prim= ary Wi-Fi settings via sending a crafted POST request to /cgi-bin/cstecgi.c= gi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51709" target=3D= "_blank" rel=3D"noopener">CVE-2026-51709</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setParentalRules function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter parental-= control behavior via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51710" target=3D= "_blank" rel=3D"noopener">CVE-2026-51710</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiWpsStart function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to open a wireless = pairing window via sending a crafted POST request to /cgi-bin/cstecgi.cgi.<=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51711" target=3D= "_blank" rel=3D"noopener">CVE-2026-51711</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setManualDialCfg function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to manipulate WAN = dial state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51713" target=3D= "_blank" rel=3D"noopener">CVE-2026-51713</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delMacFilterRules function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove MAC fil= ter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51715" target=3D= "_blank" rel=3D"noopener">CVE-2026-51715</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setOpModeCfg function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to change the device o= perating mode via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51717" target=3D= "_blank" rel=3D"noopener">CVE-2026-51717</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delStaticDhcpRules function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove static=
DHCP reservations via sending a crafted POST request to /cgi-bin/cstecgi.c= gi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51718" target=3D= "_blank" rel=3D"noopener">CVE-2026-51718</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delIpPortFilterRules function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove fire= wall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cg= i.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51720" target=3D= "_blank" rel=3D"noopener">CVE-2026-51720</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setPairCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to alter the mesh pairin=
g state via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51721" target=3D= "_blank" rel=3D"noopener">CVE-2026-51721</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiRepeaterCfg function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to repoint the d= evice to an attacker-controlled upstream Wi-Fi via sending a crafted POST r= equest to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51722" target=3D= "_blank" rel=3D"noopener">CVE-2026-51722</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the UploadCustomModule function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to install a cus= tom CGI module via sending a crafted POST request to /cgi-bin/cstecgi.cgi.<=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51723" target=3D= "_blank" rel=3D"noopener">CVE-2026-51723</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delSmartQosCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Smart QoS = rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51724" target=3D= "_blank" rel=3D"noopener">CVE-2026-51724</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to change the devic=
e clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51725" target=3D= "_blank" rel=3D"noopener">CVE-2026-51725</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delParentalRules function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental= -control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.<=
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51726" target=3D= "_blank" rel=3D"noopener">CVE-2026-51726</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the UploadFirmwareFile function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a craf= ted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.c= gi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51728" target=3D= "_blank" rel=3D"noopener">CVE-2026-51728</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to request deletion of a = managed slave device via sending a crafted POST request to /cgi-bin/cstecgi= .cgi.</td>
<td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51729" target=3D= "_blank" rel=3D"noopener">CVE-2026-51729</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delWiFiAclRules function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL=
rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51730" target=3D= "_blank" rel=3D"noopener">CVE-2026-51730</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries v=
ia sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51731" target=3D= "_blank" rel=3D"noopener">CVE-2026-51731</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi sch= edule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</=
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51733" target=3D= "_blank" rel=3D"noopener">CVE-2026-51733</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the informSlaveUpdate function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh s= lave update coordination via sending a crafted POST request to /cgi-bin/cst= ecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51734" target=3D= "_blank" rel=3D"noopener">CVE-2026-51734</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to erase system logs vi=
a sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51736" target=3D= "_blank" rel=3D"noopener">CVE-2026-51736</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the LoadDefSettings function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device=
configuration and reboot the device via sending a crafted POST request to = /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51738" target=3D= "_blank" rel=3D"noopener">CVE-2026-51738</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the killProcess function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to terminate critical s= ervices via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51740" target=3D= "_blank" rel=3D"noopener">CVE-2026-51740</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the clearDiagnosisLog function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosi=
s logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51741" target=3D= "_blank" rel=3D"noopener">CVE-2026-51741</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the guest_wifi_sync function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest vi= rtual AP interfaces via sending a crafted MQTT message to the cs_broker com= ponent.</td>
<td>2026-09-01</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51743" target=3D= "_blank" rel=3D"noopener">CVE-2026-51743</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the recv_mesh_info_sync function of TOTOLIN=
K T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh c= onfiguration synchronization from an attacker-controlled host via sending a=
crafted MQTT message to the cs_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51744" target=3D= "_blank" rel=3D"noopener">CVE-2026-51744</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh hea= rtbeat information toward the master via sending a crafted MQTT message to = the cs_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51747" target=3D= "_blank" rel=3D"noopener">CVE-2026-51747</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the updatePriChannel function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and swit=
ch the primary mesh channel via sending a crafted MQTT message to the cs_br= oker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51750" target=3D= "_blank" rel=3D"noopener">CVE-2026-51750</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delSlaveDevice function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specifie=
d slave device from local mesh management data and reboot the system via se= nding a crafted MQTT message to the cs_broker component.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51751" target=3D= "_blank" rel=3D"noopener">CVE-2026-51751</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the updateSlaveIpList function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the = slave IP inventory state via sending a crafted MQTT message to the cs_broke=
r component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51754" target=3D= "_blank" rel=3D"noopener">CVE-2026-51754</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware=
download or flash workflow on the slave device via sending a crafted MQTT = message to the cs_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51757" target=3D= "_blank" rel=3D"noopener">CVE-2026-51757</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the informSyncUpgfw function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger fir= mware update activity across mesh slaves via sending a crafted MQTT message=
to the cs_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51760" target=3D= "_blank" rel=3D"noopener">CVE-2026-51760</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale=
mesh information/state and trigger regeneration of mesh metadata via sendi=
ng a crafted MQTT message to the cs_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51762" target=3D= "_blank" rel=3D"noopener">CVE-2026-51762</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the freeStaClient function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnec=
t wireless clients via sending a crafted MQTT message to the cs_broker comp= onent.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51763" target=3D= "_blank" rel=3D"noopener">CVE-2026-51763</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the recvSlaveCloudCheckStatus function of T= OTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwr= ite cloud-result tracking files via sending a crafted MQTT message to the c= s_broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51764" target=3D= "_blank" rel=3D"noopener">CVE-2026-51764</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the recvIndirectMeshInfo function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or r= eplace mesh neighbor records via sending a crafted MQTT message to the cs_b= roker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51765" target=3D= "_blank" rel=3D"noopener">CVE-2026-51765</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the recvClearPairCfg function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset pairing s= tate and reboot the device via sending a crafted MQTT message to the cs_bro= ker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51767" target=3D= "_blank" rel=3D"noopener">CVE-2026-51767</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the remoteCloudUpdateCheck function of TOTO= LINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to restart t=
he cloud update check workflow via sending a crafted MQTT message to the cs= _broker component.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51769" target=3D= "_blank" rel=3D"noopener">CVE-2026-51769</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the sendToMasterQosConfig function of TOTOL= INK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward at= tacker-controlled QoS settings to the master via sending a crafted MQTT mes= sage to the cs_broker component..</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51770" target=3D= "_blank" rel=3D"noopener">CVE-2026-51770</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setLanguageCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language c= onfiguration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51668" target=3D= "_blank" rel=3D"noopener">CVE-2026-51668</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the getCloudDownloadStatus function of TOTO= LINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cl= oud firmware download state information via sending a crafted POST request =
to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51671" target=3D= "_blank" rel=3D"noopener">CVE-2026-51671</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to alter time synchroniza= tion settings via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</=
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51673" target=3D= "_blank" rel=3D"noopener">CVE-2026-51673</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiSignalCfg function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reduce wireless=
power or cause a Denial of Service (DoS) via sending a crafted POST reques=
t to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51688" target=3D= "_blank" rel=3D"noopener">CVE-2026-51688</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setStaticDhcpRules function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change=
static DHCP rules via sending a crafted POST request to /cgi-bin/cstecgi.c= gi.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51694" target=3D= "_blank" rel=3D"noopener">CVE-2026-51694</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS sta=
te via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51695" target=3D= "_blank" rel=3D"noopener">CVE-2026-51695</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delPortForwardRules function of TOTOLIN=
K T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-= forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51716" target=3D= "_blank" rel=3D"noopener">CVE-2026-51716</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delUrlFilterRules function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL fil= tering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51719" target=3D= "_blank" rel=3D"noopener">CVE-2026-51719</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.= 5cu.748_B20211015 allows unauthenticated attackers to retrieve recent syste=
m logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51735" target=3D= "_blank" rel=3D"noopener">CVE-2026-51735</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setDevReboot function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local de= vice and, on a master, fan out reboot commands to mesh slaves via sending a=
crafted MQTT message to the cs_broker component.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51766" target=3D= "_blank" rel=3D"noopener">CVE-2026-51766</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setElinkQosConfig function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify privile= ged QoS policy on the master device via sending a crafted MQTT message to t=
he cs_broker component.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51768" target=3D= "_blank" rel=3D"noopener">CVE-2026-51768</a></td>
</tr>
<td class=3D"vendor-product">triggerdotdev--trigger.dev</td>
<td>Trigger.dev versions before 4.5.2 fail to validate environment membersh=
ip during run replay operations, allowing authenticated attackers to inject=
task runs into arbitrary environments. Attackers can replay their own runs=
into other organizations' or projects' environments to consume victim reso= urces and pollute run history.</td>
<td>2026-09-04</td>
<td>8.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85651" target=3D= "_blank" rel=3D"noopener">CVE-2026-85651</a></td>
</tr>
<td class=3D"vendor-product">Trimble --TM4WEB 21.4.0.4</td>
<td>In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulner= able to reflected cross-site scripting via injection in a arbitrary paramet=
er appended to the URL.</td>
<td>2026-09-04</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-35499" target=3D= "_blank" rel=3D"noopener">CVE-2022-35499</a></td>
</tr>
<td class=3D"vendor-product">TRtek Technological Products Computer Software=
Hardware Industry and Trade Limited Company--Products's Store</td> <td>Improper neutralization of special elements used in an SQL command ('SQ=
L injection') vulnerability in TRtek Technological Products Computer Softwa=
re Hardware Industry and Trade Limited Company Products's Store allows SQL = Injection. This issue affects Products's Store: before 030631b2.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18210" target=3D= "_blank" rel=3D"noopener">CVE-2026-18210</a></td>
</tr>
<td class=3D"vendor-product">TrustedSite--TrustedSite</td>
<td>Unauthenticated Cross Site Scripting (XSS) in TrustedSite <=3D 1.2.5=
versions.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81771" target=3D= "_blank" rel=3D"noopener">CVE-2026-81771</a></td>
</tr>
<td class=3D"vendor-product">tsi-coop--tsi-dpdp-cms</td>
<td>A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.=
0. This vulnerability affects unknown code. The manipulation results in cli= ent-side enforcement of server-side security. The attack can be launched re= motely. The exploit has been released to the public and may be used for att= acks. Upgrading to version 0.5.1 is able to resolve this issue. It is recom= mended to upgrade the affected component.</td>
<td>2026-09-02</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84841" target=3D= "_blank" rel=3D"noopener">CVE-2026-84841</a></td>
</tr>
<td class=3D"vendor-product">Tycon Systems--TPDIN-Monitor-WEB3=C2=A0<br>=C2= =A0</td>
<td>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerabl=
e to a Missing Authorization vulnerability. This could allow an attacker to=
extract system credentials, configurations, or flash contents.</td>
<td>2026-09-04</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82684" target=3D= "_blank" rel=3D"noopener">CVE-2026-82684</a></td>
</tr>
<td class=3D"vendor-product">Tycon Systems--TPDIN-Monitor-WEB3=C2=A0<br>=C2= =A0</td>
<td>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerabl=
e to a cross-site request forgery vulnerability. This could allow an attack=
er to perform state changing operations on the device.</td>
<td>2026-09-04</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82712" target=3D= "_blank" rel=3D"noopener">CVE-2026-82712</a></td>
</tr>
<td class=3D"vendor-product">Uncode--Uncode</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Uncode <=3D 2.12.7 ver= sions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81291" target=3D= "_blank" rel=3D"noopener">CVE-2026-81291</a></td>
</tr>
<td class=3D"vendor-product">UnderConstructionPage--Under Construction</td> <td>Unauthenticated Cross Site Scripting (XSS) in Under Construction <=
=3D 5.82 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81295" target=3D= "_blank" rel=3D"noopener">CVE-2026-81295</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's WebSocket client crashes the whole Node.js process during the = opening handshake when a server responds with a subprotocol that the client=
never requested. A default WebSocket connection sends no subprotocol, but =
if the server's 101 response includes a Sec-WebSocket-Protocol header, undi=
ci dereferences a null value while checking it against the requested list a=
nd throws an uncaught TypeError. Because that code runs inside a microtask = with no surrounding error handling, the exception propagates and terminates=
the process under Node's default behavior, instead of gracefully failing t=
he connection as required by the WebSocket protocol. Any application that o= pens a WebSocket to an attacker-controlled or compromised server, or over a=
plaintext connection subject to a machine-in-the-middle, can be crashed re= motely without authentication in the default configuration. This affects un= dici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.= 0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.= </td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19534" target=3D= "_blank" rel=3D"noopener">CVE-2026-19534</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's BalancedPool constructor passes its entire options object thro= ugh an internal deep-clone that serializes and reparses the value as JSON. = Because JSON cannot represent functions, any function-valued TLS option, su=
ch as a caller-supplied checkServerIdentity callback or a custom connector = inside the connect option, is silently discarded before it reaches the TLS = layer. As a result a peer whose certificate the application's custom checkS= erverIdentity was written to reject, but which still passes Node's default = hostname and chain checks, is accepted when reached through BalancedPool. T=
he Client, Pool, and Agent dispatchers are not affected because they extrac=
t the connect and tls options before cloning. This affects undici versions = from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the app= lication supplies a function-valued connect or tls option to BalancedPool. = Users should upgrade to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84961" target=3D= "_blank" rel=3D"noopener">CVE-2026-84961</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici 8.10.0 omits the destination origin from the cache and request-d= eduplication keys when the cache or deduplicate interceptor is composed dir= ectly onto a Client or Pool. Because the internal cache key falls back to a=
n empty origin string, a cacheable or in-flight response from one upstream = origin is returned for a request to a different, trusted origin whenever th=
e method, path, and relevant headers match, which permits cross-origin info= rmation disclosure and persistent cache poisoning. The reporter demonstrate=
d a full authentication bypass in which a JWT signed with an attacker-contr= olled key was accepted as belonging to a trusted issuer, and the trusted or= igin was never contacted. This is a regression introduced in 8.10.0 and aff= ects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent,=
which carries the origin in its dispatch options, are not affected. Users = should upgrade to undici 8.10.2.</td>
<td>2026-09-04</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85152" target=3D= "_blank" rel=3D"noopener">CVE-2026-85152</a></td>
</tr>
<td class=3D"vendor-product">Unidata--netcdf-c<br>=C2=A0</td>
<td>Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnera= bility in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fi= xed 256-byte buffer without length validation. Attackers can craft HDF5 fil=
es with oversized attribute names to overflow the destination buffer, causi=
ng memory corruption and crashes when applications enumerate attribute name= s.</td>
<td>2026-09-04</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86095" target=3D= "_blank" rel=3D"noopener">CVE-2026-86095</a></td>
</tr>
<td class=3D"vendor-product">unopim--unopim</td>
<td>UnoPim before 2.1.5 contains an authenticated file upload vulnerability=
that allows authenticated administrators to upload arbitrary PHP files thr= ough the TinyMCE image upload endpoint due to missing file extension and MI=
ME type validation. Attackers can upload a PHP web shell to the public stor= age disk and execute arbitrary operating system commands on the server by a= ccessing the uploaded file at the URL returned in the server response.</td> <td>2026-09-02</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82524" target=3D= "_blank" rel=3D"noopener">CVE-2026-82524</a></td>
</tr>
<td class=3D"vendor-product">unopim--unopim</td>
<td>UnoPim before 2.1.3 fails to include integration store, update, and key= -generation routes in its ACL map, allowing any admin user to bypass permis= sion checks. Attackers with minimal admin privileges can create OAuth API i= ntegrations, mint client credentials, and escalate permissions by exploitin=
g missing authorization validation in the Bouncer middleware.</td> <td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85395" target=3D= "_blank" rel=3D"noopener">CVE-2026-85395</a></td>
</tr>
<td class=3D"vendor-product">uscnanbu--Welcart e-Commerce</td>
<td>The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cro= ss-Site Scripting via the 'custom_order' parameter in all versions up to, a=
nd including, 2.12.1 due to insufficient input sanitization and output esca= ping. This makes it possible for unauthenticated attackers to inject arbitr= ary web scripts in pages that will execute whenever a user accesses an inje= cted page. The injected payload is delivered via the guest checkout form, r= equiring no authentication, and executes when an administrator views the af= fected order in the WordPress admin panel.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19914" target=3D= "_blank" rel=3D"noopener">CVE-2026-19914</a></td>
</tr>
<td class=3D"vendor-product">usememos--memos</td>
<td>Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when=
a user changes their password, allowing attackers to maintain account acce= ss. An attacker with a stolen refresh token can call the RefreshToken RPC t=
o obtain new access tokens and rotate the refresh token indefinitely, bypas= sing the password change security measure.</td>
<td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84203" target=3D= "_blank" rel=3D"noopener">CVE-2026-84203</a></td>
</tr>
<td class=3D"vendor-product">User Frontend--User Frontend</td>
<td>The User Frontend WordPress plugin before 4.3.11 does not prevent user-= supplied field values from being deserialized when a submitted post is reop= ened in its frontend editing form, allowing authenticated users with subscr= iber-level access and above to perform PHP Object Injection, which may lead=
to remote code execution when a suitable gadget chain is present on the si= te.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19116" target=3D= "_blank" rel=3D"noopener">CVE-2026-19116</a></td>
</tr>
<td class=3D"vendor-product">util-linux--util-linux</td>
<td>util-linux versions through 2.41.5 and 2.42.2 fail to check mount helpe=
r exit status before running post-mount hooks, allowing unprivileged users =
to execute privileged operations on pre-existing filesystems. Attackers can=
exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inh= erited suid bits or modify target inode permissions after a helper fails, a= chieving privilege escalation.</td>
<td>2026-09-03</td>
<td>7.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76642" target=3D= "_blank" rel=3D"noopener">CVE-2026-76642</a></td>
</tr>
<td class=3D"vendor-product">varunvairavanlc--LeadConnector</td> <td>Unauthenticated Cross Site Scripting (XSS) in LeadConnector <=3D 4.0=
.5 versions.</td>
<td>2026-08-31</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81298" target=3D= "_blank" rel=3D"noopener">CVE-2026-81298</a></td>
</tr>
<td class=3D"vendor-product">vercel--next.js</td>
<td>Next.js is a React framework for building full-stack web applications. = From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Rout=
er or App Router without Cache Components on Windows-hosted servers do not = consistently escape backslashes in route segments before constructing incre= mental-cache paths. In packages/next/src/shared/lib/router/utils/escape-pat= h-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-sys= tem-cache.ts, a remote request can supply encoded Windows path separators t= hat traverse outside the intended cache root and expose private build data,=
including the server-reference-manifest encryption key. Disclosure of that=
key can enable remote code execution in the affected application. This iss=
ue is fixed in versions 15.5.24 and 16.3.3.</td>
<td>2026-09-01</td>
<td>9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75604" target=3D= "_blank" rel=3D"noopener">CVE-2026-75604</a></td>
</tr>
<td class=3D"vendor-product">Voltronic Power--SNMP Web Pro</td>
<td>Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote cod=
e execution vulnerability in the upload.cgi firmware update endpoint that a= llows remote attackers to execute arbitrary commands as root by uploading a=
crafted tar archive without valid credentials. Attackers can supply a mali= cious tar archive containing arbitrary executable files that are extracted =
to a privileged directory and executed as root, achieving full system compr= omise.</td>
<td>2026-09-04</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-44402" target=3D= "_blank" rel=3D"noopener">CVE-2026-44402</a></td>
</tr>
<td class=3D"vendor-product">WatchMan-Site7--WatchMan-Site7</td>
<td>The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict acc= ess to its debugging console, which executes user-supplied PHP code, allowi=
ng any authenticated user, such as a subscriber, to run arbitrary code on t=
he server.</td>
<td>2026-09-02</td>
<td>9.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77009" target=3D= "_blank" rel=3D"noopener">CVE-2026-77009</a></td>
</tr>
<td class=3D"vendor-product">WC Lovers--WCFM Marketplace</td> <td>Unauthenticated SQL Injection in WCFM Marketplace <=3D 3.8.1 version= s.</td>
<td>2026-09-02</td>
<td>9.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81286" target=3D= "_blank" rel=3D"noopener">CVE-2026-81286</a></td>
</tr>
<td class=3D"vendor-product">WC Lovers--WCFM Membership</td>
<td>Subscriber Privilege Escalation in WCFM Membership <=3D 2.11.11 vers= ions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84756" target=3D= "_blank" rel=3D"noopener">CVE-2026-84756</a></td>
</tr>
<td class=3D"vendor-product">webilia--Listdom: AI-powered Business Director=
y with Classifieds Ads Listings</td>
<td>The Listdom: AI-powered Business Directory with Classifieds Ads Listing=
s plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'ls= d[displ][style]' Parameter in all versions up to, and including, 5.8.1 due =
to insufficient input sanitization and output escaping. This makes it possi= ble for unauthenticated attackers to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page. Exploitation r= equires the Listdom Pro add-on to be active and the 'Display Options Per Li= sting' displ setting to be enabled, both of which are non-default configura= tions.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19796" target=3D= "_blank" rel=3D"noopener">CVE-2026-19796</a></td>
</tr>
<td class=3D"vendor-product">WebKit--WebKit</td>
<td>A flaw was found in WebKitGTK. Processing malicious web content can cau=
se memory corruption due to improper memory handling.</td>
<td>2026-08-31</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83596" target=3D= "_blank" rel=3D"noopener">CVE-2026-83596</a></td>
</tr>
<td class=3D"vendor-product">Webstudio --Webstudio=C2=A0<br>=C2=A0</td>
<td>Webstudio through 0.296.0 contains an unauthenticated server-side reque=
st forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset prox=
y routes when RESIZE_ORIGIN environment variable is unset. Attackers can su= pply arbitrary URLs to these endpoints to read cloud instance metadata, acc= ess internal services, and perform network reconnaissance on the instance i= nfrastructure.</td>
<td>2026-09-05</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86119" target=3D= "_blank" rel=3D"noopener">CVE-2026-86119</a></td>
</tr>
<td class=3D"vendor-product">weDevs--WP User Frontend</td>
<td>Subscriber PHP Object Injection in WP User Frontend <=3D 4.3.10 vers= ions.</td>
<td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81283" target=3D= "_blank" rel=3D"noopener">CVE-2026-81283</a></td>
</tr>
<td class=3D"vendor-product">Westermo--WeOS</td>
<td>Westermo WeOS 5.x starting from 5.24 allows OS command injection via a = media definition.</td>
<td>2026-09-02</td>
<td>7.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-46418" target=3D= "_blank" rel=3D"noopener">CVE-2025-46418</a></td>
</tr>
<td class=3D"vendor-product">wordplus--BP Better Messages</td> <td>Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <=
=3D 2.15.27 versions.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84812" target=3D= "_blank" rel=3D"noopener">CVE-2026-84812</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Ninja Forms<br>=C2=A0</td> <td>The Ninja Forms - The Contact Form Builder That Grows With You plugin f=
or WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Chil=
d 'type' Confusion via Unmatched Array Key in all versions up to, and inclu= ding, 3.15.1 due to insufficient input sanitization and output escaping. Th=
is makes it possible for unauthenticated attackers to inject arbitrary web = scripts in pages that will execute whenever a user accesses an injected pag=
e. Exploitation requires the Ninja Forms File Uploads add-on to be active, =
as the attack routes the unwhitelisted child entry through the File Uploads=
handler to write an attacker-supplied HTML file containing arbitrary JavaS= cript into any web-server-writable directory, including the site root, wher=
e it is served from the site's own origin.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19769" target=3D= "_blank" rel=3D"noopener">CVE-2026-19769</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--DynamiApps<br>=C2=A0</td>
<td>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to = Authentication Bypass to Account Takeover in all versions up to, and includ= ing, 3.29.12. This is due to the pre_update_value function lacking any capa= bility or ownership check, and ActionPost::conditions_logic() short-circuit= ing its current_user_can('edit_post') authorization gate whenever the post =
ID is non-numeric - such as the string user_1 - allowing unauthenticated fo=
rm submissions to be routed to arbitrary user records without restriction. = This makes it possible for unauthenticated attackers to overwrite any user'=
s registered email address, including an administrator's, and then leverage=
WordPress's native password-reset flow to fully take over the targeted acc= ount.</td>
<td>2026-09-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75816" target=3D= "_blank" rel=3D"noopener">CVE-2026-75816</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Gravity Forms<br>=C2=A0</td> <td>The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Si=
te Scripting via Post Body Field Value in all versions up to, and including=
, 2.10.5 due to insufficient input sanitization and output escaping. This m= akes it possible for unauthenticated attackers to inject arbitrary web scri= pts in pages that will execute whenever a user accesses an injected page. T=
he exploit survives save-time sanitization because wp_kses_post allows the = required HTML tags and attributes, and the client-side tooltip script re-pa= rses the browser-decoded aria-label value as innerHTML while only stripping=
script elements, leaving onerror and other event-handler attributes fully = intact and executable.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16649" target=3D= "_blank" rel=3D"noopener">CVE-2026-16649</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--HivePress=C2=A0<br>=C2=A0</t=
<td>The HivePress Authentication plugin for WordPress is vulnerable to Auth= entication Bypass via the access_token parameter in all versions up to, and=
including, 1.1.4. This is due to the authenticate_user function's Facebook=
authenticator resolving third-party identity by forwarding the attacker-su= pplied access_token to the Facebook Graph API and trusting the returned ema=
il and ID verbatim, without performing any application ID or audience valid= ation - specifically, no /debug_token verification and no comparison of the=
token's app_id against the configured hp_facebook_app_id. This makes it po= ssible for unauthenticated attackers to authenticate as any existing WordPr= ess user, including administrators, whose email address is associated with =
a Facebook account for which the attacker can obtain any valid access token=
. Important Note: To exploit the vulnerability, the attacker must obtain th=
e victim's access token.</td>
<td>2026-09-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18056" target=3D= "_blank" rel=3D"noopener">CVE-2026-18056</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Hummingbird - Speed Optimiza= tion, Caching, Minify, Compress & CDN=C2=A0<br>=C2=A0</td>
<td>The Hummingbird - Speed Optimization, Caching, Minify, Compress & C=
DN plugin for WordPress is vulnerable to Remote Code Execution in all versi= ons up to, and including, 3.21.0 via the log_msg() function in core/modules= /class-page-cache.php. The page-cache debug log is written to wp-content/wp= hb-logs/page-caching-log.php, a directly web-accessible PHP file that is su= pposed to be protected by a leading '<?php die(); ?>' header. That he= ader is guarded by class_exists( 'Filesystem' ), which can never match beca= use class_exists() resolves string arguments in the global namespace while = the class is Hummingbird\Core\Filesystem; when the log is created during a = front-end request the header is therefore omitted entirely. get_cookies() t= hen writes the raw name of any cookie matching the wphb_cache_ prefix into = that file without sanitization. This makes it possible for unauthenticated = attackers to write arbitrary PHP into the log file with a single anonymous = request and execute it by requesting the file directly, resulting in full r= emote code execution. Exploitation requires the site administrator to have = enabled Page Caching with the Debug Log option (non-default), and the log f= ile to be created during a front-end request - a state reached by the plugi= n's own 'Clear logs' action, any cache flush, or unattended via the plugin'=
s daily log-rotation cron, which can strip the protective header from an ex= isting log file.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83627" target=3D= "_blank" rel=3D"noopener">CVE-2026-83627</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--IPGP Visitors Origin<br>=C2= =A0</td>
<td>The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise =
or escape user input before reflecting it back in the HTTP response, allowi=
ng unauthenticated attackers to perform Reflected Cross-Site Scripting atta= cks against users who are tricked into submitting a crafted request.</td> <td>2026-09-05</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81404" target=3D= "_blank" rel=3D"noopener">CVE-2026-81404</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--iubenda=C2=A0</td>
<td>The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + mo=
re plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Co= mment Content in all versions up to, and including, 3.13.4 due to insuffici= ent input sanitization and output escaping. This makes it possible for unau= thenticated attackers to inject arbitrary web scripts in pages that will ex= ecute whenever a user accesses an injected page. The exploit works by embed= ding KSES-allowed markup such as abbr title attributes and HTML comments in=
a submitted comment so that the global strtr() substitution strips substri= ngs from an inert tag, mutating it into an executable element such as an im=
g onerror handler that runs in the WordPress origin for any visitor, includ= ing logged-in administrators.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77263" target=3D= "_blank" rel=3D"noopener">CVE-2026-77263</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--iubenda=C2=A0<br>=C2=A0</td> <td>The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + mo=
re plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Co= mment Content via AdSense Regex Rewrite in all versions up to, and includin=
g, 3.13.4 due to insufficient input sanitization and output escaping. This = makes it possible for unauthenticated attackers to inject arbitrary web scr= ipts in pages that will execute whenever a user accesses an injected page. = This vulnerability only manifests when the 'Secondary' parser engine is act= ive (parser_engine=3Ddefault); it does not exist under the default 'new' DO= M-based parser engine.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77233" target=3D= "_blank" rel=3D"noopener">CVE-2026-77233</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--JetFormBuilder - Dynamic Blo= cks<br>=C2=A0</td>
<td>The JetFormBuilder - Dynamic Blocks Form Builder WordPress plugin befor=
e 3.6.5.2 does not perform authorisation checks when resolving request-deri= ved data during page rendering, allowing unauthenticated users to read arbi= trary user, post and term properties and metadata, including password hashe=
s, private and draft content, and secrets other JetFormBuilder - Dynamic Bl= ocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.</td> <td>2026-09-05</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19858" target=3D= "_blank" rel=3D"noopener">CVE-2026-19858</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Kirki<br>=C2=A0</td>
<td>The Kirki WordPress plugin before 6.3.0 does not hold back every spelli=
ng of the HTML entities it decodes when rendering, allowing unauthenticated=
users to store JavaScript in a comment which then runs in the session of a= nyone viewing a page that displays it, including an administrator, and on e= very page of the site when its header or footer is built to show comments.<=
<td>2026-09-06</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84219" target=3D= "_blank" rel=3D"noopener">CVE-2026-84219</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Mail Mint - Email Marketing,=
Newsletter, Email Automation & WooCommerce Email<br>=C2=A0</td>
<td>The Mail Mint - Email Marketing, Newsletter, Email Automation & Woo= Commerce Emails plugin for WordPress is vulnerable to PHP Object Injection =
in all versions up to, and including, 1.31.0 via deserialization of untrust=
ed input in the 'handle_form_submission' function. This makes it possible f=
or unauthenticated attackers to inject a PHP Object. The additional presenc=
e of a POP chain allows attackers to execute code on the server. The vulner= ability was partially patched in version 1.23.1.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10196" target=3D= "_blank" rel=3D"noopener">CVE-2026-10196</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--MemberDash<br>=C2=A0</td>
<td>The MemberDash plugin for WordPress is vulnerable to Insecure Direct Ob= ject Reference in all versions up to, and including, 1.8.5 via the 'id' par= ameter due to missing validation on a user controlled key. This makes it po= ssible for unauthenticated attackers to change the password of any WordPres=
s user, including administrators, by supplying an arbitrary user ID during = registration, and take over their account without any notification sent to = the victim.</td>
<td>2026-09-06</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16310" target=3D= "_blank" rel=3D"noopener">CVE-2026-16310</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Mstore Api<br>=C2=A0</td>
<td>The Mstore Api plugin for WordPress is vulnerable to Authentication Byp= ass via JWT Forgery in versions up to, and including, 4.20.0 This is due to=
missing cryptographic signature verification in the FirebasePhoneAuthHelpe= r::verify_id_token() function, which decodes and validates Firebase ID toke=
n claims (alg, kid, aud, iss) but never calls openssl_verify() or any equiv= alent to validate the JWT signature against Google's actual public key cert= ificates. This makes it possible for unauthenticated attackers to forge a F= irebase Phone Auth JWT signed with a self-generated RSA key pair and impers= onate any phone number, resulting in unauthorized access to existing WordPr= ess accounts or creation of new arbitrary accounts.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13447" target=3D= "_blank" rel=3D"noopener">CVE-2026-13447</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Nokri-Job Board<br>=C2=A0</t=
<td>The Nokri - Job Board WordPress Theme theme for WordPress is vulnerable=
to unauthorized modification of data due to a missing capability check on = the 'nokri_account_member_permissions' function in all versions up to, and = including, 1.6.4. This makes it possible for authenticated attackers, with = Subscriber-level access and above, to add new Subscriber users with employe=
r account member permissions, who in turn can escalate privileges by updati=
ng the email address of any user, including Administrator users.</td> <td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-9049" target=3D"= _blank" rel=3D"noopener">CVE-2025-9049</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Post Grid and Gutenberg Bloc=
ks - ComboBlocks<br>=C2=A0</td>
<td>The Post Grid and Gutenberg Blocks - ComboBlocks plugin for WordPress i=
s vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 = via several functions in the ~/includes/blocks/form-wrap/function.php file.=
This makes it possible for unauthenticated attackers to execute actions wi=
th hooks in WordPress, granted no other security controls are present in th=
e function.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-11080" target=3D= "_blank" rel=3D"noopener">CVE-2024-11080</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--QuickCal=C2=A0<br>=C2=A0</td=
<td>The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Sc= ripting via Custom Field Parameters in all versions up to, and including, 1= .0.20 due to insufficient input sanitization and output escaping. This make=
s it possible for unauthenticated attackers to inject arbitrary web scripts=
in pages that will execute whenever a user accesses an injected page. The = nonce guarding the unauthenticated booked_add_appt AJAX action is publicly = embedded on any page rendering the booking calendar shortcode, making it tr= ivially obtainable by unauthenticated attackers without any prior account o=
r privilege.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15984" target=3D= "_blank" rel=3D"noopener">CVE-2026-15984</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--RegistrationMagic=C2=A0<br>= =C2=A0</td>
<td>The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify w= hich application a Facebook access token was issued to before accepting it =
as proof of identity, allowing unauthenticated attackers to log in as an ex= isting user whose token they can obtain, or to create and log into a new ac= count even when user registration is disabled.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77826" target=3D= "_blank" rel=3D"noopener">CVE-2026-77826</a></td>
</tr>
<td class=3D"vendor-product">Wordpress Plugin--SEO Flow<br>=C2=A0</td>
<td>The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not corre= ctly validate the credential supplied with its API requests, allowing unaut= henticated users to be served as the administrator who configured the SEO F= low by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exp= loitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3=
to have been configured, which is its normal operating state.</td> <td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78362" target=3D= "_blank" rel=3D"noopener">CVE-2026-78362</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Spam protection, Honeypot, A= nti-Spam by CleanTalk<br>=C2=A0</td>
<td>The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPr= ess is vulnerable to Stored Cross-Site Scripting via Comment Content aria-l= abel Placeholder in all versions up to, and including, 6.86 due to insuffic= ient input sanitization and output escaping. This makes it possible for aut= henticated attackers, with custom-level access and above, to inject arbitra=
ry web scripts in pages that will execute whenever a user accesses an injec= ted page. The payload is deliverable via unauthenticated comment submission=
and executes exclusively for non-logged-in visitors; if comment moderation=
is enabled, an approving moderator must first publish the comment before t=
he script reaches other users.</td>
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77830" target=3D= "_blank" rel=3D"noopener">CVE-2026-77830</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--SureCart<br>=C2=A0</td>
<td>The SureCart WordPress plugin before 4.6.3 does not ensure that the acc= ount affected by a customer update is the same account its permission check=
authorised, allowing users with a subscriber-level account to change anoth=
er user's email address, including an administrator's, and take over that a= ccount via a password reset. It further allows an attacker-controlled custo= mer record to be associated with an arbitrary user, and discloses customer = identifiers and email addresses to any authenticated user, which together m= ake the takeover reachable from a subscriber-level account alone.</td> <td>2026-09-06</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18480" target=3D= "_blank" rel=3D"noopener">CVE-2026-18480</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--SureForms<br>=C2=A0</td>
<td>The SureForms - Contact Form Builder, AI Forms, Payment Form, Survey &a= mp; Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting = via Text Field Entity-Encoded Payload in all versions up to, and including,=
2.12.2 due to insufficient input sanitization and output escaping. This ma= kes it possible for unauthenticated attackers to inject arbitrary web scrip=
ts in pages that will execute whenever a user accesses an injected page.</t=
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18406" target=3D= "_blank" rel=3D"noopener">CVE-2026-18406</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--The Contact Form<br>=C2=A0</=
<td>The Contact Form by Supsystic plugin for WordPress is vulnerable to Sto= red Cross-Site Scripting via IP Address Header in all versions up to, and i= ncluding, 1.10.2 due to insufficient input sanitization and output escaping=
. This makes it possible for unauthenticated attackers to inject arbitrary = web scripts in pages that will execute whenever a user accesses an injected=
page. An unauthenticated attacker can first call the 'updateNonce' action =
- which is accessible without authentication due to its absence from the pl= ugin's permission list - to obtain a valid nonce, then submit a contact for=
m with a malicious payload in a spoofed IP header such as X-Forwarded-For.<=
<td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83625" target=3D= "_blank" rel=3D"noopener">CVE-2026-83625</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--The Music Store<br>=C2=A0</t=
<td>The Music Store WordPress plugin before 1.4.5 does not sanitise and esc= ape user input before using it in a SQL statement, leading to a SQL injecti=
on exploitable by unauthenticated users.</td>
<td>2026-09-05</td>
<td>8.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82304" target=3D= "_blank" rel=3D"noopener">CVE-2026-82304</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--W3 Total Cache<br>=C2=A0</td=
<td>The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-S= ite Scripting via Comment Content via LazyLoad Background Mutator in all ve= rsions up to, and including, 2.10.5 due to insufficient input sanitization = and output escaping. This makes it possible for unauthenticated attackers t=
o inject arbitrary web scripts in pages that will execute whenever a user a= ccesses an injected page. This requires the "Lazy Load Images" feature with=
"Process background images" to be enabled, and the malicious comment to be=
approved by a moderator before execution is triggered.</td> <td>2026-09-05</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78438" target=3D= "_blank" rel=3D"noopener">CVE-2026-78438</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Welcart e-Commerce<br>=C2=A0= </td>
<td>The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object=
Injection in all versions up to, and including, 2.12.1 via deserialization=
of untrusted input in the Telecom EDY payment callback (usces_action_actin= g_transaction). Unauthenticated attackers can store arbitrary 'reserve' key= /value pairs as order metadata during a public checkout, then invoke the ca= llback with an attacker-chosen 'option' parameter to select and unserialize=
that metadata without any provider signature, source-address, transaction-= identity or ownership check. A POP chain is present in the TCPDF library bu= ndled with the plugin itself, so no additional plugin or theme is required.=
This makes it possible for unauthenticated attackers to delete arbitrary f= iles on the server, including wp-config.php, which can lead to remote code = execution when an attacker re-runs the WordPress installer against a databa=
se they control. Successful exploitation is contingent on an admin printing=
an invoice to trigger file deletion.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19887" target=3D= "_blank" rel=3D"noopener">CVE-2026-19887</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--WooCommerce=C2=A0<br>=C2=A0<=
<td>The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerab=
le to Privilege Escalation in all versions up to, and including, 10.7.1. Th=
is is due to missing capability checks and nonce verification on multiple A= JAX actions including wcap_save_connector_settings, wcap_send_manual_email,=
wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it=
possible for authenticated attackers, with subscriber-level access and abo= ve, to modify SMTP connector settings to route administrator recovery email=
s through an attacker-controlled server and intercept auto-login links to g= ain full administrative access. The plugin's auto-login feature must be ena= bled, which is the default configuration.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81543" target=3D= "_blank" rel=3D"noopener">CVE-2026-81543</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugins--HT Menu<br>=C2=A0</td>
<td>The HT Menu WordPress plugin before 1.2.7 does not perform any capabili=
ty or object-ownership check when saving navigation menu-item settings, and=
does not escape those stored settings when the menu is rendered, allowing = users with minimal permissions such as Subscribers to store JavaScript that=
executes in the browser of any visitor, administrators included, who views=
the affected menu.</td>
<td>2026-09-05</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84935" target=3D= "_blank" rel=3D"noopener">CVE-2026-84935</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugins--JCH Optimize<br>=C2=A0</td> <td>The JCH Optimize WordPress plugin before 6.0.1 does not perform a capab= ility check on one of its authenticated AJAX actions and lets the request c= hoose which internal action runs, allowing any authenticated users such as = Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 = settings and store a script that executes in the browser of any visitor or = administrator viewing the site.</td>
<td>2026-09-05</td>
<td>8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84934" target=3D= "_blank" rel=3D"noopener">CVE-2026-84934</a></td>
</tr>
<td class=3D"vendor-product">Worklenz--worklenz</td>
<td>Worklenz through 3.0.0 fails to properly validate the sort-field query = parameter in pagination helper functions, allowing authenticated users to i= nject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can=
use time-based and boolean-based blind SQL injection techniques to extract=
sensitive database content including password hashes from other tenants. T= his is an incomplete fix for CVE-2026-25947.</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85388" target=3D= "_blank" rel=3D"noopener">CVE-2026-85388</a></td>
</tr>
<td class=3D"vendor-product">worschtebrot--Affiliate Super Assistent</td> <td>The Affiliate Super Assistent plugin for WordPress is vulnerable to Sto= red Cross-Site Scripting via the 'doCommentShortcode' function in all versi= ons up to, and including, 1.10.2 due to insufficient input sanitization and=
output escaping. This makes it possible for unauthenticated attackers to i= nject arbitrary web scripts in pages that will execute whenever a user acce= sses an injected page.</td>
<td>2026-09-01</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19573" target=3D= "_blank" rel=3D"noopener">CVE-2026-19573</a></td>
</tr>
<td class=3D"vendor-product">WP Legal Pages--WP Cookie Notice for GDPR, CCP=
A & ePrivacy Consent</td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in WP Leg=
al Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Usin=
g Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA &=
ePrivacy Consent: from n/a through 4.4.1.</td>
<td>2026-08-31</td>
<td>10</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82970" target=3D= "_blank" rel=3D"noopener">CVE-2026-82970</a></td>
</tr>
<td class=3D"vendor-product">WP Manage Ninja--Fluent Forms Pro Add On Pack<=
<td>Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack &= lt;=3D 6.2.12 versions.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81296" target=3D= "_blank" rel=3D"noopener">CVE-2026-81296</a></td>
</tr>
<td class=3D"vendor-product">WP Manage Ninja--Fluent Forms Pro Add On Pack<=
<td>Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <=3D=
6.2.12 versions.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81297" target=3D= "_blank" rel=3D"noopener">CVE-2026-81297</a></td>
</tr>
<td class=3D"vendor-product">WP Swings--Upsell Order Bump Offer for WooComm= erce</td>
<td>Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer f=
or WooCommerce <=3D 3.1.5 versions.</td>
<td>2026-09-02</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81288" target=3D= "_blank" rel=3D"noopener">CVE-2026-81288</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--Mail Mint</td>
<td>Unauthenticated PHP Object Injection in Mail Mint <=3D 1.31.0 versio= ns.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84753" target=3D= "_blank" rel=3D"noopener">CVE-2026-84753</a></td>
</tr>
<td class=3D"vendor-product">wplegalpages--WPLP Cookie Consent Cookie Banne=
r & Consent Management for GDPR, CCPA & Google Consent Mode</td> <td>The WPLP Cookie Consent - Cookie Banner & Consent Management for GD= PR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to ar= bitrary file upload due to missing file type validation in the saas_upload_= logo() function combined with an authorization bypass on the WPLP connector=
REST endpoints in all versions up to, and including, 4.4.1. This makes it = possible for unauthenticated attackers to upload arbitrary files on the aff= ected site's server which may make remote code execution possible.</td> <td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75865" target=3D= "_blank" rel=3D"noopener">CVE-2026-75865</a></td>
</tr>
<td class=3D"vendor-product">wpmudev--Broken Link Checker</td>
<td>The Broken Link Checker plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via Comment Author URL / Link Log in all versions up to,=
and including, 2.4.13 due to insufficient input sanitization and output es= caping. This makes it possible for unauthenticated attackers to inject arbi= trary web scripts in pages that will execute whenever a user accesses an in= jected page. Exploitation requires an administrator to perform the plugin's=
standard dismiss-and-recheck workflow on a link submitted by the attacker = via the WordPress comment author URL field, after which the attacker's HTTP=
server issues a redirect to a URL containing an HTML/JavaScript payload th=
at is stored verbatim in the link log.</td>
<td>2026-09-02</td>
<td>7.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75528" target=3D= "_blank" rel=3D"noopener">CVE-2026-75528</a></td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 Open Banking AM</td>
<td>The administrative operations within the Carbon Console do not adequate=
ly validate specific user-supplied input. This oversight allows a malicious=
actor with administrative privileges to inject and execute arbitrary code = remotely. Successful exploitation enables a threat actor with administrativ=
e privileges and Carbon Console access to execute remote arbitrary code thr= ough specific administrative operations, leading to a complete compromise o=
f the affected system.</td>
<td>2026-09-03</td>
<td>8.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12737" target=3D= "_blank" rel=3D"noopener">CVE-2025-12737</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo (current e01e41ecc and earlier) makes three login-time secu= rity controls depend solely on the client-supplied User-Agent header. The i= sAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a=
hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or = shared secret. An attacker who submits valid credentials and sets User-Agen=
t: AVideoEncoder bypasses two-factor authentication, skips brute-force capt= cha escalation, and avoids being recorded in the login/device audit history=
. No patch is available at the time of publication.</td>
<td>2026-09-01</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84479" target=3D= "_blank" rel=3D"noopener">CVE-2026-84479</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo fails to validate password recovery token expiration in use= rRecoverPassSave.json.php, allowing attackers to use expired tokens to rese=
t account passwords indefinitely. Attackers who obtain a recovery token can=
use it at any time to change the target account's password and gain full a= ccount access.</td>
<td>2026-09-01</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84480" target=3D= "_blank" rel=3D"noopener">CVE-2026-84480</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo contains an authentication failure vulnerability where the = video_id_hash credential is a non-expiring, non-revocable bearer token that=
grants full administrator session access to the video owner's account. Att= ackers who obtain a video_id_hash can replay it indefinitely to authenticat=
e as the video owner with full privileges, and the credential remains valid=
even after the owner changes their password.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85154" target=3D= "_blank" rel=3D"noopener">CVE-2026-85154</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo contains a cross-site request forgery vulnerability in plugin/AP= I/set.json.php that allows attackers to perform state-changing actions by c= rafting GET requests that bypass CSRF protection. Attackers can navigate a = victim's browser to a malicious URL with API parameters to delete videos, d= eactivate accounts, or modify playlists without user interaction.</td> <td>2026-09-01</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83595" target=3D= "_blank" rel=3D"noopener">CVE-2026-83595</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo contains a missing authentication vulnerability in plugin/Live/o= n_publish.php that allows unauthenticated attackers to mark arbitrary sched= uled broadcasts as failed by sending crafted POST requests with schedule id= entifiers. Attackers can exploit the unguarded RTMP callback endpoint to mo= dify scheduled broadcast status fields by supplying fabricated stream keys = matching the pattern -ps-<N>, silently canceling any scheduled live b= roadcast without credentials or authorization.</td>
<td>2026-09-01</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84187" target=3D= "_blank" rel=3D"noopener">CVE-2026-84187</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo through commit 9c39d8c8 contains a cross-site request forge=
ry vulnerability in the get_domain() and isSameDomain() functions that fail=
to properly validate referer origins. Attackers can forge requests from si= bling subdomains or unparseable long-gTLD origins to perform administrative=
ObjectYPT writes including live server configuration changes.</td> <td>2026-09-01</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84482" target=3D= "_blank" rel=3D"noopener">CVE-2026-84482</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a cross-site request forgery a=
nd path traversal vulnerability in stopLive.php that allows attackers to de= lete directories by exploiting missing token validation and unsanitized key=
parameter concatenation. Attackers can craft an image tag with a traversal=
payload like key=3D../../videos to trigger recursive deletion of the video=
s directory when an admin visits a malicious page.</td>
<td>2026-09-03</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85160" target=3D= "_blank" rel=3D"noopener">CVE-2026-85160</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through version 29.0 contains an unauthenticated SQL injection v= ulnerability in the User_Location plugin's regions.json.php and cities.json= .php endpoints. The country and region GET parameters are passed directly i= nto SQL queries without escaping or prepared statement binding, allowing un= authenticated attackers to execute UNION-based SQL injection to read arbitr= ary database contents including password hashes and sensitive data.</td> <td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84208" target=3D= "_blank" rel=3D"noopener">CVE-2026-84208</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo fails to validate trusted proxies before accepting X-Real-I=
P and X-Forwarded-For headers, allowing attackers to spoof the client addre=
ss used by enforceRateLimit(). Attackers can rotate the header value per re= quest to bypass login rate limiting and perform unlimited credential guessi=
ng attacks.</td>
<td>2026-09-01</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84476" target=3D= "_blank" rel=3D"noopener">CVE-2026-84476</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo contains a path traversal vulnerability in the API get_api_= login_code endpoint that allows unauthenticated attackers to delete arbitra=
ry .log files by supplying directory traversal sequences in the code parame= ter. Attackers can exploit this to destroy audit logs and probe for file ex= istence on the server, with the vulnerability enabling both file deletion a=
nd information disclosure about the filesystem.</td>
<td>2026-09-01</td>
<td>7.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84478" target=3D= "_blank" rel=3D"noopener">CVE-2026-84478</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo contains a SQL injection vulnerability in the sort column p= arameter of the get.json.php endpoint with APIName=3Dchannels that allows u= nauthenticated attackers to order results by arbitrary database columns inc= luding users.password and users.recoverPass. Attackers can exploit this ord= ering oracle to infer password hash values and recovery tokens, and trigger=
SQL errors that disclose the full query statement and database schema.</td=
<td>2026-09-03</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85155" target=3D= "_blank" rel=3D"noopener">CVE-2026-85155</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo through commit c91b5975d contains a server-side request for= gery vulnerability in the set_api_userImages API endpoint that fails to val= idate profileImg and backgroundImg URLs before fetching them. Authenticated=
API clients can supply internal URLs to fetch cloud metadata or internal s= ervices, with responses written to publicly accessible web paths for retrie= val.</td>
<td>2026-09-03</td>
<td>7.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85164" target=3D= "_blank" rel=3D"noopener">CVE-2026-85164</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo<br>=C2=A0</td>
<td>WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.js= on.php that allows unauthenticated attackers to write files to arbitrary lo= cations by supplying a caller-chosen path in the avideoRelativePath paramet= er. Attackers can replay any previously issued ciphertext as a notifyCode t= oken, which is decrypted but never validated, to bypass authentication and = write files to the application root and subdirectories.</td>
<td>2026-09-05</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86189" target=3D= "_blank" rel=3D"noopener">CVE-2026-86189</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo<br>=C2=A0</td>
<td>WWBN AVideo contains a broken access control vulnerability in videoView= sInfo endpoints that returns complete user records including password hashe=
s, recovery tokens, and live session identifiers to unauthenticated callers=
when a hash parameter is provided. Attackers can use the disclosed session=
identifier to hijack viewer sessions, including administrator accounts, an=
d obtain sensitive personal data for all video viewers.</td>
<td>2026-09-05</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86190" target=3D= "_blank" rel=3D"noopener">CVE-2026-86190</a></td>
</tr>
<td class=3D"vendor-product">X-Series Gateway--X-Series Gateway Firmware V6= </td>
<td>An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker =
to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/u= gwdownload.cgi.</td>
<td>2026-09-04</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75160" target=3D= "_blank" rel=3D"noopener">CVE-2026-75160</a></td>
</tr>
<td class=3D"vendor-product">xorbitsai--inference</td>
<td>Xinference (affected commit 4a94832, v3.x) contains an unauthenticated = arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-regi= ster endpoint, which accepts a caller-supplied model_path parameter without=
authentication or path confinement. The endpoint reads and parses config.j= son, tokenizer_config.json, and chat_template.jinja files at the supplied p= ath and reflects the parsed content back to the caller, allowing an unauthe= nticated attacker to probe the server filesystem and extract content of fil=
es with those names in any directory.</td>
<td>2026-09-04</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85668" target=3D= "_blank" rel=3D"noopener">CVE-2026-85668</a></td>
</tr>
<td class=3D"vendor-product">XueZhiSi--Open Source Exam System</td>
<td>The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiS=
i Open Source Exam System <=3D 3.9.0 contains a vertical privilege escal= atio vulnerability. This interface accepts a user ID and then executes getU= serById(id), setDeleted(true), updateByIdFilter() in sequence, without any = validation of whether the current user has the authority to delete the targ=
et user. An authenticated teacher user (role=3D2) can delete an administrat=
or account (role=3D3), constituting a vertical privilege escalation where a=
lower-privileged user performs a high-privileged operation.</td> <td>2026-08-31</td>
<td>8.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75458" target=3D= "_blank" rel=3D"noopener">CVE-2026-75458</a></td>
</tr>
<td class=3D"vendor-product">yacy--yacy_search_server</td>
<td>YaCy Search Server through 1.941 contains an XML external entity inject= ion vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to dis= able external entity resolution. Attackers can publish malicious documents = with DOCTYPE declarations containing SYSTEM entities pointing to local file=
s, causing the crawler to exfiltrate file contents into the searchable inde= x.</td>
<td>2026-08-31</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82880" target=3D= "_blank" rel=3D"noopener">CVE-2026-82880</a></td>
</tr>
<td class=3D"vendor-product">YesWiki --YesWiki=C2=A0<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWik= i's public Bazar entry-listing APIs are vulnerable to unauthenticated SQL i= njection in numeric query / queries filters. For Bazar fields whose value s= tructure is numeric, YesWiki escapes the attacker-controlled filter value b=
ut inserts it into SQL without quotes or numeric validation. An unauthentic= ated attacker can inject boolean SQL expressions and infer database content=
s from whether entries are returned. This issue has been patched in version=
4.6.6.</td>
<td>2026-09-05</td>
<td>7.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52770" target=3D= "_blank" rel=3D"noopener">CVE-2026-52770</a></td>
</tr>
<td class=3D"vendor-product">YesWiki-- YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{= erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) a= ccepts a suppr[] array from POST and deletes every wiki page whose tag appe= ars in that array, with no authorization check anywhere in the action body =
or in the page-deletion path it invokes. Combined with YesWiki's allow-by-d= efault action ACL model, any user who has page write access, which is the d= efault for everyone (default_write_acl=3D'*') on a fresh install can perman= ently delete arbitrary wiki pages, including the front page, admin pages, a=
nd pages owned by other users. This issue has been patched in version 4.6.6= .</td>
<td>2026-09-05</td>
<td>9.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52766" target=3D= "_blank" rel=3D"noopener">CVE-2026-52766</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWik=
i through the latest development branch contains a SQL injection vulnerabil= ity in ReactionManager::deleteUserReaction() that allows any authenticated = user to inject arbitrary SQL via the {idreaction} and {id} URL path paramet= ers. The parameters are concatenated directly into a SQL LIKE clause withou=
t escaping or parameterization. This issue has been patched in version 4.6.= 6.</td>
<td>2026-09-05</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52775" target=3D= "_blank" rel=3D"noopener">CVE-2026-52775</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. From version 4.6.2 to before v= ersion 4.6.6, HttpSignatureService::verifySignature() checks the result of = PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(= ...)) { throw ... }. PHP's openssl_verify has four possible return values: =
1, 0, -1, and "false". The -1 row is the bypass: PHP's truthiness rules mak=
e -1 a truthy value, so !(-1) =3D=3D=3D false, the throw is skipped, and th=
e controller proceeds to processActivity(). Any condition that makes OpenSS= L's EVP_VerifyFinal() return -1 triggers the bypass. The reachable conseque= nce is the controller silently treats a failed verification as success and = processes the attacker's payload. This issue has been patched in version 4.= 6.6.</td>
<td>2026-09-05</td>
<td>8.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52767" target=3D= "_blank" rel=3D"noopener">CVE-2026-52767</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. From version 4.6.2 to before v= ersion 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publ= icly with acl:"public" - accepts an HTTP Signature header whose keyId param= eter is a URL. HttpSignatureService::verifySignature() parses the header an=
d immediately makes a server-side HTTP GET to that URL, before any cryptogr= aphic verification or URL validation. An unauthenticated remote attacker ca=
n therefore make YesWiki issue arbitrary outbound HTTP requests to any host=
the server can reach - internal services, cloud-metadata endpoints (169.25= 4.169.254), intranet-only admin panels, etc. - and read enough back via tim= ing and error-message oracles to scan ports, enumerate services, and (on a = real cloud instance) reach IAM metadata. The only deployment-side precondit= ion is that ActivityPub be enabled on at least one Bazar form. This issue h=
as been patched in version 4.6.6.</td>
<td>2026-09-05</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52769" target=3D= "_blank" rel=3D"noopener">CVE-2026-52769</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. From version 4.2.0 to before v= ersion 4.6.6, ApiController::deletePage() interpolates a page tag retrieved=
from the database into a DELETE FROM =C2=A6_links WHERE to_tag =3D '$tag' = query without escaping. The page tag is attacker-controlled - the POST /api= /pages/{tag} API accepts arbitrary URL-encoded values, including single quo= tes, and stores them. A low-privilege authenticated user can therefore crea=
te a page whose tag is a SQL fragment, make the page non-orphaned via the s= tandard {{include page=3D"=C2=A6"}} link mechanism, and then invoke the del= ete endpoint to execute arbitrary SQL inside the wiki database - including = time-based blind data exfiltration from any table. This issue has been patc= hed in version 4.6.6.</td>
<td>2026-09-05</td>
<td>8.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52771" target=3D= "_blank" rel=3D"noopener">CVE-2026-52771</a></td>
</tr>
<td class=3D"vendor-product">YITH--YITH Request a Quote for WooCommerce Pre= mium</td>
<td>Unauthenticated Broken Access Control in YITH Request a Quote for WooCo= mmerce Premium < 4.46.0 versions.</td>
<td>2026-09-03</td>
<td>9.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84238" target=3D= "_blank" rel=3D"noopener">CVE-2026-84238</a></td>
</tr>
<td class=3D"vendor-product">zhenorzz--goploy</td>
<td>Goploy is an open-source automation deployment system. In versions 1.17=
.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Pr= oject.Edit in cmd/server/api/project/handler.go accept a project or project= -file row id from the JSON body and act on it without checking that the pro= ject belongs to the caller's namespace. The corresponding model.ProjectFile= .GetData and model.Project.GetData queries filter only by row id. A user ho= lding the manager role (or any role that includes the FileSync / EditProjec=
t permission) in their own namespace can read, write, or delete files in an=
y project across the install, and can rewrite any project's git remote URL =
by submitting the foreign id in the body. The git-URL primitive escalates t=
o RCE on the next deploy because Edit runs git remote set-url on the projec= t's working tree. At time of publication, there are no known publicly avail= able patches.</td>
<td>2026-08-31</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53552" target=3D= "_blank" rel=3D"noopener">CVE-2026-53552</a></td>
</tr>
<td class=3D"vendor-product">zhenorzz--goploy</td>
<td>Goploy is an open-source automation deployment system. Prior to version=
1.18.0, a severe path traversal vulnerability exists in its backend API en= dpoints, specifically /deploy/fileDiff (File Compare), when handling file p= aths provided by the client. This issue has been patched in version 1.18.0.= </td>
<td>2026-08-31</td>
<td>7.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53553" target=3D= "_blank" rel=3D"noopener">CVE-2026-53553</a></td>
</tr>
<td class=3D"vendor-product">zlib--zlib</td>
<td>zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vuln= erability in the gz_vacate() function when processing non-blocking gzwrite(=
) operations with stale external buffer pointers. Attackers can trigger the=
overflow by calling gzprintf() or gzvprintf() after a write stall, causing=
an unchecked memmove() to write beyond the internal input buffer boundary.= </td>
<td>2026-09-03</td>
<td>7.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85091" target=3D= "_blank" rel=3D"noopener">CVE-2026-85091</a></td>
</tr>
<td class=3D"vendor-product">Zohocorp--ManageEngine Password Manager Pro</t=
<td>Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM36=
0 versions before 8561, and Access Manager Plus versions before 4405 are vu= lnerable to an authenticated SQL Injection vulnerability.</td> <td>2026-09-02</td>
<td>8.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14828" target=3D= "_blank" rel=3D"noopener">CVE-2026-14828</a></td>
</tr>
<td class=3D"vendor-product">ZTE--ZXDU68 S202 V5.0</td>
<td>Attackers can exploit command injection vulnerabilities to delete core = system runtime files, causing the monitoring module to crash and become par= alyzed; simultaneously, they can obtain root privileges to steal configurat= ion passwords such as SNMP, thereby tampering with critical system paramete=
rs and triggering abnormal operation of the entire power system.</td> <td>2026-08-31</td>
<td>9.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49003" target=3D= "_blank" rel=3D"noopener">CVE-2026-49003</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"medium_v">
<h2 id=3D"medium_v_title">Medium Vulnerabilities</h2>
<table class=3D"table table-style-align-center no-tablesaw" style=3D"table-= layout: fixed; width: 100%;" border=3D"1" summary=3D"Medium Vulnerabilities=
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">2FastLabs--agent-squad</td>
<td>A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affe= cted by this vulnerability is the function AgentSquad.routeRequest of the f= ile agent-squad/typescript/src/orchestrator.ts of the component Streaming A= gent Response Workflow. The manipulation results in resource consumption. I=
t is possible to launch the attack remotely. The exploit is now public and = may be used. The project was informed of the problem early through an issue=
report but has not responded yet.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85100" target=3D= "_blank" rel=3D"noopener">CVE-2026-85100</a></td>
</tr>
<td class=3D"vendor-product">Admidio--admidio</td>
<td>Admidio is an open-source user management solution. In versions 5.0.11 = and prior, the modules/plugins.php endpoint handles plugin installation, un= installation, and update operations via GET requests without CSRF token val= idation. Because these are top-level navigations, browsers include SameSite= =3DLax session cookies. An attacker crafts a malicious page that, when an a= uthenticated administrator visits it, triggers arbitrary plugin operations.=
The uninstall operation executes DROP TABLE SQL scripts and destroys plugi=
n data. This issue has been patched via commit 056b1bd.</td> <td>2026-09-04</td>
<td>5.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53760" target=3D= "_blank" rel=3D"noopener">CVE-2026-53760</a></td>
</tr>
<td class=3D"vendor-product">agentverus--agentverus-scanner</td> <td>agentverus-scanner fails to analyze compiled Python bytecode files in c= ompanion code directories, allowing attackers to bypass security scanning b=
y shipping malicious __pycache__ entries alongside benign source files. Att= ackers can execute arbitrary Python bytecode on import while the scanner re= ports a CERTIFIED verdict with high trust scores in both static and semanti=
c analysis modes.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84811" target=3D= "_blank" rel=3D"noopener">CVE-2026-84811</a></td>
</tr>
<td class=3D"vendor-product">AirAsia--MOVE App</td>
<td>A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Andro= id. This issue affects the function com.airasia.core.utils.RealPathUtil.get= RealPath of the component com.airasia.mobile. Performing a manipulation of = the argument _display_name results in path traversal. The attack requires a=
local approach. The exploit is now public and may be used. The vendor was = contacted early about this disclosure but did not respond in any way.</td> <td>2026-09-02</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84431" target=3D= "_blank" rel=3D"noopener">CVE-2026-84431</a></td>
</tr>
<td class=3D"vendor-product">Ajaxify Comments--Ajaxify Comments</td>
<td>The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP = Header Injection due to insufficient input sanitization and output escaping=
on user-supplied data. This makes it possible for unauthenticated attacker=
s to inject arbitrary HTTP headers.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2811" target=3D"= _blank" rel=3D"noopener">CVE-2026-2811</a></td>
</tr>
<td class=3D"vendor-product">All in One SEO--All in One SEO</td>
<td>The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise an=
d escape some content stored in posts before rendering it back in the post = editor, which could allow users with the contributor role and above to perf= orm Stored Cross-Site Scripting attacks that trigger when a higher privileg=
ed user edits the post.</td>
<td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82884" target=3D= "_blank" rel=3D"noopener">CVE-2026-82884</a></td>
</tr>
<td class=3D"vendor-product">Amazon --awslabs postgres-mcp-server=C2=A0<br>= =C2=A0</td>
<td>An incomplete list of disallowed inputs in the SQL validation component=
in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an = unauthenticated actor to modify data beyond the read-only scope by placing = crafted SQL into the content that is submitted when an authenticated user i= nteracts with the MCP server. To remediate this issue, users should upgrade=
to version 1.1.7 or above.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85787" target=3D= "_blank" rel=3D"noopener">CVE-2026-85787</a></td>
</tr>
<td class=3D"vendor-product">andrii-kryvoviaz--slink</td>
<td>Slink before 1.12.3 fails to properly authorize access to image comment=
endpoints, allowing unauthenticated attackers to read comment threads via = GET /api/image/{imageId}/comments and server-sent-events subscriptions. Att= ackers who obtain image IDs out of band can retrieve full comment threads o=
n public images and subscribe to live comment updates without authenticatio=
n or authorization checks.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85605" target=3D= "_blank" rel=3D"noopener">CVE-2026-85605</a></td>
</tr>
<td class=3D"vendor-product">apache -- shiro</td>
<td>When Apache Shiro is used with the Jakarta EE integration module, a low= -privileged user can craft an HTTP request that causes the server to initia=
te a connection to an attacker-controlled URL and transmit attacker-control= led data. This vulnerability affects Apache Shiro versions 2.x through 3.0.=
0 only in deployments that use the Jakarta EE integration module. Mitigatio=
n: Upgrade to version 3.0.1 or later, which fixes the issue. + Alternativel=
y, you can set the `org.apache.shiro.form-resubmit-host` (String) and `org.= apache.shiro.form-resubmit-port` (Integer) system properties to restrict th=
e host and port that Shiro will connect to when resubmitting a form.</td> <td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-58301" target=3D= "_blank" rel=3D"noopener">CVE-2026-58301</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper neutralization of input during web page generation in Apache W= icket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the b= ase class of DropDownChoice, writes the body of the default option - the en= try shown when no choice is selected - into the markup as it is, while ever=
y other option body in the same select is escaped according to the escape-m= odel-strings setting. The body comes from getNullValidDisplayValue() or get= NullKeyDisplayValue(), both of which are protected, so what they return is = not necessarily the plain text the default implementation reads from a reso= urce bundle. An application is affected where it overrides one of those met= hods and returns a value holding data an attacker can influence, or where i=
ts own nullValid or null bundle entry holds such a value. The bundles shipp=
ed with Wicket contain plain text. RadioChoice overrides getDefaultChoice t=
o emit no default option and is not affected. As a workaround, escape the v= alue in the override. This issue affects Apache Wicket: from 8.0.0 through = 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsu= pported releases from 1.5.0 onwards are also affected. Users are recommende=
d to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.</td=
<td>2026-08-31</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76986" target=3D= "_blank" rel=3D"noopener">CVE-2026-76986</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper validation of resource URL attributes in Apache Wicket allows =
an unauthenticated remote attacker to read files from the web application, = including files under WEB-INF that the servlet container would not otherwis=
e serve. The locale, style and variation attributes decoded from a package = resource URL are spliced into the resource lookup path without being checke=
d for path separators. The IPackageResourceGuard - whose rejection of .. is=
one of the two intended controls - is applied to the resource name before = those attributes are appended, and WebApplicationPath rejects only paths li= terally beginning with WEB-INF/. Neither control ever inspects the attacker= -controlled portion of the path. On servlet containers that normalize .. in=
ServletContext.getResource(), a crafted request therefore escapes the inte= nded package directory. The set of readable files is limited to the file ex= tensions permitted by the configured IPackageResourceGuard. The default Sec= urePackageResourceGuard permits only js, css, png, jpg, jpeg, gif, ico, cur=
, map, html, txt, swf, bmp, svg, avif, eot, ttf, woff and woff2, which excl= udes configuration formats. Applications that have added patterns to the gu= ard, or replaced it with the blocklist-based PackageResourceGuard, can addi= tionally disclose configuration files such as web.xml. Independently of the=
extension, the lookup performed before the guard runs acts as an existence=
oracle for arbitrary paths. This issue affects Apache Wicket 8.18.0 and be= fore, 9.23.0 and before and 10.10.0 and before. Users are recommended to up= grade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue. Users of A= pache Wicket 7.x or older, which are no longer supported, should upgrade to=
a supported version.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70449" target=3D= "_blank" rel=3D"noopener">CVE-2026-70449</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>AjaxEditableChoiceLabel in wicket-extensions, when constructed with a n= on-null IChoiceRenderer, writes the display value obtained from that render=
er into the label's markup without applying the HTML escaping Wicket perfor=
ms by default for component model values. An attacker who can influence the=
choice or model data rendered by such a label can inject HTML or script th=
at executes in the browser of any user who views the page. The same value i=
s correctly escaped when the component's dropdown editor renders it as an o= ption, so only the label rendering is affected. AjaxEditableLabel, AjaxEdit= ableChoiceLabel and AjaxEditableMultiLineLabel write the value returned by = the protected defaultNullLabel() method into the label's markup the same wa=
y when the component's model is empty, while the model value they show othe= rwise is escaped. The default implementation returns a constant, so an appl= ication is affected where it overrides that method and returns a value an a= ttacker can influence. Neither value could be escaped by configuration, bec= ause escapeModelStrings had no effect on any of the three components: it is=
read by the label they render with rather than by the component itself, an=
d nothing carried the setting across. This issue affects Apache Wicket: fro=
m 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.1= 0.0. Older, unsupported releases are also affected; the display value from = the renderer since 6.22.0 and the null label since 1.4.0. Users are recomme= nded to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.<=
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75802" target=3D= "_blank" rel=3D"noopener">CVE-2026-75802</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper neutralization of input during web page generation in Apache W= icket. org.apache.wicket.markup.html.form.Button clears the escape-model-st= rings flag in its constructor, so that the value attribute it writes is not=
encoded twice - ComponentTag already encodes attribute values when it writ=
es the tag. That reasoning holds only for the attribute. When the component=
is attached to a <button> element rather than an <input>, it w= rites its model object into the element body instead, and nothing encodes a=
n element body, so markup in the model is rendered as markup. An applicatio=
n is affected where it renders a Button on a <button> element and tha=
t button's model holds data an attacker can influence. Wicket cannot determ= ine where a model value comes from, so whether it reaches the page from a r= equest or from storage is a property of the application. The subclasses tha=
t inherit this constructor - AjaxButton, AjaxFallbackButton and WizardButto=
n - are affected on the same terms. As a workaround, calling setEscapeModel= Strings(true) on a button that renders as a <button> element escapes = the body correctly, and does not cause double encoding, because the value a= ttribute is written only for <input> elements. This issue affects Apa= che Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0=
.0 through 10.10.0. Older, unsupported releases from 6.25.0 and 7.5.0 onwar=
ds are also affected. Users are recommended to upgrade to version 8.19.0, 9= .24.0 or 10.11.0, which fix the issue.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76982" target=3D= "_blank" rel=3D"noopener">CVE-2026-76982</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper neutralization of input during web page generation in Apache W= icket. The <wicket:label> tag is provided by org.apache.wicket.markup= .html.form.AutoLabelTextResolver, which is registered by default in every W= ebApplication. The resolver writes the label it finds into the markup as it=
is, and reads no escaping setting at all, so markup in a label is rendered=
as markup. When the label comes from the labelled component's label model,=
set through FormComponent#setLabel(IModel), it is written to the markup un= escaped.=C2=A0An application is affected where the label of a form componen=
t holds data an attacker can influence. Wicket cannot determine where a mod=
el value comes from, so whether it reaches the page from a request or from = storage is a property of the application. There is no workaround. Unlike ev= ery other rendering path in Wicket, the resolver never consulted the escape= -model-strings setting, so an application had no way to ask for the label t=
o be escaped. The body of a <wicket:label> tag is markup by design an=
d is not affected; it remains the supported way to place markup in a label.=
This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 th= rough 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from=
1.5.0 onwards are also affected. Users are recommended to upgrade to versi=
on 8.19.0, 9.24.0 or 10.11.0, which fix the issue.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76983" target=3D= "_blank" rel=3D"noopener">CVE-2026-76983</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper neutralization of input during web page generation in Apache W= icket. org.apache.wicket.markup.head.MetaDataHeaderItem generates <meta&= gt; and <link> header tags. It escaped the attribute names it wrote, = but ran the attribute values through a replacement of " with \". A backslas=
h before a double quote means nothing in HTML, so a value containing a doub=
le quote ends its own attribute and what follows is parsed as further attri= butes of the generated tag. An application is affected where it supplies an=
attribute value holding data an attacker can influence, through addTagAttr= ibute or the forMetaTag and forLinkTag factory methods. A value may be give=
n as an IModel, so it is not necessarily a literal. There is no setting to = change; an application can only avoid supplying a value that contains a dou= ble quote. Note that these values have never been escaped effectively: befo=
re the change released in 6.24.0, 7.4.0 and 8.0.0 they were written with no=
escaping at all. This issue affects Apache Wicket: from 8.0.0 through 8.18= .0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsuppor= ted releases from 6.17.0 onwards are also affected. Users are recommended t=
o upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.</td> <td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76984" target=3D= "_blank" rel=3D"noopener">CVE-2026-76984</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td>
<td>Improper neutralization of input during web page generation in Apache W= icket. org.apache.wicket.extensions.markup.html.form.palette.component.Abst= ractOptions, which renders the two option lists of a Palette, escapes the i=
d and the display value of each option according to the escape-model-string=
s setting, and wrote the attribute names and values returned by getAddition= alAttributes into the <option> tag as they came. An application is af= fected where it overrides Palette.getAdditionalAttributesForChoices, Palett= e.getAdditionalAttributesForSelection or AbstractOptions.getAdditionalAttri= butes and returns a value holding data an attacker can influence. These met= hods return null by default, so an application that does not override them =
is not affected. As a workaround, escape the values in the override. This i= ssue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9= .23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.4.0 = onwards are also affected. Users are recommended to upgrade to version 8.19= .0, 9.24.0 or 10.11.0, which fix the issue.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76985" target=3D= "_blank" rel=3D"noopener">CVE-2026-76985</a></td>
</tr>
<td class=3D"vendor-product">apache -- wicket</td> <td>ResourceIsolationRequestCycleListener protects a Wicket application aga= inst cross-site=C2=A0request forgery by rejecting requests that a resource = isolation policy judges to come from another origin. Its default policy, Fe= tchMetadataResourceIsolationPolicy, was derived from=C2=A0a reference imple= mentation written to guard static resources, and it inherited two=C2=A0allo= wances that are unsafe when the thing being guarded is an action on a page:=
* Every "simple top-level navigation" was allowed. Any GET request carryin= g=C2=A0Sec-Fetch-Mode: navigate whose Sec-Fetch-Dest was neither object nor=
embed was=C2=A0allowed, whatever Sec-Fetch-Site said - including cross-sit=
e. Wicket invokes component=C2=A0listeners (Link.onClick(), form submits, b= ehaviour callbacks) through ordinary GET=C2=A0navigations, so a page under =
an attacker's control could navigate the victim's browser to a=C2=A0listene=
r URL and have that listener run inside the victim's authenticated session.=
Browsers=C2=A0send SameSite=3DLax cookies - the effective default when no = SameSite attribute is set - on=C2=A0cross-site top-level GET navigations, s=
o the victim's session cookie accompanied the=C2=A0request. * Sec-Fetch-Sit=
e: same-site was allowed unconditionally. That value means the same=C2=A0re= gistrable domain and scheme but a different origin - another subdomain or a= nother=C2=A0port. Any sibling origin could therefore invoke any listener by=
any method, POST form=C2=A0submits included, and cookies are always sent o=
n same-site requests regardless of=C2=A0SameSite. A hostile sibling origin = obtained through a subdomain takeover, through=C2=A0delegated user content,=
or through an XSS elsewhere on the site could act as the=C2=A0authenticate=
d user. Users are recommended to upgrade to version 9.24.0 or 10.11.0, whic=
h fix the issue. Affected versions * Apache Wicket 9.1.0 through 9.23.0 * A= pache Wicket 10.0.0 through 10.10.0 Not affected Any release older than 9.1= .0: * Apache Wicket 8.x (8.0.0 through 8.17.0). The resource isolation clas= ses do not exist in=C2=A0the 8.x line, which offers only the Origin/Referer= -based=C2=A0CsrfPreventionRequestCycleListener. No 8.x release requires a f= ix. * Apache Wicket 9.0.0. ResourceIsolationRequestCycleListener=C2=A0and F= etchMetadataResourceIsolationPolicy were introduced by WICKET-6786 and firs=
t shipped=C2=A0in 9.1.0 (released 2020-10-07).</td>
<td>2026-08-31</td>
<td>4.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71378" target=3D= "_blank" rel=3D"noopener">CVE-2026-71378</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Allura</td> <td>Stored XSS via markdown HTML processing=C2=A0in Apache Allura. This iss=
ue affects Apache Allura: from through 1.20.0. Users are recommended to upg= rade to version=C2=A01.21.0, which fixes the issue.</td>
<td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80180" target=3D= "_blank" rel=3D"noopener">CVE-2026-80180</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Allura</td> <td>Apache Allura: stored XSS via SVN code repositories.=C2=A0 Git reposito= ries are not known to be affected.=C2=A0 The vulnerability is likely mitiga= ted via default CSP headers. This issue affects Apache Allura: through 1.20= .0. Users are recommended to upgrade to version 1.21.0, which fixes the iss= ue.</td>
<td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80190" target=3D= "_blank" rel=3D"noopener">CVE-2026-80190</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Spark</td> <td>There is a lack of XSS escaping in the Spark History Server prior to 3.= 5.8 which allows a malicious Spark job to generate arbitrary unescaped fron= tend code which could lead to a minimal privilege escalation in browser. Us= ers are encouraged to upgrade to Spark 3.5.8 or later. This CVE is marked a=
s "low" since the path to exploit requires both relatively high permissions=
(ability to launch a Spark job) and requires tricking a user with higher p= ermissions to log in and visit the Spark history web page. Users are encour= aged to upgrade their Spark history servers to Spark 3.5.8 or later.</td> <td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32773" target=3D= "_blank" rel=3D"noopener">CVE-2026-32773</a></td>
</tr>
<td class=3D"vendor-product">apconw--Aix-DB</td>
<td>Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html=
bindings without sanitization, allowing stored cross-site scripting attack=
s. Attackers can inject malicious HTML and JavaScript through markdown cont= ent in chat responses, skill descriptions, or knowledge messages that execu=
te in users' browsers when viewed.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82881" target=3D= "_blank" rel=3D"noopener">CVE-2026-82881</a></td>
</tr>
<td class=3D"vendor-product">APITable --APITable<br>=C2=A0</td>
<td>APITable through 1.13.0-beta.1 contains an incorrect authorization vuln= erability in NodePermissionGuard that fails to enforce node-level access co= ntrol when permission lookups throw exceptions. Attackers with valid Fusion=
API tokens can write attachments to private datasheets they have been expl= icitly denied access to by exploiting the unhandled exception in the permis= sion guard.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86120" target=3D= "_blank" rel=3D"noopener">CVE-2026-86120</a></td>
</tr>
<td class=3D"vendor-product">apostrophecms--apostrophe</td>
<td>ApostropheCMS is an open-source Node.js content management system, and = sanitize-html provides a simple HTML sanitizer with a clear API. From versi=
on 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an=
animation value attribute as one flat URL and does not recognize that attr= ibuteName selecting href or xlink:href gives the sibling values, from, to, =
or by attribute SVG SMIL URL semantics. In configurations that allow the an= imate, animateColor, animateMotion, animateTransform, or set elements, a va= lues list can begin with a safe fragment and contain a later executable des= tination that survives allowedSchemesAppliedToAttributes checking. When the=
sanitized SVG is rendered, the browser can copy that later destination int=
o the live link, and a victim who activates the link can execute script in = the application's origin. This issue is fixed in version 2.17.7.</td> <td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84371" target=3D= "_blank" rel=3D"noopener">CVE-2026-84371</a></td>
</tr>
<td class=3D"vendor-product">AppFlowy-IO--AppFlowy-Cloud</td> <td>AppFlowy-Cloud through 0.9.64 fails to validate workspace membership wh=
en establishing WebSocket connections in the establish_ws_connection_v2 han= dler, allowing authenticated users to bind sessions to workspaces they do n=
ot belong to. Attackers can send sync Manifest messages with victim object = identifiers to read full document or database state from collaborations in = other workspaces without victim involvement.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85622" target=3D= "_blank" rel=3D"noopener">CVE-2026-85622</a></td>
</tr>
<td class=3D"vendor-product">Arcane --Arcane=C2=A0<br>=C2=A0</td>
<td>Arcane versions before 2.0.0 fail to properly restrict template operati= ons, allowing default user role accounts to create, modify, and delete comp= ose templates including instance-wide defaults. Attackers can inject malici= ous container configurations with privileged settings or host path mounts t= hat execute with administrative privileges when deployed by administrators.= </td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86114" target=3D= "_blank" rel=3D"noopener">CVE-2026-86114</a></td>
</tr>
<td class=3D"vendor-product">armink--struct2json</td>
<td>A vulnerability has been found in armink struct2json 1.0. This affects = the function S2J_STRUCT_GET_string_ELEMENT in the library struct2json/inc/s= 2jdef.h of the component JSON Deserialization. The manipulation of the argu= ment valuestring leads to null pointer dereference. The attack may be initi= ated remotely. The exploit has been disclosed to the public and may be used=
. The vendor was contacted early about this disclosure but did not respond =
in any way.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82803" target=3D= "_blank" rel=3D"noopener">CVE-2026-82803</a></td>
</tr>
<td class=3D"vendor-product">Arraytics--Timetics</td>
<td>Unauthenticated Broken Access Control in Timetics <=3D 1.0.61 versio= ns.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84215" target=3D= "_blank" rel=3D"noopener">CVE-2026-84215</a></td>
</tr>
<td class=3D"vendor-product">Arraytics--WP Event SOlution</td> <td>Unauthenticated Broken Access Control in WP Event SOlution <=3D 4.1.=
22 versions.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82223" target=3D= "_blank" rel=3D"noopener">CVE-2026-82223</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability has been identified in the underlying operating system =
of HPE Networking Fabric Composer that could potentially allow an unauthent= icated adjacent actor to circumvent existing authentication controls. Succe= ssful exploitation could allow an attacker to gain administrative access, m= odify system configurations, and access or manipulate sensitive data.</td> <td>2026-09-01</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73726" target=3D= "_blank" rel=3D"noopener">CVE-2026-73726</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Vulnerabilities in the API of HPE Networking Fabric Composer could allo=
w an authenticated low privilege operator user to access sensitive informat= ion. A successful exploit allows an attacker to access data beyond what is = authorized by the user's existing privilege level, which could be used to p= otentially gain further access to network services supported by HPE Network= ing Fabric Composer.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73727" target=3D= "_blank" rel=3D"noopener">CVE-2026-73727</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Denial-of-service vulnerabilities exist in the API of HPE Networking Fa= bric Composer that could allow an authenticated low privilege operator user=
to cause a denial of service. Successful exploitation could allow an attac= ker to interrupt the normal operation of the affected service.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73728" target=3D= "_blank" rel=3D"noopener">CVE-2026-73728</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the underlying operating system of HPE Networking Fa= bric Composer could allow an authenticated low privilege operator user with=
local access to upstream AFC dependencies to view sensitive information. S= uccessful exploitation could allow an attacker to access data beyond what i=
s authorized by the user's existing privilege level, potentially leading to=
further unauthorized access.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73729" target=3D= "_blank" rel=3D"noopener">CVE-2026-73729</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A privilege escalation vulnerability exists in the API of HPE Networkin=
g Fabric Composer. Successful exploitation could allow an authenticated low=
privilege operator user to change the state of certain settings of a vulne= rable system.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73730" target=3D= "_blank" rel=3D"noopener">CVE-2026-73730</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated remote attacker to conduct =
a reflected cross-site scripting (XSS) attack against a user of the interfa= ce. A successful exploit could allow an attacker to execute arbitrary scrip=
t code in a victim's browser in the context of the affected interface.</td> <td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73731" target=3D= "_blank" rel=3D"noopener">CVE-2026-73731</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the underlying operating system of HPE Networking Fa= bric Composer could allow an authenticated low privilege operator user with=
local access to obtain sensitive information. Successful exploitation coul=
d allow an attacker to retrieve sensitive data which could be used to gain = further unauthorized access to the affected system and to other systems it = interacts with.</td>
<td>2026-09-01</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73732" target=3D= "_blank" rel=3D"noopener">CVE-2026-73732</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Authentication bypasses in the API of HPE Networking Fabric Composer co= uld allow an authenticated low privilege operator user to circumvent existi=
ng authentication controls. Successful exploitation could allow an attacker=
to retain limited access to the affected system after that access should h= ave been revoked.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73733" target=3D= "_blank" rel=3D"noopener">CVE-2026-73733</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated remote attacker to redirect=
users to an arbitrary URL.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73734" target=3D= "_blank" rel=3D"noopener">CVE-2026-73734</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td> <td>Vulnerabilities in the API of HPE Networking Fabric Composer could allo=
w an authenticated low privilege operator user to access some information b= eyond their privilege level. Successful exploitation could allow an attacke=
r to obtain limited information and/or make limited changes beyond what is = authorized by the user's existing privilege level.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73735" target=3D= "_blank" rel=3D"noopener">CVE-2026-73735</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated remote attacker to view som=
e system files. Successful exploitation could allow an attacker to read fil=
es within the affected directory.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73736" target=3D= "_blank" rel=3D"noopener">CVE-2026-73736</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>An unauthenticated path traversal vulnerability exists in the API endpo= int of HPE Networking Fabric Composer. Successful exploitation could allow =
an unauthenticated adjacent attacker to manipulate user generated files, po= tentially leading to unauthorized changes in critical system configurations=
, if certain preconditions outside of the attacker's control are met.</td> <td>2026-09-01</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73737" target=3D= "_blank" rel=3D"noopener">CVE-2026-73737</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the underlying operating system of HPE Networking Fa= bric Composer could allow an authenticated low privilege operator user with=
local access to view sensitive information. Successful exploitation could = allow an attacker to retrieve information which could be used to potentiall=
y gain further privileges on the affected system.</td>
<td>2026-09-01</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73738" target=3D= "_blank" rel=3D"noopener">CVE-2026-73738</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability exists in the API of HPE Networking Fabric Composer tha=
t allows for an attacker with administrative privileges to access sensitive=
information in a cleartext format. A successful exploit allows an attacker=
to retrieve sensitive information that was expected to remain protected wi= thin the affected system.</td>
<td>2026-09-01</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73739" target=3D= "_blank" rel=3D"noopener">CVE-2026-73739</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A local privilege escalation vulnerability in HPE Networking Fabric Com= poser could allow an authenticated privileged user on the underlying host t=
o elevate their user privileges to those of a higher role. A successful exp= loit allows the attacker to change the state of certain settings of the aff= ected system.</td>
<td>2026-09-01</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73740" target=3D= "_blank" rel=3D"noopener">CVE-2026-73740</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the API of HPE Networking Fabric Composer could allo=
w an authenticated low privilege operator user to view some system files. S= uccessful exploitation could allow an attacker to access limited data beyon=
d what is authorized by the user's existing privilege level.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73741" target=3D= "_blank" rel=3D"noopener">CVE-2026-73741</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in an API endpoint of HPE Networking Fabric Composer co= uld allow an authenticated low privilege operator user to spoof the source = address attributed to their requests. Successful exploitation could allow a=
n attacker to cause inaccurate attribution information to be recorded on th=
e affected system.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73742" target=3D= "_blank" rel=3D"noopener">CVE-2026-73742</a></td>
</tr>
<td class=3D"vendor-product">ataurr--GutenKit Page Builder Blocks, Patterns=
, and Templates for Gutenberg Block Editor</td>
<td>The GutenKit - Page Builder Blocks, Patterns, and Templates for Gutenbe=
rg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scr= ipting via the 'postBodyCss' parameter in all versions up to, and including=
, 2.4.4 due to insufficient input sanitization and output escaping. This ma= kes it possible for authenticated attackers, with Contributor-level access = and above, to inject arbitrary web scripts in pages that will execute whene= ver a user accesses an injected page.</td>
<td>2026-09-03</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2573" target=3D"= _blank" rel=3D"noopener">CVE-2026-2573</a></td>
</tr>
<td class=3D"vendor-product">Autodesk--Shared Components</td>
<td>A maliciously crafted IFC file, when parsed through certain Autodesk pr= oducts, can trigger an Uncontrolled Recursion vulnerability. A malicious ac= tor may leverage this vulnerability to cause the application to terminate u= nexpectedly, resulting in a denial-of-service. Exploitation requires a user=
to open a specially crafted IFC file.</td>
<td>2026-09-02</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14255" target=3D= "_blank" rel=3D"noopener">CVE-2026-14255</a></td>
</tr>
<td class=3D"vendor-product">AVideo--AVideo<br>=C2=A0</td>
<td>AVideo API fails to enforce rate limits when clients send a bot User-Ag= ent header, allowing attackers to bypass all eight protected operations inc= luding login brute-force protection. Attackers can send requests with a bot=
User-Agent to disable rate limiting and perform unlimited password guessin=
g attempts against any account from a single IP address.</td> <td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86186" target=3D= "_blank" rel=3D"noopener">CVE-2026-86186</a></td>
</tr>
<td class=3D"vendor-product">Avo--Avo<br>=C2=A0</td>
<td>Avo is a framework to create admin panels for Ruby on Rails apps. From = version 2.28.0 to before version 3.32.0, Avo's direct attachment upload end= point lacks server-side upload authorization and bypasses the documented fi= eld-level upload policy methods such as upload_{FIELD_ID}?. An authenticate=
d Avo user who can reach the Avo attachment upload endpoint can replace or = add attachment content, including binary content, filename, and content-typ=
e metadata, on a resolved record even when both update? and upload_<fiel= d>? policies deny the operation. This primarily affects multi-role Avo P= ro/Advanced-style deployments where non-administrator or restricted operato=
r users can reach Avo and per-record or per-field operations are expected t=
o be enforced by policies. This issue has been patched in version 3.32.0.</=
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53769" target=3D= "_blank" rel=3D"noopener">CVE-2026-53769</a></td>
</tr>
<td class=3D"vendor-product">axllent--mailpit</td>
<td>Mailpit's IsInternalIP deny list function fails to block the Azure Wire= Server address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 pre= fix, allowing server-side request forgery to internal destinations. Attacke=
rs can supply hostnames resolving to these addresses in message content to = reach the link check API and proxy endpoint for accessing internal resource= s.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84697" target=3D= "_blank" rel=3D"noopener">CVE-2026-84697</a></td>
</tr>
<td class=3D"vendor-product">ays-pro--Photo Gallery by Ays Responsive Image=
Gallery</td>
<td>The Photo Gallery by Ays - Responsive Image Gallery plugin for WordPres=
s is vulnerable to generic SQL Injection via the 's' parameter in all versi= ons up to, and including, 6.8.2 due to insufficient escaping on the user su= pplied parameter and lack of sufficient preparation on the existing SQL que= ry. This makes it possible for authenticated attackers, with administrator-= level access and above, to append additional SQL queries into already exist= ing queries that can be used to extract sensitive information from the data= base. The vulnerability exists across two execution paths - $wpdb->get_v= ar() in record_count() and $wpdb->get_results() in prepare_items()/get_i= mage_categories() - enabling both blind and UNION-based exfiltration techni= ques.</td>
<td>2026-09-01</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76006" target=3D= "_blank" rel=3D"noopener">CVE-2026-76006</a></td>
</tr>
<td class=3D"vendor-product">BareBones--BBEdit</td>
<td>A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an = unknown function of the component Java Language Module. This manipulation c= auses uncontrolled recursion. Remote exploitation of the attack is possible=
. Upgrading to version 16.0 is recommended to address this issue. You shoul=
d upgrade the affected component.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82604" target=3D= "_blank" rel=3D"noopener">CVE-2026-82604</a></td>
</tr>
<td class=3D"vendor-product">BareBones--BBEdit</td>
<td>A vulnerability has been found in BareBones BBEdit up to 15.5.5. The af= fected element is an unknown function of the component Lasso Language Token= izer. Such manipulation leads to infinite loop. The attack can be executed = remotely. Upgrading to version 16.0 is sufficient to fix this issue. The af= fected component should be upgraded.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82605" target=3D= "_blank" rel=3D"noopener">CVE-2026-82605</a></td>
</tr>
<td class=3D"vendor-product">BEN Group--TubeBuddy for YouTube Extension</td=
<td>A vulnerability was detected in BEN Group TubeBuddy for YouTube Extensi=
on up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of th=
e file tubebuddymaster1.js. The manipulation of the argument t/c/r results =
in insufficient verification of data authenticity. It is possible to launch=
the attack remotely. The exploit is now public and may be used. The vendor=
was contacted early about this disclosure.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82813" target=3D= "_blank" rel=3D"noopener">CVE-2026-82813</a></td>
</tr>
<td class=3D"vendor-product">BerriAI--litellm</td>
<td>LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or n= ative) format. Prior to versions 1.88.6 and 1.96.2, any authenticated LiteL=
LM proxy user could redirect an outbound provider call to a destination the=
user controls and cause the proxy to send its configured provider credenti= als to that destination. Request validation in litellm/proxy/auth/auth_util= s.py, litellm/proxy/common_request_processing.py, litellm/proxy/health_endp= oints/_health_endpoints.py, litellm/proxy/image_endpoints/endpoints.py, and=
litellm/proxy/litellm_pre_call_utils.py used incomplete checks that did no=
t cover every sensitive parameter or inspect equivalent values across neste=
d request fields, path values, and bracket-notation form data. Routing and = credential parameters including api_base, base_url, model_list, fallbacks, = and litellm_credential_name could therefore be applied without clearing the=
operator's stored key, exposing upstream provider credentials and other co= nfigured secrets and permitting server-side requests to internal services r= eachable by the proxy. This issue is fixed in versions 1.88.6 and 1.96.2.</=
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84377" target=3D= "_blank" rel=3D"noopener">CVE-2026-84377</a></td>
</tr>
<td class=3D"vendor-product">blinkospace--blinko</td>
<td>Blinko 1.8.7 contains a cross-user private note disclosure vulnerabilit=
y in the noteReferenceList procedure that performs no ownership verificatio=
n on supplied note identifiers. Authenticated attackers can enumerate seque= ntial note IDs and retrieve complete content of other users' private notes = including attachments and tags.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85624" target=3D= "_blank" rel=3D"noopener">CVE-2026-85624</a></td>
</tr>
<td class=3D"vendor-product">Booking for Appointments and Events Calendar--= Booking for Appointments and Events Calendar</td>
<td>The Booking for Appointments and Events Calendar WordPress plugin befor=
e 2.4.9 does not require authentication or a valid request token before run= ning the post-booking action chain, allowing an unauthenticated user to tri= gger booking notifications and integration callbacks for a booking by enume= rating its identifier.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14215" target=3D= "_blank" rel=3D"noopener">CVE-2026-14215</a></td>
</tr>
<td class=3D"vendor-product">BookWyrm--BookWyrm<br>=C2=A0</td>
<td>BookWyrm through 0.9.1 fails to validate user visibility permissions in=
the status edit endpoint, allowing authenticated attackers to read followe= rs-only and direct-message reviews by enumerating sequential status IDs. At= tackers can access the raw content of restricted statuses through the edit = view, bypassing the privacy protections documented for these message types.= </td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86111" target=3D= "_blank" rel=3D"noopener">CVE-2026-86111</a></td>
</tr>
<td class=3D"vendor-product">BookWyrm--BookWyrm<br>=C2=A0</td>
<td>BookWyrm through 0.9.1 fails to validate user visibility permissions in=
the Favorite and Unfavorite views, allowing authenticated attackers to fav= orite or unfavorite followers-only and direct statuses they cannot access. = Attackers can POST to the favorite endpoint with a status ID to create unau= thorized interactions, trigger ActivityPub broadcasts, and enumerate privat=
e status IDs through response differentiation.</td>
<td>2026-09-05</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86112" target=3D= "_blank" rel=3D"noopener">CVE-2026-86112</a></td>
</tr>
<td class=3D"vendor-product">BookWyrm--BookWyrm<br>=C2=A0<br>=C2=A0</td>
<td>BookWyrm through 0.9.1 contains an authorization bypass vulnerability i=
n the edit_readthrough function that allows authenticated users to modify o= ther users' reading records. Attackers can exploit sequential ReadThrough I=
Ds to overwrite arbitrary users' start dates, finish dates, progress, and p= rogress mode, affecting reading statistics and exported data.</td> <td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86113" target=3D= "_blank" rel=3D"noopener">CVE-2026-86113</a></td>
</tr>
<td class=3D"vendor-product">Bootstrapped Ventures--WP Recipe Maker Premium= </td>
<td>The WP Recipe Maker Premium plugin for WordPress is vulnerable to Store=
d Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in = all versions up to, and including, 10.5.0 due to insufficient input sanitiz= ation and output escaping on user supplied attributes. This makes it possib=
le for authenticated attackers, with contributor-level access and above, to=
inject arbitrary web scripts in pages that will execute whenever a user ac= cesses an injected page.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-7877" target=3D"= _blank" rel=3D"noopener">CVE-2026-7877</a></td>
</tr>
<td class=3D"vendor-product">Brainstorm Force--SureForms</td>
<td>Authorization Bypass Through User-Controlled Key vulnerability in Brain= storm Force SureForms allows Exploiting Incorrectly Configured Access Contr=
ol Security Levels. This issue affects SureForms: from n/a through 2.12.5.<=
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85308" target=3D= "_blank" rel=3D"noopener">CVE-2026-85308</a></td>
</tr>
<td class=3D"vendor-product">Brave--Brave</td>
<td>The Brave WordPress plugin before 0.8.8 does not prevent a URL paramete=
r used to pre-fill a form field from being passed to WordPress's shortcode = engine, allowing unauthenticated attackers to have arbitrary shortcodes reg= istered on the site executed server-side.</td>
<td>2026-09-02</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81571" target=3D= "_blank" rel=3D"noopener">CVE-2026-81571</a></td>
</tr>
<td class=3D"vendor-product">brightvesseldev--Pre-Orders for WooCommerce</t=
<td>Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= =3D 2.3 versions.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84849" target=3D= "_blank" rel=3D"noopener">CVE-2026-84849</a></td>
</tr>
<td class=3D"vendor-product">C4illin--ConvertX</td>
<td>ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xe= latex converter that allows authenticated users to read files by uploading = LaTeX files with input directives. Attackers can upload .tex files containi=
ng \input{path} or \verbatiminput{path} directives to have the TeX engine r= ead arbitrary files accessible to the server process and include them in do= wnloadable PDF output.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85618" target=3D= "_blank" rel=3D"noopener">CVE-2026-85618</a></td>
</tr>
<td class=3D"vendor-product">Camaleon--CMS=C2=A0<br>=C2=A0</td>
<td>Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect tar= gets when fetching remote files in the Upload from URL media feature. Authe= nticated attackers can supply URLs that pass initial validation but redirec=
t to internal network addresses, allowing server-side request forgery to in= ternal services.</td>
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86100" target=3D= "_blank" rel=3D"noopener">CVE-2026-86100</a></td>
</tr>
<td class=3D"vendor-product">caoqianming--django-vue-admin</td>
<td>A weakness has been identified in caoqianming django-vue-admin 1.0. Thi=
s vulnerability affects unknown code of the file /api/file/. Executing a ma= nipulation of the argument file_id can lead to improper access controls. Th=
e attack can be executed remotely. The exploit has been made available to t=
he public and could be used for attacks. The vendor was contacted early abo=
ut this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82835" target=3D= "_blank" rel=3D"noopener">CVE-2026-82835</a></td>
</tr>
<td class=3D"vendor-product">Cascadia Web Services--MountDev AI MCP Connect=
or for WordPress</td>
<td>Missing Authorization vulnerability in Cascadia Web Services MountDev A=
I MCP Connector for WordPress allows Exploiting Incorrectly Configured Acce=
ss Control Security Levels. This issue affects MountDev AI MCP Connector fo=
r WordPress: from n/a through 1.6.5.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85306" target=3D= "_blank" rel=3D"noopener">CVE-2026-85306</a></td>
</tr>
<td class=3D"vendor-product">CatalogX--CatalogX</td>
<td>The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape = content that an unauthenticated user can store before including it in the p= roduct enquiry notification email sent to the site administrator, allowing = unauthenticated attackers to inject arbitrary content into that email, whic=
h is delivered when an unrelated visitor later submits a product enquiry.</=
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79621" target=3D= "_blank" rel=3D"noopener">CVE-2026-79621</a></td>
</tr>
<td class=3D"vendor-product">ccfos--nightingale</td>
<td>Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08= -27), contains a server-side request forgery vulnerability in the isPublicI=
P function in aiagent/tools/http.go, the SSRF guard for the http_fetch AI-a= gent tool. The function only unwraps standard IPv4-mapped (::ffff:a.b.c.d) = IPv6 addresses before checking them against the forbidden-range list, and d= oes not classify 6to4 (2002::/16), NAT64 (64:ff9b::/96, 64:ff9b:1::/48), or=
deprecated site-local (fec0::/10) addresses. On a dual-stack or NAT64-enab= led host, an attacker able to supply a URL to the http_fetch tool can bypas=
s the guard by encoding a forbidden IPv4 address (such as the cloud instanc= e-metadata endpoint 169.254.169.254) in one of these IPv6 forms to reach in= ternal or metadata services.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85692" target=3D= "_blank" rel=3D"noopener">CVE-2026-85692</a></td>
</tr>
<td class=3D"vendor-product">CDT--CDT=C2=A0<br>=C2=A0</td>
<td>CDT before 1.4.5 contains an out-of-bounds read vulnerability in the op= posedVertexInd() function when constraint edge intersections are computed i=
n floating point and round outside adjacent triangles. Attackers can supply=
nearly-degenerate constraint edges through geometry data to trigger an out= -of-bounds array access that crashes the calling process.</td>
<td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15647" target=3D= "_blank" rel=3D"noopener">CVE-2025-15647</a></td>
</tr>
<td class=3D"vendor-product">cheshire-cat-ai--core</td>
<td>Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoi=
nt fails to apply per-user filtering when retrieving episodic memory points=
. Authenticated attackers with MEMORY:READ permission can retrieve all user=
s' stored conversation messages and personal data by paginating through the=
collection using the offset cursor.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85093" target=3D= "_blank" rel=3D"noopener">CVE-2026-85093</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Secure Email</td>
<td>Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exten= sions (S/MIME) decryption functionality of Cisco Secure Email could allow a=
n unauthenticated, remote attacker to recover plain text from encrypted ema=
il messages. These vulnerabilities are due to insufficient validation of me= ssage integrity. An attacker could exploit these vulnerabilities by using a=
machine-in-the-middle technique to intercept and modify traffic between em= ail gateways. A successful exploit could allow the attacker to obtain plain= text content from the encrypted communication.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20354" target=3D= "_blank" rel=3D"noopener">CVE-2026-20354</a></td>
</tr>
<td class=3D"vendor-product">Cisco--Cisco Secure Email</td>
<td>Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Exten= sions (S/MIME) decryption functionality of Cisco Secure Email could allow a=
n unauthenticated, remote attacker to recover plain text from encrypted ema=
il messages. These vulnerabilities are due to insufficient validation of me= ssage integrity. An attacker could exploit these vulnerabilities by using a=
machine-in-the-middle technique to intercept and modify traffic between em= ail gateways. A successful exploit could allow the attacker to obtain plain= text content from the encrypted communication.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-20355" target=3D= "_blank" rel=3D"noopener">CVE-2026-20355</a></td>
</tr>
<td class=3D"vendor-product">claude-world--claude-skill-antivirus</td>
<td>claude-skill-antivirus fails to analyze executable files when scanning = local skill directories, reading only SKILL.md while ignoring Python source=
, bytecode, and other artifacts in the scripts directory. Attackers can dis= tribute skills with malicious code in non-manifest files that receive a SAF=
E verdict with 100/100 trust score despite containing unanalyzed executable=
payloads.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84810" target=3D= "_blank" rel=3D"noopener">CVE-2026-84810</a></td>
</tr>
<td class=3D"vendor-product">Cleo--Harmony</td>
<td>A vulnerability has been found in Cleo Harmony up to 5.8.1.10. Impacted=
is the function LocalUserUtil.getNativeUserByAssertions of the component S= AML Authentication. Such manipulation of the argument Email leads to improp=
er authentication. The attack can be executed remotely. The exploit has bee=
n disclosed to the public and may be used. Upgrading to version 5.8.1.11 is=
recommended to address this issue. Upgrading the affected component is rec= ommended.</td>
<td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84114" target=3D= "_blank" rel=3D"noopener">CVE-2026-84114</a></td>
</tr>
<td class=3D"vendor-product">code-projects --Daily Expense Manager 1.0<br>= =C2=A0</td>
<td>A flaw has been found in code-projects Daily Expense Manager 1.0. Affec= ted is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of=
the component Database Backup Handler. Executing a manipulation can lead t=
o information disclosure. It is possible to launch the attack remotely. The=
exploit has been published and may be used.</td>
<td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86179" target=3D= "_blank" rel=3D"noopener">CVE-2026-86179</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Hotel and Tourism Reservation<b= r>=C2=A0</td>
<td>A vulnerability was detected in code-projects Hotel and Tourism Reserva= tion in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%2= 0(1).sql of the component Database Backup Handler. The manipulation results=
in information disclosure. The attack may be launched remotely. The exploi=
t is now public and may be used.</td>
<td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86217" target=3D= "_blank" rel=3D"noopener">CVE-2026-86217</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Hotel and Tourism Reservation= =C2=A0<br>=C2=A0</td>
<td>A security vulnerability has been detected in code-projects Hotel and T= ourism Reservation in PHP 1.0. This impacts an unknown function of the file=
/ht/details.php. The manipulation of the argument room leads to cross site=
scripting. The attack may be initiated remotely. The exploit has been disc= losed publicly and may be used.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86216" target=3D= "_blank" rel=3D"noopener">CVE-2026-86216</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Online Shopping System</td>
<td>A vulnerability was found in code-projects Online Shopping System 1.0. = Affected by this vulnerability is an unknown functionality of the file /off= ersmail.php of the component Newsletter Subscription. The manipulation of t=
he argument email results in cross site scripting. The attack may be perfor= med from remote. The exploit has been made public and could be used.</td> <td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82700" target=3D= "_blank" rel=3D"noopener">CVE-2026-82700</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Online Shopping System 1.0<br>= =C2=A0</td>
<td>A flaw has been found in code-projects Online Shopping System 1.0. Impa= cted is the function mysqli_query of the file admin/adduser.php. Executing =
a manipulation of the argument mobile can lead to sql injection. The attack=
may be performed from remote. The exploit has been published and may be us= ed.</td>
<td>2026-09-04</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85643" target=3D= "_blank" rel=3D"noopener">CVE-2026-85643</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Simple Inventory System</td>
<td>A flaw has been found in code-projects Simple Inventory System 1.0. Aff= ected by this issue is some unknown functionality of the file inventorymana= gement.sql of the component Database Backup File Handler. This manipulation=
causes information disclosure. The attack may be initiated remotely. The e= xploit has been published and may be used.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82624" target=3D= "_blank" rel=3D"noopener">CVE-2026-82624</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Simple Inventory System</td>
<td>A vulnerability has been found in code-projects Simple Inventory System=
1.0. This affects an unknown part of the file /register.php of the compone=
nt User Registration. Such manipulation of the argument last_name leads to = cross site scripting. The attack may be launched remotely. The exploit has = been disclosed to the public and may be used.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82625" target=3D= "_blank" rel=3D"noopener">CVE-2026-82625</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Vehicle Management System</td> <td>A flaw has been found in code-projects Vehicle Management System 1.0. T=
he impacted element is an unknown function of the file /vehicle_management.= sql of the component SQL Database Backup File Handler. Executing a manipula= tion can lead to information disclosure. It is possible to launch the attac=
k remotely. The exploit has been published and may be used.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85517" target=3D= "_blank" rel=3D"noopener">CVE-2026-85517</a></td>
</tr>
<td class=3D"vendor-product">Comments--Comments</td>
<td>The Comments WordPress plugin before 7.6.66 does not validate a value u= sed to build a database query, allowing unauthenticated users to inject SQL=
and read comments they are not entitled to see, including comments awaitin=
g moderation, comments marked as spam or trashed, and comments on private a=
nd draft posts. The injected text reaches the query as grammar rather than =
as data and does not yield extraction of arbitrary data, so the confidentia= lity impact is the disclosed comment content rather than the database at la= rge.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19704" target=3D= "_blank" rel=3D"noopener">CVE-2026-19704</a></td>
</tr>
<td class=3D"vendor-product">Content Views--Content Views</td>
<td>The Content Views WordPress plugin before 4.5.1.2 does not check whethe=
r the user requesting a view is allowed to read the posts it returns, allow= ing unauthenticated attackers to obtain the title and content of non-public=
posts, such as draft, pending, private and scheduled posts, when a view ha=
s been configured to include them.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17517" target=3D= "_blank" rel=3D"noopener">CVE-2026-17517</a></td>
</tr>
<td class=3D"vendor-product">cozmoslabs--User Profile Builder Beautiful Use=
r Registration Forms, User Profiles & User Role Editor</td>
<td>The User Profile Builder - Beautiful User Registration Forms, User Prof= iles & User Role Editor plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via the 'email' parameter in all versions up to, and inc= luding, 4.0.0 due to insufficient input sanitization and output escaping. T= his makes it possible for unauthenticated attackers to inject arbitrary web=
scripts in pages that will execute whenever a user accesses an injected pa= ge. The payload reaches administrators with the manage_options capability w= hen they visit the Users > Unconfirmed Email Addresses list table and in= teract with row-action links, as the poisoned javascript: href is rendered = verbatim into the page HTML by row_actions().</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75964" target=3D= "_blank" rel=3D"noopener">CVE-2026-75964</a></td>
</tr>
<td class=3D"vendor-product">cozmoslabs--User Profile Builder Beautiful Use=
r Registration Forms, User Profiles & User Role Editor</td>
<td>The User Profile Builder - Beautiful User Registration Forms, User Prof= iles & User Role Editor plugin for WordPress is vulnerable to Stored Cr= oss-Site Scripting via 'date' Shortcode Attribute in all versions up to, an=
d including, 4.0.0 due to insufficient input sanitization and output escapi= ng. This makes it possible for authenticated attackers, with contributor-le= vel access and above, to inject arbitrary web scripts in pages that will ex= ecute whenever a user accesses an injected page. This requires the wppb_too= lbox_shortcodes_settings[format-date] option to be set to 'yes' by an admin= istrator for the shortcode to be active and the vulnerability to be exploit= able.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75965" target=3D= "_blank" rel=3D"noopener">CVE-2026-75965</a></td>
</tr>
<td class=3D"vendor-product">cozythemes--Cozy Blocks Page Builder for Guten= berg Editor & FSE with 700+ Patterns, 58 Blocks & Templates</td> <td>The Cozy Blocks - Page Builder for Gutenberg Editor & FSE with 700+=
Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to = authorization bypass in all versions up to, and including, 2.2.17. This is = due to the plugin not properly verifying that a user is authorized to perfo=
rm an action. This makes it possible for unauthenticated attackers to retri= eve the name, price, short description, image URL, permalink, stock status,=
and product type of draft, pending, private, and catalog-hidden WooCommerc=
e products not intended to be publicly visible. The sidebarNonce value is e= mitted unconditionally into public page HTML by multiple block renderers wi=
th no login gate, allowing unauthenticated visitors to harvest a valid nonc=
e and pass the only authentication check in the handler.</td> <td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19948" target=3D= "_blank" rel=3D"noopener">CVE-2026-19948</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions before 5.10.11 contain an authorization bypass vulne= rability in ElementsController::actionDuplicate() that allows authenticated=
users with createEntries permission to delete peer provisional drafts. Att= ackers can exploit the deleteProvisionalDraft parameter to delete another u= ser's unsaved draft without proper authorization checks, gaining access to = the victim's in-progress content.</td>
<td>2026-09-02</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84797" target=3D= "_blank" rel=3D"noopener">CVE-2026-84797</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions before 5.10.11 contain a broken access control vulne= rability in the element-indexes/save-elements endpoint that allows control = panel users to move entries into sections they cannot edit. Attackers with = limited section permissions can relocate or publish entries to unauthorized=
sections by overwriting the sectionId attribute after initial authorizatio=
n checks, bypassing the destination section permission validation.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84792" target=3D= "_blank" rel=3D"noopener">CVE-2026-84792</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross= -site scripting vulnerability in the site name field that fails to sanitize=
input. Administrators can inject arbitrary JavaScript payloads in the site=
name that execute when other users view the control panel settings pages.<=
<td>2026-09-02</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84793" target=3D= "_blank" rel=3D"noopener">CVE-2026-84793</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS before 5.11.0 fails to enforce user-group scope filters on na= tive GraphQL user relations including author, authors, uploader, draftCreat= or, and revisionCreator fields. Attackers with a scoped GraphQL token can q= uery these relations to read usernames, email addresses, and full names of = any content author or uploader including administrators.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84799" target=3D= "_blank" rel=3D"noopener">CVE-2026-84799</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS versions from 5.7.0 before 5.10.12 contain an information dis= closure vulnerability in AssetsController::actionMoveInfo that fails to enf= orce volume permissions. Authenticated control panel users can submit POST = requests to the assets/move-info endpoint with arbitrary folderIds to retri= eve asset count and total storage size for volumes they cannot access.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84802" target=3D= "_blank" rel=3D"noopener">CVE-2026-84802</a></td>
</tr>
<td class=3D"vendor-product">creativethemeshq--Blocksy Companion</td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Stored Cros= s-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in al=
l versions up to, and including, 2.1.51 due to insufficient input sanitizat= ion and output escaping. This makes it possible for authenticated attackers=
, with author-level access and above, to inject arbitrary web scripts in pa= ges that will execute whenever a user accesses an injected page.</td> <td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18488" target=3D= "_blank" rel=3D"noopener">CVE-2026-18488</a></td>
</tr>
<td class=3D"vendor-product">crmeb--CRMEB</td>
<td>CRMEB through 6.0.0 fails to validate message ownership in the edit_mes= sage handler of MessageSystemController.php, allowing authenticated users t=
o modify arbitrary system inbox messages. Attackers can update any message'=
s columns including is_del, look, and uid to delete, mark read, or reassign=
victim notifications without authorization.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85177" target=3D= "_blank" rel=3D"noopener">CVE-2026-85177</a></td>
</tr>
<td class=3D"vendor-product">Crocoblock--JetPopup</td>
<td>Missing Authorization vulnerability in Crocoblock JetPopup allows Explo= iting Incorrectly Configured Access Control Security Levels. This issue aff= ects JetPopup: from n/a through 2.0.20.2.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27347" target=3D= "_blank" rel=3D"noopener">CVE-2026-27347</a></td>
</tr>
<td class=3D"vendor-product">cypht-org--cypht</td>
<td>Cypht before 2.12.2 contains a cross-site scripting vulnerability in th=
e contacts module that allows remote attackers to execute arbitrary script = content by embedding malicious payloads within angle brackets in the FROM e= mail header. The sanitization logic removes only the first occurrence of ea=
ch angle bracket character, leaving additional angle brackets intact, which=
attackers exploit by delivering a crafted email whose FROM header executes=
script in the victim's browser when the user opens the message and accesse=
s the Add Local Contacts function.</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73524" target=3D= "_blank" rel=3D"noopener">CVE-2026-73524</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase versions before 2.10.26 omit object-level authorization checks=
on geographic information, dashboard linkage, and chart detail REST endpoi= nts, allowing authenticated users to access resources belonging to other us= ers. Attackers can overwrite or delete map geometry, modify dashboard linka= ges, and retrieve chart metadata and configuration for resources they do no=
t own by supplying arbitrary identifiers in requests.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82878" target=3D= "_blank" rel=3D"noopener">CVE-2026-82878</a></td>
</tr>
<td class=3D"vendor-product">dataease--dataease</td>
<td>DataEase before 2.10.26 contains multiple access control defects in the=
sharing link module. Tickets are not bound to the target share UUID, so a = valid ticket issued for one share can be reused against another (ShareTicke= tManage.validateTicket / POST /de2api/share/proxyInfo). The POST /de2api/sh= are/validate endpoint issues a LinkToken after password verification withou=
t requiring a ticket, bypassing the 'ticket mandatory' policy. Additionally=
, the ticket create and delete endpoints (POST /de2api/ticket/saveTicket, P= OST /de2api/ticket/delTicket) lack share-ownership checks, allowing an auth= enticated user who knows another user's ticket to modify, rebind, or delete=
it (denial of service), and GET /de2api/share/queryRelationByUserId/{uid} = allows authenticated users to enumerate other users' share mappings.</td> <td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82879" target=3D= "_blank" rel=3D"noopener">CVE-2026-82879</a></td>
</tr>
<td class=3D"vendor-product">DefaultFuction--CRM 1.0.0</td>
<td>A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts =
an unknown function of the file /modules/customers/delete.php. Performing a=
manipulation of the argument ID results in sql injection. It is possible t=
o initiate the attack remotely. The exploit is now public and may be used.<=
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86172" target=3D= "_blank" rel=3D"noopener">CVE-2026-86172</a></td>
</tr>
<td class=3D"vendor-product">DefaultFuction--CRM 1.0.0<br>=C2=A0</td>
<td>A weakness has been identified in DefaultFuction CRM 1.0.0. The impacte=
d element is an unknown function of the file /modules/orders/edit.php. This=
manipulation of the argument ID causes sql injection. The attack is possib=
le to be carried out remotely. The exploit has been made available to the p= ublic and could be used for attacks.</td>
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86170" target=3D= "_blank" rel=3D"noopener">CVE-2026-86170</a></td>
</tr>
<td class=3D"vendor-product">DefaultFuction--CRM 1.0.0<br>=C2=A0</td>
<td>A security vulnerability has been detected in DefaultFuction CRM 1.0.0.=
This affects an unknown function of the file /modules/orders/delete.php. S= uch manipulation of the argument ID leads to sql injection. The attack may =
be performed from remote. The exploit has been disclosed publicly and may b=
e used.</td>
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86171" target=3D= "_blank" rel=3D"noopener">CVE-2026-86171</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Manager</td>
<td>Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a = Reliance on Data/Memory Layout vulnerability. An unauthenticated remote att= acker could potentially exploit this vulnerability, leading to Launch of ph= ishing attacks.</td>
<td>2026-09-03</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-68860" target=3D= "_blank" rel=3D"noopener">CVE-2026-68860</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Manager</td>
<td>Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an=
Incorrect Authorization vulnerability in the REST API. A low privileged re= mote attacker could potentially exploit this vulnerability, leading to Prot= ection mechanism bypass.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74769" target=3D= "_blank" rel=3D"noopener">CVE-2026-74769</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerProtect Data Manager</td>
<td>Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a = Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high pr= ivileged remote attacker could potentially exploit this vulnerability, lead= ing to Information disclosure.</td>
<td>2026-09-03</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74768" target=3D= "_blank" rel=3D"noopener">CVE-2026-74768</a></td>
</tr>
<td class=3D"vendor-product">Dell--PowerStore 500T</td>
<td>Dell PowerStore contains an Argument Injection vulnerability. An authen= ticated user with limited privileges could potentially exploit this vulnera= bility to gain unauthorized access to sensitive sensitive system informatio= n.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79685" target=3D= "_blank" rel=3D"noopener">CVE-2026-79685</a></td>
</tr>
<td class=3D"vendor-product">Dell--SmartFabric OS10</td>
<td>Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a=
n Improper Neutralization of Special Elements used in a Command ('Command I= njection') vulnerability. A high privileged attacker with remote access cou=
ld potentially exploit this vulnerability, leading to Command execution.</t=
<td>2026-09-03</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63694" target=3D= "_blank" rel=3D"noopener">CVE-2026-63694</a></td>
</tr>
<td class=3D"vendor-product">Dell--SmartFabric OS10 Software</td>
<td>Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains a=
n Improper Neutralization of Special Elements used in an OS Command ('OS Co= mmand Injection') vulnerability. A high privileged attacker with remote acc= ess could potentially exploit this vulnerability, leading to Command execut= ion.</td>
<td>2026-09-03</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-35160" target=3D= "_blank" rel=3D"noopener">CVE-2026-35160</a></td>
</tr>
<td class=3D"vendor-product">dibo-software--diboot</td>
<td>A vulnerability has been found in dibo-software diboot 3.8.0. Affected =
by this vulnerability is an unknown functionality of the file /api/ai-sessi= on/ of the component AI Session Endpoint. Such manipulation leads to author= ization bypass. The attack can be launched remotely. The exploit has been d= isclosed to the public and may be used. The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82816" target=3D= "_blank" rel=3D"noopener">CVE-2026-82816</a></td>
</tr>
<td class=3D"vendor-product">dibo-software--diboot</td>
<td>A vulnerability was found in dibo-software diboot 3.8.0. Affected by th=
is issue is some unknown functionality of the file /admin/ of the component=
Tenant Administrator Management API. Performing a manipulation of the argu= ment tenantId results in improper access controls. The attack may be initia= ted remotely. The exploit has been made public and could be used. The vendo=
r was contacted early about this disclosure but did not respond in any way.= </td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82817" target=3D= "_blank" rel=3D"noopener">CVE-2026-82817</a></td>
</tr>
<td class=3D"vendor-product">dibo-software--diboot</td>
<td>A vulnerability was determined in dibo-software diboot 3.8.0. This affe= cts an unknown part of the file /api/iam/tenant/resource of the component T= enant Resource Assignment Handler. Executing a manipulation of the argument=
tenantId can lead to improper access controls. The attack may be launched = remotely. The exploit has been publicly disclosed and may be utilized. The = vendor was contacted early about this disclosure but did not respond in any=
way.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82818" target=3D= "_blank" rel=3D"noopener">CVE-2026-82818</a></td>
</tr>
<td class=3D"vendor-product">diem-project --diem=C2=A0<br>=C2=A0</td>
<td>A vulnerability was determined in diem-project diem up to 5.1.3. This a= ffects the function executeCommand of the file dmAdminPlugin/modules/dmCons= ole/actions/actions.class.php of the component dmConsole. This manipulation=
of the argument dm_command causes cross-site request forgery. The attack m=
ay be initiated remotely. The exploit has been publicly disclosed and may b=
e utilized. The project was informed of the problem early through an issue = report but has not responded yet.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86182" target=3D= "_blank" rel=3D"noopener">CVE-2026-86182</a></td>
</tr>
<td class=3D"vendor-product">diem-project--diem</td>
<td>A security flaw has been discovered in diem-project diem up to 5.1.3. T=
he impacted element is an unknown function of the file dmFrontPlugin/lib/dm= Widget/media/dmWidgetContentBaseMediaForm.php of the component Widget Edito=
r. Performing a manipulation results in unrestricted upload. The attack may=
be initiated remotely. The exploit has been released to the public and may=
be used for attacks. The project was informed of the problem early through=
an issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82679" target=3D= "_blank" rel=3D"noopener">CVE-2026-82679</a></td>
</tr>
<td class=3D"vendor-product">diem-project--diem</td>
<td>A vulnerability was identified in diem-project diem up to 5.1.3. The af= fected element is the function executeCommand of the file dmAdminPlugin/mod= ules/dmConsole/actions/actions.class.php of the component Administrative Co= nsole. Such manipulation of the argument dm_command leads to os command inj= ection. The attack can be launched remotely. The exploit is publicly availa= ble and might be used. The project was informed of the problem early throug=
h an issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82678" target=3D= "_blank" rel=3D"noopener">CVE-2026-82678</a></td>
</tr>
<td class=3D"vendor-product">diem-project--diem=C2=A0<br>=C2=A0</td>
<td>A vulnerability was identified in diem-project diem up to 5.1.3. This v= ulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidge= t/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipul= ation of the argument widget_id leads to authorization bypass. The attack m=
ay be launched remotely. The exploit is publicly available and might be use=
d. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A pat=
ch should be applied to remediate this issue. The project was informed of t=
he problem early through an issue report but has not responded yet.</td> <td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86183" target=3D= "_blank" rel=3D"noopener">CVE-2026-86183</a></td>
</tr>
<td class=3D"vendor-product">DimaFreund--Rentsyst</td>
<td>Missing Authorization vulnerability in DimaFreund Rentsyst allows Explo= iting Incorrectly Configured Access Control Security Levels. This issue aff= ects Rentsyst: from n/a through 2.1.2.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84835" target=3D= "_blank" rel=3D"noopener">CVE-2026-84835</a></td>
</tr>
<td class=3D"vendor-product">Doccano--Open Source Annotation Tools for Mach= ine Learning Practitioners</td>
<td>A vulnerability was identified in Doccano Open Source Annotation Tools = for Machine Learning Practitioners and Auto Labeling Pipeline Module to Ann= otate a Document Automatically up to 1.8.5. Affected by this issue is the f= unction ExampleDetail of the file /v1/projects/1/examples/ of the component=
Project Example Detail Endpoint. Such manipulation leads to improper acces=
s controls. The attack may be launched remotely. The exploit is publicly av= ailable and might be used. The vendor was contacted early about this disclo= sure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82833" target=3D= "_blank" rel=3D"noopener">CVE-2026-82833</a></td>
</tr>
<td class=3D"vendor-product">Doccano--Open Source Annotation Tools for Mach= ine Learning Practitioners</td>
<td>A security flaw has been discovered in Doccano Open Source Annotation T= ools for Machine Learning Practitioners and Auto Labeling Pipeline Module t=
o Annotate a Document Automatically up to 1.8.5. This affects the function = LabelList of the file /v1/projects/1/category-types of the component Bulk-D= elete Endpoint. Performing a manipulation results in improper access contro= ls. Remote exploitation of the attack is possible. The exploit has been rel= eased to the public and may be used for attacks. The vendor was contacted e= arly about this disclosure but did not respond in any way.</td> <td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82834" target=3D= "_blank" rel=3D"noopener">CVE-2026-82834</a></td>
</tr>
<td class=3D"vendor-product">documenso--documenso</td>
<td>Documenso 2.17.0 contains an access control vulnerability in the PDF-se= rving endpoint that fails to validate document visibility settings. Attacke=
rs with low privileges can read restricted documents within their team or c= ross-tenant by leveraging missing ownership validation on document data ide= ntifiers.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85697" target=3D= "_blank" rel=3D"noopener">CVE-2026-85697</a></td>
</tr>
<td class=3D"vendor-product">Dolibarr--Dolibarr</td>
<td>A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. = Affected by this issue is some unknown functionality of the file htdocs/cor= e/filemanagerdol/connectors/php/config.inc.php of the component Legacy File=
Manager. Executing a manipulation can lead to improper access controls. Th=
e attack can be launched remotely. The exploit has been made available to t=
he public and could be used for attacks. Upgrading to version 23.0.4 can re= solve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad= 02ec. It is suggested to upgrade the affected component.</td> <td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85401" target=3D= "_blank" rel=3D"noopener">CVE-2026-85401</a></td>
</tr>
<td class=3D"vendor-product">domainaware--parsedmarc</td>
<td>parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files usin=
g an output path derived from the email subject. When the subject consists = entirely of path traversal sequences, the filename sanitization function pr= oduces an empty string, and a fallback to the raw unsanitized subject cause=
s the resulting file to be written outside the intended samples directory. =
An attacker who can cause a forensic failure report with a crafted Subject =
to be processed can write a dot-prefixed file with attacker-controlled cont= ent to an ancestor directory of the configured samples output path. Exploit= ation requires that file output for forensic report samples is enabled.</td=
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82521" target=3D= "_blank" rel=3D"noopener">CVE-2026-82521</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Address Suggestion</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Address Suggestion allows Cross-Site = Scripting (XSS). This issue affects Address Suggestion versions: from 0.0.0=
to 1.0.25.</td>
<td>2026-09-02</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81167" target=3D= "_blank" rel=3D"noopener">CVE-2026-81167</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Blazy</td>
<td>Incorrect Authorization vulnerability in Drupal Blazy allows Forceful B= rowsing. This issue affects Blazy versions: from 0.0.0 to 3.0.18.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81165" target=3D= "_blank" rel=3D"noopener">CVE-2026-81165</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Data field</td>
<td>Missing Authorization vulnerability in Drupal Data field allows Forcefu=
l Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.</=
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81269" target=3D= "_blank" rel=3D"noopener">CVE-2026-81269</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Diff</td>
<td>Incorrect Authorization vulnerability in Drupal Diff allows Forceful Br= owsing. This issue affects Diff versions: from 0.0.0 to 2.0.1, from 2.1.0 t=
o 2.1.1.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73478" target=3D= "_blank" rel=3D"noopener">CVE-2026-73478</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Digital Signage Framework</td>
<td>Missing Authorization vulnerability in Drupal Digital Signage Framework=
allows Forceful Browsing. This issue affects Digital Signage Framework ver= sions: from 0.0.0 to 2.6.1.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81166" target=3D= "_blank" rel=3D"noopener">CVE-2026-81166</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Disable Login Page</td>
<td>Authentication Bypass Using an Alternate Path or Channel vulnerability =
in Drupal Disable Login Page allows Functionality Bypass. This issue affect=
s Disable Login Page versions: from 0.0.0 to 1.1.4.</td>
<td>2026-09-02</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16647" target=3D= "_blank" rel=3D"noopener">CVE-2026-16647</a></td>
</tr>
<td class=3D"vendor-product">Drupal--DXPR Builder: The Best Editing (AI) Ex= perience for Drupal</td>
<td>Insertion of Sensitive Information Into Sent Data vulnerability in Drup=
al DXPR Builder: The Best Editing (AI) Experience for Drupal allows Forcefu=
l Browsing. This issue affects DXPR Builder: The Best Editing (AI) Experien=
ce for Drupal versions: from 0.0.0 to 2.8.1.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81162" target=3D= "_blank" rel=3D"noopener">CVE-2026-81162</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Entity API</td>
<td>Incorrect Authorization vulnerability in Drupal Entity API allows Force= ful Browsing. This issue affects Entity API versions: from 0.0.0 to 1.8.0.<=
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81158" target=3D= "_blank" rel=3D"noopener">CVE-2026-81158</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Entity Browser</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Entity Browser allows Stored XSS. Thi=
s issue affects Entity Browser versions: from 0.0.0 to 2.16.0.</td>
<td>2026-09-02</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18986" target=3D= "_blank" rel=3D"noopener">CVE-2026-18986</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Entity PDF</td>
<td>Missing Authorization vulnerability in Drupal Entity PDF allows Forcefu=
l Browsing. This issue affects Entity PDF versions: from 0.0.0 to 2.1.5.</t=
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81164" target=3D= "_blank" rel=3D"noopener">CVE-2026-81164</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Entity Share Websub</td>
<td>Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share=
Websub allows Server Side Request Forgery. This issue affects Entity Share=
Websub versions: from 0.0.0 to 1.1.2.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73474" target=3D= "_blank" rel=3D"noopener">CVE-2026-73474</a></td>
</tr>
<td class=3D"vendor-product">Drupal--External Authentication</td>
<td>Improper Handling of Case Sensitivity vulnerability in Drupal External = Authentication allows Privilege Escalation. This issue affects External Aut= hentication versions: from 0.0.0 to 2.0.13.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73476" target=3D= "_blank" rel=3D"noopener">CVE-2026-73476</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Gammu SMS Daemon</td>
<td>Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS = Daemon versions: *.*.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76755" target=3D= "_blank" rel=3D"noopener">CVE-2026-76755</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Gammu SMS Daemon</td>
<td>Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS = Daemon versions: *.*.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76756" target=3D= "_blank" rel=3D"noopener">CVE-2026-76756</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Gammu SMS Daemon</td>
<td>Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS = Daemon versions: *.*.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76757" target=3D= "_blank" rel=3D"noopener">CVE-2026-76757</a></td>
</tr>
<td class=3D"vendor-product">Drupal--LDAP / Active Directory Integration</t=
<td>Improper Neutralization of Special Elements used in an LDAP Query ('LDA=
P Injection') vulnerability in Drupal LDAP / Active Directory Integration a= llows LDAP Injection. This issue affects LDAP / Active Directory Integratio=
n versions: from 0.0.0 to 2.2.1.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81205" target=3D= "_blank" rel=3D"noopener">CVE-2026-81205</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Link content parser</td>
<td>Vulnerability in Drupal Link content parser. This issue affects Link co= ntent parser versions: *.*.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76758" target=3D= "_blank" rel=3D"noopener">CVE-2026-76758</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Monster Menus</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Monster Menus allows Stored XSS. This=
issue affects Monster Menus versions: from 0.0.0 to 9.5.3.</td> <td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81201" target=3D= "_blank" rel=3D"noopener">CVE-2026-81201</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Quick Tabs</td>
<td>Incorrect Authorization vulnerability in Drupal Quick Tabs allows Force= ful Browsing. This issue affects Quick Tabs versions: from 0.0.0 to 4.3.1.<=
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73477" target=3D= "_blank" rel=3D"noopener">CVE-2026-73477</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Slick Carousel</td>
<td>Improper Neutralization of Input During Web Page Generation ("Cross-sit=
e Scripting") vulnerability in Drupal Slick Carousel allows Stored XSS. Thi=
s issue affects Slick Carousel versions: from 0.0.0 to 2.1.0.</td>
<td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81160" target=3D= "_blank" rel=3D"noopener">CVE-2026-81160</a></td>
</tr>
<td class=3D"vendor-product">DSpace--DSpace</td>
<td>DSpace open source software is a repository application which provides = durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and=
10.0, the Curation Task feature allows an output path to be used by the re= porter (-r parameter), typically used to stream results and status of curat= ion task operations. It is not restricted to any particular base path, mean= ing that any path writable by the DSpace (often 'tomcat') user is allowed. = This constitutes a Path Traversal Vulnerability in the curate script. This = issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.</td> <td>2026-09-02</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49831" target=3D= "_blank" rel=3D"noopener">CVE-2026-49831</a></td>
</tr>
<td class=3D"vendor-product">DSpace--DSpace</td>
<td>DSpace open source software is a repository application which provides = durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9= .0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerabi= lity is possible via the COAR Notify / LDN service in DSpace. The attacker = MUST already have DSpace administrator credentials in order to perform the = attack. When reading a file input stream of an "inbound pattern" / "templat= e", used to generate an LDN message, the LDN class does not check for path = traversal or restrict the templates to a known base path. This could allow =
an untrusted file from elsewhere in the file system (e.g. an export log, a = bitstream path, a temporary file) to be read and interpreted as an Apache V= elocity template. This issue has been patched in versions 8.4, 9.3, and 10.= 0.</td>
<td>2026-09-02</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49833" target=3D= "_blank" rel=3D"noopener">CVE-2026-49833</a></td>
</tr>
<td class=3D"vendor-product">DSpace--DSpace</td>
<td>DSpace open source software is a repository application which provides = durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and=
10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE = Harvester), the ORE Ingestion Crosswalk does not validate the URI scheme. T= his may allow for local file inclusion via malicious paths like file:///etc= /passwd. The attacker MUST already have DSpace collection administrator pri= vileges in order to perform the attack. This issue has been patched in vers= ions 7.6.7, 8.4, 9.3, and 10.0.</td>
<td>2026-09-02</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49830" target=3D= "_blank" rel=3D"noopener">CVE-2026-49830</a></td>
</tr>
<td class=3D"vendor-product">dubinc--dub</td>
<td>Dub contains an open redirect vulnerability in the redir_url query para= meter that is accepted on every short link without validation or domain all= owlist enforcement. Attackers can append the redir_url parameter to any sho=
rt link to redirect visitors to arbitrary external URLs through the trusted=
Dub domain, bypassing destination blacklists and potentially enabling phis= hing attacks with link cloaking enabled.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85676" target=3D= "_blank" rel=3D"noopener">CVE-2026-85676</a></td>
</tr>
<td class=3D"vendor-product">E-cab Taxi Booking Manager for Woocommerce--E-= cab Taxi Booking Manager for Woocommerce</td>
<td>The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before = 2.0.5 does not validate a client-supplied trip distance and base-price valu=
e on the server before pricing a booking, allowing unauthenticated attacker=
s to manipulate the order total down to zero and place real taxi-booking or= ders at an arbitrary price.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84045" target=3D= "_blank" rel=3D"noopener">CVE-2026-84045</a></td>
</tr>
<td class=3D"vendor-product">Ebyte--Ebyte NE2-D11 Firmware</td>
<td>The affected Ebyte product exports administrative credentials and other=
sensitive configuration information without adequate protection. An unauth= enticated attacker on the adjacent network who can obtain an exported confi= guration file could recover valid credentials and use them to access the de= vice or similarly configured systems.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77975" target=3D= "_blank" rel=3D"noopener">CVE-2026-77975</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6214K</td>
<td>A vulnerability was identified in Edimax BR-6214K 1.40. This affects th=
e function system of the file www/wlanMP.asp of the component asp_WlanMP En= dpoint. Such manipulation of the argument ateFunc leads to os command injec= tion. It is possible to launch the attack remotely. The exploit is publicly=
available and might be used. The vendor was contacted early about this dis= closure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82702" target=3D= "_blank" rel=3D"noopener">CVE-2026-82702</a></td>
</tr>
<td class=3D"vendor-product">Edimax--BR-6214K</td>
<td>A security flaw has been discovered in Edimax BR-6214K 1.40. This vulne= rability affects the function system of the file www/ping.asp of the compon= ent asp_setPing Endpoint. Performing a manipulation of the argument pingstr=
results in os command injection. The attack can be initiated remotely. The=
exploit has been released to the public and may be used for attacks. The v= endor was contacted early about this disclosure but did not respond in any = way.</td>
<td>2026-08-31</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82703" target=3D= "_blank" rel=3D"noopener">CVE-2026-82703</a></td>
</tr>
<td class=3D"vendor-product">elastic -- apm_server</td>
<td>Improper Handling of Highly Compressed Data (CWE-409) in APM Server can=
lead to a persistent denial of service via Excessive Allocation (CAPEC-130=
). An authenticated user with write access to source map content could stor=
e specially crafted, highly compressed content that exhausts the memory ava= ilable to APM Server when it is later processed, terminating the process. T=
he condition recurs on every restart until the stored content is removed.</=
<td>2026-09-02</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78594" target=3D= "_blank" rel=3D"noopener">CVE-2026-78594</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elastic_cloud_on_kubernetes</td>
<td>Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) = can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-= 690). An actor holding limited Kubernetes permissions confined to a single = namespace could cause attacker-controlled certificate material to be includ=
ed in the Elasticsearch client trust bundle managed by ECK in a separate na= mespace.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78609" target=3D= "_blank" rel=3D"noopener">CVE-2026-78609</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elasticsearch</td>
<td>Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')=
(CWE-444) in Elasticsearch can lead to information disclosure via HTTP Req= uest Smuggling (CAPEC-33). Under specific proxy deployment configurations, =
a network attacker could obtain confidential responses intended for other a= uthenticated users.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78605" target=3D= "_blank" rel=3D"noopener">CVE-2026-78605</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elasticsearch</td>
<td>Missing Authorization (CWE-862) in the Elasticsearch custom inference s= ervice can lead to information disclosure via Privilege Abuse (CAPEC-122). =
A user holding only inference execution privileges could cause outbound inf= erence traffic to be directed to a destination of their choosing and could = cause administrator-provisioned credentials to be exposed.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78607" target=3D= "_blank" rel=3D"noopener">CVE-2026-78607</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elasticsearch</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Elast= icsearch can lead to a denial of service via Excessive Allocation (CAPEC-13= 0). A user with elevated privileges can submit a specially crafted request = that causes excessive memory consumption, which may render the affected nod=
e unavailable.</td>
<td>2026-09-01</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56143" target=3D= "_blank" rel=3D"noopener">CVE-2026-56143</a></td>
</tr>
<td class=3D"vendor-product">elastic -- filebeat</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Fileb= eat can lead to a denial of service via Excessive Allocation (CAPEC-130). A=
n attacker able to reach the Filebeat HTTP ingestion endpoint could send sp= ecially crafted compressed requests that exhaust the memory resources of th=
e Filebeat process.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78588" target=3D= "_blank" rel=3D"noopener">CVE-2026-78588</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Kiban=
a can lead to a denial of service via Excessive Allocation (CAPEC-130). An = authenticated user with low-level permissions could submit a specially craf= ted request that causes excessive resource consumption, which may render Ki= bana unavailable.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-33465" target=3D= "_blank" rel=3D"noopener">CVE-2026-33465</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Neutralization of Special Elements in Data Query Logic (CWE-94=
3) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-= 676). An authenticated user with access to the affected query functionality=
could submit specially crafted input that alters the intended query logic,=
returning data the user is not authorized to read.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63138" target=3D= "_blank" rel=3D"noopener">CVE-2026-63138</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lea=
d to a denial of service via Excessive Allocation (CAPEC-130). An authentic= ated user holding Streams management privileges could supply specially craf= ted content that expands to a far larger volume of data during processing, = exhausting the memory available to Kibana. The Kibana process is terminated=
by the host and remains unavailable to all users until the service is rest= arted.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72628" target=3D= "_blank" rel=3D"noopener">CVE-2026-72628</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Uncaught Exception (CWE-248) in Kibana can lead to a denial of service = via Input Data Manipulation (CAPEC-153). An authenticated user holding only=
the low-privileged feature access required to use the Observability AI Ass= istant can submit a specially crafted request that produces an unhandled er= ror condition, terminating the Kibana process and denying service to all us= ers and spaces on that instance until it is restarted.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72644" target=3D= "_blank" rel=3D"noopener">CVE-2026-72644</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Kiban=
a can lead to a denial of service via Excessive Allocation (CAPEC-130). An = authenticated user can submit a specially crafted request that causes exces= sive resource consumption, which may render Kibana unavailable.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72652" target=3D= "_blank" rel=3D"noopener">CVE-2026-72652</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Execution with Unnecessary Privileges (CWE-250) in the Kibana machine l= earning feature can lead to information disclosure via Privilege Abuse (CAP= EC-122). An operation available to users holding only read access to the ma= chine learning feature was performed with an internal service identity rath=
er than the identity of the requesting user. Such a user could therefore re= ceive data from Elasticsearch indices they are not authorized to read. No E= lasticsearch cluster or index privileges are required.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72654" target=3D= "_blank" rel=3D"noopener">CVE-2026-72654</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Kiban=
a can lead to a denial of service via Excessive Allocation (CAPEC-130). An = authenticated user holding only low, read-level Agent Builder privileges co= uld submit a specially crafted request that causes Kibana to consume an unb= ounded amount of memory, terminating the process and denying service to all=
users of the instance.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72682" target=3D= "_blank" rel=3D"noopener">CVE-2026-72682</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Allocation of Resources Without Limits or Throttling (CWE-770) in Kiban=
a can lead to a denial of service via Excessive Allocation (CAPEC-130). An = authenticated user with low-level privileges could submit a specially craft=
ed request that causes Kibana to consume an unbounded amount of memory, ren= dering it unavailable to all users.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78586" target=3D= "_blank" rel=3D"noopener">CVE-2026-78586</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized d= eletion of resources via Path Traversal (CAPEC-126). A low-privileged user = could cause a subsequent action taken by a higher-privileged user in the Fl= eet administration interface to act on an unintended target, resulting in t=
he deletion of resources including accounts with elevated privileges.</td> <td>2026-09-02</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78591" target=3D= "_blank" rel=3D"noopener">CVE-2026-78591</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized d= eletion of internal resources via Path Traversal (CAPEC-126). A low-privile= ged user holding Fleet write access could cause a subsequent administrative=
delete action to act on unintended internal resources. Exploitation requir=
es an administrator to interact with the affected Fleet interface.</td> <td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78599" target=3D= "_blank" rel=3D"noopener">CVE-2026-78599</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Missing Authorization (CWE-862) in Kibana can lead to information discl= osure via Privilege Abuse (CAPEC-122). An authorization control was not app= lied to an internal Kibana APM integration function, allowing any authentic= ated Kibana user to read APM server credentials that should be restricted t=
o users holding APM or Fleet administrative privileges.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78608" target=3D= "_blank" rel=3D"noopener">CVE-2026-78608</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized mo= dification of data via Accessing Functionality Not Properly Constrained by = ACLs (CAPEC-1). An authenticated user holding only Security Solution read a= ccess in a Kibana space could enumerate and change the state of Entity Stor=
e maintainer tasks, silently disabling Entity Analytics maintenance for tha=
t space.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72641" target=3D= "_blank" rel=3D"noopener">CVE-2026-72641</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Incorrect Authorization (CWE-863) in the Kibana machine learning featur=
e can lead to information disclosure via Exploiting Incorrectly Configured = Access Control Security Levels (CAPEC-180). An authenticated user holding m= achine learning job management privileges within a single Kibana space coul=
d cause a job's saved object to become accessible across all spaces in the = Kibana instance, without holding access rights to those additional spaces.<=
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78598" target=3D= "_blank" rel=3D"noopener">CVE-2026-78598</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Missing Authorization (CWE-862) in Kibana can lead to information discl= osure via Privilege Abuse (CAPEC-122). An authorization control was not app= lied to a Kibana Entity Store configuration operation, allowing an authenti= cated user with elevated Kibana privileges to indirectly cause a background=
task to read from Elasticsearch indices that user is not authorized to acc= ess. Derived entity data from those indices is then exposed through the ent= ity store output.</td>
<td>2026-09-02</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78601" target=3D= "_blank" rel=3D"noopener">CVE-2026-78601</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead t=
o a loss of security monitoring via Accessing Functionality Not Properly Co= nstrained by ACLs (CAPEC-1). An authenticated user holding only read-level = Security feature access, and no Elasticsearch privileges, could stop the re= curring Privilege Monitoring engine task for a Kibana space. Privileged use=
r monitoring then stops producing data for that space while the engine cont= inues to report a healthy state to operators.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-72633" target=3D= "_blank" rel=3D"noopener">CVE-2026-72633</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature=
can lead to information disclosure via Query System for Information (CAPEC= -54). An authenticated user holding Osquery live-query privileges could det= ermine whether a scheduled query identifier exists in a Kibana space they a=
re not authorized to access.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78584" target=3D= "_blank" rel=3D"noopener">CVE-2026-78584</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Missing Authorization (CWE-862) in the Kibana Entity Store feature can = lead to unauthorized credential creation via Accessing Functionality Not Pr= operly Constrained by ACLs (CAPEC-1). An authenticated user holding only lo= w-privilege Security feature access could invoke an administrative operatio=
n that creates and persists Elasticsearch API keys under the caller's ident= ity, bypassing the elevated cluster and Kibana privileges that the document=
ed Entity Store setup flow requires.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78597" target=3D= "_blank" rel=3D"noopener">CVE-2026-78597</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Missing Authorization (CWE-862) in Kibana can lead to information discl= osure via Exploiting Incorrectly Configured Access Control Security Levels = (CAPEC-180). An authenticated user holding minimal Elasticsearch privileges=
could bypass Kibana feature authorization and space access controls, resul= ting in the unauthorized disclosure of Fleet deployment metadata from the d= efault Kibana space.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78603" target=3D= "_blank" rel=3D"noopener">CVE-2026-78603</a></td>
</tr>
<td class=3D"vendor-product">elastic -- kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized di= sclosure, modification, and deletion of data via Accessing Functionality No=
t Properly Constrained by ACLs (CAPEC-1). Where two authenticated principal=
s originating from different authentication realms share the same username = value, one could read, modify, and delete the other's private Elastic AI As= sistant Knowledge Base entries.</td>
<td>2026-09-01</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78606" target=3D= "_blank" rel=3D"noopener">CVE-2026-78606</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Elastic Maps Server</td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Trav= ersal') (CWE-22) in Elastic Maps Server can lead to information disclosure = via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach t=
he service over the network could cause it to return the contents of files = outside its intended content directory that are readable by the server proc= ess.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78602" target=3D= "_blank" rel=3D"noopener">CVE-2026-78602</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to information dis= closure via Exploiting Incorrectly Configured Access Control Security Level=
s (CAPEC-180).</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82299" target=3D= "_blank" rel=3D"noopener">CVE-2026-82299</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>An insufficiently validated configuration field in Kibana's Cribl integ= ration allows an authenticated user holding Kibana Fleet management privile= ges to inject attacker-controlled expressions into a server-side script tem= plate, resulting in an Elasticsearch ingest pipeline being written beyond t=
he caller's authorized Elasticsearch permissions.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78593" target=3D= "_blank" rel=3D"noopener">CVE-2026-78593</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Missing Authorization in Kibana Leading to Information Disclosure / Mis= sing Authorization (CWE-862) in the Kibana Fleet feature can lead to inform= ation disclosure via Privilege Abuse (CAPEC-122). An authenticated user hol= ding read-level Fleet agent privileges in one Kibana space could enumerate = agent metadata and access diagnostic content belonging to agents enrolled i=
n other Kibana spaces.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78595" target=3D= "_blank" rel=3D"noopener">CVE-2026-78595</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Missing Authorization in Kibana Leading to Unauthorized Modification of=
Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized = modification of data via Privilege Abuse (CAPEC-122). An authenticated user=
holding Security read-level access in a single Kibana space could trigger = Entity Analytics migration operations that perform privileged writes across=
all Kibana spaces, regardless of that user's actual access scope.</td> <td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78596" target=3D= "_blank" rel=3D"noopener">CVE-2026-78596</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Incorrect Authorization (CWE-863) in the Kibana machine learning featur=
e can lead to unauthorized resource consumption via Exploiting Incorrectly = Configured Access Control Security Levels (CAPEC-180). An authenticated use=
r could invoke machine learning functionality beyond their authorization sc= ope, consuming cluster resources they should not be able to reach.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82293" target=3D= "_blank" rel=3D"noopener">CVE-2026-82293</a></td>
</tr>
<td class=3D"vendor-product">Elastic--Kibana</td>
<td>Incorrect Authorization (CWE-863) in Kibana can lead to denial of servi=
ce via Exploiting Incorrectly Configured Access Control Security Levels (CA= PEC-180).</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82298" target=3D= "_blank" rel=3D"noopener">CVE-2026-82298</a></td>
</tr>
<td class=3D"vendor-product">Elegant Themes--Divi</td>
<td>The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripti=
ng via the `redirect_url` parameter of the `et_pb_contact_form` shortcode i=
n all versions up to, and including, 4.27.6. This is due to the `redirect_u= rl` attribute being sanitized with `esc_attr()` instead of `esc_url()` befo=
re being rendered into the `data-redirect_url` HTML data attribute. Additio= nally, `redirect_url` is absent from the hardcoded `$url_options` array in = `class-et-builder-element.php`, so it does not receive `esc_url_raw()` sani= tization during shortcode parsing. After a successful form submission, clie= nt-side JavaScript reads this data attribute and passes it directly to `win= dow.location.href`, executing arbitrary JavaScript from a `javascript:` URI=
. This makes it possible for authenticated attackers, with Contributor-leve=
l access and above, to inject arbitrary web scripts in pages that execute w= henever a user submits the contact form.</td>
<td>2026-09-02</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3850" target=3D"= _blank" rel=3D"noopener">CVE-2026-3850</a></td>
</tr>
<td class=3D"vendor-product">Elegant Themes--Divi</td>
<td>The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripti=
ng via the Dynamic Content feature's legacy JSON format in all versions up = to, and including, 4.27.6. This is due to two compounding flaws: (1) the sa= ve-time sanitization filter `et_builder_sanitize_dynamic_content_fields()` = only searches for dynamic content markers in the `@ET-DC@...@` format, but = the rendering engine also supports a legacy JSON format that is silently co= nverted at render time, completely bypassing the save-time filter, and (2) = the `post_meta_key` resolver in `et_builder_filter_resolve_default_dynamic_= content()` does not apply `wp_kses_post()` to the resolved meta value when = `enable_html` is set to `on`, passing raw `get_post_meta()` output directly=
to the page. This makes it possible for authenticated attackers, with Cont= ributor-level access and above, to inject arbitrary web scripts in pages th=
at will execute whenever a user accesses an injected page.</td> <td>2026-09-02</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3851" target=3D"= _blank" rel=3D"noopener">CVE-2026-3851</a></td>
</tr>
<td class=3D"vendor-product">Elegant Themes--Divi</td>
<td>The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripti=
ng via the `skype_url` shortcode attribute of the Social Media Follow modul=
e in all versions up to, and including, 4.27.6. This is due to a three-part=
sanitization failure: (1) the `skype_url` field is not included in the `$u= rl_options` whitelist in `class-et-builder-element.php`, so it never invoke=
s `esc_url_raw()` during shortcode processing, (2) the render code in `Soci= alMediaFollowItem.php` explicitly skips `esc_url()` for Skype URLs (`! $is_= skype ? esc_url( $url ) : $skype_url`), and (3) only `sanitize_text_field()=
` is applied, which preserves single and double quote characters allowing a= ttribute breakout. The unsanitized value is interpolated directly into a si= ngle-quoted `href` attribute (`href=3D'{$social_network_link_url}'`). This = makes it possible for authenticated attackers, with Contributor-level acces=
s and above, to inject arbitrary web scripts in pages that will execute whe= never a user interacts with the injected element.</td>
<td>2026-09-03</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3852" target=3D"= _blank" rel=3D"noopener">CVE-2026-3852</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Quality Management</td>
<td>A vulnerability was identified in Eleveo Quality Management 9.7.0. The = affected element is the function QuestionnaireService.runDataExportNow of t=
he component Questionnaire Service. Such manipulation of the argument file_= name leads to path traversal. The attack may be performed from remote. The = exploit is publicly available and might be used. The vendor was contacted e= arly about this disclosure but did not respond in any way.</td> <td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85409" target=3D= "_blank" rel=3D"noopener">CVE-2026-85409</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Quality Management</td>
<td>A vulnerability was found in Eleveo Quality Management 9.7.0. This issu=
e affects some unknown processing of the file /enc-fwk-data/api/v3/conversa= tions/<ID>/events of the component Conversation Handler. The manipula= tion of the argument labels results in denial of service. The attack can be=
executed remotely. The exploit has been made public and could be used. The=
vendor was contacted early about this disclosure but did not respond in an=
y way.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85407" target=3D= "_blank" rel=3D"noopener">CVE-2026-85407</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Quality Management</td>
<td>A vulnerability was determined in Eleveo Quality Management 9.7.0. Impa= cted is an unknown function of the file /enc-fwk-data/api/v3/conversations/= <ID>/events of the component Conversation Handler. This manipulation =
of the argument createdBy causes dynamically-determined object attributes. = The attack is possible to be carried out remotely. The exploit has been pub= licly disclosed and may be utilized. The vendor was contacted early about t= his disclosure but did not respond in any way.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85408" target=3D= "_blank" rel=3D"noopener">CVE-2026-85408</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.1, an authenticated user can edit their own inactive s= ubscription and set replacement_subscription_id to a subscription ID belong= ing to another user. The write is accepted, and later the stats logic deref= erences that foreign subscription ID without user_id scoping. This lets the=
attacker infer the victim subscription's monthly-normalized cost by observ= ing changes in their own stats output. This does not expose the full victim=
subscription object, but it does expose derived financial metadata. This i= ssue has been patched in version 4.9.1.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50198" target=3D= "_blank" rel=3D"noopener">CVE-2026-50198</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the fi= rst Fixer/API Layer credential globally instead of loading the credential f=
or the authenticated user. As a result, a normal authenticated user without=
their own provider key can trigger exchange-rate refreshes using another u= ser's stored provider credential. This issue has been patched in version 4.= 9.1.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50199" target=3D= "_blank" rel=3D"noopener">CVE-2026-50199</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (=
no admin rights required) can make the server open arbitrary outbound SMTP = connections to internal/link-local addresses, by setting the SMTP host of t= heir personal email notifications to an internal IP. The per-user notificat= ion settings endpoint (endpoints/notifications/saveemailnotifications.php) = performs no SSRF validation, and the notification cron (endpoints/cronjobs/= sendnotifications.php) feeds that user-controlled host straight into PHPMai= ler ($mail->Host =3D $email['smtpAddress']). When the user's subscriptio=
n notification fires, the server connects to the chosen host:port. This iss=
ue has been patched in version 5.0.0.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77352" target=3D= "_blank" rel=3D"noopener">CVE-2026-77352</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 5.0.0, Wallos allows authenticated users to inject arbitra=
ry iCalendar properties and events into their exported .ics feed by embeddi=
ng raw CRLF sequences in subscription names or notes. Because the input val= idation layer only encodes HTML metacharacters but never strips newlines, a=
nd the export layer decodes those entities back before writing iCal output,=
an attacker with any valid account can craft a subscription whose name bre= aks out of the current VEVENT block and inserts fully attacker-controlled c= alendar events - including spoofed organizers, arbitrary email addresses in=
ATTENDEE properties, and misleading event content - into any calendar appl= ication subscribed to that feed. This issue has been patched in version 5.0= .0.</td>
<td>2026-08-31</td>
<td>4.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77353" target=3D= "_blank" rel=3D"noopener">CVE-2026-77353</a></td>
</tr>
<td class=3D"vendor-product">emlog--emlog</td>
<td>Emlog is an open source website building system. Prior to version 2.6.1=
6, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataB= yLogin(). The $account parameter is directly interpolated into SQL queries = without any filtering. The vulnerability is reachable through the auth cook=
ie validation path, where $username is extracted from the cookie and passed=
unfiltered into SQL - guarded only by an HMAC signature that requires AUTH= _KEY to forge. This issue has been patched in version 2.6.16.</td> <td>2026-09-04</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53756" target=3D= "_blank" rel=3D"noopener">CVE-2026-53756</a></td>
</tr>
<td class=3D"vendor-product">enchant97--note-mark</td>
<td>Note Mark is an open-source note-taking application. Prior to version 0= .19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that ac= cepts a "deleted" query parameter. When the request is ?deleted=3Dtrue, the=
service runs the query with Unscoped() (bypassing GORM's soft-delete scope=
) but keeps the read-authorization clause as "owner_id =3D ? OR is_public =
=3D ?". As a result, any unauthenticated caller can enumerate the metadata =
of soft-deleted ("trashed") notes belonging to any public book - notes the = owner explicitly deleted and expected to be removed from public view. This = issue has been patched in version 0.19.5.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50554" target=3D= "_blank" rel=3D"noopener">CVE-2026-50554</a></td>
</tr>
<td class=3D"vendor-product">ePayco Payment Gateway for WooCommerce--ePayco=
Payment Gateway for WooCommerce</td>
<td>The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.=
7 does not properly verify the authenticity of payment confirmation request=
s, allowing unauthenticated attackers to mark orders as paid without a vali=
d gateway signature.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84043" target=3D= "_blank" rel=3D"noopener">CVE-2026-84043</a></td>
</tr>
<td class=3D"vendor-product">Exterro--FTK Imager</td>
<td>Exterro FTK Imager before 8.3 contains an XML external entity (XXE) inj= ection vulnerability that allows attackers to read arbitrary files from the=
host filesystem by embedding malicious external entity references and atta= cker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP=
evidence item. Attackers can craft a malicious UFDR archive that, when pre= viewed by an examiner, causes the XML parser to resolve file:// external en= tity references and execute msxsl:script within the external stylesheet to = exfiltrate the resolved file contents to an attacker-controlled endpoint vi=
a a generated image URL.</td>
<td>2026-09-03</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82525" target=3D= "_blank" rel=3D"noopener">CVE-2026-82525</a></td>
</tr>
<td class=3D"vendor-product">FasterXML--jackson-databind</td> <td>jackson-databind's deserializer for java.nio.file.Path resolves an atta= cker-supplied URI without restricting the URI scheme. In JDKFromStringDeser= ializer.NioPathHelper.deserialize, a string bound from untrusted JSON is pa= ssed to new URI(value) and then to Path.of(uri). When that throws FileSyste= mNotFoundException, the code enumerates ServiceLoader<FileSystemProvider= > and calls provider.getPath(uri) on the first provider whose scheme mat= ches the attacker-chosen scheme. Untrusted JSON can therefore select and dr= ive an arbitrary registered FileSystemProvider during readValue under a def= ault JsonMapper, and forces provider class loading at the same time. With o= nly the JDK built-in providers (file, jar/zipfs) present, the resolved path=
is inert and no mount or network I/O occurs; further impact requires a sid= e-effecting third-party FileSystemProvider on the classpath. This affects c= om.fasterxml.jackson.core:jackson-databind from 2.8.0 before 2.18.10, from = 2.19.0 before 2.21.6, and from 2.22.0 before 2.22.2, and tools.jackson.core= :jackson-databind from 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. User=
s should upgrade to 2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2. Binding java.= nio.file.Path from untrusted JSON should be avoided regardless of version.<=
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19032" target=3D= "_blank" rel=3D"noopener">CVE-2026-19032</a></td>
</tr>
<td class=3D"vendor-product">FasterXML--jackson-databind</td> <td>DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applie=
d automatically whenever @JsonTypeInfo is used without an explicitly config= ured custom validator. It denies polymorphic resolution only for a fixed se=
t of "unsafe base types", and its isSafeSubType method returns true uncondi= tionally for every base type outside that set. java.lang.Comparable was abs= ent from the list despite being implemented by a very large fraction of JDK=
and application classes, comparable in breadth to java.io.Serializable, wh= ich is on the list for that reason. An application declaring an @JsonTypeIn= fo-annotated property or class with Comparable as its base type, and no cus= tom PolymorphicTypeValidator, will accept a type identifier for essentially=
any class implementing Comparable. This yields an attacker-controlled obje=
ct instantiation primitive; a demonstrated case constructs a java.io.File f=
or an arbitrary attacker-chosen path, which becomes path-traversal-adjacent=
if the application subsequently calls path-sensitive methods on the value.=
No class implementing Comparable has been identified that yields code exec= ution through deserialization alone. Global Default Typing via activateDefa= ultTyping is not affected, because that method structurally requires an exp= licit PolymorphicTypeValidator argument. This affects com.fasterxml.jackson= .core:jackson-databind from 2.11.0 before 2.18.10, from 2.19.0 before 2.21.=
6, and from 2.22.0 before 2.22.2, and tools.jackson.core:jackson-databind f= rom 3.0.0 before 3.1.6 and from 3.2.0 before 3.2.2. Users should upgrade to=
2.18.10, 2.21.6, 2.22.2, 3.1.6, or 3.2.2.</td>
<td>2026-09-01</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83557" target=3D= "_blank" rel=3D"noopener">CVE-2026-83557</a></td>
</tr>
<td class=3D"vendor-product">FastGPT--FastGPT</td>
<td>FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoS=
QL injection in the POST /api/core/chat/getHistories endpoint. An unauthent= icated attacker can inject malicious NoSQL operators via crafted JSON paylo= ads to bypass authorization checks, resulting in unauthorized access to cha=
t history titles of all users across the platform.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79483" target=3D= "_blank" rel=3D"noopener">CVE-2026-79483</a></td>
</tr>
<td class=3D"vendor-product">Ffmpeg--Ffmpeg v.7.0</td>
<td>Buffer Overflow vulnerability in Ffmpeg v.7.0 and after allows an attac= ker to cause a denial of service via the libavformat/iamf_writer.c componen= t</td>
<td>2026-09-01</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52295" target=3D= "_blank" rel=3D"noopener">CVE-2026-52295</a></td>
</tr>
<td class=3D"vendor-product">filamentphp--filament</td>
<td>Filament is a collection of full-stack components for accelerated Larav=
el development. From 4.0.0 until 4.12.6 and 5.7.6, packages/panels/src/Auth= /MultiFactor/App/AppAuthentication.php uses AppAuthentication::verifyCode()=
with a used-code cache key derived from both the app authentication secret=
and the submitted TOTP code. This isolates the newest accepted timestep by=
code instead of by secret, allowing a previously issued app-based MFA code=
to be accepted after a newer code has already been used. Reuse of the exac=
t same code was already prevented, but another code inside the accepted tim=
e window remained usable. An attacker who obtains the target account's pass= word and one app-based MFA code can use that code for the remainder of the = configured window, which is approximately four minutes with the default set= tings, even after the legitimate account holder logs in with a newer code. = Email-based MFA is not affected. This issue is fixed in versions 4.12.6 and=
5.7.6.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84306" target=3D= "_blank" rel=3D"noopener">CVE-2026-84306</a></td>
</tr>
<td class=3D"vendor-product">Flatpak--Flatpak<br>=C2=A0</td>
<td>A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) ra=
ce condition exists in the `org.freedesktop.Flatpak.SystemHelper` component=
. This vulnerability occurs because a privileged `chmod` operation executes=
before the OSTree repository validation within the `Deploy()` function. An=
attacker can exploit this timing window to redirect symlinks to arbitrary = files, potentially leading to unauthorized file manipulation or information=
disclosure.</td>
<td>2026-09-04</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76925" target=3D= "_blank" rel=3D"noopener">CVE-2026-76925</a></td>
</tr>
<td class=3D"vendor-product">FLVMeta--FLVMeta</td>
<td>A vulnerability was found in FLVMeta up to 1.2.2. Affected is the funct= ion amf_string_new of the file src/amf.c of the component AMF String Proces= sing. The manipulation of the argument length results in heap-based buffer = overflow. The attack can be launched remotely. The exploit has been made pu= blic and could be used. The patch is identified as f412a33b9a84c2d1a9dee145= a868feddbf64879e. A patch should be applied to remediate this issue. The pr= oject maintainer doubts the security impact: "While I acknowledged the bugs=
and provided fixes, I have yet to see any way to exploit these alleged vul= nerabilities."</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82820" target=3D= "_blank" rel=3D"noopener">CVE-2026-82820</a></td>
</tr>
<td class=3D"vendor-product">FLVMeta--FLVMeta</td>
<td>A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this=
vulnerability is the function amf_object_get of the file src/amf.c of the = component AMF Object Parsing. This manipulation causes null pointer derefer= ence. The attack may be initiated remotely. The exploit has been publicly d= isclosed and may be utilized. Patch name: 52642f7dfb76ec7334016622dde60b1ae= 963d79b. To fix this issue, it is recommended to deploy a patch. The projec=
t maintainer doubts the security impact: "While I acknowledged the bugs and=
provided fixes, I have yet to see any way to exploit these alleged vulnera= bilities."</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82821" target=3D= "_blank" rel=3D"noopener">CVE-2026-82821</a></td>
</tr>
<td class=3D"vendor-product">FormLayer--FormLayer</td>
<td>The FormLayer WordPress plugin before 1.0.9 does not perform any author= ization check before returning a form's full stored configuration in the re= sponse to its public submission handler, allowing unauthenticated users to = disclose notification recipient addresses, confirmation redirect targets an=
d integration settings, including those of unpublished forms.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78151" target=3D= "_blank" rel=3D"noopener">CVE-2026-78151</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitia= lized heap memory in Save Session Info PDU reserved padding fields. Three P=
DU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, rdp_write_lo= gon_info_plain, and rdp_write_logon_info_ex) use Stream_Seek instead of Str= eam_Zero for reserved pad bytes (up to 576 bytes), leaving previously freed=
heap contents in the outgoing PDU. Because the send buffer is allocated wi=
th malloc (not zeroed), stale heap data - which may include cleartext crede= ntials from prior sessions - can be sent to the receiving peer. FreeRDP-bas=
ed servers using rdpUpdate::SaveSessionInfo and freerdp-proxy (which forwar=
ds these PDUs) are affected, allowing disclosure of server/proxy process me= mory to a downstream client.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85089" target=3D= "_blank" rel=3D"noopener">CVE-2026-85089</a></td>
</tr>
<td class=3D"vendor-product">FreeRDP--FreeRDP</td>
<td>FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability =
in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconst= ruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with s= pecific frame geometry to trigger an out-of-bounds memory read past the all= ocated luma plane.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85090" target=3D= "_blank" rel=3D"noopener">CVE-2026-85090</a></td>
</tr>
<td class=3D"vendor-product">Frontend Admin by DynamiApps--Frontend Admin b=
y DynamiApps</td>
<td>The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does n=
ot properly validate a user-controllable directory path before deleting fil=
es within it, allowing unauthenticated attackers to delete index.php and .h= taccess files outside the intended directory, including the WordPress root,=
which can render the site inoperable. Successful exploitation requires a n= on-default form configuration.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81347" target=3D= "_blank" rel=3D"noopener">CVE-2026-81347</a></td>
</tr>
<td class=3D"vendor-product">GamiPress--GamiPress</td>
<td>The GamiPress WordPress plugin before 7.9.9.6 does not properly restric=
t its video watch-tracking functionality, allowing users with a role as low=
as Subscriber to award the configured gamification points, achievements an=
d ranks to arbitrary users including administrators, and to accrue them wit= hout limit.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77764" target=3D= "_blank" rel=3D"noopener">CVE-2026-77764</a></td>
</tr>
<td class=3D"vendor-product">Gastromenum--Gastromenum Ticket and QR Menu Sy= stem</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu S= ystem allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu = System: before 2026.08.31.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19057" target=3D= "_blank" rel=3D"noopener">CVE-2026-19057</a></td>
</tr>
<td class=3D"vendor-product">Gastromenum--Gastromenum Ticket and QR Menu Sy= stem</td>
<td>Missing Authorization vulnerability in Gastromenum Gastromenum Ticket a=
nd QR Menu System allows Accessing Functionality Not Properly Constrained b=
y ACLs. This issue affects Gastromenum Ticket and QR Menu System: before 20= 26.08.31.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19081" target=3D= "_blank" rel=3D"noopener">CVE-2026-19081</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detectio=
n to modular pages, allowing authenticated page editors to store Twig-assem= bled XSS payloads. Attackers with page-edit rights can create modular pages=
with malicious Twig code that executes in visitor browsers when the parent=
page is rendered, including in administrator sessions.</td> <td>2026-09-04</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85598" target=3D= "_blank" rel=3D"noopener">CVE-2026-85598</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav versions before 1.10.55 contain a path traversal vulnerability in = the admin plugin's Save As action that fails to validate the language code = parameter. An authenticated admin user with admin.pages.create permission c=
an supply directory traversal sequences in the lang POST field to write arb= itrary .md files outside the pages directory with attacker-controlled conte= nt.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85603" target=3D= "_blank" rel=3D"noopener">CVE-2026-85603</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav Admin (getgrav/grav-plugin-admin2) versions <=3D 2.0.19 contain=
a stored cross-site scripting vulnerability in the tHtml() function (src/l= ib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as u= sernames into translation templates before parsing the result as markdown. = Grav's server-side username validation (DataUser::isValidUsername) blocks f= ilesystem-dangerous characters but not <, >, ", or ', allowing an att= acker to register a username containing an HTML payload. When an administra= tor views a UI surface that renders the username through tHtml()-such as th=
e two-factor force-disable confirmation prompt or the 'page is locked' edit=
or notice-the payload executes in their authenticated session. Fixed in 2.0= .21.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85600" target=3D= "_blank" rel=3D"noopener">CVE-2026-85600</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>Grav Admin before 2.0.20 fails to sanitize output from marked.parse() b= efore injecting it into the DOM via Svelte's {@html} directive in MarkdownE= ditor and MarkdownModal components. Attackers can inject javascript: URI sc= hemes in plugin or theme changelogs to execute arbitrary code in authentica= ted admin sessions without requiring site access.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85601" target=3D= "_blank" rel=3D"noopener">CVE-2026-85601</a></td>
</tr>
<td class=3D"vendor-product">getgrav--grav</td>
<td>The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through = 9.1.19 select the reCAPTCHA version to validate based solely on which respo= nse field key is present in the submitted payload. On a site configured for=
reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 = field name (g-recaptcha-response instead of token), causing validation to u=
se the v2 branch, which never applies the score threshold or verifies the e= xpected action. This results in a complete bypass of reCAPTCHA v3 bot prote= ction. The issue is fixed in version 9.1.20.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85602" target=3D= "_blank" rel=3D"noopener">CVE-2026-85602</a></td>
</tr>
<td class=3D"vendor-product">GFI Software--GFI Exinda AI</td>
<td>GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vuln= erability in the diagnostic file deletion handler. The unlink_or_email_file=
() function accepts parameters prefixed with v_file_row_ and appends their = values directly to a base directory path without sanitizing for directory t= raversal sequences. An authenticated attacker with Admin privileges can del= ete arbitrary files from the system in the context of root.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74236" target=3D= "_blank" rel=3D"noopener">CVE-2026-74236</a></td>
</tr>
<td class=3D"vendor-product">GFI Software--GFI Exinda AI</td>
<td>GFI Exinda AI and ClearView before 7.6.5 contains an argument injection=
vulnerability in the Tools Iperf Client functionality. The web_tools_cmd()=
function constructs an iperf command using the server and options paramete=
rs without sanitization, permitting injection of arbitrary iperf flags. An = authenticated attacker with Unprivileged (lowest-level) access can supply t=
he iperf -F flag to read an arbitrary file from the system and transmit its=
contents to an attacker-controlled server.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74237" target=3D= "_blank" rel=3D"noopener">CVE-2026-74237</a></td>
</tr>
<td class=3D"vendor-product">GFI Software--GFI Exinda AI</td>
<td>GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vuln= erability in the system maintenance configuration download handler. The wcf= _handle_download() function accepts parameters prefixed with v_del_ and app= ends their values directly to the base configuration directory path without=
sanitizing for directory traversal sequences. An authenticated attacker wi=
th Admin privileges can read arbitrary files from the system in the context=
of root.</td>
<td>2026-09-04</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74235" target=3D= "_blank" rel=3D"noopener">CVE-2026-74235</a></td>
</tr>
<td class=3D"vendor-product">GNOME--gvfs</td>
<td>A flaw was found in the AFP backend in gvfs. When mounting a share, a m= alicious AFP server can cause the DSI read path to process a length that ex= ceeds the size requested by the client. The function does not verify the se= rver-provided length against the pre-sized reply buffer, causing the operat= ion to access past the intended boundaries. This issue allows a malicious s= erver to overflow a heap buffer and crash the gvfsd-afp process, resulting =
in a denial of service.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84269" target=3D= "_blank" rel=3D"noopener">CVE-2026-84269</a></td>
</tr>
<td class=3D"vendor-product">GNOME--gvfs</td>
<td>A flaw was found in the SFTP backend in gvfs. When mounting a share, a = malicious SFTP server can cause read_string() to allocate a buffer with a c= ertain length but the function does not verify that the buffer is completel=
y filled, leaving the remainder of the buffer containing uninitialized heap=
contents. If the server sends a short FXP_HANDLE reply, these uninitialize=
d bytes are taken as the file handle. The client will then echo these unini= tialized bytes back to the server on all subsequent requests using that han= dle. With a length of 128 bytes, this issue allows the malicious server to = deterministically read uninitialized heap memory from the gvfsd-sftp proces=
s, leaking its heap base and the load address of the libgio library, result= ing in a deterministic defeat of Address Space Layout Randomization (ASLR).= </td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84267" target=3D= "_blank" rel=3D"noopener">CVE-2026-84267</a></td>
</tr>
<td class=3D"vendor-product">GNOME--gvfs</td>
<td>A flaw was found in the MTP backend in gvfs. When reading a file from a=
mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length r= eturned by the device without limiting it to the original size requested by=
the client. If a malicious MTP device responds with more bytes than reques= ted, this unrestricted length is passed directly to memcpy(). This causes t=
he operation to read memory outside the intended boundaries. This allows an=
attacker who plugs in a malicious MTP device to cause a segmentation fault=
when a file is read and crash the gvfsd-mtp process, resulting in a denial=
of service.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84270" target=3D= "_blank" rel=3D"noopener">CVE-2026-84270</a></td>
</tr>
<td class=3D"vendor-product">gonic --gonic=C2=A0<br>=C2=A0</td>
<td>gonic versions before 0.22.0 fail to validate administrator privileges =
in the startScan endpoint, allowing any authenticated user to trigger media=
library rescans. Attackers can repeatedly call the startScan endpoint to f= orce CPU and I/O-intensive filesystem operations, causing denial of service=
on multi-user instances.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86118" target=3D= "_blank" rel=3D"noopener">CVE-2026-86118</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in SiteSettings in Google Chrome prior to 152.0= .7977.75 allowed a remote attacker to bypass system access restrictions via=
a crafted HTML page. (Chromium security severity: Medium)</td> <td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84332" target=3D= "_blank" rel=3D"noopener">CVE-2026-84332</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Information leak in MediaCapture in Google Chrome prior to 152.0.7977.7=
5 allowed a remote attacker to potentially leak sensitive information via a=
crafted HTML page. (Chromium security severity: Medium)</td> <td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84348" target=3D= "_blank" rel=3D"noopener">CVE-2026-84348</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Improper input validation in Omnibox in Google Chrome prior to 152.0.79= 77.75 allowed a remote attacker leveraging social engineering to bypass web=
origin policy via crafted network traffic. (Chromium security severity: Hi= gh)</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84357" target=3D= "_blank" rel=3D"noopener">CVE-2026-84357</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Missing authorization in FileSystem in Google Chrome prior to 152.0.797= 7.75 allowed a remote attacker who had compromised the renderer process and=
leveraged social engineering to obtain sensitive information via a crafted=
HTML page. (Chromium security severity: Medium)</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84323" target=3D= "_blank" rel=3D"noopener">CVE-2026-84323</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Confused deputy in CredentialProvider in Google Chrome on on Windows pr= ior to 152.0.7977.75 allowed a remote attacker who had compromised the rend= erer process to leak sensitive information via a crafted HTML page. (Chromi=
um security severity: Low)</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84329" target=3D= "_blank" rel=3D"noopener">CVE-2026-84329</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977= .75 allowed a remote attacker to spoof address bar via a crafted HTML page.=
(Chromium security severity: Low)</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84356" target=3D= "_blank" rel=3D"noopener">CVE-2026-84356</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Improper privilege management in Downloads in Google Chrome prior to 15= 2.0.7977.75 allowed a remote attacker who had compromised the renderer proc= ess to spoof address bar via a crafted HTML page. (Chromium security severi= ty: Medium)</td>
<td>2026-09-02</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84358" target=3D= "_blank" rel=3D"noopener">CVE-2026-84358</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Incorrect authorization in Autofill in Google Chrome on on Android prio=
r to 152.0.7977.75 allowed a remote attacker leveraging social engineering =
to obtain sensitive information via a crafted HTML page. (Chromium security=
severity: Low)</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84327" target=3D= "_blank" rel=3D"noopener">CVE-2026-84327</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Use of released resource in Mobile in Google Chrome on on Android prior=
to 152.0.7977.82 allowed a remote attacker leveraging social engineering t=
o bypass web origin policy via a crafted HTML page. (Chromium security seve= rity: Medium)</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85044" target=3D= "_blank" rel=3D"noopener">CVE-2026-85044</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>UI misrepresentation in FullScreen in Google Chrome on on Android prior=
to 152.0.7977.75 allowed a remote attacker to spoof address bar via a craf= ted HTML page. (Chromium security severity: Medium)</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84330" target=3D= "_blank" rel=3D"noopener">CVE-2026-84330</a></td>
</tr>
<td class=3D"vendor-product">gouguoa--gouguoa</td>
<td>A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.=
1. This vulnerability affects the function update of the file app/home/cont= roller/Index.php of the component edit_personal Endpoint. Such manipulation=
of the argument position_id leads to dynamically-determined object attribu= tes. The attack can be executed remotely. The exploit has been disclosed pu= blicly and may be used. Upgrading to version 6.0.3 is able to resolve this = issue. Upgrading the affected component is advised.</td>
<td>2026-09-02</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84430" target=3D= "_blank" rel=3D"noopener">CVE-2026-84430</a></td>
</tr>
<td class=3D"vendor-product">Grafana--Grafana Enterprise</td>
<td>When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAM=
L library skips validation of the InResponseTo field on all SAML responses,=
including SP-initiated logins. This removes anti-replay protection, allowi=
ng an attacker who obtains a valid signed SAML assertion to replay it and g= ain a session as the victim user. Only instances with the allow_idp_initiat=
ed SAML setting enabled are affected; this setting is off by default and Gr= afana OSS is not affected.</td>
<td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12704" target=3D= "_blank" rel=3D"noopener">CVE-2026-12704</a></td>
</tr>
<td class=3D"vendor-product">Grafana--PostgreSQL Datasource</td>
<td>An authenticated user with permission to query a SQL data source can by= pass the fix for CVE-2026-33375 by injecting the timeGroup macro through a = WHERE clause, which Grafana's regex-based macro parsing does not reject. Ev= aluating the injected macro causes uncontrolled memory consumption that can=
terminate the Grafana server process, resulting in a denial of service. Th=
e Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.</t=
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19475" target=3D= "_blank" rel=3D"noopener">CVE-2026-19475</a></td>
</tr>
<td class=3D"vendor-product">grokability--snipe-it</td>
<td>Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the asse= ts.edit permission instead of assets.delete, allowing users without delete = rights to restore soft-deleted assets. Attackers with edit permissions can = post asset identifiers to the bulk restore endpoint to undo administrator d= eletions and bypass intended permission separation.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84206" target=3D= "_blank" rel=3D"noopener">CVE-2026-84206</a></td>
</tr>
<td class=3D"vendor-product">growilabs--growi</td>
<td>GROWI contains an access control vulnerability in the GET /_api/v3/atta= chment/:id endpoint that fails to validate page access permissions. Authent= icated attackers can retrieve attachment metadata from pages they cannot vi=
ew by supplying known attachment identifiers.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84204" target=3D= "_blank" rel=3D"noopener">CVE-2026-84204</a></td>
</tr>
<td class=3D"vendor-product">growilabs--growi</td>
<td>GROWI contains an access control vulnerability in the GET /_api/v3/revi= sions/:id endpoint that validates access against a query parameter but retu= rns the revision identified by the path parameter without confirming they r= eference the same page. Authenticated attackers can pair a page identifier = they can access with an arbitrary revision identifier to read revision cont= ent from pages they lack permission to view.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84205" target=3D= "_blank" rel=3D"noopener">CVE-2026-84205</a></td>
</tr>
<td class=3D"vendor-product">Gutentor--Gutentor</td>
<td>The Gutentor WordPress plugin before 4.0.6 does not apply the correct c= ontext restriction to one of its REST endpoints, exposing the plaintext pas= swords of password-protected posts to any authenticated user with at least = the Subscriber role.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16983" target=3D= "_blank" rel=3D"noopener">CVE-2026-16983</a></td>
</tr>
<td class=3D"vendor-product">h3 --h3=C2=A0<br>=C2=A0</td>
<td>h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability i=
n the redirectBack() utility that fails to sanitize protocol-relative paths=
in the Referer header pathname. Attackers can craft a same-origin URL with=
a double-slash path segment that passes origin validation but produces a L= ocation header interpreted by browsers as a protocol-relative redirect to a=
n external domain.</td>
<td>2026-09-06</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86205" target=3D= "_blank" rel=3D"noopener">CVE-2026-86205</a></td>
</tr>
<td class=3D"vendor-product">h3 --h3=C2=A0<br>=C2=A0</td>
<td>h3 versions before 1.15.9 contain a path traversal vulnerability in the=
serveStatic utility. A double-decoding flaw allows a request path containi=
ng double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, = which survives resolveDotSegments() because that function only checks for l= iteral '.' characters. When the resulting asset ID is resolved by URL-based=
backends (CDN, S3, object storage), %2e%2e is interpreted as '..' per RFC = 3986, enabling path traversal to read arbitrary files from the backend.</td=
<td>2026-09-06</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86251" target=3D= "_blank" rel=3D"noopener">CVE-2026-86251</a></td>
</tr>
<td class=3D"vendor-product">h3 --h3=C2=A0<br>=C2=A0</td>
<td>h3 (npm package) versions <=3D 2.0.1-rc.14 contain a path traversal = vulnerability in serveStatic(). On Node.js deployments, event.url.pathname =
is not normalized, so percent-encoded dot segments (%2e%2e) are passed to d= ecodeURI() and decoded to ../ sequences without sanitization. An unauthenti= cated remote attacker can send crafted requests to endpoints served by serv= eStatic() to read arbitrary files outside the intended static directory. Fi= xed in 1.15.6 and 2.0.1-rc.15.</td>
<td>2026-09-06</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86253" target=3D= "_blank" rel=3D"noopener">CVE-2026-86253</a></td>
</tr>
<td class=3D"vendor-product">h3 --h3=C2=A0<br>=C2=A0<br>=C2=A0</td>
<td>h3 versions before 1.15.9 fail to sanitize carriage return characters i=
n EventStream data and comment fields, allowing attackers to inject arbitra=
ry SSE events by including unsanitized carriage returns. Attackers can inje=
ct event type directives, split single push calls into multiple browser-par= sed events, or escape comment fields to inject data, bypassing the prior CV=
E fix that only addressed newline injection.</td>
<td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86252" target=3D= "_blank" rel=3D"noopener">CVE-2026-86252</a></td>
</tr>
<td class=3D"vendor-product">heymrun--heym</td>
<td>Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send = and WebSocket Trigger nodes, allowing authenticated users to connect to int= ernal services. Attackers can craft workflow nodes with arbitrary URLs and = headers to reach internal services and read responses from the WebSocket Tr= igger node.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84207" target=3D= "_blank" rel=3D"noopener">CVE-2026-84207</a></td>
</tr>
<td class=3D"vendor-product">HIPAA FORMS--HIPAA FORMS</td>
<td>The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded auth= entication bypass via a hardcoded parameter alongside all AJAX requests. Th=
e server explicitly checks for this value to skip nonce validation entirely=
. This allows unauthenticated attackers to access protected AJAX endpoints.= </td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-2688" target=3D"= _blank" rel=3D"noopener">CVE-2026-2688</a></td>
</tr>
<td class=3D"vendor-product">Hitachi Energy--RTU500 series CMU firmware</td=
<td>RTU500 has a vulnerability, where high-load scenarios, such as sending =
GI requests at short intervals, may cause a NULL pointer dereference in the=
last entry of the enhanced message queue. This can cause a BCI_IEC104 fata=
l write error, resulting in connection interruption and restart, and ultima= tely a denial of service for bidirectional IEC 60870-5-104 communication.</=
<td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17539" target=3D= "_blank" rel=3D"noopener">CVE-2026-17539</a></td>
</tr>
<td class=3D"vendor-product">honojs--@hono/oauth-providers</td> <td>@hono/oauth-providers is Authentication middleware for Hono. Prior to v= ersion 0.8.6, the built-in social login providers accept an OAuth callback = even when the `state` value is absent on both sides, so the anti-CSRF check=
passes for a callback that never came from a genuine login attempt. This d= efeats the `state`-based CSRF protection under default usage. Version 0.8.6=
has a patch.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81888" target=3D= "_blank" rel=3D"noopener">CVE-2026-81888</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-394=
08 does not cover every traversal sequence, and toSSG() can still write fil=
es outside the configured output directory when a route parameter contains = consecutive parent-directory segments. Static site generation builds each o= utput path from the route path and values supplied through ssgParams, then = verifies that the result stays inside the output directory using the same n= ormalization routine that built the path. That routine does not fully colla= pse runs of consecutive parent-directory segments, allowing a path that the=
check accepts to resolve outside the output directory, and the check also = treats output directories that differ in how they are rooted as equivalent.=
This arises when an application generates a static site from route paramet=
er values it does not fully control, such as slugs from a CMS, API, or user=
submission. An untrusted ssgParams value can create or overwrite files els= ewhere in the build environment and alter generated artifacts or deployment=
output. The vulnerability affects build-time static site generation only; = request-time routing and applications with entirely developer-controlled ss= gParams values are not affected. This issue is fixed in version 4.13.5.</td=
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84365" target=3D= "_blank" rel=3D"noopener">CVE-2026-84365</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark = after a literal hash fragment as the start of a query string, so the applic= ation can read request parameters that browsers, new URL(), reverse proxies=
, filtering rules, parameter allow and deny lists, access logging, request = validation, and other middleware do not observe. The Cache Middleware remov=
es the fragment when building its cache key, allowing a response influenced=
by parameters inside the fragment to be stored under a key that omits thos=
e parameters and later served to other users. This can bypass filtering and=
auditing, poison cached responses, and enable stored cross-site scripting = when an affected parameter is reflected into cached HTML without escaping. = Exploitation requires a runtime and intermediary path that passes a literal=
hash character through to the request URL; Cloudflare Workers and intermed= iaries that strip fragments are not affected. This issue is fixed in versio=
n 4.13.5.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84363" target=3D= "_blank" rel=3D"noopener">CVE-2026-84363</a></td>
</tr>
<td class=3D"vendor-product">honojs--hono</td>
<td>Hono is a Web application framework that provides support for any JavaS= cript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form=
field names into nested objects with dot-notation parsing enabled, it does=
not limit the nesting depth or the total number of intermediate objects cr= eated. Empty segments are preserved, so one deeply dotted field name can en= code one nesting level per byte, while a large number of shallowly dotted f= ields can create the same amplification across a request. A request body wi= thin a normal size limit can therefore allocate an object graph far larger = than the request after the body has already been accepted. An unauthenticat=
ed attacker who can reach an affected endpoint can send concurrent requests=
that exhaust the JavaScript heap, terminate the server process, and leave = the service unavailable until restart. Dot-notation parsing is not enabled =
by default, and applications using the default behavior are not affected. T= his issue is fixed in version 4.13.5.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84364" target=3D= "_blank" rel=3D"noopener">CVE-2026-84364</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability in the web-based management interface of AOS-CX could a= llow an authenticated remote attacker to conduct a server-side request forg= ery (SSRF) attack. A successful exploit allows an attacker to enumerate inf= ormation about the internal structure of the AOS-CX host, leading to potent= ial disclosure and limited modification of sensitive information.</td> <td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73757" target=3D= "_blank" rel=3D"noopener">CVE-2026-73757</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A privilege escalation vulnerability exists in the API endpoint of AOS-= CX. Successful exploitation could allow an authenticated low privilege oper= ator user to change the state of certain settings of a vulnerable system.</=
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73758" target=3D= "_blank" rel=3D"noopener">CVE-2026-73758</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Vulnerabilities in AOS-CX could allow an unauthenticated remote malicio=
us actor to trigger a denial-of-service condition by sending specially craf= ted packets. Successful exploitation of these vulnerabilities results in di= sruption of normal operation on affected devices.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73759" target=3D= "_blank" rel=3D"noopener">CVE-2026-73759</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An authenticated Path Traversal vulnerability exists in AOS-CX. Success= ful exploitation of this vulnerability allows an attacker to read arbitrary=
files from the web-based management interface of the underlying operating = system, which could lead to remote unauthorized access to files.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73760" target=3D= "_blank" rel=3D"noopener">CVE-2026-73760</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>An out-of-bounds read vulnerability exists in the underlying operating = system of AOS-CX that could lead to unauthenticated information disclosure =
by sending a specially crafted packet. Successful exploitation of this vuln= erability results in the ability to disclose sensitive information from the=
underlying operating system.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73761" target=3D= "_blank" rel=3D"noopener">CVE-2026-73761</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability has been identified in the API endpoint of AOS-CX that = could allow a remote actor to circumvent existing access controls. In some = cases this could enable unauthorized access to management functionality tha=
t should be restricted by the configured access control policy.</td> <td>2026-09-01</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73762" target=3D= "_blank" rel=3D"noopener">CVE-2026-73762</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Buffer overflow vulnerabilities exist in an underlying service of AOS-C=
X that could lead to an unauthenticated denial-of-service condition by send= ing specially crafted packets to the affected device. Successful exploitati=
on of these vulnerabilities results in a disruption of normal operation of = the underlying operating system.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73772" target=3D= "_blank" rel=3D"noopener">CVE-2026-73772</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Denial-of-service vulnerabilities exist in the command line interface o=
f AOS-CX. Successful exploitation could allow an authenticated user to disr= upt the normal operation of a vulnerable system.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73754" target=3D= "_blank" rel=3D"noopener">CVE-2026-73754</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A privilege escalation vulnerability exists in the API endpoint of AOS-= CX. Successful exploitation could allow an authenticated low-privilege oper= ator user, after a required user action, to access sensitive information fr=
om the vulnerable system.</td>
<td>2026-09-01</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73755" target=3D= "_blank" rel=3D"noopener">CVE-2026-73755</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>A vulnerability in an API endpoint of AOS-CX could allow a remote unaut= henticated attacker to obtain sensitive information via a man-in-the-middle=
attack. Successful exploitation allows an attacker to retrieve data which = could be used to further compromise the confidentiality of the affected sys= tem.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73756" target=3D= "_blank" rel=3D"noopener">CVE-2026-73756</a></td>
</tr>
<td class=3D"vendor-product">hpe -- arubaos-cx</td>
<td>Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Succ= essful exploitation could allow an authenticated malicious actor to cause a=
denial-of-service condition on the affected system.</td>
<td>2026-09-01</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73783" target=3D= "_blank" rel=3D"noopener">CVE-2026-73783</a></td>
</tr>
<td class=3D"vendor-product">huggingface--tokenizers</td>
<td>tokenizers (Hugging Face) is affected by an out-of-bounds buffer access=
in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a = tokenizer.json via Tokenizer::from_file/from_str, the builder sizes a scrat=
ch buffer to the longest vocabulary key, then writes each concatenated merg=
e rule into it. A merge whose concatenated token exceeds the longest vocabu= lary key overruns the buffer, which Rust turns into a panic that aborts the=
process in Rust and FFI embeddings. This occurs at load time with no encod= ing required, so an attacker who supplies a crafted tokenizer.json can caus=
e a denial of service. A secondary defect at the same location can cause a = usize underflow (panic in debug, potential memory corruption in release) wh=
en continuing_subword_prefix is set and a merge token is shorter than the p= refix. Observed in version 0.23.1.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85670" target=3D= "_blank" rel=3D"noopener">CVE-2026-85670</a></td>
</tr>
<td class=3D"vendor-product">IBM-- App Connect Enterprise<br>=C2=A0</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a local attacker to obtain sensitive information due to improper=
logging of credentials.</td>
<td>2026-09-04</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16689" target=3D= "_blank" rel=3D"noopener">CVE-2026-16689</a></td>
</tr>
<td class=3D"vendor-product">IBM-- i<br>=C2=A0</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to obtain sensitive information due to the use of hardcoded cryptographic=
constants to obfuscate encryption keys.</td>
<td>2026-09-04</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16693" target=3D= "_blank" rel=3D"noopener">CVE-2026-16693</a></td>
</tr>
<td class=3D"vendor-product">IBM-- i<br><br>=C2=A0</td>
<td>IBM i 7.6, 7.5, and 7.4 could allow a remote authenticated attacker to = modify certain system messages due to improper authorization.</td> <td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16941" target=3D= "_blank" rel=3D"noopener">CVE-2026-16941</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a local attacker to obtain sensitive information due to improper=
logging of database credentials.</td>
<td>2026-09-04</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19649" target=3D= "_blank" rel=3D"noopener">CVE-2026-19649</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a local attacker to cause a denial of service due to uncontrolle=
d recursion.</td>
<td>2026-09-04</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17440" target=3D= "_blank" rel=3D"noopener">CVE-2026-17440</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a local attacker to obtain sensitive information due to credenti= als being written to trace logs in cleartext.</td>
<td>2026-09-04</td>
<td>5.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17442" target=3D= "_blank" rel=3D"noopener">CVE-2026-17442</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a remote authenticated attacker to obtain sensitive information = due to an XML external entity (XXE) injection flaw.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17443" target=3D= "_blank" rel=3D"noopener">CVE-2026-17443</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a remote authenticated attacker to obtain sensitive information = due to an XML external entity (XXE) injection.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17444" target=3D= "_blank" rel=3D"noopener">CVE-2026-17444</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 c= ould allow a remote attacker to cause a denial of service due to an infinit=
e loop.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78543" target=3D= "_blank" rel=3D"noopener">CVE-2026-78543</a></td>
</tr>
<td class=3D"vendor-product">IBM--App Connect Enterprise<br>=C2=A0</td>
<td>IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thro= ugh 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 T= oolkit could allow an authenticated user to cause a denial-of-service condi= tion due to improper validation of XML entities.</td>
<td>2026-09-04</td>
<td>5.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16180" target=3D= "_blank" rel=3D"noopener">CVE-2026-16180</a></td>
</tr>
<td class=3D"vendor-product">IBM--Cloud Pak for Business Automation</td>
<td>CP4BA - IBM Enterprise Records could allow a local attacker to obtain s= ensitive information due to the use of a broken or risky cryptographic algo= rithm.</td>
<td>2026-09-04</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81859" target=3D= "_blank" rel=3D"noopener">CVE-2026-81859</a></td>
</tr>
<td class=3D"vendor-product">IBM--Cloud Pak for Data System<br>=C2=A0</td> <td>IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could al= low an unauthorized user to inject data into log messages due to improper n= eutralization of special elements when written to log files.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14350" target=3D= "_blank" rel=3D"noopener">CVE-2026-14350</a></td>
</tr>
<td class=3D"vendor-product">IBM--Db2 Mirror for i</td>
<td>IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attack=
er to delete historical flight-recorder archives due to improper access con= trol in an SQL procedure.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17483" target=3D= "_blank" rel=3D"noopener">CVE-2026-17483</a></td>
</tr>
<td class=3D"vendor-product">IBM--Db2 Mirror for i</td>
<td>IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to = obtain information due to a race condition involving a predictable Unix dom= ain socket path in a world-writable directory.</td>
<td>2026-09-04</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18567" target=3D= "_blank" rel=3D"noopener">CVE-2026-18567</a></td>
</tr>
<td class=3D"vendor-product">IBM--Db2 Mirror for i<br>=C2=A0</td>
<td>IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to=
cause a denial of service due to an out-of-bounds read.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16660" target=3D= "_blank" rel=3D"noopener">CVE-2026-16660</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a d= enial of service and compromise integrity due to a buffer overflow.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17207" target=3D= "_blank" rel=3D"noopener">CVE-2026-17207</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to cause a denial of service due to a NULL pointer dereference.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17273" target=3D= "_blank" rel=3D"noopener">CVE-2026-17273</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to corrupt memory due to an integer underflow.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18341" target=3D= "_blank" rel=3D"noopener">CVE-2026-18341</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to o= btain sensitive information in PASE. An attacker could exploit this vulnera= bility to access information about process they shouldn't be permitted to a= ccess.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18887" target=3D= "_blank" rel=3D"noopener">CVE-2026-18887</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to bypass security restrictions due to predictable server seeds.</td> <td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17274" target=3D= "_blank" rel=3D"noopener">CVE-2026-17274</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker=
to cause a denial of service due to an off-by-one write in the LPD queue n= ame parser.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17469" target=3D= "_blank" rel=3D"noopener">CVE-2026-17469</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a d= enial of service due to a buffer overflow.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17470" target=3D= "_blank" rel=3D"noopener">CVE-2026-17470</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a d= enial of service due to improper validation of the prefix length in ICMPv6 = Router Advertisements.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17255" target=3D= "_blank" rel=3D"noopener">CVE-2026-17255</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to cause a denial of service due to a stack-based buffer overflow.</td> <td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17259" target=3D= "_blank" rel=3D"noopener">CVE-2026-17259</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a de= nial of service due to a stack-based buffer overflow.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17270" target=3D= "_blank" rel=3D"noopener">CVE-2026-17270</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute ar= bitrary commands due to improper neutralization of special elements used in=
an OS command.</td>
<td>2026-09-04</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17499" target=3D= "_blank" rel=3D"noopener">CVE-2026-17499</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker=
to inject parameters into a CL command due to improper neutralization of s= pecial elements.</td>
<td>2026-09-04</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18073" target=3D= "_blank" rel=3D"noopener">CVE-2026-18073</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to cause a denial of service due to a memory leak.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18076" target=3D= "_blank" rel=3D"noopener">CVE-2026-18076</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to cause a denial of service due to an integer overflow.</td> <td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18078" target=3D= "_blank" rel=3D"noopener">CVE-2026-18078</a></td>
</tr>
<td class=3D"vendor-product">IBM--i<br>=C2=A0</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a d= enial of service and affect data integrity due to missing authentication fo=
r critical functions.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17057" target=3D= "_blank" rel=3D"noopener">CVE-2026-17057</a></td>
</tr>
<td class=3D"vendor-product">IBM--i<br>=C2=A0</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute ar= bitrary commands due to improper neutralization of special elements used in=
an OS command.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16826" target=3D= "_blank" rel=3D"noopener">CVE-2026-16826</a></td>
</tr>
<td class=3D"vendor-product">IBM--i<br>=C2=A0<br>=C2=A0</td>
<td>IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacke=
r to bypass security restrictions due to improper authentication during ser= vice-name matching.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16892" target=3D= "_blank" rel=3D"noopener">CVE-2026-16892</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticate=
d attacker to obtain sensitive information due to improper limitation of a = pathname to a restricted directory.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17622" target=3D= "_blank" rel=3D"noopener">CVE-2026-17622</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to obtain sensitive information due to path traversal.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19299" target=3D= "_blank" rel=3D"noopener">CVE-2026-19299</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to obtain sensitive information due to improper validation of sy= mbolic links.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19302" target=3D= "_blank" rel=3D"noopener">CVE-2026-19302</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site s= cripting vulnerability in the Playground chat interface.</td> <td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8447" target=3D"= _blank" rel=3D"noopener">CVE-2026-8447</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authentic= ated attacker to write arbitrary files to the server due to improper input = validation in the SaveToFileComponent. The application constructs local fil=
e paths using attacker-controlled input without sufficient sanitization whe=
n handling requests to the /api/v1/run/{flow_id} endpoint. An attacker with=
low-privileged authenticated access (such as a valid API key or user sessi= on) can supply crafted path values, including absolute paths or path traver= sal sequences, allowing arbitrary file writes to locations writable by the = Langflow process. Successful exploitation may lead to unauthorized file cre= ation or modification, potentially resulting in further compromise dependin=
g on the deployment environment.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9138" target=3D"= _blank" rel=3D"noopener">CVE-2026-9138</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attac= kers to bypass localhost-only MCP configuration installation by spoofing X-= Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config fi= les (~/.cursor/mcp.json, etc.).</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9186" target=3D"= _blank" rel=3D"noopener">CVE-2026-9186</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to = traverse directories on the system. An attacker could send a specially craf= ted URL request containing "dot dot " sequences ( /.. /) to view arbitrary = files on the system.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17621" target=3D= "_blank" rel=3D"noopener">CVE-2026-17621</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticate=
d attacker to obtain sensitive information due to a server-side request for= gery (SSRF) vulnerability.</td>
<td>2026-09-04</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17631" target=3D= "_blank" rel=3D"noopener">CVE-2026-17631</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticate=
d attacker to obtain sensitive information due to server-side request forge= ry.</td>
<td>2026-09-04</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19301" target=3D= "_blank" rel=3D"noopener">CVE-2026-19301</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS</td>
<td>IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticate=
d attacker to obtain sensitive information and inject messages into workflo=
w history due to improper authorization.</td>
<td>2026-09-04</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17627" target=3D= "_blank" rel=3D"noopener">CVE-2026-17627</a></td>
</tr>
<td class=3D"vendor-product">IBM--Langflow OSS<br>=C2=A0</td>
<td>IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated atta= cker to traverse directories on the system. An attacker could send a specia= lly crafted URL request containing "dot dot" sequences (/../) to view arbit= rary files on the system.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14470" target=3D= "_blank" rel=3D"noopener">CVE-2026-14470</a></td>
</tr>
<td class=3D"vendor-product">IBM--MQ Agent</td>
<td>IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated user w= ith a valid session cookie can submit arbitrarily large or computationallye= xpensive requests that cause the LLM agent workers to be held for extended = periods - rangingfrom tens of seconds to over ten minutes per request. When=
multiple such requests are sentconcurrently, the agent worker pool becomes=
exhausted, causing all other IBM MQ Console users toexperience degraded pe= rformance or complete unavailability of the AI Agent feature.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19645" target=3D= "_blank" rel=3D"noopener">CVE-2026-19645</a></td>
</tr>
<td class=3D"vendor-product">IBM--Netezza Software</td>
<td>IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations th=
at are performed without validating bucket ownership using the ExpectedBuck= etOwner parameter. This omission may allow a remote attacker to exploit mis= configurations or naming collisions to redirect application requests to an = unintended S3 bucket under their control.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9745" target=3D"= _blank" rel=3D"noopener">CVE-2026-9745</a></td>
</tr>
<td class=3D"vendor-product">IBM--Netezza Software</td>
<td>IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate=
or improperly validates TLS certificate validation, which could allow an a= ttacker to obtain sensitive information using man in the middle techniques.= </td>
<td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9036" target=3D"= _blank" rel=3D"noopener">CVE-2026-9036</a></td>
</tr>
<td class=3D"vendor-product">IBM--Netezza Software</td>
<td>IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an un= authorized user to inject data into log messages due to improper neutraliza= tion of special elements when written to log files.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9736" target=3D"= _blank" rel=3D"noopener">CVE-2026-9736</a></td>
</tr>
<td class=3D"vendor-product">IBM--Netezza Software</td>
<td>IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate=
or improperly validates TLS certificate validation, which could allow an a= ttacker to obtain sensitive information using man in the middle techniques.= </td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9744" target=3D"= _blank" rel=3D"noopener">CVE-2026-9744</a></td>
</tr>
<td class=3D"vendor-product">IBM--Qiskit SDK</td>
<td>Qiskit could allow a local attacker to cause a denial of service due to=
a stack overflow during deserialization of QPY payloads. A malicious QPY p= ayload can trigger a segmentation fault, causing the application to crash w= hen deserializing untrusted input.</td>
<td>2026-09-03</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19795" target=3D= "_blank" rel=3D"noopener">CVE-2026-19795</a></td>
</tr>
<td class=3D"vendor-product">IBM--QRadar</td>
<td>IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded=
credentials, such as a password or cryptographic key, which it uses for it=
s own inbound authentication, outbound communication to external components=
, or encryption of internal data.</td>
<td>2026-09-04</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-5522" target=3D"= _blank" rel=3D"noopener">CVE-2026-5522</a></td>
</tr>
<td class=3D"vendor-product">IBM--UCD - IBM UrbanCode Deploy</td>
<td>IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.25, and 7.3 through 7.= 3.2.20 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.15, 8.1 through 8.= 1.2.8, and 8.2 through 8.2.2.1 IBM DevOps Deploy / IBM UrbanCode Deploy (UC=
D) is susceptible to an formation disclosure vulnerability when processing = redacted property values. If a deployment is configured with a secure prope= rty that starts with certain non-ASCII characters, the redaction engine may=
fail to mask subsequent ASCII secure values embedded inside unsecure prope= rties. An authenticated user with permissions to view deployment request de= tails could exploit this flaw via the UI or API to view sensitive values in=
plain text that should otherwise be redacted.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78658" target=3D= "_blank" rel=3D"noopener">CVE-2026-78658</a></td>
</tr>
<td class=3D"vendor-product">ILIAS--ILIAS</td>
<td>A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This=
affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject=
of the file Services/Repository/Service/Resources/ZipAdapter.php of the co= mponent MediaPool. The manipulation results in unrestricted upload. The att= ack may be launched remotely. Upgrading to version 9.22, 10.10 and 11.3 is = able to mitigate this issue. The patch is identified as ef5d7f99fe1ea0381db= 04b333a2906548b3590e4/b0d61be43671b6bfe91baf469a5ee11e764f2e23. It is recom= mended to upgrade the affected component.</td>
<td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85135" target=3D= "_blank" rel=3D"noopener">CVE-2026-85135</a></td>
</tr>
<td class=3D"vendor-product">ILIAS-eLearning e.V.--ILIAS</td>
<td>ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file = read vulnerability in the SOAP addFile method that allows authenticated use=
rs to read server files by supplying crafted XML with COPY-mode imports. At= tackers can construct absolute file paths through an unsandboxed import dir= ectory and retrieve sensitive files including configuration files containin=
g database credentials and setup passwords.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82877" target=3D= "_blank" rel=3D"noopener">CVE-2026-82877</a></td>
</tr>
<td class=3D"vendor-product">Insyde Software--InsydeH2O</td>
<td>An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and=
administrator password hashes are exposed in runtime UEFI variables, leadi=
ng to escalation of privilege</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-43613" target=3D= "_blank" rel=3D"noopener">CVE-2021-43613</a></td>
</tr>
<td class=3D"vendor-product">Insyde Software--InsydeH2O</td>
<td>Error in handling the PlatformLangCodes UEFI variable could cause a buf= fer overflow, leading to resource exhaustion and failure.</td> <td>2026-09-03</td>
<td>6.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-43614" target=3D= "_blank" rel=3D"noopener">CVE-2021-43614</a></td>
</tr>
<td class=3D"vendor-product">Interinfo--DreamMaker</td>
<td>DreamMaker developed by Interinfo has a Reflected Cross-site Scripting = vulnerability. Authenticated remote attackers can execute arbitrary JavaScr= ipt codes in user's browser via a malicious website.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85541" target=3D= "_blank" rel=3D"noopener">CVE-2026-85541</a></td>
</tr>
<td class=3D"vendor-product">invoiceninja--Invoice Ninja</td>
<td>A weakness has been identified in invoiceninja Invoice Ninja up to 5.13= .26. This affects an unknown part of the file /vedor/profile/ of the compon= ent Vendor Portal Profile Update. Executing a manipulation of the argument = vendor_contact can lead to authorization bypass. The attack may be performe=
d from remote. The exploit has been made available to the public and could =
be used for attacks. Upgrading to version 5.13.27 is able to mitigate this = issue. This patch is called f86fd9697ce7bd0d28adbe2e6c5890780482ea90. The a= ffected component should be upgraded.</td>
<td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83743" target=3D= "_blank" rel=3D"noopener">CVE-2026-83743</a></td>
</tr>
<td class=3D"vendor-product">invoiceninja--Invoice Ninja</td>
<td>A security vulnerability has been detected in invoiceninja Invoice Ninj=
a up to 5.13.26. This vulnerability affects the function Purify::isHostSafe=
of the file app/Services/Pdf/Purify.php of the component invoices Endpoint=
. The manipulation of the argument notes leads to server-side request forge= ry. It is possible to initiate the attack remotely. The exploit has been di= sclosed publicly and may be used. The vendor was contacted early about this=
disclosure but did not respond in any way.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83744" target=3D= "_blank" rel=3D"noopener">CVE-2026-83744</a></td>
</tr>
<td class=3D"vendor-product">IObit--Uninstaller</td>
<td>A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the = function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the comp= onent IOCTL Handler. Executing a manipulation can lead to improper privileg=
e management. The attack requires local access. The vendor was contacted ea= rly about this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82670" target=3D= "_blank" rel=3D"noopener">CVE-2026-82670</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode --Sales and Inventory System 1.0<= br>=C2=A0</td>
<td>A vulnerability was identified in itsourcecode Sales and Inventory Syst=
em 1.0. This impacts an unknown function of the file /pages/pro_del.php. Th=
e manipulation of the argument ID leads to sql injection. The attack is pos= sible to be carried out remotely. The exploit is publicly available and mig=
ht be used.</td>
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86163" target=3D= "_blank" rel=3D"noopener">CVE-2026-86163</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode --Sales and Inventory System 1.0<= br>=C2=A0</td>
<td>A security flaw has been discovered in itsourcecode Sales and Inventory=
System 1.0. Affected is an unknown function of the file /pages/trans_view.= php. The manipulation of the argument ID results in sql injection. The atta=
ck may be performed from remote. The exploit has been released to the publi=
c and may be used for attacks.</td>
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86164" target=3D= "_blank" rel=3D"noopener">CVE-2026-86164</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A weakness has been identified in itsourcecode Online Medicine Delivery=
System 1.0. Affected by this vulnerability is the function doupdateimage o=
f the file /customer/controller.php?action=3Dphotos of the component Custom=
er Controller. Executing a manipulation of the argument photo can lead to u= nrestricted upload. The attack may be performed from remote. The exploit ha=
s been made available to the public and could be used for attacks.</td> <td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85186" target=3D= "_blank" rel=3D"noopener">CVE-2026-85186</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A vulnerability was determined in itsourcecode Online Medicine Delivery=
System 1.0. This issue affects the function addwishlist of the file /custo= mer/controller.php?action=3Daddwish of the component Wishlist. This manipul= ation of the argument proid causes sql injection. The attack may be initiat=
ed remotely.</td>
<td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85205" target=3D= "_blank" rel=3D"noopener">CVE-2026-85205</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Sales and Inventory System</td> <td>A vulnerability was identified in itsourcecode Sales and Inventory Syst=
em 1.0. This impacts an unknown function of the file /pages/inv_edit.php. T=
he manipulation of the argument ID leads to sql injection. It is possible t=
o initiate the attack remotely. The exploit is publicly available and might=
be used.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82609" target=3D= "_blank" rel=3D"noopener">CVE-2026-82609</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Sales and Inventory System</td> <td>A weakness has been identified in itsourcecode Sales and Inventory Syst=
em 1.0. The affected element is an unknown function of the file /pages/inv_= searchfrm.php. This manipulation of the argument ID causes sql injection. T=
he attack may be initiated remotely. The exploit has been made available to=
the public and could be used for attacks.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82696" target=3D= "_blank" rel=3D"noopener">CVE-2026-82696</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Sales and Inventory System</td> <td>A flaw has been found in itsourcecode Sales and Inventory System 1.0. T=
he affected element is an unknown function of the file /pages/inv_del.php. = Executing a manipulation of the argument ID can lead to sql injection. The = attack can be executed remotely. The exploit has been published and may be = used.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85383" target=3D= "_blank" rel=3D"noopener">CVE-2026-85383</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Sales and Inventory System 1.0<b= r>=C2=A0</td>
<td>A weakness has been identified in itsourcecode Sales and Inventory Syst=
em 1.0. Affected by this vulnerability is an unknown functionality of the f= ile /pages/sup_del.php?type=3Dsupplier. Executing a manipulation of the arg= ument ID can lead to sql injection. The attack may be performed from remote=
. The exploit has been made available to the public and could be used for a= ttacks.</td>
<td>2026-09-06</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86232" target=3D= "_blank" rel=3D"noopener">CVE-2026-86232</a></td>
</tr>
<td class=3D"vendor-product">JeecgBoot--JeecgBoot</td>
<td>JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerabil= ity in the SystemApiController component. An authenticated attacker with an=
y valid JWT token can access multiple API endpoints (including queryAllUser=
, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve se= nsitive information of all users, including real names, phone numbers, emai=
l addresses, employee numbers, and role definitions, due to missing fine-gr= ained permission checks and incomplete data desensitization.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78970" target=3D= "_blank" rel=3D"noopener">CVE-2026-78970</a></td>
</tr>
<td class=3D"vendor-product">jeecgboot--jeewx-boot</td>
<td>A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e= 1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid= 3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com= /jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUplo=
ad Endpoint. Executing a manipulation of the argument File can lead to unre= stricted upload. The attack can be executed remotely. The exploit has been = publicly disclosed and may be utilized. This product implements a rolling r= elease for ongoing delivery, which means version information for affected o=
r updated releases is unavailable. The project was informed of the problem = early through an issue report but has not responded yet.</td> <td>2026-08-31</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82629" target=3D= "_blank" rel=3D"noopener">CVE-2026-82629</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and=
CLI endpoints for updating agent configuration do not prevent a submitted = configuration from overwriting a different agent by specifying that agent's=
name in the submitted XML document, allowing attackers with Agent/Configur=
e permission on one agent to take over a different agent, gaining control o=
f its configuration and obtaining access to its inbound agent secret and en= vironment variables.</td>
<td>2026-09-02</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84651" target=3D= "_blank" rel=3D"noopener">CVE-2026-84651</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e5800= 8a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form = data binding allows setting public static fields of the bound configuration=
object, allowing attackers who can submit configuration forms to modify pu= blic static fields of the configuration objects those forms are bound to, r= esulting in changes that apply globally to the Jenkins instance.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84654" target=3D= "_blank" rel=3D"noopener">CVE-2026-84654</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can=
appear as nested field values in other deserialized XML objects, allowing = attackers with Overall/Read permission to create user objects by submitting=
crafted XML.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84646" target=3D= "_blank" rel=3D"noopener">CVE-2026-84646</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map = keys when serializing objects as JSON and Python through its REST API, allo= wing attackers able to control map property names to inject arbitrary field=
s into JSON and Python API responses.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84655" target=3D= "_blank" rel=3D"noopener">CVE-2026-84655</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 an=
d earlier allows attackers with Item/Read permission on at least one job to=
read build parameter names and values of jobs they have no access to.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84656" target=3D= "_blank" rel=3D"noopener">CVE-2026-84656</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI co= mmand does not check the Item/Cancel permission when using the -s flag to c= ancel a build triggered to wait for completion, allowing attackers with Ite= m/Build permission to cancel builds started by other users.</td>
<td>2026-09-02</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84657" target=3D= "_blank" rel=3D"noopener">CVE-2026-84657</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins GitLab Plugin</td>
<td>Jenkins GitLab Plugin 1.9.16 and earlier allows overwriting the global = GitLab connection configuration through Stapler data binding, allowing atta= ckers to connect to an attacker-specified URL using GitLab API tokens alrea=
dy configured by administrators.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84664" target=3D= "_blank" rel=3D"noopener">CVE-2026-84664</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Job Configuration His= tory Plugin</td>
<td>Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earli=
er allows overwriting the plugin's history recording configuration through = Stapler data binding, allowing attackers to redirect history storage to an = attacker-specified directory and modify history recording settings.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84666" target=3D= "_blank" rel=3D"noopener">CVE-2026-84666</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins LDAP Plugin</td>
<td>Jenkins LDAP Plugin 807.809.vd3a_4e5e4ec98 and earlier allows connectin=
g to a specified URL through Stapler data binding, allowing attackers to co= nnect to an attacker-specified URL.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84662" target=3D= "_blank" rel=3D"noopener">CVE-2026-84662</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Parameterized Remote = Trigger Plugin</td>
<td>Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores to= kens unencrypted in job config.xml files on the Jenkins controller where th=
ey can be viewed by users with Item/Extended Read permission or access to t=
he Jenkins controller file system.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84676" target=3D= "_blank" rel=3D"noopener">CVE-2026-84676</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Pipeline: Build Step = Plugin</td>
<td>A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v= 4b_67ea_11b_152 and earlier causes downstream builds triggered by the `buil=
d` step to be canceled even when the build's authentication lacks Item/Canc=
el permission on the downstream job.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84660" target=3D= "_blank" rel=3D"noopener">CVE-2026-84660</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Pipeline: Build Step = Plugin</td>
<td>A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v= 4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitFo= rBuild` step when the `propagateAbort` parameter is used to be canceled eve=
n when the build's authentication lacks Item/Cancel permission on the downs= tream job.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84661" target=3D= "_blank" rel=3D"noopener">CVE-2026-84661</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Pipeline: Groovy Libr= aries Plugin</td>
<td>A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: = Groovy Libraries Plugin 798.v5cc688825312 and earlier allows attackers to d= elete shared library caches.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84663" target=3D= "_blank" rel=3D"noopener">CVE-2026-84663</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Script Security Plugi= n</td>
<td>Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier uses the=
`@DataBoundConstructor` annotation on a constructor that loads script appr= oval configuration, allowing attackers able to submit certain forms to read=
that configuration.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84658" target=3D= "_blank" rel=3D"noopener">CVE-2026-84658</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins Script Security Plugi= n</td>
<td>Jenkins Script Security Plugin 1412.v7737b_3405f86 and earlier does not=
enforce a permission check in the method that controls the "Force the use =
of the sandbox globally in the system" setting, allowing attackers to disab=
le it through Stapler data binding.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84659" target=3D= "_blank" rel=3D"noopener">CVE-2026-84659</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins update-center2</td> <td>Jenkins update-center2 3.18.3 and earlier does not escape plugin-provid=
ed values (plugin names, descriptions, and version metadata) on plugin down= load index pages, resulting in a stored cross-site scripting (XSS) vulnerab= ility exploitable by attackers able to provide a plugin for hosting.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84677" target=3D= "_blank" rel=3D"noopener">CVE-2026-84677</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins XebiaLabs XL Deploy P= lugin</td>
<td>Missing permission checks in Jenkins XebiaLabs XL Deploy Plugin 26.1.0 = and earlier allow attackers with Overall/Read permission to enumerate crede= ntials IDs of credentials stored in Jenkins.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84674" target=3D= "_blank" rel=3D"noopener">CVE-2026-84674</a></td>
</tr>
<td class=3D"vendor-product">JetStyleManager for Gutenber--JetStyleManager = for Gutenberg</td>
<td>The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does no=
t have CSRF protection on some of its AJAX actions, allowing attackers to m= ake a logged-in user with the edit_posts capability (Contributor and above)=
delete or modify custom widget skins via a crafted request, provided they = can trick the user into performing an action such as clicking a link.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81432" target=3D= "_blank" rel=3D"noopener">CVE-2026-81432</a></td>
</tr>
<td class=3D"vendor-product">jofpin--trape</td>
<td>A vulnerability was identified in jofpin trape 1.0.0. Affected by this = vulnerability is an unknown functionality of the file core/stats.py of the = component Login Endpoint. The manipulation leads to missing authentication.=
The attack may be initiated remotely. The exploit is publicly available an=
d might be used. The project was informed of the problem early through an i= ssue report but has not responded yet.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85636" target=3D= "_blank" rel=3D"noopener">CVE-2026-85636</a></td>
</tr>
<td class=3D"vendor-product">John James Jacoby--bbPress</td>
<td>Missing Authorization vulnerability in John James Jacoby bbPress allows=
Exploiting Incorrectly Configured Access Control Security Levels. This iss=
ue affects bbPress: from n/a through 2.6.14.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74010" target=3D= "_blank" rel=3D"noopener">CVE-2026-74010</a></td>
</tr>
<td class=3D"vendor-product">jtsylve--LiME</td>
<td>LiME through 1.12.0 fails to validate the disk acquisition output path = and does not use O_NOFOLLOW when opening the operator-supplied path paramet= er, allowing unprivileged local users to overwrite arbitrary root-owned fil= es. An attacker who controls the output directory can create a symbolic lin=
k with the expected filename pointing to any root-owned file, and when the = acquisition runs in kernel context, LiME follows the link and truncates the=
target file with the memory acquisition stream.</td>
<td>2026-09-03</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85092" target=3D= "_blank" rel=3D"noopener">CVE-2026-85092</a></td>
</tr>
<td class=3D"vendor-product">Kevin Pirnie--KP Agent Ready</td>
<td>Insertion of Sensitive Information Into Sent Data vulnerability in Kevi=
n Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue=
affects KP Agent Ready: from n/a before 1.2.08.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85307" target=3D= "_blank" rel=3D"noopener">CVE-2026-85307</a></td>
</tr>
<td class=3D"vendor-product">Keyence Corporation--XG-X VisionTerminal</td> <td>XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporati=
on improperly restrict XML external entity references. If a user opens a sp= ecially crafted setting file, the sensitive information stored in the syste=
m where XG VisionTerminal or XG-X VisionTerminal is installed may be disclo= sed.</td>
<td>2026-09-03</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82918" target=3D= "_blank" rel=3D"noopener">CVE-2026-82918</a></td>
</tr>
<td class=3D"vendor-product">kimai--kimai</td>
<td>Kimai before 2.65.0 fails to properly validate permissions when removin=
g team access to activities, projects, and customers via API endpoints. Aut= henticated users with edit_team permission can revoke team access without t=
he required permissions_activity check, bypassing authorization controls.</=
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84804" target=3D= "_blank" rel=3D"noopener">CVE-2026-84804</a></td>
</tr>
<td class=3D"vendor-product">kimai--kimai</td>
<td>Kimai before 2.63.0 contains an improper authorization vulnerability in=
team access endpoints that allows authenticated users with team edit permi= ssions and read-only access to grant team access to customers, projects, or=
activities. Attackers can exploit insufficient permission checks by sendin=
g POST requests to team access endpoints to modify access control lists for=
entities they should not be able to modify.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84806" target=3D= "_blank" rel=3D"noopener">CVE-2026-84806</a></td>
</tr>
<td class=3D"vendor-product">kimai--kimai</td>
<td>Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper=
authorization vulnerability in the default team creation endpoints. An aut= henticated user with project permission-management privileges can create or=
use a customer, project, or activity whose name matches an existing team; = because the endpoints POST /api/customers/{id}/team, POST /api/projects/{id= }/team, and POST /api/activities/{id}/team reuse an existing team of the sa=
me name and add the current user as teamlead without verifying that the use=
r is authorized to manage that team, the attacker gains unauthorized team-l= ead (administration) rights over the existing team. Fixed in 2.65.0.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84807" target=3D= "_blank" rel=3D"noopener">CVE-2026-84807</a></td>
</tr>
<td class=3D"vendor-product">kimai--kimai</td>
<td>Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only wor= k-contract preferences for low-privilege users in the PATCH /api/users/{id}= /preferences endpoint. Although the web interface gates these employment-co= ntract fields behind the contract_other_profile admin permission, the WorkC= ontractPreferenceSubscriber (introduced in 2.61.0) registers the preference=
s as enabled without a permission check, so an authenticated regular user c=
an use the API to modify their own admin-only work-contract data. The issue=
is fixed in 2.63.0 by applying the same permission check to the API endpoi= nt.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84805" target=3D= "_blank" rel=3D"noopener">CVE-2026-84805</a></td>
</tr>
<td class=3D"vendor-product">kimai--kimai</td>
<td>Kimai versions before 2.65.0 contain an authorization bypass vulnerabil= ity in the REST API timesheet collection endpoint that fails to enforce act= ivity-team access controls. Users with view_other_timesheet permission can = list timesheets using activities restricted to teams they do not belong to,=
bypassing intended data isolation.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84808" target=3D= "_blank" rel=3D"noopener">CVE-2026-84808</a></td>
</tr>
<td class=3D"vendor-product">Kings Plugins--MarketKing</td>
<td>Missing Authorization vulnerability in Kings Plugins MarketKing allows = Exploiting Incorrectly Configured Access Control Security Levels. This issu=
e affects MarketKing: from n/a through 2.1.60.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85311" target=3D= "_blank" rel=3D"noopener">CVE-2026-85311</a></td>
</tr>
<td class=3D"vendor-product">KiviCare--KiviCare</td>
<td>The KiviCare WordPress plugin before 4.5.5 does not perform authorizati=
on checks on some of its REST endpoints, allowing unauthenticated attackers=
to disclose the patient roster and, when a payment gateway is configured, = the payment gateway secret key.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13611" target=3D= "_blank" rel=3D"noopener">CVE-2026-13611</a></td>
</tr>
<td class=3D"vendor-product">klaussilveira--GitList</td>
<td>A vulnerability was detected in klaussilveira GitList 2.0.0. Affected b=
y this issue is the function SimpleXMLElement of the file src/SCM/System/Gi= t/CommandLine.php of the component XML Parsing. Performing a manipulation r= esults in denial of service. The attack is possible to be carried out remot= ely. The exploit is now public and may be used. Upgrading to version 3.0.0-= beta can resolve this issue. The patch is named f67609d52c1812fa8a7ed80eae5= e795cfd72115f. It is advisable to upgrade the affected component.</td> <td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82669" target=3D= "_blank" rel=3D"noopener">CVE-2026-82669</a></td>
</tr>
<td class=3D"vendor-product">Kriesi--Enfold</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Kriesi Enfold allows Reflected XSS. This iss=
ue affects Enfold: from n/a through 8.0.</td>
<td>2026-09-03</td>
<td>5.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84815" target=3D= "_blank" rel=3D"noopener">CVE-2026-84815</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno before v1.13.4 is vulnerable to server-side request forgery (SS= RF) via its Service Call functionality. An attacker with permission to crea=
te Kyverno (Cluster)Policies can specify an external URL in a policy's apiC= all/service configuration; although Service Call is documented for in-clust=
er services, it also resolves external addresses, allowing requests to an a= ttacker-controlled server. Because policy context data (including contents =
of Kubernetes resources such as secrets) is sent in these requests, an atta= cker can exfiltrate sensitive cluster data.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15613" target=3D= "_blank" rel=3D"noopener">CVE-2025-15613</a></td>
</tr>
<td class=3D"vendor-product">langgenius--dify</td>
<td>A vulnerability was determined in langgenius dify 1.13.0. Affected is t=
he function router.replace of the file web/app/(shareLayout)/components/spl= ash.tsx of the component Splash Layout. This manipulation of the argument r= edirect_url causes cross site scripting. The attack is possible to be carri=
ed out remotely. The exploit has been publicly disclosed and may be utilize=
d. The vendor was contacted early about this disclosure but did not respond=
in any way.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85021" target=3D= "_blank" rel=3D"noopener">CVE-2026-85021</a></td>
</tr>
<td class=3D"vendor-product">Laravel-Backpack--CRUD</td>
<td>backpack/crud provides Create, Read, Update & Delete (CRUD) functio=
ns for Backpack, a collection of Laravel packages that help users build cus= tom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/= Library/Uploaders/SingleBase64Image.php methods SingleBase64Image::uploadFi= les and SingleBase64Image::uploadRepeatableFiles, used by image fields thro= ugh withFiles(), accept any data URI beginning with data:image without vali= dating the declared MIME subtype or decoded bytes, while src/app/Library/Up= loaders/Support/FileNameGenerator.php method FileNameGenerator::getExtensio= nFromFile applies mime_content_type() to the data URI instead of the decode=
d content. An authenticated administrator can therefore store arbitrary fil=
e content under an extensionless filename on the configured disk, which can=
cause stored cross-site scripting or other unintended behavior when the fi=
le is served and accessed. This issue is fixed in version 7.0.38 and 6.8.14= .</td>
<td>2026-08-31</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54179" target=3D= "_blank" rel=3D"noopener">CVE-2026-54179</a></td>
</tr>
<td class=3D"vendor-product">levelfourstorefront--Shopping Cart & eComm= erce Store</td>
<td>The Shopping Cart & eCommerce Store plugin for WordPress is vulnera= ble to generic SQL Injection via the 'product_order' parameter in all versi= ons up to, and including, 5.9.2 due to insufficient escaping on the user su= pplied parameter and lack of sufficient preparation on the existing SQL que= ry. This makes it possible for authenticated attackers, with administrator-= level access and above, to append additional SQL queries into already exist= ing queries that can be used to extract sensitive information from the data= base. This is a second-order SQL injection: the payload is written to the e= c_pageoption table via the ec_ajax_save_page_options handler - which applie=
s no sanitization to raw $_POST values - and is later retrieved with strips= lashes() (bypassing WordPress magic-quotes protection) before being concate= nated directly into SQL on every store page render.</td>
<td>2026-09-01</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17589" target=3D= "_blank" rel=3D"noopener">CVE-2026-17589</a></td>
</tr>
<td class=3D"vendor-product">libjxl--libjxl</td>
<td>libjxl before 0.12 contains an integer underflow vulnerability in the c= ontainer box parser that allows remote attackers to inject arbitrary metada=
ta by exploiting 64-bit box size truncation to size_t on 32-bit platforms. = Attackers can supply a crafted JPEG XL file causing the decoder to parse at= tacker-controlled codestream bytes as phantom box headers, enabling injecti=
on of arbitrary metadata (Exif, XMP, IPTC, JUMBF) and potential out-of-boun=
ds reads.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82522" target=3D= "_blank" rel=3D"noopener">CVE-2026-82522</a></td>
</tr>
<td class=3D"vendor-product">libpcap --BPF interpreter<br>=C2=A0</td> <td>libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction=
as a signed integer to implement looping via backward jumps, but it does n=
ot limit the number of loop iterations. In particular uncommon use cases a = crafted filter program can cause the interpreter to loop infinitely.</td> <td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6554" target=3D"= _blank" rel=3D"noopener">CVE-2026-6554</a></td>
</tr>
<td class=3D"vendor-product">libpcap--BPF interpreter<br>=C2=A0</td> <td>libpcap BPF interpreter calls abort() if it encounters a BPF instructio=
n that has an invalid opcode. In particular uncommon use cases a crafted fi= lter program can terminate the OS process.</td>
<td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31911" target=3D= "_blank" rel=3D"noopener">CVE-2026-31911</a></td>
</tr>
<td class=3D"vendor-product">libpcap--BPF interpreter<br>=C2=A0</td> <td>libpcap BPF interpreter detects neither reaching the end of the filter = program buffer due to lack of a return instruction nor executing a jump ins= truction with an offset that translates to a pointer outside of the buffer.=
In particular uncommon use cases a crafted filter program can cause the in= terpreter to try reading the OS process memory in the 32GiB around the buff=
er on 64-bit architectures and in the entire address space on 32-bit archit= ectures.</td>
<td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-31912" target=3D= "_blank" rel=3D"noopener">CVE-2026-31912</a></td>
</tr>
<td class=3D"vendor-product">libpcap--BPF interpreter<br>=C2=A0</td> <td>libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions = does not check whether the immediate value is zero. In particular uncommon = use cases a crafted filter program can cause a division by zero.</td> <td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6244" target=3D"= _blank" rel=3D"noopener">CVE-2026-6244</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabili= ties in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVp= nVrfRouteDistinguisher fields from SNMP polling are rendered without saniti= zation. Attackers controlling a monitored network device can inject arbitra=
ry JavaScript through SNMP responses that executes in the browser of any us=
er viewing VRF-related pages.</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84191" target=3D= "_blank" rel=3D"noopener">CVE-2026-84191</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS versions <=3D 26.4.0 contain a stored cross-site scripting = vulnerability in the graph_descr.<graphtype> configuration settings, = which are echoed verbatim without HTML escaping in includes/html/pages/grap= hs.inc.php. An administrator can store a malicious HTML payload that execut=
es in the browser of any authenticated user who views the affected graph ty= pe. The issue is fixed in version 26.7.0.</td>
<td>2026-09-01</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84188" target=3D= "_blank" rel=3D"noopener">CVE-2026-84188</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td>
<td>In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer ov= erflow and resultant heap-based buffer overflow.</td>
<td>2026-09-05</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86138" target=3D= "_blank" rel=3D"noopener">CVE-2026-86138</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td>
<td>In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overf= low.</td>
<td>2026-09-05</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86139" target=3D= "_blank" rel=3D"noopener">CVE-2026-86139</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td>
<td>In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlX= PtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.</td> <td>2026-09-05</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86142" target=3D= "_blank" rel=3D"noopener">CVE-2026-86142</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td>
<td>In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCa= llback and xmlBufUse causes negative lengths to reach write callbacks, aka =
a lack of a check for integer overflow before calling writecallback. This h=
as security relevance for many types of uses of that length value within a = callback.</td>
<td>2026-09-05</td>
<td>6.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86143" target=3D= "_blank" rel=3D"noopener">CVE-2026-86143</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td>
<td>In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXInclud= eProcessTree do not propagate parseFlags. This has security relevance for, = for example, the XML_PARSE_NONET flag, if (without it) a custom resource lo= ader accesses the internet and triggers XML external entity injection, SSRF=
, or a denial of service (e.g., for an attacker-controlled internet resourc=
e that is intentionally slow).</td>
<td>2026-09-05</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86144" target=3D= "_blank" rel=3D"noopener">CVE-2026-86144</a></td>
</tr>
<td class=3D"vendor-product">light0011--cms</td>
<td>A security vulnerability has been detected in light0011 cms c774dce31c6= df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Thi=
s issue affects some unknown processing of the file App/Home/Controller/Cha= pterController.class.php of the component Chapter Controller. Such manipula= tion of the argument content leads to authorization bypass. The attack may =
be launched remotely. The exploit has been disclosed publicly and may be us= ed. This product operates on a rolling release basis, ensuring continuous d= elivery. Consequently, there are no version details for either affected or = updated releases. The project was informed of the problem early through an = issue report but has not responded yet.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85381" target=3D= "_blank" rel=3D"noopener">CVE-2026-85381</a></td>
</tr>
<td class=3D"vendor-product">light0011--cms</td>
<td>A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c= 53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the f= unction htmlspecialchars_decode of the file App/Home/View/Default/Chapter/o= neChapter.tpl of the component Chapter Content Output. Performing a manipul= ation of the argument content results in cross site scripting. Remote explo= itation of the attack is possible. The exploit is now public and may be use=
d. This product follows a rolling release approach for continuous delivery,=
so version details for affected or updated releases are not provided. The = project was informed of the problem early through an issue report but has n=
ot responded yet.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85382" target=3D= "_blank" rel=3D"noopener">CVE-2026-85382</a></td>
</tr>
<td class=3D"vendor-product">Lightstar--SmartIT Desktop Manager</td> <td>SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded = Credentials vulnerability. Unauthenticated remote attackers can obtain the = SFTP service credentials of the SmartIT Agent application from the source c= ode, thereby browsing the file system of the user's host.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85149" target=3D= "_blank" rel=3D"noopener">CVE-2026-85149</a></td>
</tr>
<td class=3D"vendor-product">livecomposer--Live Composer Free WordPress Web= site Builder</td>
<td>The Live Composer - Free WordPress Website Builder plugin for WordPress=
is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode=
attribute of the dslc_modules_section and dslc_modules_area shortcodes in = versions up to, and including, 2.1.19. This is due to insufficient input sa= nitization and output escaping on the user-supplied attribute, which is con= catenated into the HTML id=3D"" attribute of the rendered <div> eleme=
nt in the dslc_modules_section_front() and dslc_modules_area_front() functi= ons without esc_attr(). This makes it possible for authenticated attackers,=
with Contributor-level access and above, to inject arbitrary web scripts i=
n pages that will execute whenever a user accesses an injected page.</td> <td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13203" target=3D= "_blank" rel=3D"noopener">CVE-2026-13203</a></td>
</tr>
<td class=3D"vendor-product">livecomposer--Live Composer Free WordPress Web= site Builder</td>
<td>The Live Composer - Free WordPress Website Builder plugin for WordPress=
is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_= output Shortcode in all versions up to, and including, 2.1.19 due to insuff= icient input sanitization and output escaping. This makes it possible for a= uthenticated attackers, with contributor-level access and above, to inject = arbitrary web scripts in pages that will execute whenever a user accesses a=
n injected page. The injected payload survives save-time wp_kses_post filte= ring because KSES treats shortcode delimiters as opaque, and the unescaped = fields - including main_heading_title, view_all_link, main_heading_link_tit= le, and main_filter_title_all - are only rendered when do_shortcode() execu= tes at page-view time.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16786" target=3D= "_blank" rel=3D"noopener">CVE-2026-16786</a></td>
</tr>
<td class=3D"vendor-product">livecomposer--Live Composer Free WordPress Web= site Builder</td>
<td>The Live Composer - Free WordPress Website Builder plugin for WordPress=
is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Short= code in all versions up to, and including, 2.1.19 due to insufficient input=
sanitization and output escaping. This makes it possible for authenticated=
attackers, with contributor-level access and above, to inject arbitrary we=
b scripts in pages that will execute whenever a user accesses an injected p= age.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16787" target=3D= "_blank" rel=3D"noopener">CVE-2026-16787</a></td>
</tr>
<td class=3D"vendor-product">livecomposer--Live Composer Free WordPress Web= site Builder</td>
<td>The Live Composer - Free WordPress Website Builder plugin for WordPress=
is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_outp=
ut Shortcode in all versions up to, and including, 2.1.19 due to insufficie=
nt input sanitization and output escaping. This makes it possible for authe= nticated attackers, with contributor-level access and above, to inject arbi= trary web scripts in pages that will execute whenever a user accesses an in= jected page. WordPress's shortcode-aware kses handling preserves the serial= ized shortcode body as a placeholder before content filtering runs, allowin=
g attacker-controlled values such as view_all_link, main_heading_link_title=
, main_filter_title_all, and button_text to reach render-time sinks entirel=
y unescaped.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16788" target=3D= "_blank" rel=3D"noopener">CVE-2026-16788</a></td>
</tr>
<td class=3D"vendor-product">LiveJournal Shortcode--LiveJournal Shortcode</=
<td>The LiveJournal Shortcode WordPress plugin through 1.1.1 does not valid= ate and escape some of its shortcode attributes before outputting them back=
in a page/post where the shortcode is embed, which could allow users with = the contributor role and above to perform Stored Cross-Site Scripting attac= ks</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-3773" target=3D"= _blank" rel=3D"noopener">CVE-2024-3773</a></td>
</tr>
<td class=3D"vendor-product">llmware-ai--llmware</td>
<td>llmware 0.4.6 contains an SQL injection vulnerability in the collection= -database layer (llmware/resources.py) where filter and lookup values are d= irectly string-interpolated into SQL WHERE clauses without parameterization=
or escaping, in both the SQLite and PostgreSQL backends. The filter valida= tor only checks keys against an allow-list and never sanitizes values. Atta= cker-controlled filter values reaching the public API via Library.block_loo= kup and Query.text_query_with_custom_filter / text_query_by_author_or_speak=
er can neutralize the intended filter to disclose rows the caller was scope=
d out of (cross-document/cross-collection disclosure); on PostgreSQL the fl=
aw permits boolean- and UNION-based SQL injection.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85689" target=3D= "_blank" rel=3D"noopener">CVE-2026-85689</a></td>
</tr>
<td class=3D"vendor-product">lobehub--lobehub</td>
<td>LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform=
webhook signatures in the QQ and Feishu adapters. The webhook route (/api/= agent/webhooks/:platform) is unauthenticated by design and delegates verifi= cation to each adapter; the QQ adapter performs no Ed25519 signature verifi= cation on dispatched message events, and the Feishu adapter only performs a=
n optional static-token comparison that is skipped when no token is configu= red (the default) and is not a body signature. An unauthenticated attacker = who knows the public webhook URL can POST forged inbound messages with an a= ttacker-chosen sender identity and arbitrary text, causing the bot owner's = agent to process attacker-controlled input and treat the attacker as a trus= ted platform sender.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85621" target=3D= "_blank" rel=3D"noopener">CVE-2026-85621</a></td>
</tr>
<td class=3D"vendor-product">LogNet--grpc-spring-boot-starter</td>
<td>A vulnerability has been found in LogNet grpc-spring-boot-starter up to=
5.2.0. Affected is an unknown function of the component Annotation Process= ing. Such manipulation leads to improper authorization. The attack may be p= erformed from remote. A high complexity level is associated with this attac=
k. The exploitability is told to be difficult. The exploit has been disclos=
ed to the public and may be used. The project was informed of the problem e= arly through an issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82594" target=3D= "_blank" rel=3D"noopener">CVE-2026-82594</a></td>
</tr>
<td class=3D"vendor-product">lukeseager--Persistent Login</td>
<td>The Persistent Login plugin for WordPress is vulnerable to generic SQL = Injection via 'wppl_device_id' Cookie in all versions up to, and including,=
3.1.0 due to insufficient escaping on the user supplied parameter and lack=
of sufficient preparation on the existing SQL query. This makes it possibl=
e for authenticated attackers, with subscriber-level access and above, to a= ppend additional SQL queries into already existing queries that can be used=
to extract sensitive information from the database. This vulnerability is = only exploitable when the plugin's Login History feature is enabled.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18752" target=3D= "_blank" rel=3D"noopener">CVE-2026-18752</a></td>
</tr>
<td class=3D"vendor-product">Magepeople inc.--Booking and Rental Manager</t=
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Magepeople inc. Booking and Rental Manager a= llows Stored XSS. This issue affects Booking and Rental Manager: from n/a t= hrough 2.7.7.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85303" target=3D= "_blank" rel=3D"noopener">CVE-2026-85303</a></td>
</tr>
<td class=3D"vendor-product">magepeopleteam--Booking and Rental Manager</td=
<td>Subscriber Broken Access Control in Booking and Rental Manager <=3D = 2.7.6 versions.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81762" target=3D= "_blank" rel=3D"noopener">CVE-2026-81762</a></td>
</tr>
<td class=3D"vendor-product">malach-it--boruta-server</td>
<td>Boruta is a standalone authorization server that aims to implement OAut=
h 2.0 and Openid Connect up to decentralized identity specifications. Prior=
to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values=
in business event logs. Logged values could include access tokens, refresh=
tokens, authorization codes, agent tokens, direct-post codes, ID tokens, V=
P tokens, and tokens submitted to introspection or revocation endpoints. An=
attacker with access to Boruta logs, log aggregation systems, or the admin= istration log viewer could recover these credentials and use them until exp= iration or revocation. This issue has been patched in version 0.10.0.</td> <td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55221" target=3D= "_blank" rel=3D"noopener">CVE-2026-55221</a></td>
</tr>
<td class=3D"vendor-product">Mamunur Rashid--Classified Listing</td> <td>Missing Authorization vulnerability in Mamunur Rashid Classified Listin=
g allows Accessing Functionality Not Properly Constrained by ACLs. This iss=
ue affects Classified Listing: from n/a through 6.1.1.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84217" target=3D= "_blank" rel=3D"noopener">CVE-2026-84217</a></td>
</tr>
<td class=3D"vendor-product">MapQuest--Get Directions App</td>
<td>A vulnerability was identified in MapQuest Get Directions App 10.16.1 o=
n Android. This vulnerability affects the function getDataColumn of the fil=
e ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The m= anipulation leads to path traversal. An attack has to be approached locally=
. The exploit is publicly available and might be used. The vendor was conta= cted early about this disclosure but did not respond in any way.</td> <td>2026-09-02</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84442" target=3D= "_blank" rel=3D"noopener">CVE-2026-84442</a></td>
</tr>
<td class=3D"vendor-product">MapSVG--MapSVG</td>
<td>Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <=3D 8.= 15.0 versions.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82852" target=3D= "_blank" rel=3D"noopener">CVE-2026-82852</a></td>
</tr>
<td class=3D"vendor-product">marqo-ai--marqo</td>
<td>Marqo 2.26.0 contains a server-side request forgery vulnerability in th=
e add_documents endpoint that allows unauthenticated attackers to trigger r= equests to arbitrary URLs by supplying malicious media field values. Attack= ers can exploit download_image_from_url and fetch_content_sample functions = which lack destination filtering and host validation to access internal ser= vices and cloud metadata endpoints.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85662" target=3D= "_blank" rel=3D"noopener">CVE-2026-85662</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not perform an authorization check before returning per-student course en= rollment and progress data, allowing unauthenticated attackers to disclose = the enrolled courses and learning progress of any registered user.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81195" target=3D= "_blank" rel=3D"noopener">CVE-2026-81195</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not restrict access to a REST route that lists an author's courses, nor d= oes it filter that listing by publication status, allowing unauthenticated = users to read the titles and IDs of unpublished (draft, pending and private=
) courses.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81197" target=3D= "_blank" rel=3D"noopener">CVE-2026-81197</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not perform an authorization check before returning a student's learning = statistics, allowing unauthenticated attackers to disclose the course count=
s, points, certificates, quiz and assignment totals of any registered user.= </td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81199" target=3D= "_blank" rel=3D"noopener">CVE-2026-81199</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not properly verify authorization when retrieving order line-item data, a= llowing any authenticated user including Subscribers to read other instruct= ors' course sales records by supplying another user's identifier.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81194" target=3D= "_blank" rel=3D"noopener">CVE-2026-81194</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions--X-Series Gateway=C2=A0</td>
<td>An information disclosure vulnerability in the ugw-deviceinfo method of=
/cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 ret= urns detailed system version fields (operatingsystem, gatewayversion) to an=
y authenticated user, including users with the low-privileged Standard role= .</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75163" target=3D= "_blank" rel=3D"noopener">CVE-2026-75163</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions--X-Series Gateway=C2=A0</td>
<td>An arbitrary file read vulnerability in /cgi-bin/ugwdownload.cgi of MBS= -Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated = user with the low-privileged Standard role to retrieve arbitrary files from=
the device filesystem via the file query string parameter.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75164" target=3D= "_blank" rel=3D"noopener">CVE-2026-75164</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions--X-Series Gateway=C2=A0</td>
<td>An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solut= ions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user w= ith the low-privileged Standard role to write arbitrary content to files wi= thin /uxx/config/ and /ugw/config/.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75168" target=3D= "_blank" rel=3D"noopener">CVE-2026-75168</a></td>
</tr>
<td class=3D"vendor-product">mckaywrigley--chatbot-ui</td>
<td>Chatbot UI contains an authorization bypass vulnerability in the retrie= val endpoint that allows authenticated attackers to access private file con= tent belonging to other users by supplying arbitrary file UUIDs. The endpoi=
nt uses a service-role Supabase client that bypasses row-level security and=
fails to validate file ownership, enabling attackers to retrieve indexed c= ontent chunks from victim files through crafted POST requests.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85693" target=3D= "_blank" rel=3D"noopener">CVE-2026-85693</a></td>
</tr>
<td class=3D"vendor-product">Menulux Software Inc.--Menulux Portal</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Menulux Software Inc. Menulux Portal allows = Stored XSS. This issue affects Menulux Portal: before 20260903211448.</td> <td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18957" target=3D= "_blank" rel=3D"noopener">CVE-2026-18957</a></td>
</tr>
<td class=3D"vendor-product">Menulux Software Inc.--Menulux Portal</td>
<td>Missing Authorization vulnerability in Menulux Software Inc. Menulux Po= rtal allows Accessing Functionality Not Properly Constrained by ACLs. This = issue affects Menulux Portal: before 20260903211448.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19043" target=3D= "_blank" rel=3D"noopener">CVE-2026-19043</a></td>
</tr>
<td class=3D"vendor-product">Metabase--Metabase<br>=C2=A0</td>
<td>Metabase versions before 0.63.1 fail to enforce data analyst permission=
checks on glossary API endpoints, allowing any authenticated user to creat=
e, modify, and delete glossary entries. Attackers can submit requests to PO= ST, PUT, and DELETE glossary endpoints to tamper with instance-wide busines=
s glossary data without proper authorization.</td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86116" target=3D= "_blank" rel=3D"noopener">CVE-2026-86116</a></td>
</tr>
<td class=3D"vendor-product">mikel--mail</td>
<td>Mail is an internet library for Ruby designed to handle email generatio=
n, parsing, and sending. Prior to 2.9.1, Mail::Utilities.q_value_decode and=
Mail::Utilities.b_value_decode used a single String#match and an overly gr= eedy charset capture to decode only the first RFC 2047 encoded-word and mis= handle surrounding or subsequent text. A crafted malformed encoded-word in =
an address display name or local part could cross ? delimiters and make dec= oded From, To, or Reply-To header values differ from the raw values inspect=
ed by a human reviewer or downstream parser, enabling apparent sender or re= cipient spoofing, phishing, or authorization-check bypass. This issue is fi= xed in version 2.9.1.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63435" target=3D= "_blank" rel=3D"noopener">CVE-2026-63435</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C Driver</td>
<td>An incorrect numeric conversion in the JSON parsing component of the Mo= ngoDB C Driver's BSON library may cause an unusually large text value to be=
silently shortened, or the corresponding field to be omitted, while the pa= rsing operation still reports success and returns no error. An unauthentica= ted party who can supply the input processed by an application that uses th=
is component may cause that application to hold data that does not match wh=
at was submitted, which may result in unintended alteration of data.</td> <td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84963" target=3D= "_blank" rel=3D"noopener">CVE-2026-84963</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C Driver</td>
<td>A double free in the OpenSSL-based TLS certificate revocation checking = path of the MongoDB C Driver can be reached by a TLS endpoint that the clie=
nt already trusts. During the handshake, specially formed certificate data = can cause the same heap object to be released twice. An unauthenticated par=
ty acting as the trusted endpoint may cause the connecting client applicati=
on to terminate unexpectedly.</td>
<td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84964" target=3D= "_blank" rel=3D"noopener">CVE-2026-84964</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C Driver</td>
<td>An integer wraparound in an allocation size calculation in the BSON lib= rary's JSON parsing code can cause a buffer to be released while a followin=
g copy operation still writes through the stale pointer. On builds where si= zes are 32 bits, an unauthenticated party able to supply a sufficiently lar=
ge JSON input to an application that links the library may cause that appli= cation to terminate unexpectedly, resulting in denial of service.</td> <td>2026-09-03</td>
<td>5.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84965" target=3D= "_blank" rel=3D"noopener">CVE-2026-84965</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C++ Driver</td>
<td>A numeric truncation weakness exists in the JSON parsing component of t=
he MongoDB C++ Driver's BSON library. An actor who controls the text that a=
n embedding application hands to the library's public JSON parsing interfac=
e, when that text is very large, can cause the library to read memory beyon=
d the supplied buffer and return it to the caller, to silently accept only = part of the input as a complete document, or to terminate the process. No M= ongoDB server, credentials, or non-default configuration is required; the e= ffect is confined to the process that uses the library.</td> <td>2026-09-03</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84970" target=3D= "_blank" rel=3D"noopener">CVE-2026-84970</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C++ Driver</td>
<td>An incorrect numeric type conversion in the BSON document building comp= onent of the MongoDB C++ Driver may cause a length value to be interpreted = incorrectly. When an application supplies an extremely large, non-terminate=
d field name to the builder, the library may read memory outside the intend=
ed buffer and terminate the calling process. No authentication is required,=
but the calling application must pass the oversized name in a specific for= m.</td>
<td>2026-09-03</td>
<td>5.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84966" target=3D= "_blank" rel=3D"noopener">CVE-2026-84966</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--libmongocrypt</td>
<td>Improper handling of an unexpected value size in the decryption path of=
a client-side encryption library can cause a failed internal check that te= rminates the process using the library. A party able to place a suitably fo= rmed encrypted value where an application will decrypt it, or able to contr=
ol the responses the application receives, may cause that application to st=
op running.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84971" target=3D= "_blank" rel=3D"noopener">CVE-2026-84971</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--libmongocrypt</td>
<td>An unauthorized user with key vault write access may cause an authorize=
d client to issue arbitrary authenticated Google Cloud KMS API calls under = the authorized user's identity, escalating database-level access into cloud=
key control and defeating client-side encryption.</td>
<td>2026-09-03</td>
<td>4.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84962" target=3D= "_blank" rel=3D"noopener">CVE-2026-84962</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--MongoDB for VS Code</td>
<td>A component of the MongoDB extension for Visual Studio Code does not ne= utralize special characters in a connection string before that value is pla= ced into a command line the extension composes for an integrated terminal. =
An unauthenticated remote unauthorized-user who persuades a developer to ac= cept a user-supplied connection target, and then to open the extension's sh= ell feature, can place characters of the unauthorized-user's choosing into = that command line. No privileges on the developer's machine are required, b=
ut several user actions are. The confirmation the developer sees does not d= isplay the supplied text.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84967" target=3D= "_blank" rel=3D"noopener">CVE-2026-84967</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--PHP Driver</td>
<td>An out-of-bounds read in the BSON decoding component of the MongoDB PHP=
driver may allow an unauthenticated party who supplies specially formed in= put to have a small amount of adjacent process memory copied into an error = message that is returned to application code. This may result in unintended=
disclosure of limited memory contents.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84968" target=3D= "_blank" rel=3D"noopener">CVE-2026-84968</a></td>
</tr>
<td class=3D"vendor-product">moos-ivp--moos-ivp</td>
<td>MOOS-IvP through 24.8.1 fails to properly validate variable names extra= cted from alog files in the SplitHandler, allowing attackers to write files=
outside the split directory. Attackers can supply crafted alog files with = backslash sequences in variable names to escape the output directory and ap= pend to arbitrary files on Windows systems.</td>
<td>2026-09-03</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85456" target=3D= "_blank" rel=3D"noopener">CVE-2026-85456</a></td>
</tr>
<td class=3D"vendor-product">MotoPress Appointment Booking--MotoPress Appoi= ntment Booking</td>
<td>The MotoPress Appointment Booking WordPress plugin before 2.4.8 does no=
t perform an authorization or ownership check when handling a user-supplied=
booking identifier on an unauthenticated endpoint, allowing unauthenticate=
d attackers to permanently delete other users' reservations. This is an inc= omplete fix of CVE-2026-9180: the deletion remains reachable on sites using=
payment confirmation, confirmed through version 2.4.7.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15232" target=3D= "_blank" rel=3D"noopener">CVE-2026-15232</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Other issue in the DOM: Navigation component. This vulnerability was fi= xed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153= .2.</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84136" target=3D= "_blank" rel=3D"noopener">CVE-2026-84136</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Denial-of-service in the PDF Viewer component. This vulnerability was f= ixed in Firefox 155 and Thunderbird 155.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84138" target=3D= "_blank" rel=3D"noopener">CVE-2026-84138</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Clickjacking issue in the DOM: Events component. This vulnerability was=
fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird = 153.2.</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84139" target=3D= "_blank" rel=3D"noopener">CVE-2026-84139</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Use-after-free in the JavaScript: GC component. This vulnerability was = fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 1= 53.2.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84118" target=3D= "_blank" rel=3D"noopener">CVE-2026-84118</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Use-after-free in the Audio/Video component. This vulnerability was fix=
ed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.=
2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84120" target=3D= "_blank" rel=3D"noopener">CVE-2026-84120</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Use-after-free in the Audio/Video component. This vulnerability was fix=
ed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, = Thunderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84122" target=3D= "_blank" rel=3D"noopener">CVE-2026-84122</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Use-after-free in the DOM: Core & HTML component. This vulnerabilit=
y was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderb= ird 155, Thunderbird 140.15, and Thunderbird 153.2.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84124" target=3D= "_blank" rel=3D"noopener">CVE-2026-84124</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Use-after-free in the DOM: Core & HTML component. This vulnerabilit=
y was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunder= bird 153.2.</td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84125" target=3D= "_blank" rel=3D"noopener">CVE-2026-84125</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Incorrect boundary conditions in the Layout: Grid component. This vulne= rability was fixed in Firefox 155 and Thunderbird 155.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84126" target=3D= "_blank" rel=3D"noopener">CVE-2026-84126</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox</td>
<td>Spoofing issue in the DOM: Core & HTML component. This vulnerabilit=
y was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunder= bird 153.2.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84137" target=3D= "_blank" rel=3D"noopener">CVE-2026-84137</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox_mobile</td>
<td>A malicious webpage could stall a popup's cross-origin navigation after=
commit, causing the address bar to display the destination origin while co= ntinuing to render attacker-controlled content. This vulnerability was fixe=
d in Firefox for iOS 155.0.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81267" target=3D= "_blank" rel=3D"noopener">CVE-2026-81267</a></td>
</tr>
<td class=3D"vendor-product">mozilla -- firefox_mobile</td>
<td>Information disclosure in the WebExtensions component in Firefox for An= droid. This vulnerability was fixed in Firefox 155.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84127" target=3D= "_blank" rel=3D"noopener">CVE-2026-84127</a></td>
</tr>
<td class=3D"vendor-product">Mstfakts --College-Management-System<br>=C2=A0= </td>
<td>A vulnerability was identified in Mstfakts College-Management-System. T=
he affected element is an unknown function of the file Front-end/server.php=
of the component Logout Handler. Such manipulation of the argument log_out=
leads to session expiration. It is possible to launch the attack remotely.=
The exploit is publicly available and might be used. This product takes th=
e approach of rolling releases to provide continious delivery. Therefore, v= ersion details for affected and updated releases are not available. The pro= ject was informed of the problem early through an issue report but has not = responded yet.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86215" target=3D= "_blank" rel=3D"noopener">CVE-2026-86215</a></td>
</tr>
<td class=3D"vendor-product">MultiVendorX--MultiVendorX</td>
<td>The MultiVendorX WordPress plugin before 5.0.15 does not have proper au= thorisation controls on one of its REST API listing routes, allowing unauth= enticated users to retrieve vendor contact and payout details, pending payo=
ut amounts, and administrative notes attached to store applications.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74927" target=3D= "_blank" rel=3D"noopener">CVE-2026-74927</a></td>
</tr>
<td class=3D"vendor-product">MW WP Form--MW WP Form</td>
<td>The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcode=
s in user-submitted values from being executed when it merges those values = into a message that it later processes for shortcodes, allowing unauthentic= ated users to run any shortcode registered on the site. Exploitation requir=
es the site to have been configured to echo a submitted value back to the v= isitor after submission.</td>
<td>2026-09-01</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78363" target=3D= "_blank" rel=3D"noopener">CVE-2026-78363</a></td>
</tr>
<td class=3D"vendor-product">nameprep--nameprep</td>
<td>URI versions before 5.36 for Perl encode non-NFC host names to non-stan= dard punycode labels via missing normalization in nameprep. nameprep lowerc= ases each host label but performs no Unicode normalization. IDNA requires a=
label to be normalized to Form C before it is encoded (RFC 5891), so a lab=
el that is not already in NFC is encoded to a different A-label than its no= rmalized form. A label built from the precomposed Devanagari sequence U+095=
8 U+093E encodes to xn--72b5c without normalization but to xn--11b2fg after=
NFC normalization, and xn--72b5c does not round-trip back to the original = label. Any caller that reads host() from a URI built from untrusted input a=
nd uses it for a security decision (an allow or deny list, an SSRF filter, = deduplication, a cache key) sees the non-standard label, while a client tha=
t fetches the same URL resolves the NFC form, so the check and the fetch ca=
n disagree about the host.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19953" target=3D= "_blank" rel=3D"noopener">CVE-2026-19953</a></td>
</tr>
<td class=3D"vendor-product">NASA--earthdata-search</td>
<td>A flaw has been found in NASA earthdata-search 1.0.0. Affected by this = issue is the function OpenSearchGranuleSearchLambda of the file serverless/= src/openSearchGranuleSearch/handler.js of the component granules Endpoint. = Executing a manipulation of the argument openSearchOsdd can lead to server-= side request forgery. The attack can be launched remotely. The exploit has = been published and may be used. The vendor was contacted early about this d= isclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82802" target=3D= "_blank" rel=3D"noopener">CVE-2026-82802</a></td>
</tr>
<td class=3D"vendor-product">nbviewer--nbviewer<br>=C2=A0</td>
<td>nbviewer through 1.0.1 contains a path traversal vulnerability in Local= FileHandler.can_show() that uses string-prefix comparison instead of proper=
path validation. Attackers can read files from sibling directories outside=
the configured root by requesting paths that share the root as a textual p= refix, disclosing unintended notebooks and credentials.</td> <td>2026-09-06</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86258" target=3D= "_blank" rel=3D"noopener">CVE-2026-86258</a></td>
</tr>
<td class=3D"vendor-product">NetBox --NetBox=C2=A0<br>=C2=A0</td>
<td>NetBox through 4.7.0 fails to properly scope user-private records in RE=
ST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmark=
s. Authenticated users with view permissions can access all users' private = records through unscoped querysets, disclosing which users watch or bookmar=
k which objects.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86176" target=3D= "_blank" rel=3D"noopener">CVE-2026-86176</a></td>
</tr>
<td class=3D"vendor-product">NetBox-- NetBox=C2=A0<br>=C2=A0</td>
<td>NetBox through 4.7.0 fails to redact sensitive data source backend cred= entials in REST and GraphQL API responses. Authenticated users with only vi=
ew permission can retrieve plaintext passwords and secret keys for Git and = Amazon S3 backends through API endpoints, gaining unauthorized access to ex= ternal repositories and storage buckets.</td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86175" target=3D= "_blank" rel=3D"noopener">CVE-2026-86175</a></td>
</tr>
<td class=3D"vendor-product">Netgate--pfSense Plus</td>
<td>pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users=
with the Status: Monitoring privilege to inject arbitrary JavaScript via g= raph configuration parameters in /status_monitoring.php. Multiple POST para= meters including graph-left, graph-right, time-period, resolution, start-da= te, end-date, start-time, end-time, graph-type, invert, and refresh-interva=
l are concatenated and written to the global pfSense XML configuration with= out sanitization, then echoed unsanitized into a JavaScript string context =
on page render. Because the setting is stored in the global configuration, = the payload executes in the browser of every user who visits the Status: Mo= nitoring page.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56126" target=3D= "_blank" rel=3D"noopener">CVE-2026-56126</a></td>
</tr>
<td class=3D"vendor-product">Netgate--pfSense Plus</td>
<td>pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users=
with the Firewall: Rules: Edit privilege to inject arbitrary JavaScript vi=
a the descr parameter in /firewall_rules_edit.php. The firewall rule descri= ption is stored in the pfSense XML configuration with only backslash-escapi=
ng applied and no HTML sanitization, then rendered without encoding in the = firewall log table in /status_logs_filter.php. The payload executes in the = browser of any user with the Status: Logs: Firewall privilege who views the=
affected log entries.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56127" target=3D= "_blank" rel=3D"noopener">CVE-2026-56127</a></td>
</tr>
<td class=3D"vendor-product">Netgate--pfSense Plus</td>
<td>pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users=
with the Firewall: Schedules: Edit privilege to inject arbitrary JavaScrip=
t via the descr parameter in /firewall_schedule_edit.php. The schedule desc= ription is stored without HTML sanitization and subsequently inserted into =
an HTML attribute value in /firewall_rules.php with only single-quote escap= ing applied, permitting double-quote breakout. The payload executes in the = browser of any user with the Firewall: Rules privilege who views the rules = list with the affected schedule attached.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-56128" target=3D= "_blank" rel=3D"noopener">CVE-2026-56128</a></td>
</tr>
<td class=3D"vendor-product">Nexcess--BookIt</td>
<td>Unauthenticated Bypass Vulnerability in BookIt <=3D 2.6.0.3 versions= .</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84767" target=3D= "_blank" rel=3D"noopener">CVE-2026-84767</a></td>
</tr>
<td class=3D"vendor-product">Ninja Forms--Ninja Forms</td>
<td>The Ninja Forms WordPress plugin before 3.15.2 does not restrict its RE=
ST abilities to administrators, accepting a Ninja Forms WordPress plugin be= fore 3.15.2-specific capability as equivalent to full site administration, = which allows any user granted that capability to read Ninja Forms WordPress=
plugin before 3.15.2 settings and stored form submissions, overwrite the N= inja Forms WordPress plugin before 3.15.2's configuration, and create or mo= dify arbitrary posts and pages. The capability belongs to no default WordPr= ess role and the Ninja Forms WordPress plugin before 3.15.2 never grants it=
, so an administrator must have assigned it, typically when delegating acce=
ss to the form builder.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80438" target=3D= "_blank" rel=3D"noopener">CVE-2026-80438</a></td>
</tr>
<td class=3D"vendor-product">nocobase--nocobase</td>
<td>NocoBase fails to sanitize rich text field values in the read renderer,=
allowing users with create permissions to store malicious HTML with event = handlers. Attackers can write arbitrary markup through the collection API t= hat executes in the browsers of all users viewing the affected record.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84701" target=3D= "_blank" rel=3D"noopener">CVE-2026-84701</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>Nodemailer before 8.0.8 disables TLS certificate verification in lib/fe= tch/index.js through rejectUnauthorized: false, allowing attackers to inter= cept OAuth2 token requests. Attackers in a machine-in-the-middle position c=
an capture OAuth client secrets, refresh tokens, and access tokens transmit= ted over compromised HTTPS connections.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82662" target=3D= "_blank" rel=3D"noopener">CVE-2026-82662</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>nodemailer before 6.9.9 contains a regular expression denial of service=
vulnerability in email parsing when attachDataUrls parameter is set or pro= cessing embedded file attachments. Attackers can send specially crafted ema= ils with malicious data URLs or embedded attachments to cause the event loo=
p to hang and deny service.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-58379" target=3D= "_blank" rel=3D"noopener">CVE-2024-58379</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableU= rlAccess options during message normalization in jsonTransport. Attackers c=
an read local files or fetch URLs by supplying path or href values in messa=
ge content fields, bypassing intended access controls.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82660" target=3D= "_blank" rel=3D"noopener">CVE-2026-82660</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>Nodemailer before 8.0.9 fails to sanitize carriage return and line feed=
characters in list comment fields, allowing attackers to inject arbitrary = message headers. An attacker with control over list.*.comment parameters ca=
n inject CRLF sequences to create additional headers in generated RFC822 me= ssages, altering mail client behavior and message semantics.</td> <td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82661" target=3D= "_blank" rel=3D"noopener">CVE-2026-82661</a></td>
</tr>
<td class=3D"vendor-product">nodemailer--nodemailer</td>
<td>Nodemailer versions before 8.0.5 contain an SMTP command injection vuln= erability in the transport name option used in EHLO/HELO commands. The name=
parameter is concatenated directly into SMTP commands without sanitizing c= arriage return and line feed characters, allowing attackers to inject arbit= rary SMTP commands for email spoofing and phishing attacks.</td>
<td>2026-08-31</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82853" target=3D= "_blank" rel=3D"noopener">CVE-2026-82853</a></td>
</tr>
<td class=3D"vendor-product">Nokia--NSP</td>
<td>NSP is vulnerable to a stored XSS due to insufficient validation or enc= oding of user-controlled input in a workflow application. An authenticated = attacker with access to the workflow application could embed harmful code t= hat runs when another user views the content.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40464" target=3D= "_blank" rel=3D"noopener">CVE-2026-40464</a></td>
</tr>
<td class=3D"vendor-product">Nokia--NSP</td>
<td>NSP is vulnerable to an open redirect due to insufficient server-side v= alidation of the URL (or redirect) parameter.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-40465" target=3D= "_blank" rel=3D"noopener">CVE-2026-40465</a></td>
</tr>
<td class=3D"vendor-product">Notification Bar for WordPress--Notification B=
ar for WordPress</td>
<td>The Notification Bar for WordPress plugin through 1.1.8 exposes an unau= thenticated CSV export script that discloses all stored subscriber emails.<=
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15481" target=3D= "_blank" rel=3D"noopener">CVE-2025-15481</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A vulnerability has been found in NousResearch hermes-agent 0.18.0. Thi=
s affects the function fetchLinkTitle of the file apps/desktop/src/app/arti= facts/index.tsx of the component Link Title Fetch. Such manipulation of the=
argument url leads to server-side request forgery. The attack can be launc= hed remotely. The vendor was contacted early about this disclosure but did = not respond in any way.</td>
<td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85106" target=3D= "_blank" rel=3D"noopener">CVE-2026-85106</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by = this issue is some unknown functionality of the file gateway/platforms/api_= server.py of the component Session Chat Interface. This manipulation causes=
denial of service. The attack is possible to be carried out remotely. The = exploit has been published and may be used. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84287" target=3D= "_blank" rel=3D"noopener">CVE-2026-84287</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A vulnerability has been found in NousResearch hermes-agent up to 0.18.=
2. This affects the function HermesACPAgent.prompt of the file acp_adapter/= session.py of the component ACP Prompt Workflow. Such manipulation leads to=
denial of service. The attack may be performed from remote. The exploit ha=
s been disclosed to the public and may be used. The vendor was contacted ea= rly about this disclosure but did not respond in any way.</td>
<td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84288" target=3D= "_blank" rel=3D"noopener">CVE-2026-84288</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A vulnerability was found in NousResearch hermes-agent up to 0.18.2. Th=
is vulnerability affects the function list_tools of the file tools/mcp_tool= .py of the component MCP Tool. Performing a manipulation results in uncontr= olled memory allocation. It is possible to initiate the attack remotely. Th=
e exploit has been made public and could be used. The vendor was contacted = early about this disclosure but did not respond in any way.</td> <td>2026-09-01</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84289" target=3D= "_blank" rel=3D"noopener">CVE-2026-84289</a></td>
</tr>
<td class=3D"vendor-product">NousResearch--hermes-agent</td>
<td>A vulnerability was found in NousResearch hermes-agent 0.18.0. This vul= nerability affects the function resourceBufferFromUrl of the file apps/desk= top/electron/main.ts of the component Electron Main Process. Performing a m= anipulation results in allocation of resources. The attack may be initiated=
remotely. copyImageFromUrl() entry point no longer reachable on current ma= in. That function did exist at v2026.8.3 but was removed by v2026.8.19. The=
modern copy-image path is Electron-native event.sender.copyImageAt().</td> <td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85107" target=3D= "_blank" rel=3D"noopener">CVE-2026-85107</a></td>
</tr>
<td class=3D"vendor-product">ntegrals--openbrowser</td>
<td>A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa9= 61750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown fun= ctionality of the file packages/core/src/agent/agent.ts of the component Br= owser Agent Message Construction. Performing a manipulation results in reso= urce consumption. It is possible to initiate the attack remotely. The explo=
it has been made public and could be used. This product is using a rolling = release to provide continious delivery. Therefore, no version details for a= ffected nor updated releases are available. The vendor was contacted early = about this disclosure but did not respond in any way.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84833" target=3D= "_blank" rel=3D"noopener">CVE-2026-84833</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.16.5, Nuclio Dashboard exposes POST /api/functions=
without authentication by default (NOP auth mode). The spec.handler field = (e.g., mymodule:myfunction) is parsed by functionconfig.ParseHandler() whic=
h splits on : only - no path validation is applied to the module portion. T= his issue has been patched in version 1.16.5.</td>
<td>2026-09-02</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52832" target=3D= "_blank" rel=3D"noopener">CVE-2026-52832</a></td>
</tr>
<td class=3D"vendor-product">onyx-dot-app--onyx</td>
<td>Onyx 4.6.6 fails to properly restrict access to custom tool credentials=
stored in custom_headers, allowing any authenticated user to read admin-de= fined API keys. Attackers with basic authentication can call GET /tool/{too= l_id} or GET /tool endpoints to retrieve plaintext authorization headers an=
d third-party API credentials, then use them to directly access upstream AP= Is.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85700" target=3D= "_blank" rel=3D"noopener">CVE-2026-85700</a></td>
</tr>
<td class=3D"vendor-product">Open5GS --Open5GS=C2=A0<br>=C2=A0</td>
<td>A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerabili=
ty affects unknown code of the component AMF/MME. The manipulation leads to=
improper authorization. The attack is possible to be carried out remotely.=
The exploit has been disclosed to the public and may be used. The identifi=
er of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this is= sue, it is recommended to deploy a patch.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86212" target=3D= "_blank" rel=3D"noopener">CVE-2026-86212</a></td>
</tr>
<td class=3D"vendor-product">open62541--open62541</td>
<td>A vulnerability was detected in open62541 up to 1.5.5. Affected by this=
vulnerability is the function UA_DataValue_backend_copyRange of the file p= lugins/historydata/ua_history_data_backend_memory.c of the component Histor=
y Backend. The manipulation results in use after free. The attack can be la= unched remotely. The exploit is now public and may be used. The project clo= sed the issue report, stating that this is not the official way to report a=
security vulnerability.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82623" target=3D= "_blank" rel=3D"noopener">CVE-2026-82623</a></td>
</tr>
<td class=3D"vendor-product">openedx--openedx-platform</td>
<td>Open edX Platform enables the authoring and delivery of online learning=
at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied = files[].url, performs a server-side fetch using "requests.get(url, allow_re= directs=3DTrue)". The fetched bytes are then returned inside a ZIP response=
. This enables SSRF with response exfiltration. Redirect-following is enabl= ed, and there is no timeout in the vulnerable fetch path. This issue has be=
en patched via commit 00b7c3c.</td>
<td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55421" target=3D= "_blank" rel=3D"noopener">CVE-2026-55421</a></td>
</tr>
<td class=3D"vendor-product">openedx--openedx-platform</td>
<td>Open edX Platform enables the authoring and delivery of online learning=
at any scale. Prior to commit 3a5ac85, a security vulnerability has been i= dentified in the Open edX LMS platform's LTI (Learning Tools Interoperabili= ty) Provider implementation. The validate_timestamp_and_nonce function in l= ms/djangoapps/lti_provider/signature_validator.py does not validate OAuth n= onces or timestamps, allowing an attacker who captures a valid LTI launch r= equest to replay it an unlimited number of times without detection. This is= sue has been patched via commit 3a5ac85.</td>
<td>2026-09-02</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53636" target=3D= "_blank" rel=3D"noopener">CVE-2026-53636</a></td>
</tr>
<td class=3D"vendor-product">OpenListTeam--OpenList</td>
<td>OpenList a file list program that supports multiple storage. Prior to 4= .2.3, OpenList's offline-download feature at POST /api/fs/add_offline_downl= oad with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its = bytes under a per-task temporary directory before transferring them to the = user's destination storage. The temporary filename comes from the attacker-= controlled Content-Disposition header, is passed from parseFilenameFromCont= entDisposition in internal/offline_download/http/util.go to filepath.Join(t= ask.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/= client.go, and is opened with os.Create without a containment check. Becaus=
e filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDow= nload on any path can traverse out of task.TempDir and create, truncate, or=
overwrite any file writable by the OpenList process whose parent directory=
already exists. The server/handles/offline_download.go AddOfflineDownload = route uses normal user authentication rather than AuthAdmin, and local-stor= age destinations fall through tryPutUrl in internal/offline_download/tool/a= dd.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version=
4.2.3.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75602" target=3D= "_blank" rel=3D"noopener">CVE-2026-75602</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>OpenPanel before 2.3.0 contains a cross-tenant broken object level auth= orization vulnerability in the report.getLayouts and report.resetLayout tRP=
C procedures that fail to scope dashboard queries to the caller's project. = Authenticated attackers can supply their own projectId with a victim organi= zation's guessable dashboardId to read confidential report definitions or p= ermanently delete dashboard layouts across tenant boundaries.</td> <td>2026-09-04</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85611" target=3D= "_blank" rel=3D"noopener">CVE-2026-85611</a></td>
</tr>
<td class=3D"vendor-product">Openpanel-dev--openpanel</td>
<td>Openpanel before 2.3.0 contains an insecure direct object reference vul= nerability in the report.getLayouts and report.resetLayout tRPC procedures = that fail to bind dashboardId to the authorized projectId. Authenticated at= tackers can supply an arbitrary victim dashboardId with their own projectId=
to read report layouts and configurations or delete dashboard grid arrange= ments across tenants.</td>
<td>2026-09-04</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85615" target=3D= "_blank" rel=3D"noopener">CVE-2026-85615</a></td>
</tr>
<td class=3D"vendor-product">oppia--oppia</td>
<td>Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is d= ecorated with open_access, allowing any registered user to enumerate privil= eged accounts and roles. Attackers can query the endpoint with filter_crite= rion parameters to retrieve usernames holding specific roles, banned flags,=
and managed topic identifiers without authorization.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85210" target=3D= "_blank" rel=3D"noopener">CVE-2026-85210</a></td>
</tr>
<td class=3D"vendor-product">OwnerRez--OwnerRez API</td>
<td>Subscriber Broken Access Control in OwnerRez API <=3D 1.2.6 versions= .</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81758" target=3D= "_blank" rel=3D"noopener">CVE-2026-81758</a></td>
</tr>
<td class=3D"vendor-product">PassMark--PerformanceTest<br>=C2=A0</td> <td>PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1=
build 1000, and OSForensics before 11.1 build 1016 contain a privilege esc= alation and denial-of-service vulnerability in DirectIo64.sys that allows l= ocal attackers to read arbitrary Model-Specific Registers or write zero to = any MSR through exposed IOCTLs with insufficient blocklist enforcement. Att= ackers can exploit the unrestricted write IOCTL to zero out the system call=
handler MSR, causing an immediate unrecoverable kernel crash on the next s= ystem call, or read security-sensitive MSRs used to locate kernel data stru= ctures.</td>
<td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80115" target=3D= "_blank" rel=3D"noopener">CVE-2026-80115</a></td>
</tr>
<td class=3D"vendor-product">Passster--Passster</td>
<td>The Passster WordPress plugin before 4.2.24 does not handle input prope= rly in an AJAX action, allowing unauthenticated users to retrieve the value=
of password protected content</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15489" target=3D= "_blank" rel=3D"noopener">CVE-2025-15489</a></td>
</tr>
<td class=3D"vendor-product">Passster--Passster</td>
<td>The Passster WordPress plugin before 4.2.26 has a flaw in its global pr= otection checks, allowing unauthenticated users to bypass the protection of= fered via crafted URLs</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15490" target=3D= "_blank" rel=3D"noopener">CVE-2025-15490</a></td>
</tr>
<td class=3D"vendor-product">pdfme--common</td>
<td>@pdfme/common before 5.5.10 contains a server-side request forgery vuln= erability in the getB64BasePdf function that fetches arbitrary URLs without=
validation when basePdf is attacker-controlled. Attackers who control the = basePdf template field can force servers or clients to make requests to int= ernal endpoints, enabling metadata exfiltration, network reconnaissance, an=
d blind request forgery attacks.</td>
<td>2026-08-31</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82866" target=3D= "_blank" rel=3D"noopener">CVE-2026-82866</a></td>
</tr>
<td class=3D"vendor-product">pdfme--pdf-lib</td>
<td>pdfme pdf-lib versions before 5.5.10 contain an unbounded buffer growth=
vulnerability in the DecodeStream.ensureBuffer() method that allows attack= ers to cause denial of service by supplying a crafted PDF with a FlateDecod=
e stream containing a decompression bomb. Attackers can upload a small comp= ressed PDF that decompresses to hundreds of megabytes, exhausting memory an=
d crashing the Node.js process or freezing browser tabs during PDF parsing.= </td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82864" target=3D= "_blank" rel=3D"noopener">CVE-2026-82864</a></td>
</tr>
<td class=3D"vendor-product">pdfme--schemas</td>
<td>@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerabili=
ty in the Select schema plugin that fails to sanitize option values before = interpolating them into HTML via innerHTML. Attackers can supply malicious = templates with crafted option values containing HTML and JavaScript to exec= ute arbitrary code in users' browsers.</td>
<td>2026-08-31</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82867" target=3D= "_blank" rel=3D"noopener">CVE-2026-82867</a></td>
</tr>
<td class=3D"vendor-product">pdfme--schemas</td>
<td>@pdfme/schemas before 5.5.9 contains a cross-site scripting vulnerabili=
ty in the SVG schema plugin that renders user-supplied SVG content directly=
to innerHTML without sanitization. Attackers can inject malicious SVG with=
embedded scripts, event handlers, or foreignObject elements to execute arb= itrary JavaScript in users' browsers when viewing or filling templates.</td=
<td>2026-08-31</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82868" target=3D= "_blank" rel=3D"noopener">CVE-2026-82868</a></td>
</tr>
<td class=3D"vendor-product">pdfme--schemas</td>
<td>pdfme schemas before 5.5.10 contains a cross-site scripting vulnerabili=
ty in the multiVariableText property panel that assigns unsanitized i18n la= bel values to innerHTML. Attackers who control label overrides through opti= ons.labels can inject arbitrary JavaScript that executes when users open th=
e Designer and select a multiVariableText field without variable placeholde= rs.</td>
<td>2026-08-31</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82865" target=3D= "_blank" rel=3D"noopener">CVE-2026-82865</a></td>
</tr>
<td class=3D"vendor-product">Peppermint-Lab--peppermint</td>
<td>Peppermint through 0.5.5 contains an authorization bypass vulnerability=
in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated=
attackers to delete sessions for any user by supplying arbitrary user IDs.=
Attackers can forcibly log out any user including administrators by callin=
g the logout handler with another user's ID, since the endpoint performs no=
authorization checks to verify the caller owns the target account.</td> <td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85392" target=3D= "_blank" rel=3D"noopener">CVE-2026-85392</a></td>
</tr>
<td class=3D"vendor-product">phpseclib--phpseclib</td>
<td>phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4= .0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/In= teger.php performs data-dependent conditional modular reductions in add() a=
nd subtract(). During the Montgomery ladder in phpseclib/Crypt/EC/BaseCurve= s/Montgomery.php, the reduction behavior of each step depends on the secret=
scalar prefix, creating per-step timing and libgmp call-count observations=
that can reveal a reused 251-bit clamped private scalar. The phpseclib/Cry= pt/EC/Formats/Keys/MontgomeryPrivate.php derivation path invokes the pure-P=
HP multiplication without a native-engine check, while phpseclib/Crypt/EC/F= ormats/Keys/PKCS8.php reaches it when ext-sodium is unavailable. Exploitati=
on requires a reused or long-lived X25519 private key, knowledge of the cor= responding public key, execution of the pure-PHP path, and a local observer=
capable of resolving individual ladder steps or libgmp entry-point calls. = Ephemeral X25519 keys, including phpseclib's normal SSH exchange path, are = not affected. Recovery of the scalar permanently compromises operations tha=
t reuse that key. This issue is fixed in versions 3.0.57 and 4.0.1.</td> <td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84308" target=3D= "_blank" rel=3D"noopener">CVE-2026-84308</a></td>
</tr>
<td class=3D"vendor-product">Pik Online Software Solutions Inc.--Pik Online=
Portal</td>
<td>Use of a One-Way hash without a salt vulnerability in Pik Online Softwa=
re Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affect=
s Pik Online Portal: through 3.5.1.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6217" target=3D"= _blank" rel=3D"noopener">CVE-2026-6217</a></td>
</tr>
<td class=3D"vendor-product">Pixelfed--Pixelfed<br>=C2=A0</td>
<td>Pixelfed through 0.12.9 fails to validate follower status in StoryCompo= seController react and comment endpoints, allowing authenticated users to a= ccess follower-only stories. Attackers can enumerate sequential story IDs a=
nd submit reactions or comments to retrieve story media URLs and author inf= ormation without following the account.</td>
<td>2026-09-05</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86178" target=3D= "_blank" rel=3D"noopener">CVE-2026-86178</a></td>
</tr>
<td class=3D"vendor-product">Plane --Plane=C2=A0<br>=C2=A0</td>
<td>Plane through 1.4.2 fails to validate that issues belong to the deploy = board's project in the public comment endpoint. Authenticated attackers can=
post comments to arbitrary issues across workspaces by supplying an issue_=
id parameter to the public deploy-board comment endpoint.</td> <td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86174" target=3D= "_blank" rel=3D"noopener">CVE-2026-86174</a></td>
</tr>
<td class=3D"vendor-product">PocketMine-MP--PocketMine-MP<br>=C2=A0</td>
<td>PocketMine-MP versions before 3.15.4 contain a denial of service vulner= ability in the InventoryTransaction component's findResultItem() method. Ma= licious clients can send specially crafted InventoryTransactionPackets with=
multiple conflicting pathways to cause exponential processing complexity, = freezing the server.</td>
<td>2026-09-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2020-37277" target=3D= "_blank" rel=3D"noopener">CVE-2020-37277</a></td>
</tr>
<td class=3D"vendor-product">PocketMine-MP--PocketMine-MP<br>=C2=A0</td>
<td>PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values=
in MovePlayerPacket position and rotation fields. Malicious clients can se=
nd crafted movement packets with invalid floating-point values to crash ser= vers through unhandled mathematical operations or prevent clients from rend= ering other players.</td>
<td>2026-09-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-48007" target=3D= "_blank" rel=3D"noopener">CVE-2021-48007</a></td>
</tr>
<td class=3D"vendor-product">PocketMine-MP--PocketMine-MP<br>=C2=A0</td>
<td>PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, al= lowing attackers to exhaust player slots by creating sessions without sendi=
ng LoginPacket. Attackers can flood the server with unauthenticated connect= ions that occupy max-player slots, preventing legitimate players from joini= ng.</td>
<td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-51008" target=3D= "_blank" rel=3D"noopener">CVE-2022-51008</a></td>
</tr>
<td class=3D"vendor-product">Pods--Pods</td>
<td>The Pods WordPress plugin before 3.3.9.2 does not restrict which functi= ons a display callback may resolve to, allowing users with the author role = and above to read arbitrary files from the server, including files outside = the web root. Only sites using the restricted display-callback mode are aff= ected, which is the automatic default on installations whose first Pods ver= sion predates 3.1.</td>
<td>2026-09-04</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74853" target=3D= "_blank" rel=3D"noopener">CVE-2026-74853</a></td>
</tr>
<td class=3D"vendor-product">PostgreSQL--Anonymizer=C2=A0<br>=C2=A0</td>
<td>PostgreSQL Anonymizer contains a SQL injection vulnerability in two imp= ort functions. A user can create a malicious JSON document containing speci= ally crafted object names. If a superuser subsequently calls anon.import_da= tabase_rules() or anon.import_roles_rules(), the malicious code is executed=
with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1=
.4 and later</td>
<td>2026-09-06</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19634" target=3D= "_blank" rel=3D"noopener">CVE-2026-19634</a></td>
</tr>
<td class=3D"vendor-product">PostgreSQL--Anonymizer=C2=A0<br>=C2=A0</td>
<td>PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_da= tabase_parallel() function that allows the owner of a table to run arbitrar=
y code with superuser privilege. The issue is fixed in PostgreSQL Anonymize=
r 3.2.0 and later versions</td>
<td>2026-09-06</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83534" target=3D= "_blank" rel=3D"noopener">CVE-2026-83534</a></td>
</tr>
<td class=3D"vendor-product">potpie-ai--potpie</td>
<td>potpie through 2.0.0 fails to verify user ownership on the POST /conver= sations/{conversation_id}/code-changes/sync endpoint. Authenticated attacke=
rs can write arbitrary file changes into other users' conversations by supp= lying their conversation IDs, allowing unauthorized modification of pending=
changes.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85669" target=3D= "_blank" rel=3D"noopener">CVE-2026-85669</a></td>
</tr>
<td class=3D"vendor-product">PublishPress--PublishPress Permissions</td>
<td>Unauthenticated Insecure Direct Object References (IDOR) in PublishPres=
s Permissions <=3D 4.8.3 versions.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84771" target=3D= "_blank" rel=3D"noopener">CVE-2026-84771</a></td>
</tr>
<td class=3D"vendor-product">PX4 --Autopilot=C2=A0<br>=C2=A0</td>
<td>PX4 Autopilot through 1.17.0 contains a null pointer dereference vulner= ability in param_set_default_file() and param_set_backup_file() functions t= hat allows attackers to crash the autopilot process. Attackers can invoke '= param select' or 'param select-backup' commands with no path argument from = any PX4 shell to trigger the crash.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86097" target=3D= "_blank" rel=3D"noopener">CVE-2026-86097</a></td>
</tr>
<td class=3D"vendor-product">PX4 --Autopilot=C2=A0<br>=C2=A0</td>
<td>PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in=
TemperatureCalibration::start() due to a race condition between task spawn= ing and object deletion. Attackers can trigger the calibration process via = shell commands to write to freed heap memory, corrupting unrelated objects =
or allocator metadata and destabilizing heap operations.</td> <td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86096" target=3D= "_blank" rel=3D"noopener">CVE-2026-86096</a></td>
</tr>
<td class=3D"vendor-product">PX4--PX4-Autopilot</td>
<td>PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_b= ench command that writes a four-byte block number into a user-supplied size=
d allocation. Attackers can invoke sd_bench with a block size below four by= tes to overflow the heap buffer and potentially execute code or crash the s= ystem.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84698" target=3D= "_blank" rel=3D"noopener">CVE-2026-84698</a></td>
</tr>
<td class=3D"vendor-product">pydantic--httpx2</td>
<td>HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.= 10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py rep= eatedly copies and rescans buffered text in _SSELineDecoder.decode() when a=
n attacker-controlled or compromised SSE endpoint splits one unterminated l= ine across many response chunks. The behavior affects httpx2.Client.sse() a=
nd httpx2.AsyncClient.sse(), and the total processing work grows quadratica= lly with the line length, allowing a crafted stream to consume excessive CP=
U and block a synchronous worker or asynchronous event loop. This issue is = fixed in version 2.10.0.</td>
<td>2026-09-02</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84378" target=3D= "_blank" rel=3D"noopener">CVE-2026-84378</a></td>
</tr>
<td class=3D"vendor-product">pydantic--httpx2</td>
<td>HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Fi= leField.render_headers() in src/httpx2/httpx2/_multipart.py directly interp= olates attacker-controlled content_type values and custom headers from the = files=3D three-element (filename, content, content_type) tuple and the file= s=3D four-element (filename, content, content_type, headers) tuple into mul= tipart/form-data part headers without validating header names or values. CR=
or LF characters can terminate a part header, inject additional part heade= rs, or end the part header block early, allowing a downstream multipart par= ser to treat attacker-supplied lines as genuine headers and potentially alt=
er part semantics or bypass header-based checks. This issue is fixed in ver= sion 2.11.0.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84379" target=3D= "_blank" rel=3D"noopener">CVE-2026-84379</a></td>
</tr>
<td class=3D"vendor-product">pydantic--httpx2</td>
<td>HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Re= quest._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Con= tent-Length header to a request that already contains a caller-supplied Tra= nsfer-Encoding header because its setdefault() processing checks each defau=
lt header independently rather than treating the two framing headers as mut= ually exclusive. Fixed-size byte, JSON, form, and known-length multipart bo= dies can therefore be serialized over HTTP/1.1 with both headers, allowing = request smuggling or connection desynchronization when downstream intermedi= aries disagree about which framing header takes precedence. This issue is f= ixed in version 2.11.0.</td>
<td>2026-09-02</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84380" target=3D= "_blank" rel=3D"noopener">CVE-2026-84380</a></td>
</tr>
<td class=3D"vendor-product">QD--QD</td>
<td>Stored Cross-Site Scripting (XSS) in TaskRunHandler.post() in web/handl= ers/task.py in QD 20220208 through 20250803. When a task is run via /task/&= lt;taskid>/run, the handler renders task log content (logtmp) into the H= TML response using Python % string formatting without HTML encoding. logtmp=
is populated from the exception object or from new_env.variables.__log__, = which is attacker-controlled via the template extract_variables mechanism. =
A low-privileged authenticated attacker can create a crafted HAR template t= hat extracts arbitrary HTML/JavaScript into the __log__ variable via the ap= i://util/unicode endpoint. When a victim triggers the task run, the embedde=
d script executes in the victim browser within the QD application context.<=
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51153" target=3D= "_blank" rel=3D"noopener">CVE-2026-51153</a></td>
</tr>
<td class=3D"vendor-product">QuantumNous--new-api</td>
<td>A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15=
. Affected by this issue is some unknown functionality of the file /api/usa= ge/token/ of the component Revoked API Token Handler. Executing a manipulat= ion can lead to session expiration. The attack may be performed from remote=
. The exploit has been publicly disclosed and may be utilized. Upgrading to=
version 1.0.0-rc.17 can resolve this issue. This patch is called 0d5995eb6= 3f8801d32eb32fbe74b75b68752bfa9. The affected component should be upgraded.= </td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82909" target=3D= "_blank" rel=3D"noopener">CVE-2026-82909</a></td>
</tr>
<td class=3D"vendor-product">ramon-victor--freegpt-webui<br>=C2=A0</td>
<td>A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb415= 55c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJail= break of the file server/backend.py of the component Jailbreak Mode. Execut= ing a manipulation can lead to allocation of resources. The attack can be e= xecuted remotely. The exploit has been published and may be used. This prod= uct implements a rolling release for ongoing delivery, which means version = information for affected or updated releases is unavailable. This vulnerabi= lity only affects products that are no longer supported by the maintainer.<=
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85703" target=3D= "_blank" rel=3D"noopener">CVE-2026-85703</a></td>
</tr>
<td class=3D"vendor-product">ramon-victor--freegpt-webui<br>=C2=A0</td>
<td>A vulnerability has been found in ramon-victor freegpt-webui up to 098d= b3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatC= ompletion.create of the file g4f/__init__.py of the component Authenticatio=
n Check. Such manipulation leads to missing authentication. The attack may =
be performed from remote. The exploit has been disclosed to the public and = may be used. This product utilizes a rolling release system for continuous = delivery, and as such, version information for affected or updated releases=
is not disclosed. This vulnerability only affects products that are no lon= ger supported by the maintainer.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85701" target=3D= "_blank" rel=3D"noopener">CVE-2026-85701</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277.1 does not check whet= her a post is password protected before using its content to build publicly=
generated SEO metadata, allowing unauthenticated users to read the content=
of password-protected posts.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77782" target=3D= "_blank" rel=3D"noopener">CVE-2026-77782</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277 does not verify that = the metadata row being updated belongs to the object the user was authorise=
d against, allowing users with the Author role and above to overwrite arbit= rary post and user metadata, including that belonging to higher-privileged = users.</td>
<td>2026-09-02</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77788" target=3D= "_blank" rel=3D"noopener">CVE-2026-77788</a></td>
</tr>
<td class=3D"vendor-product">Reader Tools--PDF Reader App</td>
<td>A security vulnerability has been detected in Reader Tools PDF Reader A=
pp 98.8 on Android. The affected element is the function ActSplashNew.handl= eDeeplink of the component File Handler. The manipulation of the argument _= display_name leads to path traversal. An attack has to be approached locall=
y. The exploit has been disclosed publicly and may be used. The vendor was = contacted early about this disclosure but did not respond in any way.</td> <td>2026-09-02</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84852" target=3D= "_blank" rel=3D"noopener">CVE-2026-84852</a></td>
</tr>
<td class=3D"vendor-product">Really Simple Plugins--Really Simple SSL</td> <td>Unauthenticated Denial of Service Attack in Really Simple SSL <=3D 9= .8.0 versions.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84775" target=3D= "_blank" rel=3D"noopener">CVE-2026-84775</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= </td>
<td>A flaw was found in Ansible Automation Platform's automation-controller=
(AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes = the requested instance_groups with only a read-level permission check, wher= eas the standard single-job launch path requires use-level permission on th=
e same field. A principal that holds read (but not use) permission on an in= stance group -- for example the built-in read-only System Auditor role -- t= ogether with execute permission on a job template can launch bulk jobs onto=
instance groups they are not authorized to use, bypassing execution-placem= ent isolation.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84470" target=3D= "_blank" rel=3D"noopener">CVE-2026-84470</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= </td>
<td>A flaw was found in the jwcrypto library, which is used for implementin=
g Javascript Object Signing and Encryption (JOSE) standards. The issue occu=
rs when the library verifies a General JSON Serialization JWS using a set o=
f keys. Due to a coding error, the library fails to correctly identify the = specific key ID (kid) and may instead accept a signature made by any valid = key in the set. This can allow an attacker with a valid key to bypass autho= rization checks in applications that rely on the key ID to identify specifi=
c tenants or users.</td>
<td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84185" target=3D= "_blank" rel=3D"noopener">CVE-2026-84185</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Ansible Automation Platform 2= </td>
<td>A flaw was found in pulpcore's content serving application. Files uploa= ded to Pulp file-type repositories are served with their original content t= ype (e.g., text/html for .html files, image/svg+xml for .svg files) and wit= hout a Content-Disposition: attachment header when using local filesystem s= torage. An authenticated user or attacker with content upload permissions c=
an upload a specially crafted HTML or SVG file containing JavaScript, which=
executes in the browser of any user who visits the file URL, resulting in = stored cross-site scripting (XSS) in the context of the host application.</=
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84232" target=3D= "_blank" rel=3D"noopener">CVE-2026-84232</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Build of Keycloak</td>
<td>A flaw was found in the first-broker-login flow of the Keycloak identit=
y management service. When a user links a social identity provider account =
to their local account, the verification proof generated is not strictly bo= und to the specific upstream identity being verified. This allows an attack=
er with a different account on the same social provider to intercept the pr= ocess and link their own account to the victim's local profile, gaining una= uthorized access.</td>
<td>2026-09-02</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82968" target=3D= "_blank" rel=3D"noopener">CVE-2026-82968</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Certificate System 9</td>
<td>An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest= /certrequests) returns HTTP 500 with internal Java stack traces for unauthe= nticated malformed requests. The same unauthenticated error path emits larg=
e multi-line stack traces into the CA debug log, creating a log-amplificati=
on resource exhaustion vector (disk growth and I/O contention) without requ= iring authentication.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-11873" target=3D= "_blank" rel=3D"noopener">CVE-2026-11873</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Certificate System 9</td>
<td>An unauthenticated client can query the Security Domain hosts inventory=
via GET /ca/rest/securityDomain/hosts and receive a structured response en= umerating internal PKI/CA hosts and roles (security domain topology and par= ticipating subsystems), without requiring a principal, client certificate, =
or session.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53682" target=3D= "_blank" rel=3D"noopener">CVE-2026-53682</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>An integer overflow was found in Corosync's handling of membership comm=
it token messages. The length-validation check for these messages can be by= passed on 32-bit systems due to an integer overflow in the calculation of t=
he expected message length, allowing a crafted network packet to trigger an=
out-of-bounds memory access that crashes the Corosync daemon. This results=
in a denial of service for the affected cluster node. The overflow does no=
t occur on 64-bit systems, where the length calculation is correctly perfor= med in 64-bit arithmetic.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81666" target=3D= "_blank" rel=3D"noopener">CVE-2026-81666</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in libtpms, a library that provides software TPM 2.0 e= mulation. When restoring TPM 2.0 state (for example during a virtual machin= e's power-on or state/migration restore), a malformed state blob can supply=
an oversized skip-block length that is not validated against the remaining=
size of the input buffer. This can drive an internal size counter negative=
, which bypasses a subsequent bounds check due to an unsafe signed-to-unsig= ned conversion, causing the parser to read memory outside the bounds of the=
heap buffer holding the state data. Successful exploitation can crash the = process hosting libtpms (such as swtpm), resulting in a denial of service o=
f the emulated TPM device and the virtual machine that depends on it. No da=
ta corruption or information disclosure was confirmed.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85769" target=3D= "_blank" rel=3D"noopener">CVE-2026-85769</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>A flaw was found in libsoup. When a client sends an HTTP/2 request body=
from a non-pollable input stream, the library can buffer more data than th=
e current flow-control window later allows. A malicious HTTP/2 server can s= hrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in pro= gress. The client then copies the full buffer into a smaller DATA callback = without a runtime bounds check, which can abort the process or fail the HTT= P/2 session.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85534" target=3D= "_blank" rel=3D"noopener">CVE-2026-85534</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 10</td>
<td>reset_password.html parses query string parameters and uses the 'url' p= arameter as a redirection target (window.location =3D url) after password r= eset, optionally delayed by a 'delay' parameter. No validation or allowlist= ing is performed on url, enabling an attacker to redirect users to an arbit= rary external site after completion of the password-reset workflow.</td> <td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53683" target=3D= "_blank" rel=3D"noopener">CVE-2026-53683</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 7</td>
<td>A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea= _num_ptrs field from on-disk extended attribute metadata is consumed withou=
t bounds validation, causing a heap buffer over-read that may disclose sens= itive memory contents or cause a crash when processing crafted GFS2 filesys= tem images.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71222" target=3D= "_blank" rel=3D"noopener">CVE-2026-71222</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 7</td>
<td>A stack overflow vulnerability was found in gfs2-utils. The hash table = traversal code in metawalk.c uses alloca() with an exponentially-derived si=
ze from the untrusted on-disk di_depth field without bounds validation. A c= rafted GFS2 filesystem image with a large di_depth value causes stack exhau= stion and a denial of service when processed by fsck.gfs2, gfs2_edit, or sa= vemeta.</td>
<td>2026-09-03</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71219" target=3D= "_blank" rel=3D"noopener">CVE-2026-71219</a></td>
</tr>
<td class=3D"vendor-product">Red Hat--Red Hat Enterprise Linux 7</td>
<td>A stack overflow vulnerability was found in gfs2-utils. The metadata wa=
lk code in metawalk.c uses alloca() with an untrusted inode height value fr=
om on-disk metadata without bounds validation, causing stack exhaustion and=
a denial of service when processing crafted GFS2 filesystem images.</td> <td>2026-09-03</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71224" target=3D= "_blank" rel=3D"noopener">CVE-2026-71224</a></td>
</tr>
<td class=3D"vendor-product">RegistrationMagic--RegistrationMagic</td>
<td>The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate=
the total price of a paid registration server-side, allowing unauthenticat=
ed users to complete a paid registration without paying and obtain an activ= ated account.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77793" target=3D= "_blank" rel=3D"noopener">CVE-2026-77793</a></td>
</tr>
<td class=3D"vendor-product">RegistrationMagic--RegistrationMagic</td>
<td>The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate=
a client-supplied quantity multiplier when calculating the total price of =
a paid registration, allowing unauthenticated users to register without pay= ing and obtain an activated account holding the role the form grants.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77794" target=3D= "_blank" rel=3D"noopener">CVE-2026-77794</a></td>
</tr>
<td class=3D"vendor-product">Releasit--Releasit COD Form & Upsells</td> <td>A vulnerability was detected in Releasit Releasit COD Form & Upsell=
s v1. This vulnerability affects unknown code of the component OTP Validati= on. The manipulation results in client-side enforcement of server-side secu= rity. The attack may be launched remotely. The exploit is now public and ma=
y be used. Upgrading to version v2 is able to resolve this issue. The affec= ted component should be upgraded.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84110" target=3D= "_blank" rel=3D"noopener">CVE-2026-84110</a></td>
</tr>
<td class=3D"vendor-product">Restaurant Menu and Food Ordering--Restaurant = Menu and Food Ordering</td>
<td>The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 do=
es not verify that a PayPal payment notification genuinely originates from = PayPal, allowing unauthenticated attackers to forge a payment notification = and mark their own order as paid and completed without making any payment.<=
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84044" target=3D= "_blank" rel=3D"noopener">CVE-2026-84044</a></td>
</tr>
<td class=3D"vendor-product">Restrict User Access--Restrict User Access</td=
<td>The Restrict User Access WordPress plugin before 2.8.1 does not normali=
se the REST API route before checking it against the routes its content pro= tection covers, allowing unauthenticated users to bypass that protection an=
d read restricted content and enumerate users.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78153" target=3D= "_blank" rel=3D"noopener">CVE-2026-78153</a></td>
</tr>
<td class=3D"vendor-product">RightNow-AI--OpenFang</td>
<td>A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. Thi=
s vulnerability affects the function shell_exec of the file crates/openfang= -runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory a= llocation. The attack is possible to be carried out remotely. The exploit h=
as been made available to the public and could be used for attacks. The ven= dor was contacted early about this disclosure but did not respond in any wa= y.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84888" target=3D= "_blank" rel=3D"noopener">CVE-2026-84888</a></td>
</tr>
<td class=3D"vendor-product">Rowboat--Rowboat=C2=A0<br>=C2=A0</td>
<td>Rowboat through 0.9.1 fails to validate custom MCP server and webhook U= RLs, allowing authenticated users to configure arbitrary destinations. Atta= ckers can point these URLs at internal services and cloud metadata endpoint=
s to perform server-side request forgery and enumerate internal network top= ology.</td>
<td>2026-09-05</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86122" target=3D= "_blank" rel=3D"noopener">CVE-2026-86122</a></td>
</tr>
<td class=3D"vendor-product">rowboatlabs--rowboat</td>
<td>A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The im= pacted element is the function request.text/req.json of the file apps/rowbo= at/app/api/composio/webhook/route.ts of the component Composio Webhook Endp= oint. The manipulation results in denial of service. It is possible to laun=
ch the attack remotely. The exploit is now public and may be used. Upgradin=
g to version 0.9.2 is sufficient to resolve this issue. Upgrading the affec= ted component is recommended. The legacy Next.js app was deleted at 0.9.2 r= ather than patched, leaving no security control behind.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84856" target=3D= "_blank" rel=3D"noopener">CVE-2026-84856</a></td>
</tr>
<td class=3D"vendor-product">rpcap--rpcap<br>=C2=A0</td>
<td>The rpcap client code that processes a RPCAP_MSG_PACKET message receive=
d from the server incorrectly validates its headers. A malicious server can=
send a crafted message and cause the client to treat up to 20 bytes of the=
client process memory beyond the end of the buffer as if it was a part of = the captured packet.</td>
<td>2026-09-05</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18238" target=3D= "_blank" rel=3D"noopener">CVE-2026-18238</a></td>
</tr>
<td class=3D"vendor-product">rpcapd --rpcapd=C2=A0<br>=C2=A0</td>
<td>rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_R=
EQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never=
frees the memory, so it leaks memory even under normal use. A malicious cl= ient can cause the server to leak memory substantially faster.</td> <td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18313" target=3D= "_blank" rel=3D"noopener">CVE-2026-18313</a></td>
</tr>
<td class=3D"vendor-product">Saad Iqbal--WP EasyPay</td>
<td>Unauthenticated Bypass Vulnerability in WP EasyPay <=3D 4.5.3 versio= ns.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84762" target=3D= "_blank" rel=3D"noopener">CVE-2026-84762</a></td>
</tr>
<td class=3D"vendor-product">sambitraj--Student-Management-System</td>
<td>A vulnerability was detected in sambitraj Student-Management-System up =
to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown functi=
on of the file aca.sql. Performing a manipulation results in use of default=
password. Remote exploitation of the attack is possible. The exploit is no=
w public and may be used. This product follows a rolling release approach f=
or continuous delivery, so version details for affected or updated releases=
are not provided. The project was informed of the problem early through an=
issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82698" target=3D= "_blank" rel=3D"noopener">CVE-2026-82698</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--mTower</td>
<td>Untrusted pointer dereference vulnerability in Samsung Open Source mTow=
er allows Pointer Manipulation. This issue affects mTower: before 102d3dc75= cf8e58e68e4bea54ae3c803992c91be.</td>
<td>2026-09-01</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10420" target=3D= "_blank" rel=3D"noopener">CVE-2026-10420</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--mTower</td>
<td>NULL pointer dereference vulnerability in Samsung Open Source mTower al= lows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5= d5ebf9b14bc020bf1c2c37489a.</td>
<td>2026-09-01</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82926" target=3D= "_blank" rel=3D"noopener">CVE-2026-82926</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--mTower</td>
<td>Untrusted pointer dereference vulnerability in Samsung Open Source mTow=
er allows Pointer Manipulation. This issue affects mTower: before 06994e303= 637512e39062f3e037c222e8448e57e.</td>
<td>2026-09-01</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82927" target=3D= "_blank" rel=3D"noopener">CVE-2026-82927</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--rlottie</td>
<td>Uncontrolled Recursion vulnerability in Samsung Open Source rlottie all= ows Serialized Data with Nested Payloads. This issue affects rlottie: befor=
e 8de0d9e6ca80ffef654965505981727b9fa06a51.</td>
<td>2026-08-31</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82797" target=3D= "_blank" rel=3D"noopener">CVE-2026-82797</a></td>
</tr>
<td class=3D"vendor-product">Samsung Open Source--TizenFX</td> <td>Out-of-bounds Write and Improper Validation of Array Index vulnerabilit=
y in Samsung Open Source TizenFX Samsung/TizenFX allows Overflow Buffers.</=
<td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85084" target=3D= "_blank" rel=3D"noopener">CVE-2026-85084</a></td>
</tr>
<td class=3D"vendor-product">Samsung Opensource--rLottie</td>
<td>Out-of-bounds read vulnerability in Samsung Opensource rLottie allows O= verread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d76= 1453ad4630.</td>
<td>2026-09-04</td>
<td>4.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49509" target=3D= "_blank" rel=3D"noopener">CVE-2026-49509</a></td>
</tr>
<td class=3D"vendor-product">sc Internet Vivoo--WP Rentals</td> <td>Authorization Bypass Through User-Controlled Key vulnerability in sc In= ternet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Con= trol Security Levels. This issue affects WP Rentals: from n/a before 3.16.0= .</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27432" target=3D= "_blank" rel=3D"noopener">CVE-2026-27432</a></td>
</tr>
<td class=3D"vendor-product">sdcb--chats</td>
<td>A vulnerability was detected in sdcb chats up to 1.12.0. This affects t=
he function McpController of the file src/BE/web/Controllers/Users/Mcps/Mcp= Controller.cs of the component fetch-tools Endpoint. The manipulation resul=
ts in server-side request forgery. The attack may be launched remotely. The=
exploit is now public and may be used. The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82905" target=3D= "_blank" rel=3D"noopener">CVE-2026-82905</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A vulnerability was identified in SeaCMS up to 13.6. Affected by this v= ulnerability is the function unlink of the file /member.php?action=3Dchgpwd= submit of the component Avatar Upload. Such manipulation of the argument ol= dpic leads to path traversal. It is possible to launch the attack remotely.=
The exploit is publicly available and might be used.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82599" target=3D= "_blank" rel=3D"noopener">CVE-2026-82599</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A security vulnerability has been detected in SeaCMS up to 13.6. This v= ulnerability affects unknown code of the file /ass.php. The manipulation le= ads to authorization bypass. The attack may be initiated remotely. The expl= oit has been disclosed publicly and may be used.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82602" target=3D= "_blank" rel=3D"noopener">CVE-2026-82602</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A vulnerability was detected in SeaCMS up to 13.6. This issue affects s= ome unknown processing of the file /member.php?action=3Ddel_pl of the compo= nent Comment Cache. The manipulation of the argument itype/vid results in p= ath traversal. The attack may be launched remotely. The exploit is now publ=
ic and may be used.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82603" target=3D= "_blank" rel=3D"noopener">CVE-2026-82603</a></td>
</tr>
<td class=3D"vendor-product">SeaCMS--SeaCMS</td>
<td>A weakness has been identified in SeaCMS up to 13.6. This affects an un= known part of the file /err.php. Executing a manipulation of the argument e= rrtxt can lead to cross site scripting. The attack can be launched remotely=
. The exploit has been made available to the public and could be used for a= ttacks.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82601" target=3D= "_blank" rel=3D"noopener">CVE-2026-82601</a></td>
</tr>
<td class=3D"vendor-product">SEOPress--SEOPress</td>
<td>Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Ser= ver Side Request Forgery. This issue affects SEOPress: from n/a through 10.= 1.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85305" target=3D= "_blank" rel=3D"noopener">CVE-2026-85305</a></td>
</tr>
<td class=3D"vendor-product">SEOWriting--SEOWriting</td>
<td>SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-= site scripting vulnerability that allows authenticated contributors to inje=
ct malicious JavaScript by exploiting an overly permissive KSES allowlist t= hat explicitly permits the onload event handler on iframe elements. Attacke=
rs can store crafted JavaScript payloads in post content that execute when = the affected post is viewed or previewed by higher-privileged users, potent= ially leading to privilege escalation or account compromise.</td> <td>2026-09-02</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75134" target=3D= "_blank" rel=3D"noopener">CVE-2026-75134</a></td>
</tr>
<td class=3D"vendor-product">Septeo IT Solutions--UpSignOn</td>
<td>UpSignOn for Windows before 7.19.0 contains a sensitive data exposure v= ulnerability that allows local attackers to recover the master password and=
decrypt vault contents by reading a retained backup key from the process m= emory of UpSignOn.exe, even after the vault has been re-locked. Attackers c=
an extract the backup key from process memory to decrypt the encrypted mast=
er password backup stored in v6-vault1.DATA.txt, then use the recovered mas= ter password to decrypt the main vault and export all password manager entr= ies in cleartext.</td>
<td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75135" target=3D= "_blank" rel=3D"noopener">CVE-2026-75135</a></td>
</tr>
<td class=3D"vendor-product">Septeo IT Solutions--UpSignOn</td>
<td>UpSignOn for Windows before 7.19.0 contains an insecure credential stor= age vulnerability that allows local attackers to retrieve the biometric unl= ock key stored in the Windows PasswordVault API without triggering any auth= entication prompt. Attackers can access the stored biometric key from a sta= ndard local process within the same Windows session to decrypt the protecte=
d vault files and export the entire password manager contents in cleartext.= </td>
<td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75136" target=3D= "_blank" rel=3D"noopener">CVE-2026-75136</a></td>
</tr>
<td class=3D"vendor-product">Septeo IT Solutions--UpSignOn</td>
<td>UpSignOn for Windows before 7.19.0 contains a sensitive data exposure v= ulnerability that allows local attackers to recover cleartext vault data fr=
om process memory even after the application has been locked. Attackers can=
use the PROCESS_VM_READ permission to read the memory space of UpSignOn.ex=
e and extract sensitive fields including entry names, URLs, usernames, pass= words, TOTP secrets, and notes.</td>
<td>2026-09-02</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75137" target=3D= "_blank" rel=3D"noopener">CVE-2026-75137</a></td>
</tr>
<td class=3D"vendor-product">shabti--Frontend Admin by DynamiApps</td>
<td>The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to = Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions u=
p to, and including, 3.29.11 due to insufficient input sanitization and out= put escaping. This makes it possible for authenticated attackers, with cont= ributor-level access and above, to inject arbitrary web scripts in pages th=
at will execute whenever a user accesses an injected page.</td> <td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12747" target=3D= "_blank" rel=3D"noopener">CVE-2026-12747</a></td>
</tr>
<td class=3D"vendor-product">sigoden--aichat</td>
<td>A flaw has been found in sigoden aichat up to 0.30.4. This affects an u= nknown function of the file src/serve.rs of the component API Endpoint. Thi=
s manipulation causes uncontrolled memory allocation. The attack can be ini= tiated remotely. The exploit has been published and may be used. The vendor=
was contacted early about this disclosure but did not respond in any way.<=
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84857" target=3D= "_blank" rel=3D"noopener">CVE-2026-84857</a></td>
</tr>
<td class=3D"vendor-product">silverks--Graphene</td>
<td>Subscriber Cross Site Scripting (XSS) in Graphene <=3D 2.9.4 version= s.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81281" target=3D= "_blank" rel=3D"noopener">CVE-2026-81281</a></td>
</tr>
<td class=3D"vendor-product">Sim --Sim=C2=A0<br>=C2=A0</td>
<td>Sim before 0.8.14 classifies tool requests as internal based on URL pre= fix matching without scheme normalization, skipping SSRF validation and min= ting internal authentication tokens. Authenticated workflow authors can byp= ass external URL validation by supplying paths starting with /api/ in HTTP = blocks to reach internal-only endpoints like POST /api/function/execute.</t=
<td>2026-09-05</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86115" target=3D= "_blank" rel=3D"noopener">CVE-2026-86115</a></td>
</tr>
<td class=3D"vendor-product">Simple Membership MailChimp Integration--Simpl=
e Membership MailChimp Integration</td>
<td>The Simple Membership MailChimp Integration WordPress plugin before 1.9=
.8 does not have CSRF checks in its settings page, allowing attackers to tr= ick a logged-in administrator into changing the configured third-party API = key. Once replaced, all subsequent member registration data (name, email, m= embership level) is sent to the attacker-controlled account.</td> <td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8151" target=3D"= _blank" rel=3D"noopener">CVE-2026-8151</a></td>
</tr>
<td class=3D"vendor-product">simular-ai--Agent-S</td>
<td>A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affec= ted by this vulnerability is the function ImageData of the file gui_agents/= s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulat= ion of the argument img_bytes can lead to resource consumption. The attack = may be launched remotely. The exploit has been publicly disclosed and may b=
e utilized. The vendor was contacted early about this disclosure but did no=
t respond in any way.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84886" target=3D= "_blank" rel=3D"noopener">CVE-2026-84886</a></td>
</tr>
<td class=3D"vendor-product">simular-ai--Agent-S</td>
<td>A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This = impacts an unknown function of the file code_agent.py of the component Code= Agent. Such manipulation leads to denial of service. The attack can be laun= ched remotely. The exploit has been disclosed to the public and may be used=
. The vendor was contacted early about this disclosure but did not respond =
in any way.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84885" target=3D= "_blank" rel=3D"noopener">CVE-2026-84885</a></td>
</tr>
<td class=3D"vendor-product">simular-ai--Agent-S</td>
<td>A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affec= ted by this issue is some unknown functionality of the file grounding.py of=
the component Model-generated GUI Action Execution Workflow. The manipulat= ion leads to denial of service. Remote exploitation of the attack is possib= le. The exploit is publicly available and might be used. The vendor was con= tacted early about this disclosure but did not respond in any way.</td> <td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84887" target=3D= "_blank" rel=3D"noopener">CVE-2026-84887</a></td>
</tr>
<td class=3D"vendor-product">SiYuan --SiYuan=C2=A0<br>=C2=A0</td>
<td>SiYuan versions before v3.8.2 fail to properly filter private attribute= -view cell values in the getAttributeViewKeys endpoint. Publish readers can=
retrieve hidden KeyValues payloads from rows bound to inaccessible documen= ts, exposing private database contents without authorization.</td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86192" target=3D= "_blank" rel=3D"noopener">CVE-2026-86192</a></td>
</tr>
<td class=3D"vendor-product">SiYuan --SiYuan=C2=A0<br>=C2=A0</td>
<td>SiYuan versions before v3.8.2 contain an information disclosure vulnera= bility in the getAttributeViewKeysByID endpoint that allows publish readers=
to enumerate private attribute view key definitions without verifying pare=
nt database visibility. Attackers can access the endpoint to retrieve compl= ete key schemas including sensitive field names and relation definitions fr=
om hidden databases.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86191" target=3D= "_blank" rel=3D"noopener">CVE-2026-86191</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan through 3.8.1 contains an authorization bypass vulnerability in = the /api/file/getFile endpoint that allows readers to retrieve files from n= otebooks explicitly configured as Visible:false. Attackers with reader role=
can access private workspace files including notebook metadata and interna=
l configuration by knowing the hidden notebook identifier and file path.</t=
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85578" target=3D= "_blank" rel=3D"noopener">CVE-2026-85578</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan versions before v3.8.2 contain a path guard bypass vulnerability=
in the MCP file-access handler that uses case-sensitive matching on Linux = filesystems. Attackers can read the protected publishAccess.json file by re= questing case-variant paths like PublishAccess.json to disclose sensitive p= ublish-access configuration and metadata.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85580" target=3D= "_blank" rel=3D"noopener">CVE-2026-85580</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan versions before v3.8.2 contain an unbounded session creation vul= nerability in the publish-service Basic Auth handler that allows authentica= ted attackers to exhaust memory. Attackers can repeatedly authenticate with=
valid credentials to create persistent session entries without expiry or c= apacity limits, causing indefinite process memory growth and denial of serv= ice.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85582" target=3D= "_blank" rel=3D"noopener">CVE-2026-85582</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan versions before v3.8.2 contain a path traversal vulnerability in=
the reader-accessible file-read endpoint that follows symlinks when openin=
g authorized asset paths. Attackers with reader role can request a logical = asset under data/assets/ that is a symlink to a file outside the workspace = and receive the target file bytes, bypassing workspace boundary restriction= s.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85583" target=3D= "_blank" rel=3D"noopener">CVE-2026-85583</a></td>
</tr>
<td class=3D"vendor-product">siyuan-note--siyuan</td>
<td>SiYuan is affected by an information disclosure vulnerability (confirme=
d in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactio= ns/undoState endpoint. The endpoint returns the peekMutatedRootIDs list fro=
m the global undo-log stack for a caller-supplied root ID without applying = publish-access visibility filtering. An authenticated reader who knows the = root ID of a visible document can obtain the internal root IDs of other doc= uments (including private or unpublished ones) modified in the same cross-d= ocument transaction, disclosing internal identifiers and cross-document rel= ationships. Document body contents are not directly exposed.</td> <td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85579" target=3D= "_blank" rel=3D"noopener">CVE-2026-85579</a></td>
</tr>
<td class=3D"vendor-product">Slack --Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. F= rom version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oi= dc/login is reachable without authentication and is registered outside the = Web UI rate-limited auth routes. Every request creates a fresh random OIDC = state value and stores it in an in-memory map for 10m. Expired states are s= wept lazily, but there is no rate limit or maximum live-state cap on the al= location path. An unauthenticated remote client can therefore grow OIDC.sta= tes for the full state TTL, bounded by request throughput rather than by co= nfigured auth rate limits. This issue has been patched in version 0.5.0.</t=
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55512" target=3D= "_blank" rel=3D"noopener">CVE-2026-55512</a></td>
</tr>
<td class=3D"vendor-product">Slack --Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. F= rom version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-crea= tion path ignores both the server-wide enrollment_token_ttl security settin=
g and per-network network_config.enrollment_token_ttl overrides. API host c= reation and token-regeneration paths use the configured TTL resolver, but P= OST /ui/hosts hardcodes now.Add(24 * time.Hour) for newly minted agent enro= llment tokens. In deployments that intentionally reduce enrollment-token li= fetime, any authenticated operator who can create a host through the Web UI=
can still mint a bearer enrollment token valid for about 24 hours. This is= sue has been patched in version 0.5.0.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55513" target=3D= "_blank" rel=3D"noopener">CVE-2026-55513</a></td>
</tr>
<td class=3D"vendor-product">smub--Charitable Donation & Fundraising Pl= atform (Donation Forms, Recurring Donations & Fundraising Campaigns)</t=
<td>The Charitable - Donation & Fundraising Platform (Donation Forms, R= ecurring Donations & Fundraising Campaigns) plugin for WordPress is vul= nerable to generic SQL Injection via 'order' Shortcode Attribute in all ver= sions up to, and including, 1.8.12.1 due to insufficient escaping on the us=
er supplied parameter and lack of sufficient preparation on the existing SQ=
L query. This makes it possible for authenticated attackers, with contribut= or-level access and above, to append additional SQL queries into already ex= isting queries that can be used to extract sensitive information from the d= atabase. The [charitable_donors] shortcode is accessible to Contributor-lev=
el users via draft or pending post previews, providing an authenticated but=
low-privileged entry point for exploitation.</td>
<td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77189" target=3D= "_blank" rel=3D"noopener">CVE-2026-77189</a></td>
</tr>
<td class=3D"vendor-product">Snowflake--Snowflake JDBC Driver</td>
<td>Improper input validation of the auto-configuration account identifier =
in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-= bearing login request to be redirected to an attacker-selected HTTPS endpoi= nt. An attacker able to control the account value could cause the driver to=
transmit a reusable login credential to a host of their choosing and repla=
y it to obtain the privileges granted to that credential. Successful exploi= tation requires an application using jdbc:snowflake:auto with a connections= .toml section that omits an explicit host and a lower-trust principal able =
to set the account value; ordinary JDBC URLs are unaffected. The fix is ava= ilable in Snowflake JDBC Driver version 4.3.4. Users must manually upgrade.= </td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85528" target=3D= "_blank" rel=3D"noopener">CVE-2026-85528</a></td>
</tr>
<td class=3D"vendor-product">Soarkey--StudentManagement</td>
<td>A security flaw has been discovered in Soarkey StudentManagement and = =C3=A5=C2=AD=C2=A6=C3=A7=E2=80=9D=C5=B8=C3=A4=C2=BF=C2=A1=C3=A6=C2=81=C2=AF= =C3=A7=C2=AE=C2=A1=C3=A7=C2=90=E2=80=A0=C3=A7=C2=B3=C2=BB=C3=A7=C2=BB=C5=B8=
up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function = CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performin=
g a manipulation of the argument cno results in sql injection. It is possib=
le to initiate the attack remotely. The exploit has been released to the pu= blic and may be used for attacks. The project was informed of the problem e= arly through an issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82620" target=3D= "_blank" rel=3D"noopener">CVE-2026-82620</a></td>
</tr>
<td class=3D"vendor-product">Social Media Share Buttons & Social Sharin=
g Icons--Social Media Share Buttons & Social Sharing Icons</td>
<td>The Social Media Share Buttons & Social Sharing Icons WordPress plu= gin before 3.0.1 does not escape the post title before outputting it in an = inline JavaScript event handler, allowing users with the Contributor role a=
nd above to perform Stored Cross-Site Scripting attacks which are triggered=
when a visitor interacts with the affected button. Exploitation requires t=
he Social Media Share Buttons & Social Sharing Icons WordPress plugin b= efore 3.0.1 to be running a non-default icon display configuration.</td> <td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19719" target=3D= "_blank" rel=3D"noopener">CVE-2026-19719</a></td>
</tr>
<td class=3D"vendor-product">Solace Extra--Solace Extra</td>
<td>The Solace Extra WordPress plugin before 1.7.0 does not perform any aut= horization or post-status checks in one of its AJAX actions, allowing unaut= henticated visitors to read the content of non-published (draft, pending, p= rivate, and trashed) Site Builder parts that WordPress would otherwise not = serve.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16966" target=3D= "_blank" rel=3D"noopener">CVE-2026-16966</a></td>
</tr>
<td class=3D"vendor-product">SolidInvoice--SolidInvoice</td>
<td>SolidInvoice is an open-source invoicing platform. Prior to version 3.0= .1, `UserInvitation` entities have no expiry timestamp. Invitation links ma= iled to users remain valid indefinitely, meaning a leaked, forwarded, or ar= chived invitation email can be used at any time in the future to join a com= pany or silently add a compromised email account to a company. Version 3.0.=
1 fixes the issue.</td>
<td>2026-09-04</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61608" target=3D= "_blank" rel=3D"noopener">CVE-2026-61608</a></td>
</tr>
<td class=3D"vendor-product">SolidInvoice--SolidInvoice</td>
<td>SolidInvoice is an open-source invoicing platform. Prior to version 3.0= .1, an authenticated user can view the API request history of any other use= r's API tokens within the same company by manipulating two writable Symfony=
UX LiveComponent props on the `DataGrid` component. Version 3.0.1 fixes th=
e issue.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61688" target=3D= "_blank" rel=3D"noopener">CVE-2026-61688</a></td>
</tr>
<td class=3D"vendor-product">SolidInvoice--SolidInvoice</td>
<td>SolidInvoice is an open-source invoicing platform. Prior to version 3.0= .1, the REST API authenticator accepts bearer tokens via a `?token=3D` URL = query parameter as a fallback to the `X-API-TOKEN` header. This causes long= -lived API credentials to be recorded in server access logs, proxy logs, br= owser history, and HTTP Referer headers sent to third-party origins. Versio=
n 3.0.1 fixes the issue.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61614" target=3D= "_blank" rel=3D"noopener">CVE-2026-61614</a></td>
</tr>
<td class=3D"vendor-product">SpecterOps--BloodHound</td>
<td>A weakness has been identified in SpecterOps BloodHound up to 9.5.1. Th=
e affected element is the function NewV2API of the file cmd/api/src/api/reg= istration/v2.go of the component Graph Write Endpoint. Executing a manipula= tion can lead to improper authorization. It is possible to launch the attac=
k remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficie=
nt to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a196= 51d9cebb. You should upgrade the affected component.</td>
<td>2026-09-03</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85241" target=3D= "_blank" rel=3D"noopener">CVE-2026-85241</a></td>
</tr>
<td class=3D"vendor-product">StackStorm--st2</td>
<td>A weakness has been identified in StackStorm st2 up to 3.9.0. This issu=
e affects the function assert_user_is_admin_if_user_query_param_is_provided=
of the file st2api/st2api/controllers/v1/actionexecutions.py of the compon= ent NoOp RBAC backend. This manipulation of the argument User causes improp=
er privilege management. The attack is possible to be carried out remotely.=
The exploit has been made available to the public and could be used for at= tacks. Prior advisory CVE-2022-44009 was reported as a follow-up on the sam=
e sink, but this issue is distinct: it needs no Jinja RBAC und affects defa= ult install with RBAC disabled. The project was informed of the problem ear=
ly through an issue report but has not responded yet.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85513" target=3D= "_blank" rel=3D"noopener">CVE-2026-85513</a></td>
</tr>
<td class=3D"vendor-product">StackStorm--st2</td>
<td>A security vulnerability has been detected in StackStorm st2 up to 3.9.=
0. Impacted is an unknown function of the file st2api/st2api/controllers/v1= /auth.py of the component API Key Handler. Such manipulation of the argumen=
t api_key_api.user leads to improper privilege management. The attack may b=
e performed from remote. The exploit has been disclosed publicly and may be=
used. The project was informed of the problem early through an issue repor=
t but has not responded yet.</td>
<td>2026-09-04</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85514" target=3D= "_blank" rel=3D"noopener">CVE-2026-85514</a></td>
</tr>
<td class=3D"vendor-product">Stormshield--Stormshield Network Security</td> <td>It's possible to run a stored XSS in Stormshield's web administration p= anel. To exploit this vulnerability, a SNS administrator with appropriate p= ermissions must inject=C2=A0 some malicious script in a group's comments in=
the webservices administration interface.</td>
<td>2026-09-04</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14466" target=3D= "_blank" rel=3D"noopener">CVE-2026-14466</a></td>
</tr>
<td class=3D"vendor-product">Strategy11 Team--Business Directory</td> <td>Unauthenticated Broken Access Control in Business Directory <=3D 6.4= .26 versions.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84758" target=3D= "_blank" rel=3D"noopener">CVE-2026-84758</a></td>
</tr>
<td class=3D"vendor-product">Strategy11 Team--Business Directory</td> <td>Unauthenticated Insecure Direct Object References (IDOR) in Business Di= rectory <=3D 6.4.26 versions.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84769" target=3D= "_blank" rel=3D"noopener">CVE-2026-84769</a></td>
</tr>
<td class=3D"vendor-product">Studio-42--elFinder</td>
<td>elFinder is an open-source file manager for web, written in JavaScript = using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFi= nderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so va= lidateCsrfToken() is not called for this state-changing operation. In the s= hipped php/connector.minimal.php-dist configuration, FTP network mounts are=
enabled by default, and attacker-controlled protocol, host, path, port, us= er, pass, alias, and options arguments flow through elFinder::netmount() in=
php/elFinder.class.php to php/elFinderVolumeFTP.class.php. A cross-site re= quest can therefore persist an attacker-chosen FTP mount in the victim's se= ssion, cause the PHP server to connect to an attacker-chosen FTP host and p= ort, and send supplied credentials without an X-elFinder-CSRF token. This i= ssue is fixed in version 2.1.70.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81890" target=3D= "_blank" rel=3D"noopener">CVE-2026-81890</a></td>
</tr>
<td class=3D"vendor-product">sulu--sulu</td>
<td>Sulu is an open-source PHP content management system based on the Symfo=
ny framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBund= le/Controller/MediaStreamController.php allows the /media/{id}/download/{sl= ug} route and its administration variant to honor the inline query paramete=
r for scriptable MIME types. The vulnerable stored Content-Type values incl= ude text/html, application/xhtml+xml, text/xml, and application/xml. An att= acker with media upload permission can store an HTML, XHTML, or XML documen=
t and create a link using inline=3D1, causing the application to return the=
file on the Sulu origin instead of forcing Content-Disposition attachment.=
When an authenticated victim opens the link, attacker-controlled JavaScrip=
t can execute with the victim's Sulu-origin session and can read data or pe= rform actions as that victim. This issue is fixed in versions 2.6.25 and 3.= 0.8.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82396" target=3D= "_blank" rel=3D"noopener">CVE-2026-82396</a></td>
</tr>
<td class=3D"vendor-product">Supsystic--Ultimate Maps by Supsystic</td>
<td>Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsy= stic allows Exploiting Incorrectly Configured Access Control Security Level=
s. This issue affects Ultimate Maps by Supsystic: from n/a through 1.5.3.</=
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85309" target=3D= "_blank" rel=3D"noopener">CVE-2026-85309</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Rancher</td>
<td>A flaw was found in Rancher Manager. The /v3/users update path did not = enforce immutability of a User resource's `username` and `principalIds` fie= lds. A user holding the `update` verb on `users.management.cattle.io` could=
inject a foreign identity provider principal into any account, so that the=
next login by the owner of that principal was bound to the victim's accoun=
t and inherited its role bindings. This issue affects Rancher: before 2.15.= 1.</td>
<td>2026-09-03</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71403" target=3D= "_blank" rel=3D"noopener">CVE-2026-71403</a></td>
</tr>
<td class=3D"vendor-product">svg--svgo</td>
<td>SVGO, short for SVG Optimizer, is a Node.js library and command-line ap= plication for optimizing SVG files. From version 1.0.0 until versions 2.8.4=
, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElem= ent in versions 2 and 3 and implemented in plugins/removeScripts.js, remove=
s SVG and XHTML script elements but does not inspect executable HTML conten=
t inside SVG foreignObject elements. Event-handler attributes such as onloa=
d and onbeforetoggle, srcdoc documents, and executable URLs in the action, = data, formaction, href, and src attributes can remain in attacker-controlle=
d SVG input. When an application uses the plugin as its only protection and=
serves the optimized SVG in an active browser context, the payload can exe= cute script in the viewer's origin, expose data, modify content, or perform=
actions as the victim. This issue is fixed in versions 2.8.4, 3.3.5, and 4= .1.0.</td>
<td>2026-09-01</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84369" target=3D= "_blank" rel=3D"noopener">CVE-2026-84369</a></td>
</tr>
<td class=3D"vendor-product">Systerel--S2OPC</td>
<td>A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affec= ted element is the function set_range_matrix_on_string_array of the file sr= c/Common/opcua_types/sopc_builtintypes.c of the component String Array Rang=
e Writing. This manipulation causes out-of-bounds read. The attack is possi= ble to be carried out remotely. The project was informed of the problem ear=
ly through an issue report but has not responded yet.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82618" target=3D= "_blank" rel=3D"noopener">CVE-2026-82618</a></td>
</tr>
<td class=3D"vendor-product">Systerel--S2OPC</td>
<td>A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impac= ted element is the function monitored_item_event_filter_treatment_bs__init_= event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/sub= scription_mgr.c. Such manipulation of the argument EventFilter leads to use=
after free. The attack may be performed from remote. The exploit is public=
ly available and might be used. The name of the patch is a4cee16a851b971be4= 47a6ed531173702c722b99. It is best practice to apply a patch to resolve thi=
s issue.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82619" target=3D= "_blank" rel=3D"noopener">CVE-2026-82619</a></td>
</tr>
<td class=3D"vendor-product">TechStore--TechStore 1.0</td>
<td>TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_d= isplay, the application echoes the id parameter verbatim into the rendered = page, permitting execution of attacker-supplied JavaScript in users browser= .</td>
<td>2026-08-31</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-63607" target=3D= "_blank" rel=3D"noopener">CVE-2025-63607</a></td>
</tr>
<td class=3D"vendor-product">Tencent--AI-Infra-Guard</td>
<td>Tencent AI-Infra-Guard's skill-scan component excludes compiled Python = bytecode files from analysis by hardcoding __pycache__ directories and .pyc= /.pyo/.pyd extensions into skip lists across multiple scanning surfaces. At= tackers can distribute skills with benign Python source files alongside mal= icious compiled bytecode that executes on import while the scanner reports =
a safe verdict, enabling code execution when operators install the skill.</=
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84809" target=3D= "_blank" rel=3D"noopener">CVE-2026-84809</a></td>
</tr>
<td class=3D"vendor-product">Tenda --CP3<br>=C2=A0</td>
<td>A security vulnerability has been detected in Tenda CP3 27.5.57.101. Im= pacted is an unknown function of the file custom-x/softap/hostapd. Such man= ipulation of the argument wpa_passphrase leads to hard-coded credentials. T=
he attack can be launched remotely. The exploit has been disclosed publicly=
and may be used.</td>
<td>2026-09-05</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86150" target=3D= "_blank" rel=3D"noopener">CVE-2026-86150</a></td>
</tr>
<td class=3D"vendor-product">The4--Kalles Addons</td>
<td>Subscriber Cross Site Scripting (XSS) in Kalles Addons <=3D 1.0.6 ve= rsions.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81778" target=3D= "_blank" rel=3D"noopener">CVE-2026-81778</a></td>
</tr>
<td class=3D"vendor-product">Theme My Login--Theme My Login</td>
<td>The My Login WordPress plugin before 7.2.0 does not enforce the network=
's registration setting when processing site signups on multisite installat= ions, allowing users with a subscriber account, and unauthenticated users o=
n some networks, to create new sites and be granted administrator over them= .</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81583" target=3D= "_blank" rel=3D"noopener">CVE-2026-81583</a></td>
</tr>
<td class=3D"vendor-product">ThemeGoods--Grand Tour</td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tou=
r allows Cross Site Request Forgery. This issue affects Grand Tour: from n/=
a through 5.5.1.</td>
<td>2026-09-02</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66652" target=3D= "_blank" rel=3D"noopener">CVE-2026-66652</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 fails to escape database contents when re= ndering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. = Any MOOS publisher can set variable values containing script payloads that = execute in the browser of operators viewing the web interface.</td> <td>2026-09-03</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85453" target=3D= "_blank" rel=3D"noopener">CVE-2026-85453</a></td>
</tr>
<td class=3D"vendor-product">themoos--core-moos</td>
<td>MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability =
in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte pas=
t the serial telegram stack buffer. Attackers controlling the serial line c=
an send a full-length telegram to trigger the off-by-one write, corrupting = the stack and potentially enabling code execution.</td>
<td>2026-09-03</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85454" target=3D= "_blank" rel=3D"noopener">CVE-2026-85454</a></td>
</tr>
<td class=3D"vendor-product">ThimPress--LearnPress</td>
<td>LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site s= cripting vulnerability that allows authenticated attackers with the Instruc= tor role to inject persistent malicious payloads by submitting unsanitized = input into quiz question answer title fields. Attackers can store arbitrary=
JavaScript through the answer title parameter, which is rendered through a=
n unescaped HTML sink to execute in the browsers of any user who views the = affected quiz question, including students, other instructors, and administ= rators.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82024" target=3D= "_blank" rel=3D"noopener">CVE-2026-82024</a></td>
</tr>
<td class=3D"vendor-product">ThimPress--LearnPress</td>
<td>LearnPress WordPress Plugin before 4.4.6 contains a broken object-level=
authorization vulnerability that allows authenticated attackers with the I= nstructor role to add answers to quiz questions owned by other instructors =
by exploiting a missing ownership check on the question answer insert path.=
Attackers can supply arbitrary question identifiers during answer insertio=
n, bypassing instructor-boundary restrictions to persistently modify quiz c= ontent across courses they do not own.</td>
<td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82023" target=3D= "_blank" rel=3D"noopener">CVE-2026-82023</a></td>
</tr>
<td class=3D"vendor-product">thimpress--LearnPress WordPress LMS Plugin for=
Create and Sell Online Courses</td>
<td>The LearnPress plugin for WordPress is vulnerable to SQL Injection via = the 'orderby' parameter of the export_order_csv AJAX action in versions up = to, and including, 4.4.4. This is due to insufficient escaping on the user = supplied parameter and lack of sufficient preparation on the existing SQL q= uery in the LP_Order::handle_params_query_list_orders() and DataBase::execu= te() functions - only the literal values 'date' and 'title' are normalized,=
while any other attacker-controlled string is assigned directly to the fil= ter's order_by property and concatenated into the ORDER BY clause without $= wpdb->prepare() or an identifier whitelist. This makes it possible for a= uthenticated attackers, with administrator-level access and above, to appen=
d additional SQL queries into already existing queries that can be used to = extract sensitive information from the database.</td>
<td>2026-09-01</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77823" target=3D= "_blank" rel=3D"noopener">CVE-2026-77823</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vu= lnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_= decode() on sanitized FAQ content, reversing entity-encoding protection. Au= thenticated users with FAQ editing privileges can inject JavaScript payload=
s that execute in the browsers of all users viewing the affected FAQ pages.= </td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85593" target=3D= "_blank" rel=3D"noopener">CVE-2026-85593</a></td>
</tr>
<td class=3D"vendor-product">Toggl O--Toggl Track Extension</td>
<td>A security vulnerability has been detected in Toggl O=C3=83=C5=93 Toggl=
Track Extension 4.11.16. This affects an unknown function of the component=
postMessage Handler. The manipulation leads to origin validation error. It=
is possible to initiate the attack remotely. The exploit has been disclose=
d publicly and may be used. The vendor was contacted early about this discl= osure but did not respond in any way.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82811" target=3D= "_blank" rel=3D"noopener">CVE-2026-82811</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet through 3.0.0-ee-beta.2 contains authorization bypass vulnerabi= lities in the POST /api/v2/resources/export endpoint that allow authenticat=
ed users to disclose TooljetDB table schemas across workspace boundaries an=
d export app definitions across granular permission boundaries. Attackers c=
an supply a body-provided organization_id parameter to access schemas from = other workspaces, or bypass per-app authorization gates to export restricte=
d app definitions within their workspace.</td>
<td>2026-08-31</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82873" target=3D= "_blank" rel=3D"noopener">CVE-2026-82873</a></td>
</tr>
<td class=3D"vendor-product">ToolJet--ToolJet</td>
<td>ToolJet before v3.16.208 contains an authorization bypass vulnerability=
in TooljetDB controller endpoints that accept organizationId from URL path=
without verifying it matches the authenticated user's workspace. Authentic= ated users can enumerate, create, rename, and delete TooljetDB tables in an=
y other workspace by manipulating the organizationId parameter in requests.= </td>
<td>2026-08-31</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82875" target=3D= "_blank" rel=3D"noopener">CVE-2026-82875</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiScheduleCfg function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter when Wi= -Fi is available via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51703" target=3D= "_blank" rel=3D"noopener">CVE-2026-51703</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setApWiFiSchCfg function of TOTOLINK T6=
4.1.5cu.748_B20211015 allows unauthenticated attackers to alter wireless a= vailability windows via sending a crafted POST request to /cgi-bin/cstecgi.= cgi.</td>
<td>2026-08-31</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51712" target=3D= "_blank" rel=3D"noopener">CVE-2026-51712</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setRoamingCfg function of TOTOLINK T6 4= .1.5cu.748_B20211015 allows unauthenticated attackers to alter roaming beha= vior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51714" target=3D= "_blank" rel=3D"noopener">CVE-2026-51714</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the SystemSettings function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administ= rative import and export endpoint information via sending a crafted POST re= quest to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51727" target=3D= "_blank" rel=3D"noopener">CVE-2026-51727</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi = schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51732" target=3D= "_blank" rel=3D"noopener">CVE-2026-51732</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the clearTracerouteLog function of TOTOLINK=
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase tracero= ute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51737" target=3D= "_blank" rel=3D"noopener">CVE-2026-51737</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the CloudSrvVersionCheck function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger clo=
ud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi= .</td>
<td>2026-08-31</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51739" target=3D= "_blank" rel=3D"noopener">CVE-2026-51739</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the discoverWan function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discover=
y logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51742" target=3D= "_blank" rel=3D"noopener">CVE-2026-51742</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the updatePriStaList function of TOTOLINK T=
6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the pri= mary station list via sending a crafted MQTT message to the cs_broker compo= nent.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51745" target=3D= "_blank" rel=3D"noopener">CVE-2026-51745</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the sendStaticInfoToMaster function of TOTO= LINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update st= ored slave inventory records via sending a crafted MQTT message to the cs_b= roker component.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51748" target=3D= "_blank" rel=3D"noopener">CVE-2026-51748</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the staticInfoSend function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger static in= formation reporting to the configured master via sending a crafted MQTT mes= sage to the cs_broker component.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51752" target=3D= "_blank" rel=3D"noopener">CVE-2026-51752</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the meshSlaveUpgfw function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to start firmware fl= ashing using existing upgrade files via sending a crafted MQTT message to t=
he cs_broker component.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51756" target=3D= "_blank" rel=3D"noopener">CVE-2026-51756</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the updateLanIp function of TOTOLINK T6 4.1= .5cu.748_B20211015 allows unauthenticated attackers to refresh the LAN addr= ess state via sending a crafted MQTT message to the cs_broker component.</t=
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51761" target=3D= "_blank" rel=3D"noopener">CVE-2026-51761</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWizardCfg function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to reconfigure WAN, Wi= -Fi, and device initialization state via sending a crafted POST request to = /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51666" target=3D= "_blank" rel=3D"noopener">CVE-2026-51666</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the getWiFiIpMacTable function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Wi-Fi c= lient MAC-to-IP mappings via sending a crafted POST request to /cgi-bin/cst= ecgi.cgi.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51667" target=3D= "_blank" rel=3D"noopener">CVE-2026-51667</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setSyslogCfg function of TOTOLINK T6 4.= 1.5cu.748_B20211015 allows unauthenticated attackers to alter logging behav= ior via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51678" target=3D= "_blank" rel=3D"noopener">CVE-2026-51678</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setLanCfg function of TOTOLINK T6 4.1.5= cu.748_B20211015 allows unauthenticated attackers to alter LAN network conf= iguration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51683" target=3D= "_blank" rel=3D"noopener">CVE-2026-51683</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setIpPortFilterRules function of TOTOLI=
NK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter firew= all policies via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</t=
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51702" target=3D= "_blank" rel=3D"noopener">CVE-2026-51702</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setWiFiMeshConfig function of TOTOLINK =
T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter mesh con= figurations via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td=
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51704" target=3D= "_blank" rel=3D"noopener">CVE-2026-51704</a></td>
</tr>
<td class=3D"vendor-product">TOTOLINK--TOTOLINK T6</td>
<td>Incorrect access control in the setSmartQosCfg function of TOTOLINK T6 = 4.1.5cu.748_B20211015 allows unauthenticated attackers to degrade traffic h= andling via sending a crafted POST request to /cgi-bin/cstecgi.cgi.</td> <td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-51706" target=3D= "_blank" rel=3D"noopener">CVE-2026-51706</a></td>
</tr>
<td class=3D"vendor-product">Tranquil_IT--WAPT</td>
<td>WAPT Server versions 2.6.1.17834 and earlier contains a SQL injection v= ulnerability in the `columns` parameter of the GET `/api/v3/hosts` endpoint=
. A remote authenticated user with read-only privileges can inject arbitrar=
y PostgreSQL expressions into the SQL query constructed by WAPT. By exploit= ing the injection point, an attacker can inject additional PostgreSQL state= ments, bypass the host scope restrictions applied to the account, and read = information from other rows or tables within the database.</td> <td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75132" target=3D= "_blank" rel=3D"noopener">CVE-2026-75132</a></td>
</tr>
<td class=3D"vendor-product">triggerdotdev--trigger.dev</td>
<td>Trigger.dev before 4.5.2 contains a server-side request forgery vulnera= bility in webhook alert channel delivery URLs that are fetched without vali= dation or SSRF protection. Authenticated users with organization membership=
can create alert channels with URLs targeting internal services and metada=
ta endpoints, allowing the server to issue POST requests to restricted reso= urces.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85650" target=3D= "_blank" rel=3D"noopener">CVE-2026-85650</a></td>
</tr>
<td class=3D"vendor-product">tsi-coop--tsi-dpdp-cms</td>
<td>A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. Th=
is affects an unknown part of the file InterceptingFilter.java of the compo= nent Bootstrap Setup Endpoint. The manipulation leads to missing authentica= tion. The attack can be initiated remotely. The exploit is publicly availab=
le and might be used. Upgrading to version 0.5.1 is able to mitigate this i= ssue. Upgrading the affected component is recommended.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84840" target=3D= "_blank" rel=3D"noopener">CVE-2026-84840</a></td>
</tr>
<td class=3D"vendor-product">tsi-coop--tsi-dpdp-cms</td>
<td>A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Af= fected by this issue is some unknown functionality of the file web.xml of t=
he component Admin Console/DPO Compliance Console. Executing a manipulation=
can lead to missing authentication. It is possible to launch the attack re= motely. The exploit has been publicly disclosed and may be utilized. Upgrad= ing to version 0.5.1 can resolve this issue. It is suggested to upgrade the=
affected component.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84839" target=3D= "_blank" rel=3D"noopener">CVE-2026-84839</a></td>
</tr>
<td class=3D"vendor-product">tursodatabase--turso</td>
<td>Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability =
in the table-leaf page reader that uses an attacker-controlled cell-count f= ield without bounds validation. Attackers can craft a malicious database fi=
le with a modified cell count value to trigger an index-out-of-bounds panic=
when querying, causing denial of service in any application that opens unt= rusted database files.</td>
<td>2026-09-04</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85698" target=3D= "_blank" rel=3D"noopener">CVE-2026-85698</a></td>
</tr>
<td class=3D"vendor-product">Tycon Systems--TPDIN-Monitor-WEB3<br>=C2=A0</t=
<td>Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerabl=
e to a use of hard-coded credential vulnerability. This could allow an atta= cker to intercept sensitive information or credentials.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77847" target=3D= "_blank" rel=3D"noopener">CVE-2026-77847</a></td>
</tr>
<td class=3D"vendor-product">tymotey--Easy Waveform Player</td>
<td>The Easy Waveform Player plugin for WordPress is vulnerable to Stored C= ross-Site Scripting via the shortcode_easywaveformplayer() function in all = versions up to, and including, 1.2.2 due to insufficient input sanitization=
and output escaping. This makes it possible for authenticated attackers, w= ith Contributor-level access and above, to inject arbitrary web scripts in = pages that will execute whenever a user accesses an injected page.</td> <td>2026-09-02</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-7963" target=3D"= _blank" rel=3D"noopener">CVE-2025-7963</a></td>
</tr>
<td class=3D"vendor-product">Typora--Typora</td>
<td>A vulnerability was found in Typora up to 1.13.8/1.14.6. This vulnerabi= lity affects unknown code of the component Mermaid Rendering Engine. The ma= nipulation of the argument classDef/style results in cross site scripting. = The attack may be launched remotely. The exploit has been made public and c= ould be used. Upgrading to version 1.14.8 is able to resolve this issue. Yo=
u should upgrade the affected component. The vendor was contacted early, re= sponded in a very professional manner and quickly released a fixed version =
of the affected product.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82805" target=3D= "_blank" rel=3D"noopener">CVE-2026-82805</a></td>
</tr>
<td class=3D"vendor-product">uhop--stream-json</td>
<td>stream-json is a micro-library of stream components for processing JSON=
and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filter=
s pick, ignore, filter, and replace in src/core/filters/filter-base.js reco= mpute the full path string from the nesting stack for every checkable token=
. Because the stack length equals the current nesting depth and a checkable=
token is emitted at every level, a depth D document costs O(D=C3=82=C2=B2)=
rather than O(D) to process. The issue is triggered by nesting depth rathe=
r than byte volume, including the documented pick({filter: 'data'}) travers= al-until-match path, so an application that sends untrusted JSON through a = string or RegExp filter can block the Node.js event loop and cause denial o=
f service with a small deeply nested document. The streamArray, streamObjec=
t, and streamValues streamers are not affected because they use the constan= t-time asm.depth getter. This issue is fixed in version 3.5.0.</td> <td>2026-09-03</td>
<td>6.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71429" target=3D= "_blank" rel=3D"noopener">CVE-2026-71429</a></td>
</tr>
<td class=3D"vendor-product">UKR Solution--Print Barcode Labels for your Wo= oCommerce products/orders</td>
<td>Subscriber Sensitive Data Exposure in Print Barcode Labels for your Woo= Commerce products/orders <=3D 4.0.0 versions.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81280" target=3D= "_blank" rel=3D"noopener">CVE-2026-81280</a></td>
</tr>
<td class=3D"vendor-product">Ultimate Before After Image Slider & Galle= ry--Ultimate Before After Image Slider & Gallery</td>
<td>The Ultimate Before After Image Slider & Gallery WordPress plugin b= efore 4.7.19 does not properly escape the slider's after-label value before=
its bundled client-side script re-injects it into the DOM, allowing users = with the Author role and above to store a payload that executes in the brow= ser of anyone (including an administrator) who views the slider.</td> <td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15663" target=3D= "_blank" rel=3D"noopener">CVE-2025-15663</a></td>
</tr>
<td class=3D"vendor-product">Ultimate Before After Image Slider & Galle= ry--Ultimate Before After Image Slider & Gallery</td>
<td>The Ultimate Before After Image Slider & Gallery WordPress plugin b= efore 4.7.19 does not properly escape the slider's before-label value befor=
e its bundled client-side script re-injects it into the DOM, allowing users=
with the Author role and above to store a payload that executes in the bro= wser of anyone (including an administrator) who views the slider.</td> <td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15664" target=3D= "_blank" rel=3D"noopener">CVE-2025-15664</a></td>
</tr>
<td class=3D"vendor-product">Ultimate Member--Ultimate Member</td>
<td>The Ultimate Member WordPress plugin before 2.13.0 does not check wheth=
er a comment has been approved, or whether the profile it belongs to is pri= vate, before returning profile activity to unauthenticated visitors, allowi=
ng them to read the content of comments still awaiting moderation.</td> <td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19251" target=3D= "_blank" rel=3D"noopener">CVE-2026-19251</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's cache interceptor does not handle the Set-Cookie response head=
er anywhere in its cache path, so it neither refuses to store nor strips th=
at header. In shared cache mode, which is the default, an otherwise cacheab=
le response that carries a Set-Cookie header, for example one marked with a=
public and max-age directive, is stored and then re-served to a later call=
er that matches the same cache key. As a result one caller's cookie is disc= losed to a different caller, and an untrusted server can inject cookies int=
o cached responses served to all subsequent callers. This violates the requ= irement that a shared cache must not store cookies. This affects undici ver= sions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upg= rade to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84933" target=3D= "_blank" rel=3D"noopener">CVE-2026-84933</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's retry handler can leave an already-exposed response body pendi=
ng forever. When a server returns a successful response that declares a Con= tent-Length, sends only part of the body, and closes the connection, the re= try handler retries the request. If the retry returns a non-retryable statu=
s such as 400, the handler forwards that new response downstream and replac=
es its internal response stream, but the original response body that the ap= plication still holds is never ended or destroyed. As a result calls that r= ead that body never settle, and the configured body timeout does not fire b= ecause its timer is tied to the connection parser rather than the orphaned = body. An attacker-controlled server can trigger this with two short respons=
es without keeping a connection open, and repeated requests accumulate pend= ing promises and streams that can exhaust application concurrency or memory=
. This affects undici versions from 7.11.0 up to 7.29.1 and from 8.0.0 up t=
o 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.</td> <td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18149" target=3D= "_blank" rel=3D"noopener">CVE-2026-18149</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's decompress interceptor decompresses response bodies according =
to the untrusted Content-Encoding header. While the number of content-encod= ing layers is capped, the total decompressed output size is unbounded and t= here is no configuration option to limit it. A malicious or faulty upstream=
can therefore return a small compressed payload, a compression bomb, that = expands to hundreds of megabytes or more in client memory, an asymmetric re= source consumption that can exhaust memory and crash the process. This affe= cts undici versions from 7.15.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. U= sers should upgrade to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84890" target=3D= "_blank" rel=3D"noopener">CVE-2026-84890</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's experimental WebSocketStream client crashes the whole Node.js = process when a remote peer closes the TCP connection without a WebSocket cl= ose handshake. On an unclean close the internal socket-close handler calls = abort on the writable stream unconditionally and discards the returned prom= ise, but per the WHATWG Streams standard aborting a locked writable returns=
a promise that rejects with a TypeError. Because the application holds a w= riter on that writable, which is the only way to write, the rejection is ne= ver observed and Node's default unhandled-rejection behavior terminates the=
process. An untrusted server can therefore crash a client with a single ab= rupt disconnect, with no authentication and no application mistake. This af= fects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. = Users should upgrade to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85014" target=3D= "_blank" rel=3D"noopener">CVE-2026-85014</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici bundles a WebSocket client whose permessage-deflate size-limit c= leanup removes all listeners from the internal zlib inflate stream, includi=
ng its error listener, while that stream can still emit. When a remote peer=
sends a compressed payload that crosses the built-in 128 MiB decompressed-= payload limit and then contains a malformed DEFLATE byte, the inflate strea=
m emits a data error with no listener attached, which Node.js treats as a f= atal unhandled error and terminates the entire process. Exploitation is rem= ote and unauthenticated, requires no application mistake, and is asymmetric=
, since roughly 130 KB on the wire expands past the limit and crashes the p= rocess, and reconnecting can repeat the crash. This affects undici versions=
from 6.25.0 up to 6.28.1, from 7.28.0 up to 7.29.1, and from 8.1.0 up to 8= .10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.</td> <td>2026-09-04</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85024" target=3D= "_blank" rel=3D"noopener">CVE-2026-85024</a></td>
</tr>
<td class=3D"vendor-product">Unlimited Elements--Unlimited Elements For Ele= mentor (Free Widgets, Addons, Templates)</td>
<td>Missing Authorization vulnerability in Unlimited Elements Unlimited Ele= ments For Elementor (Free Widgets, Addons, Templates) allows Exploiting Inc= orrectly Configured Access Control Security Levels. This issue affects Unli= mited Elements For Elementor (Free Widgets, Addons, Templates): from n/a th= rough 2.0.17.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85304" target=3D= "_blank" rel=3D"noopener">CVE-2026-85304</a></td>
</tr>
<td class=3D"vendor-product">usebruno--bruno</td>
<td>Bruno versions through 4.1.0 fail to validate file paths in request bod=
y declarations, allowing attackers to read arbitrary local files by using p= arent-directory traversal segments. When a collection is executed, attacker=
s can craft a request with a body:file path containing ../ sequences that r= esolve outside the collection directory, causing the application to read an=
d exfiltrate arbitrary files to attacker-controlled endpoints.</td> <td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85665" target=3D= "_blank" rel=3D"noopener">CVE-2026-85665</a></td>
</tr>
<td class=3D"vendor-product">User Frontend--User Frontend</td>
<td>The User Frontend WordPress plugin before 4.3.11 does not enforce its s= ubscription-purchase requirement when processing frontend post submissions,=
only when rendering the form, allowing unauthenticated users to create and=
, depending on the form's configuration, immediately publish posts through = forms restricted to paying subscribers.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-17563" target=3D= "_blank" rel=3D"noopener">CVE-2026-17563</a></td>
</tr>
<td class=3D"vendor-product">valkey-io--valkey</td>
<td>A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Aff= ected by this vulnerability is the function createSlotImportJob of the file=
src/cluster_migrateslots.c of the component Slot Migration. The manipulati=
on of the argument job_name results in out-of-bounds read. The attack can b=
e executed remotely. The exploit is now public and may be used. Upgrading t=
o version 9.0.5 and 9.1.1 addresses this issue. The patch is identified as = f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected component =
is advised.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85522" target=3D= "_blank" rel=3D"noopener">CVE-2026-85522</a></td>
</tr>
<td class=3D"vendor-product">VeronaLabs--WP Statistics</td>
<td>Unauthenticated Cross Site Scripting (XSS) in WP Statistics <=3D 14.= 16.11 versions.</td>
<td>2026-09-03</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84774" target=3D= "_blank" rel=3D"noopener">CVE-2026-84774</a></td>
</tr>
<td class=3D"vendor-product">vidIQ--Vision for YouTube Extension</td>
<td>A security flaw has been discovered in vidIQ Vision for YouTube Extensi=
on 3.199.0 on Chrome. The affected element is the function window.addEventL= istener of the component postMessage Handler. Performing a manipulation of = the argument vidiqEvent results in information disclosure. The attack is po= ssible to be carried out remotely. The exploit has been released to the pub= lic and may be used for attacks. The vendor explains: "At this time, vidIQ = does not accept security vulnerability submissions, and we do not have a bu=
g bounty program in place."</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82809" target=3D= "_blank" rel=3D"noopener">CVE-2026-82809</a></td>
</tr>
<td class=3D"vendor-product">VillaTheme--Product Variations Swatches for Wo= oCommerce</td>
<td>Subscriber Cross Site Scripting (XSS) in Product Variations Swatches fo=
r WooCommerce <=3D 1.1.18 versions.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81282" target=3D= "_blank" rel=3D"noopener">CVE-2026-81282</a></td>
</tr>
<td class=3D"vendor-product">vitest-dev--vitest</td>
<td>Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 = and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin ex= ports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:= interceptor:register handler on Vite's unauthenticated HMR WebSocket withou=
t validating redirect targets against the file-serving allowlist. The imple= mentation processes event.redirect without enforcing server.fs.allow and se= rver.fs.deny through isFileLoadingAllowed. A remote client that can reach a=
n exposed development server can submit an opaque URL scheme preserving .. = segments, causing join(server.config.root, redirectUrl.pathname) to resolve=
outside the project root. The plugin's load hook then returns readFile(moc= k.redirect, 'utf-8') as module source, disclosing local files readable by t=
he dev-server process. Vitest browser mode uses a token-authenticated RPC a=
nd is not remotely unauthenticated by default, although the same boundary c= heck was missing on that path. This issue is fixed in versions 4.1.11 and 5= .0.0-rc.2.</td>
<td>2026-09-01</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84373" target=3D= "_blank" rel=3D"noopener">CVE-2026-84373</a></td>
</tr>
<td class=3D"vendor-product">wakujs--waku</td>
<td>Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Wak= u's RSC request dispatcher invokes server actions without validating the re= quest's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can = therefore cause a victim browser to issue an authenticated POST to a regist= ered server action endpoint using a CORS-safelisted content type (text/plai= n), which does not trigger a preflight. Any state-mutating server action th=
at the application exposes via 'use server' can be invoked with the victim'=
s cookies attached. This issue has been patched in version 1.0.0-beta.1.</t=
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49455" target=3D= "_blank" rel=3D"noopener">CVE-2026-49455</a></td>
</tr>
<td class=3D"vendor-product">WC Lovers--WCFM Marketplace</td>
<td>Contributor Cross Site Scripting (XSS) in WCFM Marketplace <=3D 3.8.=
2 versions.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83562" target=3D= "_blank" rel=3D"noopener">CVE-2026-83562</a></td>
</tr>
<td class=3D"vendor-product">WC Lovers--WCFM Membership</td>
<td>Missing Authorization vulnerability in WC Lovers WCFM Membership allows=
Exploiting Incorrectly Configured Access Control Security Levels. This iss=
ue affects WCFM Membership: from n/a through 2.11.11.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-32480" target=3D= "_blank" rel=3D"noopener">CVE-2026-32480</a></td>
</tr>
<td class=3D"vendor-product">WC Vendors--WC Vendors</td>
<td>The WC Vendors WordPress plugin before 2.7.2.1 does not verify ownershi=
p or the object type of user-supplied IDs when saving product variations, a= llowing authenticated users with the vendor role to modify product variatio=
ns belonging to other vendors, and to change the status and title of arbitr= ary posts, via IDOR.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81428" target=3D= "_blank" rel=3D"noopener">CVE-2026-81428</a></td>
</tr>
<td class=3D"vendor-product">WC Vendors--WC Vendors</td>
<td>The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF prote= ction on some of its front-end order shipment status actions, which could a= llow attackers to make a logged-in vendor change the shipment status of the=
ir own orders via a crafted request.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81426" target=3D= "_blank" rel=3D"noopener">CVE-2026-81426</a></td>
</tr>
<td class=3D"vendor-product">WC Vendors--WC Vendors</td>
<td>The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the=
vendor submitting a front-end order shipment status change owns the refere= nced order, allowing any authenticated vendor to mark another vendor's orde=
r as shipped, add an order note falsely attributed to the victim vendor, an=
d trigger the customer shipment notification email.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81427" target=3D= "_blank" rel=3D"noopener">CVE-2026-81427</a></td>
</tr>
<td class=3D"vendor-product">wger --wger<br>=C2=A0</td>
<td>wger versions through master contain an incomplete authorization bypass=
in wger/core/views/user.py where three views retain the original gym-scope=
check using raw integer comparison instead of the is_same_gym() helper, al= lowing gym staff with gym=3DNone to delete, deactivate, or activate any oth=
er user with gym=3DNone. Attackers with gym.manage_gym permission and gym= =3DNone affiliation can permanently delete user accounts, lock users out vi=
a deactivation, or undo defensive deactivations by exploiting the None !=3D=
None comparison edge case.</td>
<td>2026-09-06</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86254" target=3D= "_blank" rel=3D"noopener">CVE-2026-86254</a></td>
</tr>
<td class=3D"vendor-product">wger --wger<br>=C2=A0</td>
<td>wger before 2.5 fails to validate the maximum duration of routine date = ranges, allowing authenticated users to create routines spanning arbitraril=
y long periods. Attackers can trigger the date_sequence computation via rou= tine detail endpoints, forcing the server to iterate thousands of times per=
request and exhaust worker threads, denying service to legitimate users.</=
<td>2026-09-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86255" target=3D= "_blank" rel=3D"noopener">CVE-2026-86255</a></td>
</tr>
<td class=3D"vendor-product">wger--wger=C2=A0<br>=C2=A0</td>
<td>wger before 2.6 (affected versions <=3D 2.5.0) contains an open redi= rect vulnerability in the trainer_login view (wger/core/views/user.py). Aft=
er a trainer enters impersonation mode, the view redirects to the user-supp= lied 'next' GET parameter via HttpResponseRedirect() without validating it = with url_has_allowed_host_and_scheme(). An attacker who delivers a crafted = link to an authenticated trainer can redirect the trainer's browser to an a= ttacker-controlled domain, enabling phishing and leaking the wger URL struc= ture (including the impersonated user's user_pk) via the Referer header.</t=
<td>2026-09-06</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86256" target=3D= "_blank" rel=3D"noopener">CVE-2026-86256</a></td>
</tr>
<td class=3D"vendor-product">wger--wger=C2=A0<br>=C2=A0</td>
<td>wger before 2.6 fails to sanitize first_name and last_name fields in th=
e gym member TSV export endpoint, allowing any gym member to inject spreads= heet formulas. Attackers can inject formulas like =3DHYPERLINK to exfiltrat=
e admin data or execute code when admins open the exported file in Excel or=
LibreOffice Calc.</td>
<td>2026-09-06</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86257" target=3D= "_blank" rel=3D"noopener">CVE-2026-86257</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Accept Stripe Payments<br>= =C2=A0</td>
<td>The Accept Stripe Payments WordPress plugin before 2.1.4 does not verif=
y that the product fulfilled when a checkout is completed matches the produ=
ct the authoritative payment was actually made for, checking only that the = amount paid is at least the referenced product's price, allowing unauthenti= cated attackers who complete a genuine payment to obtain fulfilment for a d= ifferent, equal- or lower-priced product than the one they paid for.</td> <td>2026-09-05</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81424" target=3D= "_blank" rel=3D"noopener">CVE-2026-81424</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Dear Flipbook - PDF Flipboo=
k, 3D Flipbook, PDF embed, PDF viewer<br>=C2=A0</td>
<td>The Dear Flipbook - PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer pl= ugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'po= st_content (class attribute of .dvcss element)' parameter in all versions u=
p to, and including, 2.4.30 due to insufficient input sanitization and outp=
ut escaping. This makes it possible for authenticated attackers, with contr= ibutor-level access and above, to inject arbitrary web scripts in pages tha=
t will execute whenever a user accesses an injected page. The payload is em= bedded as a Base64-encoded JSON object in a CSS class name on a Custom HTML=
block; the frontend parseCSSElements() function decodes it client-side wit=
h atob() and JSON.parse() and renders the logo property as raw HTML, meanin=
g no server-side or client-side sanitization intercepts the malicious scrip=
t before DOM insertion.</td>
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8623" target=3D"= _blank" rel=3D"noopener">CVE-2026-8623</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Dear Flipbook - PDF Flipboo=
k, 3D Flipbook, PDF embed, PDF viewer<br>=C2=A0</td>
<td>The Dear Flipbook - PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer pl= ugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'po= st_content (Custom HTML block inner HTML)' parameter in all versions up to,=
and including, 2.4.30 due to insufficient input sanitization and output es= caping. This makes it possible for authenticated attackers, with contributo= r-level access and above, to inject arbitrary web scripts in pages that wil=
l execute whenever a user accesses an injected page. A Contributor-level at= tacker can insert a crafted .df-element div with data-df-lightbox=3D'thumb'=
via a Custom HTML block, whose inner HTML is passed as the title argument =
to parseThumbs() at render time, enabling both innerHTML injection into a s= pan element and attribute breakout via an onerror handler on a constructed = img element.</td>
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-8625" target=3D"= _blank" rel=3D"noopener">CVE-2026-8625</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Greenshift<br>=C2=A0</td> <td>The Greenshift WordPress plugin before 13.2.0 does not properly escape =
a block animation attribute before outputting it within an HTML attribute, = allowing users with contributor-level access and above to inject arbitrary = web scripts that execute when the content is viewed.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83544" target=3D= "_blank" rel=3D"noopener">CVE-2026-83544</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --JetFormBuilder - Dynamic Bl= ocks Form Builder<br>=C2=A0</td>
<td>The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or=
strip line breaks from address values it sources from submitted form field=
s before adding them to the headers of the e-mails it sends, allowing unaut= henticated users to inject arbitrary e-mail headers, add hidden recipients = and spoof the sender. Exploitation requires the site to be configured to ta=
ke one of the message's addresses from a form field.</td>
<td>2026-09-06</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19862" target=3D= "_blank" rel=3D"noopener">CVE-2026-19862</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --JetFormBuilder - Dynamic Bl= ocks Form Builder=C2=A0<br>=C2=A0</td>
<td>The JetFormBuilder - Dynamic Blocks Form Builder WordPress plugin befor=
e 3.6.5.2 does not properly sanitise and escape a form field's value before=
including it in the HTML notification emails it sends, allowing unauthenti= cated users to inject arbitrary HTML into messages delivered to administrat= ors and other recipients. Whether injected script executes depends on the r= ecipient's mail client, but the injected markup is rendered regardless.</td=
<td>2026-09-05</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19861" target=3D= "_blank" rel=3D"noopener">CVE-2026-19861</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Smart Post<br>=C2=A0</td> <td>The Smart Post WordPress plugin before 4.0.8 does not check whether a p= ost is password protected before returning its content and its stored passw= ord through an unauthenticated AJAX action, allowing unauthenticated users =
to read protected post content and the password that guards it.</td> <td>2026-09-05</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78149" target=3D= "_blank" rel=3D"noopener">CVE-2026-78149</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin-- Custom Contact Forms<br>=C2= =A0</td>
<td>The Custom Contact Forms plugin for WordPress is vulnerable to authoriz= ation bypass in all versions up to, and including, 7.16. This is due to the=
plugin not properly verifying that a user is authorized to perform an acti= on. This makes it possible for authenticated attackers, with contributor-le= vel access and above, to permanently force-delete arbitrary posts of any po=
st type (including pages, administrator-authored posts, and WooCommerce pro= ducts) and write arbitrary ccf_field_* post meta onto any post regardless o=
f ownership or post type. The top-level form ID is checked via edit_post/pu= blish_posts, but the nested fields[].ID and choices[].ID paths processed by=
_create_and_map_fields() and _create_and_map_choices() carry no equivalent=
capability or post-type guard, leaving those sinks fully exposed while del= ete_item() and delete_submission() contain explicit post-type restriction f= ixes demonstrating the developer's awareness of scoping requirements.</td> <td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75018" target=3D= "_blank" rel=3D"noopener">CVE-2026-75018</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin-- Eventin<br>=C2=A0</td>
<td>The Eventin WordPress plugin before 4.1.21 does not properly validate a=
template path value before using it to include a local file, allowing user=
s with contributor-level access and above to include and execute arbitrary = local PHP files.</td>
<td>2026-09-05</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84898" target=3D= "_blank" rel=3D"noopener">CVE-2026-84898</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin-- Video Player for YouTube=C2= =A0<br>=C2=A0</td>
<td>The Video Player for YouTube WordPress plugin before 2.1.0 does not pro= perly sanitise and escape user-supplied input before using it in a SQL stat= ement, allowing users with the Contributor role and above to perform SQL in= jection attacks and read arbitrary data from the database.</td> <td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84937" target=3D= "_blank" rel=3D"noopener">CVE-2026-84937</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Accept Stripe Payments<br>= =C2=A0</td>
<td>The Accept Stripe Payments WordPress plugin before 2.1.4 does not valid= ate a user-supplied URL before using it in a redirect, allowing unauthentic= ated attackers to redirect visitors to an arbitrary external website, which=
can be leveraged for phishing.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81423" target=3D= "_blank" rel=3D"noopener">CVE-2026-81423</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--B2BKing - Ultimate WooCommer=
ce B2B and Wholesale<br>=C2=A0</td>
<td>The B2BKing - Ultimate WooCommerce B2B and Wholesale Plugin - Wholesale=
Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not=
verify that a role selected during registration is one actually offered on=
the registration form, allowing unauthenticated users to assign themselves=
to restricted B2B customer groups and to skip the manual account-approval = workflow during self-registration.</td>
<td>2026-09-06</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85038" target=3D= "_blank" rel=3D"noopener">CVE-2026-85038</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Beaver Builder<br>=C2=A0</td=
<td>The Beaver Builder Plugin (Starter Version) plugin for WordPress is vul= nerable to Reflected Cross-Site Scripting via 'no_results_message' node_pre= view Parameter in all versions up to, and including, 2.11.0.1 due to insuff= icient input sanitization and output escaping. This makes it possible for u= nauthenticated attackers to inject arbitrary web scripts in pages that exec= ute if they can successfully trick a user into performing an action such as=
clicking on a link.</td>
<td>2026-09-05</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18843" target=3D= "_blank" rel=3D"noopener">CVE-2026-18843</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Bold Page Builder<br>=C2=A0<=
<td>The Bold Page Builder WordPress plugin before 5.9.8 does not properly v= alidate a link URL before outputting it in an HTML attribute, relying on a = filter that can be evaded, allowing users with the Contributor role and abo=
ve to inject arbitrary web scripts that execute when a user clicks the affe= cted link.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84021" target=3D= "_blank" rel=3D"noopener">CVE-2026-84021</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Bold Page Builder<br>=C2=A0<=
<td>The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise a=
nd escape several shortcode attributes before outputting them in HTML attri= butes, allowing users with the Contributor role and above to inject arbitra=
ry web scripts that execute when a user views the affected page.</td> <td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84022" target=3D= "_blank" rel=3D"noopener">CVE-2026-84022</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Bold Page Builder<br>=C2=A0<=
<td>The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise a=
nd escape a shortcode attribute before outputting it in an HTML attribute, = allowing users with the Contributor role and above to inject arbitrary web = scripts that execute when a user views the affected page.</td> <td>2026-09-06</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84028" target=3D= "_blank" rel=3D"noopener">CVE-2026-84028</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--CatFolders Document Gallery = & PDF Library=C2=A0<br>=C2=A0</td>
<td>The CatFolders Document Gallery & PDF Library WordPress plugin befo=
re 2.0.7 does not properly validate a block attribute before using it as an=
HTML tag name in its gallery output, allowing users with the Author role a=
nd above to inject arbitrary web scripts that execute in the browser of any= one who views the affected post.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84930" target=3D= "_blank" rel=3D"noopener">CVE-2026-84930</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Divi theme<br>=C2=A0</td>
<td>The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Si=
te Scripting via the `image_src` attribute of the `et_pb_video_slider_item`=
shortcode in all versions up to, and including, 4.27.6. This is due to the=
`image_src` field not being included in the `$url_options` whitelist (whic=
h only contains `url`, `button_link`, `button_url`), so it never receives `= esc_url_raw()` at save time. On the server side, the value is rendered into=
a `data-image` HTML attribute using `esc_attr()`, which encodes double quo= tes as `&quot;`. However, the client-side JavaScript carousel code in `= custom.unified.js` reads this attribute using jQuery's `.data('image')`, wh= ich returns the browser-decoded value (with `&quot;` decoded back to `"= `). The decoded value is then concatenated directly into an HTML string and=
injected into the DOM via `jQuery.after()` without re-escaping. This makes=
it possible for authenticated attackers, with Contributor-level access and=
above, to inject arbitrary web scripts in pages that will execute whenever=
a user hovers over the carousel thumbnail.</td>
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3853" target=3D"= _blank" rel=3D"noopener">CVE-2026-3853</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Divi theme=C2=A0<br>=C2=A0</=
<td>The Divi theme for WordPress is vulnerable to Server-Side Request Forge=
ry in all versions up to, and including, 4.27.6. This is due to the `et_pb_= set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` i= nstead of `wp_safe_remote_get()` to fetch a remote image URL, which does no=
t restrict requests to private or reserved IP ranges. This makes it possibl=
e for authenticated attackers, with Contributor-level access and above, to = make web requests to arbitrary locations originating from the web applicati=
on server. The response body is not returned to the attacker (blind SSRF), = but two oracles exist: a status oracle (the returned URL string differs dep= ending on whether the target responded with HTTP 200) and a timing oracle (= response time varies by target reachability).</td>
<td>2026-09-05</td>
<td>5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4361" target=3D"= _blank" rel=3D"noopener">CVE-2026-4361</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--EmbedPress<br>=C2=A0</td>
<td>The EmbedPress WordPress plugin before 4.6.4 does not have proper autho= rization on a public review-loading action, allowing unauthenticated users =
to force the site to make repeated billable third-party API requests using = the site's own configured API key, and to create an unbounded number of att= acker-controlled rows in the database.</td>
<td>2026-09-05</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84936" target=3D= "_blank" rel=3D"noopener">CVE-2026-84936</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Eventin<br>=C2=A0</td>
<td>The Eventin WordPress plugin before 4.1.22 does not properly check auth= orization on several of its event-management REST routes, allowing users wi=
th contributor-level access and above to change the site's front-page setti=
ng to an event they do not own and to create, edit and delete global event = and speaker taxonomy terms they should not be able to manage.</td> <td>2026-09-05</td>
<td>4.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84901" target=3D= "_blank" rel=3D"noopener">CVE-2026-84901</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Events Manager - Calendar, B= ookings, Tickets, and more<br>=C2=A0</td>
<td>The Events Manager - Calendar, Bookings, Tickets, and more! plugin for = WordPress is vulnerable to Stored Cross-Site Scripting via event attribute = values in all versions up to, and including, 7.3.3. This is due to insuffic= ient input sanitization when storing attribute values (using only `wp_unsla= sh()` without sanitization) and lack of output escaping when rendering the = '#_ATT{key}' placeholder. This makes it possible for authenticated attacker=
s, with Author-level access and above, or unauthenticated attackers when an= onymous event submissions are enabled, to inject arbitrary web scripts that=
execute when any user views the affected event page.</td>
<td>2026-09-05</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-14945" target=3D= "_blank" rel=3D"noopener">CVE-2025-14945</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Gallery : FooGallery=C2=A0<b= r>=C2=A0</td>
<td>The Gallery : FooGallery plugin for WordPress is vulnerable to Stored C= ross-Site Scripting via 'custom_settings' Shortcode Attribute in all versio=
ns up to, and including, 3.3.2 due to insufficient input sanitization and o= utput escaping. This makes it possible for authenticated attackers, with co= ntributor-level access and above, to inject arbitrary web scripts in pages = that will execute whenever a user accesses an injected page.</td> <td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85414" target=3D= "_blank" rel=3D"noopener">CVE-2026-85414</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Greenshift=C2=A0<br>=C2=A0</=
<td>The Greenshift WordPress plugin before 13.2.0 does not validate a user-= supplied URL before fetching it server-side, allowing users with contributo= r-level access and above to make the server issue requests to arbitrary hos=
ts and read the response.</td>
<td>2026-09-05</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83543" target=3D= "_blank" rel=3D"noopener">CVE-2026-83543</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--JetFormBuilder=C2=A0<br>=C2= =A0</td>
<td>The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a = request parameter before rendering it as message content, allowing unauthen= ticated users to execute arbitrary shortcodes registered on the site on any=
page displaying a form. Escaping is applied to that content before a later=
shortcode-expansion pass rather than after it, so the escaping can be bypa= ssed.</td>
<td>2026-09-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19859" target=3D= "_blank" rel=3D"noopener">CVE-2026-19859</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Joli Table Of Contents=C2=A0= <br>=C2=A0</td>
<td>The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanit= ise or escape a shortcode attribute value before outputting it inside an HT=
ML element's attribute, allowing users with the Author role and above to in= ject arbitrary HTML attributes and JavaScript that execute in the browser o=
f any user who views the post, including higher-privileged users such as ad= ministrators. This crosses a privilege boundary even on multisite, where su=
ch users are not permitted to post unfiltered HTML.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84931" target=3D= "_blank" rel=3D"noopener">CVE-2026-84931</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--King Addons for Elementor=C2= =A0<br>=C2=A0</td>
<td>The King Addons for Elementor WordPress plugin before 51.1.77 does not = escape a widget display-style setting before outputting it in an HTML attri= bute, allowing users with Contributor-level access and above to store JavaS= cript that executes in the browser of any visitor to the affected page, inc= luding logged-in administrators.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84896" target=3D= "_blank" rel=3D"noopener">CVE-2026-84896</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Kirki<br>=C2=A0</td>
<td>The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied=
identifier before using it in a SQL query, allowing users with editor-leve=
l access and above to append arbitrary SQL and read the contents of the dat= abase, including user credentials.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84221" target=3D= "_blank" rel=3D"noopener">CVE-2026-84221</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--LearnDash LMS=C2=A0<br>=C2= =A0</td>
<td>The LearnDash LMS plugin for WordPress is vulnerable to authorization b= ypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly ve= rifying that a user is authorized to perform an action. This makes it possi= ble for unauthenticated attackers to enroll arbitrary users in paid courses=
without payment verification, bypassing the entire payment system and gain= ing unauthorized access to premium educational content.</td>
<td>2026-09-05</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12843" target=3D= "_blank" rel=3D"noopener">CVE-2026-12843</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Masteriyo LMS<br>=C2=A0</td> <td>The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and e= scape some course settings before outputting them in a page available to al=
l visitors, allowing users with a course-author role to perform Stored Cros= s-Site Scripting attacks that run in the session of anyone viewing the cour= se, including a logged-in administrator.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82846" target=3D= "_blank" rel=3D"noopener">CVE-2026-82846</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Ninja Forms - Save Progress= =C2=A0<br>=C2=A0</td>
<td>The Ninja Forms - Save Progress plugin for WordPress is vulnerable to M= issing Authorization in versions up to, and including, 3.0.30. This is due =
to the lack of capability checks and nonce verification in the 'bulk_action=
s' function. This makes it possible for authenticated attackers, with subsc= riber-level access and above, to delete arbitrary database records from the=
'wp_nf3_objects' table, such as saved submissions.</td>
<td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15550" target=3D= "_blank" rel=3D"noopener">CVE-2026-15550</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Ninja Forms=C2=A0<br>=C2=A0<=
<td>The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not pr= event shortcodes in request-derived values from being executed when it subs= titutes them into content it later processes for shortcodes, allowing unaut= henticated users to run any shortcode registered on the site.</td>
<td>2026-09-06</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80437" target=3D= "_blank" rel=3D"noopener">CVE-2026-80437</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Pods - Custom Content Types = and Fields<br>=C2=A0</td>
<td>The Pods - Custom Content Types and Fields plugin for WordPress is vuln= erable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute i=
n all versions up to, and including, 3.3.9.1 due to insufficient input sani= tization and output escaping. This makes it possible for authenticated atta= ckers, with contributor-level access and above, to inject arbitrary web scr= ipts in pages that will execute whenever a user accesses an injected page.<=
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76573" target=3D= "_blank" rel=3D"noopener">CVE-2026-76573</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Real Estate Papi=C2=A0<br>= =C2=A0</td>
<td>The Real Estate Papi WordPress theme through 1.0.5 does not perform cap= ability or CSRF checks on one of its AJAX actions, allowing any authenticat=
ed user, such as a subscriber, to install a fixed set of companion from the=
WordPress.org repository. Where the request runs in the session of a user = who can activate , those are activated as well.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13159" target=3D= "_blank" rel=3D"noopener">CVE-2026-13159</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Redirection for Contact Form=
7<br>=C2=A0</td>
<td>The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3= .2.11 does not prevent shortcodes in submitted form values from being execu= ted when it substitutes those values into an action's settings and then pro= cesses those settings for shortcodes, allowing unauthenticated users to run=
any shortcode registered on the site and read its output.</td>
<td>2026-09-06</td>
<td>4.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80439" target=3D= "_blank" rel=3D"noopener">CVE-2026-80439</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Search Atlas SEO=C2=A0<br>= =C2=A0</td>
<td>The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a = nonce or capability check before processing a settings update in one of its=
early-priority handlers, allowing any authenticated user such as a Subscri= ber to overwrite or delete the site's stored Google service-account credent= ials.</td>
<td>2026-09-05</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15247" target=3D= "_blank" rel=3D"noopener">CVE-2026-15247</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Social Chat - Click To Chat = App Button<br>=C2=A0</td>
<td>The Social Chat - Click To Chat App Button plugin for WordPress is vuln= erable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute =
in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insu= fficient input sanitization and output escaping. This makes it possible for=
authenticated attackers, with contributor-level access and above, to injec=
t arbitrary web scripts in pages that will execute whenever a user accesses=
an injected page. The exploit requires no user interaction beyond page loa=
d, as setting auto_open and consent_enabled to 'yes' in the injected data-b=
ox JSON causes the consent box - and the embedded script - to execute immed= iately on page load.</td>
<td>2026-09-05</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18404" target=3D= "_blank" rel=3D"noopener">CVE-2026-18404</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--SureCart<br>=C2=A0</td>
<td>The SureCart WordPress plugin before 4.7.0 does not consult the site's = user registration setting before creating WordPress accounts, allowing unau= thenticated users to create an account and receive a logged-in session even=
when registration is disabled.</td>
<td>2026-09-06</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75793" target=3D= "_blank" rel=3D"noopener">CVE-2026-75793</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Theme My Login=C2=A0<br>=C2= =A0</td>
<td>The Theme My Login plugin for WordPress is vulnerable to Missing Author= ization in versions up to, and including, 7.1.15 on Multisite installations=
. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog=
` branch failing to enforce the network's `active_signup` registration poli= cy, checking only `is_user_logged_in()` while sibling branches such as `val= idate-blog-signup` apply the full policy gate. This makes it possible for a= uthenticated attackers, with Subscriber-level access and above, to directly=
POST `stage=3Dgimmeanotherblog` to Theme My Login's signup route, bypassin=
g the configured registration policy entirely - even when it is set to `non=
e` or `user` - which causes `wpmu_create_blog()` to execute with the attack= er's user ID, after which WordPress core assigns the Administrator role on = the newly created subsite via `add_user_to_blog()`. The privilege gain is s= coped to the newly created subsite only; the attacker's account retains Sub= scriber-level access on the main site and does not obtain Super Admin or ne= twork-level capabilities such as `manage_network` or `manage_sites`.</td> <td>2026-09-05</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83628" target=3D= "_blank" rel=3D"noopener">CVE-2026-83628</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Unlimited Elements For Eleme= ntor<br>=C2=A0</td>
<td>The Unlimited Elements For Elementor plugin for WordPress is vulnerable=
to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all vers= ions up to, and including, 2.0.17 due to insufficient input sanitization an=
d output escaping. This makes it possible for unauthenticated attackers to = inject arbitrary web scripts in pages that execute if they can successfully=
trick a user into performing an action such as clicking on a link. The fro= nt-end AJAX handler is registered on the public 'wp' action with no nonce, = capability, or referer check, and the raw attacker-controlled id value is i= nterpolated verbatim into an exception message that is echoed back without = escaping; when the response is served as text/html rather than application/= json, the browser parses the injected markup.</td>
<td>2026-09-05</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75586" target=3D= "_blank" rel=3D"noopener">CVE-2026-75586</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--VikWidgetsLoader<br>=C2=A0</=
<td>The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise o=
r escape a block attribute before outputting it inside an inline script, al= lowing users with the Contributor role to store arbitrary JavaScript that e= xecutes in the browser of any user viewing the affected post, including the=
administrator who reviews the pending submission.</td>
<td>2026-09-05</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84899" target=3D= "_blank" rel=3D"noopener">CVE-2026-84899</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--WP File Download<br>=C2=A0</=
<td>The WP File Download plugin for WordPress is vulnerable to Directory Tr= aversal in all versions up to, and including, 6.3.8 via the 'remoteurl' par= ameter. This makes it possible for authenticated attackers, with subscriber= -level access and above, to read the contents of arbitrary files on the ser= ver, which can contain sensitive information. An authenticated attacker wit=
h Subscriber-level access first poisons the _wpfd_file_metadata['file'] pos= t-meta value via the unprotected file.save handler, after which the streami=
ng endpoint - hooked on init with no authentication requirement - resolves = and streams the traversed file path to any caller, including unauthenticate=
d visitors.</td>
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14975" target=3D= "_blank" rel=3D"noopener">CVE-2026-14975</a></td>
</tr>
<td class=3D"vendor-product">Worklenz--worklenz</td>
<td>Worklenz before 3.0.0 fails to verify task ownership by organization wh=
en resolving task-scoped API endpoints, allowing authenticated users to acc= ess another tenant's task data. Attackers can query task endpoints with arb= itrary task UUIDs to retrieve work logs, comments, attachments, and project=
insights belonging to other organizations.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85389" target=3D= "_blank" rel=3D"noopener">CVE-2026-85389</a></td>
</tr>
<td class=3D"vendor-product">WP Chill--Gallery PhotoBlocks</td>
<td>Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <=3D 1= .3.4 versions.</td>
<td>2026-09-02</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84781" target=3D= "_blank" rel=3D"noopener">CVE-2026-84781</a></td>
</tr>
<td class=3D"vendor-product">Wp Edit Password Protected--Wp Edit Password P= rotected</td>
<td>The Wp Edit Password Protected WordPress plugin before 1.3.5 allows pro= tecting page content, but this protection can be bypassed by using the REST=
API.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-8945" target=3D"= _blank" rel=3D"noopener">CVE-2025-8945</a></td>
</tr>
<td class=3D"vendor-product">WP Express Checkout--WP Express Checkout</td> <td>The WP Express Checkout WordPress plugin before 2.4.9 does not verify s= erver-side that a payment was actually completed before marking an order as=
paid, allowing unauthenticated users to forge a completed order without pa= ying.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83533" target=3D= "_blank" rel=3D"noopener">CVE-2026-83533</a></td>
</tr>
<td class=3D"vendor-product">WP Fastest Cache--WP Fastest Cache</td>
<td>The WP Fastest Cache WordPress plugin before 1.5.1 does not include a s=
et of tracking-related query parameters in its page-cache key while still c= aching pages requested with them, allowing unauthenticated attackers to hav=
e a page rendered under their own request context stored under, and served = from, the clean URL's cache entry to every subsequent visitor.</td> <td>2026-09-01</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74916" target=3D= "_blank" rel=3D"noopener">CVE-2026-74916</a></td>
</tr>
<td class=3D"vendor-product">WP Manage Ninja--FluentBooking Pro</td> <td>Unauthenticated Bypass Vulnerability in FluentBooking Pro <=3D 2.2.1=
versions.</td>
<td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84766" target=3D= "_blank" rel=3D"noopener">CVE-2026-84766</a></td>
</tr>
<td class=3D"vendor-product">WP Swings--Ultimate Gift Cards For WooCommerce= </td>
<td>Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCom= merce <=3D 3.2.9 versions.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84760" target=3D= "_blank" rel=3D"noopener">CVE-2026-84760</a></td>
</tr>
<td class=3D"vendor-product">wpbakery--WPBakery Page Builder</td>
<td>The WPBakery Page Builder plugin for WordPress is vulnerable to Stored = Cross-Site Scripting via the 'data' parameter in all versions up to, and in= cluding, 8.7.4 due to insufficient input sanitization and output escaping. = This makes it possible for authenticated attackers, with subscriber-level a= ccess and above, to inject arbitrary web scripts in pages that will execute=
whenever a user accesses an injected page. The wp_kses_post sanitization a= pplied during save does not neutralize the payload because the malicious sc= ript content is base64-encoded as plain alphanumeric text with no HTML tags=
to strip; the vc_raw_html shortcode template then decodes and echoes this = content unescaped at render time.</td>
<td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15101" target=3D= "_blank" rel=3D"noopener">CVE-2026-15101</a></td>
</tr>
<td class=3D"vendor-product">wpdevteam--BetterDocs AI Documentation, Knowle= dge Base, MCP Server, Docs, Wikis, FAQ & Chatbot</td>
<td>The BetterDocs - AI Documentation, Knowledge Base, Docs, Wikis, FAQ wit=
h Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting=
via Heading 'id' Attribute in Post Content in all versions up to, and incl= uding, 4.8.1 due to insufficient input sanitization and output escaping. Th=
is makes it possible for authenticated attackers, with contributor-level ac= cess and above, to inject arbitrary web scripts in pages that will execute = whenever a user accesses an injected page. The exploit survives wp_kses_pos=
t because entity-encoded quotes in a heading id attribute are treated as a = single legitimate attribute value at save time; the dangerous payload only = materialises after process_content_for_toc() calls html_entity_decode() on = the stored content and the broken id is extracted by a lazy regex before be= ing echoed unescaped into the Table of Contents output.</td> <td>2026-09-01</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75980" target=3D= "_blank" rel=3D"noopener">CVE-2026-75980</a></td>
</tr>
<td class=3D"vendor-product">WPExperts--Post SMTP</td>
<td>Missing Authorization vulnerability in WPExperts Post SMTP allows Explo= iting Incorrectly Configured Access Control Security Levels. This issue aff= ects Post SMTP: from 4.0.0 through beta.1.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81278" target=3D= "_blank" rel=3D"noopener">CVE-2026-81278</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--Mail Mint</td>
<td>Unauthenticated Broken Access Control in Mail Mint <=3D 1.31.0 versi= ons.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84755" target=3D= "_blank" rel=3D"noopener">CVE-2026-84755</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels</td>
<td>Unauthenticated Broken Access Control in WPFunnels <=3D 3.12.13 vers= ions.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84754" target=3D= "_blank" rel=3D"noopener">CVE-2026-84754</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels</td>
<td>The WPFunnels WordPress plugin before 3.13.0 does not check whether use=
r registration is enabled on the site before creating accounts from opt-in = form submissions, relying on a value supplied in the request instead, allow= ing unauthenticated attackers to create WordPress user accounts even when r= egistration is disabled. This is an incomplete fix for CVE-2025-12353: the = check added in 3.6.3 covers only one of the three registration paths.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15691" target=3D= "_blank" rel=3D"noopener">CVE-2025-15691</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels</td>
<td>The WPFunnels WordPress plugin before 3.13.0 does not verify that the p= roduct requested through a checkout order bump is the product that bump's d= iscount was configured for, allowing unauthenticated users to obtain any pu= rchasable product at a discount intended for a different one, with the redu= ced price carried through to the total of the order they place.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79630" target=3D= "_blank" rel=3D"noopener">CVE-2026-79630</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels</td>
<td>The WPFunnels WordPress plugin before 3.13.0 does not restrict access t=
o the log files it writes to a predictable location under the public upload=
s directory, allowing unauthenticated users to download customer order deta= ils and opt-in form submissions when logging is enabled.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79631" target=3D= "_blank" rel=3D"noopener">CVE-2026-79631</a></td>
</tr>
<td class=3D"vendor-product">WPFunnels--WPFunnels</td>
<td>The WPFunnels WordPress plugin before 3.13.0 does not perform any autho= risation or nonce check in one of its opt-in submission handlers, and takes=
the notification recipients and subject from the request, allowing unauthe= nticated users to make the site send emails to arbitrary recipients with an=
arbitrary subject.</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79632" target=3D= "_blank" rel=3D"noopener">CVE-2026-79632</a></td>
</tr>
<td class=3D"vendor-product">WPGMaps--WP Go Maps</td>
<td>Unauthenticated Denial of Service Attack in WP Go Maps <=3D 10.1.08 = versions.</td>
<td>2026-09-02</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84780" target=3D= "_blank" rel=3D"noopener">CVE-2026-84780</a></td>
</tr>
<td class=3D"vendor-product">wpinsider-1--Simple Membership</td>
<td>The Simple Membership plugin for WordPress is vulnerable to Authenticat= ion Bypass leading to Administrator Account Takeover in versions up to, and=
including, 4.8.0. This is due to improper identity verification during the=
public registration flow in WordPress Multisite environments, where the pl= ugin binds new Simple Membership records to existing global WordPress users=
based solely on matching username and email, without requiring password ve= rification or ownership proof, and fails to properly detect Administrator r= oles on child sites. This makes it possible for unauthenticated attackers t=
o take over Administrator accounts on child sites in a Multisite network by=
registering a Simple Membership account with a victim's credentials on a s= ite where public registration is enabled, then updating the victim's global=
WordPress password through the profile edit functionality. The vulnerabili=
ty was partially patched in version 4.8.1.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77194" target=3D= "_blank" rel=3D"noopener">CVE-2026-77194</a></td>
</tr>
<td class=3D"vendor-product">WPKoi WordPress Themes--WPKoi Templates for El= ementor</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for E= lementor allows DOM-Based XSS. This issue affects WPKoi Templates for Eleme= ntor: from n/a through 3.7.2.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85302" target=3D= "_blank" rel=3D"noopener">CVE-2026-85302</a></td>
</tr>
<td class=3D"vendor-product">WPLP Cookie Consent--WPLP Cookie Consent</td> <td>The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly=
validate a pagination parameter before using it in a SQL query, allowing u= sers with administrator privileges to perform SQL injection attacks.</td> <td>2026-09-04</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82186" target=3D= "_blank" rel=3D"noopener">CVE-2026-82186</a></td>
</tr>
<td class=3D"vendor-product">WPMU DEV--Broken Link Checker</td>
<td>Editor Server Side Request Forgery (SSRF) in Broken Link Checker <=
=3D 2.4.14 versions.</td>
<td>2026-09-02</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84772" target=3D= "_blank" rel=3D"noopener">CVE-2026-84772</a></td>
</tr>
<td class=3D"vendor-product">WPvivid Backup, Migration & Staging--WPviv=
id Backup, Migration & Staging</td>
<td>The WPvivid - Backup, Migration & Staging WordPress plugin before 0= .9.134 does not validate a user supplied file name before using it to build=
a write path, allowing administrators to write files of permitted types to=
arbitrary locations on the server and to overwrite existing files.</td> <td>2026-09-04</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82193" target=3D= "_blank" rel=3D"noopener">CVE-2026-82193</a></td>
</tr>
<td class=3D"vendor-product">WPvivid Backup, Migration & Staging--WPviv=
id Backup, Migration & Staging</td>
<td>The WPvivid - Backup, Migration & Staging WordPress plugin before 0= .9.134 does not validate a user supplied path before using it in a file del= etion routine, allowing administrators to delete arbitrary files on the ser= ver, including files outside the web root.</td>
<td>2026-09-04</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82194" target=3D= "_blank" rel=3D"noopener">CVE-2026-82194</a></td>
</tr>
<td class=3D"vendor-product">WPvivid Backup, Migration & Staging--WPviv=
id Backup, Migration & Staging</td>
<td>The WPvivid - Backup, Migration & Staging WordPress plugin before 0= .9.133 does not sanitise a user supplied list of identifiers before using i=
t in a SQL query, allowing administrators to perform SQL injection attacks.= </td>
<td>2026-09-02</td>
<td>4.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82182" target=3D= "_blank" rel=3D"noopener">CVE-2026-82182</a></td>
</tr>
<td class=3D"vendor-product">WSO2--WSO2 API Manager</td>
<td>The API Publisher component previously used a non-cryptographic pseudor= andom number generator (PRNG) to create shared secrets for Webhook HMAC val= idation. This PRNG lacks sufficient entropy for security-sensitive operatio= ns, allowing a sophisticated attacker to predict future secrets. This enabl=
es malicious actors to forge event payloads with valid HMAC signatures, byp= assing the API Gateway's authenticity verification. Successful exploitation=
could allow an attacker to predict shared secrets used for Webhook HMAC va= lidation and forge event payloads with valid signatures. This may enable by= passing API Gateway authenticity checks, leading to unauthorized event inje= ction, data manipulation, or downstream system compromise.</td> <td>2026-09-03</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-3416" target=3D"= _blank" rel=3D"noopener">CVE-2026-3416</a></td>
</tr>
<td class=3D"vendor-product">WWBN --AVideo=C2=A0<br>=C2=A0</td>
<td>WWBN AVideo generates passwords for external-login accounts using rand(=
) instead of a cryptographic generator, producing only 31-bit integers. Att= ackers with access to password hashes can recover plaintext passwords in mi= nutes through offline brute-force attacks due to unsalted MD5-based hashing= .</td>
<td>2026-09-05</td>
<td>5.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86187" target=3D= "_blank" rel=3D"noopener">CVE-2026-86187</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a cross-site request forgery v= ulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and for= bidIfInvalidToken protections. Attackers can craft malicious image tags to = overwrite authenticated streamers' RTMP keys, passwords, and titles, hijack= ing live broadcasts.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85162" target=3D= "_blank" rel=3D"noopener">CVE-2026-85162</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a server-side request forgery = vulnerability in the EPG parser that allows authenticated uploaders to fetc=
h arbitrary internal URLs. An attacker can supply an internal URL via the e= pg_link parameter during video upload, which is validated only for syntax a=
nd later fetched server-side during EPG generation without SSRF protection = checks.</td>
<td>2026-09-03</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85163" target=3D= "_blank" rel=3D"noopener">CVE-2026-85163</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo Live_schedule::setTitle() and setDescription() store POST input = without sanitization, allowing users with streaming permission to inject ma= licious scripts. Unauthenticated attackers can access remindMe.php to execu=
te stored XSS payloads in victim browsers without requiring authentication.= </td>
<td>2026-09-01</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84477" target=3D= "_blank" rel=3D"noopener">CVE-2026-84477</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo through commit 9c39d8c8 contains an incomplete authenticati=
on bypass in encryptPass.json.php that allows unauthenticated attackers to = compute valid HMAC tokens using the public site URL and current time. Attac= kers can forge authentication tokens by computing hash_hmac with the site's=
base URL as the key and submit arbitrary passwords to receive encrypted ha= shes, enabling offline precomputation attacks against stolen password datab= ases.</td>
<td>2026-09-01</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84483" target=3D= "_blank" rel=3D"noopener">CVE-2026-84483</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo fails to properly validate access controls on the public ch= annel page, allowing unauthenticated visitors to view unlisted and group-re= stricted videos through hardcoded visibility flags and an undefined propert=
y. Attackers can access the channel endpoint to retrieve sensitive video co= ntent that should be hidden, including full URLs to unlisted videos and thu= mbnails of member-only content, regardless of the operator's hidePrivateVid= eos setting.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85156" target=3D= "_blank" rel=3D"noopener">CVE-2026-85156</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo contains a broken access control vulnerability in the unaut= henticated feed/index.php endpoint that disables per-video visibility check=
s when a program_id parameter is supplied. Attackers can enumerate playlist=
identifiers and retrieve unlisted and group-restricted videos by requestin=
g the RSS feed with any visible playlist id, including empty playlists that=
return the entire site's hidden video catalogue.</td>
<td>2026-09-03</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85157" target=3D= "_blank" rel=3D"noopener">CVE-2026-85157</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a reflected cross-site scripti=
ng vulnerability in videoEmbeded.php that echoes the link parameter inside =
an HTML comment with zero escaping. Attackers can close the comment with --= > and inject arbitrary JavaScript that executes when victims visit the c= rafted embed URL.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85158" target=3D= "_blank" rel=3D"noopener">CVE-2026-85158</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a reflected cross-site scripti=
ng vulnerability in userLogin.php where the cancelUri parameter is echoed i=
n an href attribute after isSafeRedirectURL checks protocol only, not HTML = characters. Unauthenticated attackers can inject event handlers via relativ=
e URLs with embedded quotes to execute arbitrary JavaScript when users inte= ract with the Cancel button.</td>
<td>2026-09-03</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85159" target=3D= "_blank" rel=3D"noopener">CVE-2026-85159</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a reflected cross-site scripti=
ng vulnerability in userLogin.php that allows unauthenticated attackers to = inject arbitrary JavaScript by closing the script tag with </script>.=
Attackers can craft a malicious URL with an error parameter containing scr= ipt breakout sequences to execute arbitrary JavaScript in the victim's brow= ser context on the login page.</td>
<td>2026-09-04</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85577" target=3D= "_blank" rel=3D"noopener">CVE-2026-85577</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>AVideo through commit c91b5975d contains a cross-site request forgery v= ulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInva= lidToken checks. Attackers can craft malicious image tags to delete authent= icated victims' live poster and thumbnail files via GET requests.</td> <td>2026-09-03</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85161" target=3D= "_blank" rel=3D"noopener">CVE-2026-85161</a></td>
</tr>
<td class=3D"vendor-product">xibosignage--xibo-cms</td>
<td>Xibo is an open source digital signage platform with a web content mana= gement system and Windows display player software. Prior to 4.4.3, missing = Authorization in Module::settingsForm allows to view (not change) super adm= in-restricted module settings and leak the full module entity. Exploitation=
of the vulnerability is possible on behalf of an authorized user who has a= ccess to the Module View feature, which are not granted to non-admins as st= andard. Users should upgrade to version 4.4.3 which fixes this issue. Upgra= ding to a fixed version is necessary to remediate. Users unable to upgrade = should revoke such privileges from users they do not trust.</td> <td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52730" target=3D= "_blank" rel=3D"noopener">CVE-2026-52730</a></td>
</tr>
<td class=3D"vendor-product">Xinhu--Rainrock RockOA</td>
<td>A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. Af= fected by this issue is the function getOrder of the file webmain/webmainAc= tion.php. Executing a manipulation of the argument highorder can lead to sq=
l injection. The attack can be launched remotely. The exploit has been made=
available to the public and could be used for attacks. The vendor was cont= acted early about this disclosure but did not respond in any way.</td> <td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84109" target=3D= "_blank" rel=3D"noopener">CVE-2026-84109</a></td>
</tr>
<td class=3D"vendor-product">Xinhu--Rainrock RockOA</td>
<td>A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. Th=
e impacted element is the function toaddval of the file /index.php?m=3Dinde= x&a=3Dpublicsavevalue&ajaxbool=3Dtrue. Executing a manipulation of = the argument Value can lead to sql injection. The attack may be performed f= rom remote. The exploit has been publicly disclosed and may be utilized. Th=
e vendor was contacted early about this disclosure but did not respond in a=
ny way.</td>
<td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84153" target=3D= "_blank" rel=3D"noopener">CVE-2026-84153</a></td>
</tr>
<td class=3D"vendor-product">Xpro Addons 140+ Widgets for Elementor--Xpro A= ddons 140+ Widgets for Elementor</td>
<td>The Xpro Addons - 140+ Widgets for Elementor WordPress plugin before 1.= 7.8 does not perform any capability or post-status check before rendering a=
WooCommerce product summary from a supplied product identifier, allowing u= nauthenticated visitors to retrieve the title, price, SKU, description and = stock details of products that are not publicly published (draft, pending, = private or scheduled status).</td>
<td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84146" target=3D= "_blank" rel=3D"noopener">CVE-2026-84146</a></td>
</tr>
<td class=3D"vendor-product">Xpro Addons--Xpro Addons</td>
<td>The Xpro Addons WordPress plugin before 1.7.4 does not properly escape = some of its widgets' settings before outputting them within HTML attributes=
, which could allow users with the Contributor role and above to perform St= ored Cross-Site Scripting attacks.</td>
<td>2026-09-02</td>
<td>6.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83547" target=3D= "_blank" rel=3D"noopener">CVE-2026-83547</a></td>
</tr>
<td class=3D"vendor-product">Xtemos--WoodMart</td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-sit=
e Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This i= ssue affects WoodMart: from n/a before 8.3.8.</td>
<td>2026-09-04</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-27086" target=3D= "_blank" rel=3D"noopener">CVE-2026-27086</a></td>
</tr>
<td class=3D"vendor-product">XueZhiSi--Open Source Exam System</td> <td>XueZhiSi Open Source Exam System <=3D 3.9.0 has a privilege escalati=
on vulnerability in the teacher-end interface POST /api/teacher/user/page/l= ist. The role parameter in UserPageRequestVM is fully controllable by the r= equester.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75460" target=3D= "_blank" rel=3D"noopener">CVE-2026-75460</a></td>
</tr>
<td class=3D"vendor-product">yaojingang--GEOFlow</td>
<td>A security vulnerability has been detected in yaojingang GEOFlow up to = 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/H= omeController.php of the component JSON-LD Theme Handler. The manipulation =
of the argument Search leads to cross site scripting. The attack is possibl=
e to be carried out remotely. The exploit has been disclosed publicly and m=
ay be used. Upgrading to version 2.1.1 is able to mitigate this issue. The = identifier of the patch is 67abfd864a15d169a78429f3290c91cb3b93e849. Upgrad= ing the affected component is recommended.</td>
<td>2026-08-31</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82664" target=3D= "_blank" rel=3D"noopener">CVE-2026-82664</a></td>
</tr>
<td class=3D"vendor-product">yaojingang--GEOFlow</td>
<td>A flaw has been found in yaojingang GEOFlow up to 2.1.0. This issue aff= ects the function preview of the file app/Http/Controllers/Admin/SiteThemeE= ditorController.php of the component Superadmin Theme Editor. This manipula= tion of the argument blade causes code injection. It is possible to initiat=
e the attack remotely. The exploit has been published and may be used. Upgr= ading to version 2.1.1 is capable of addressing this issue. Patch name: 67a= bfd864a15d169a78429f3290c91cb3b93e849. Upgrading the affected component is = advised.</td>
<td>2026-08-31</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82666" target=3D= "_blank" rel=3D"noopener">CVE-2026-82666</a></td>
</tr>
<td class=3D"vendor-product">yaojingang--GEOFlow</td>
<td>A vulnerability has been found in yaojingang GEOFlow up to 2.1.0. Impac= ted is the function DistributionController.isValidHttpEndpoint of the file = app/Services/GeoFlow/GenericHttpEndpointResolver.php. Such manipulation of = the argument endpoint_url leads to server-side request forgery. It is possi= ble to launch the attack remotely. The exploit has been disclosed to the pu= blic and may be used. Upgrading to version 2.1.1 is recommended to address = this issue. The name of the patch is 67abfd864a15d169a78429f3290c91cb3b93e8= 49. It is advisable to upgrade the affected component.</td>
<td>2026-08-31</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82667" target=3D= "_blank" rel=3D"noopener">CVE-2026-82667</a></td>
</tr>
<td class=3D"vendor-product">YesWiki -- YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar = form-field templates still apply |raw('html') to field.label / field.hint i=
n attribute and label-body contexts, resulting stored XSS in form renders. = This issue has been patched in version 4.6.6.</td>
<td>2026-09-05</td>
<td>5.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52772" target=3D= "_blank" rel=3D"noopener">CVE-2026-52772</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki</td>
<td>YesWiki is a wiki system written in PHP. From version 4.1.0 to before v= ersion 4.6.6, YesWiki's archived-revision view reflects the time GET parame= ter into a hidden HTML input in handlers/page/show.php without escaping. Be= cause MySQL coerces malformed DATETIME strings, an attacker can append HTML=
or JavaScript to a valid archived revision timestamp, still load that arch= ived revision, and execute arbitrary JavaScript in the victim's browser. Th=
e vulnerable form is only rendered when the victim can both read and edit t=
he target page. In restricted deployments this requires a victim with read = and write access to that page. On a default doryphore 4.6.5 install, public=
pages such as PagePrincipale were editable anonymously during validation, =
so the issue can also affect unauthenticated visitors in that configuration=
. This issue has been patched in version 4.6.6.</td>
<td>2026-09-05</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52773" target=3D= "_blank" rel=3D"noopener">CVE-2026-52773</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWik= i's Bazar widget handler reflects the id GET parameter into HTML attributes=
using strip_tags() only. Because strip_tags() does not escape double quote=
s, an attacker can break out of the attribute value, inject an event handle=
r such as onmouseover, and execute arbitrary JavaScript in the victim's bro= wser. This issue is reachable without authentication. During validation, th=
e vulnerable widget route returned the injected HTML for both /HomePage/wid= get?id=3D... and /NoSuchPage/widget?id=3D..., which shows that no login, no=
page ownership, no edit rights, and not even a valid page tag were require=
d. The only routing prerequisite observed was that the Bazar extension is e= nabled and the request includes an id parameter. This issue has been patche=
d in version 4.6.6.</td>
<td>2026-09-05</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52774" target=3D= "_blank" rel=3D"noopener">CVE-2026-52774</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the re= centchanges action (actions/recentchanges.php) accepts a period argument fr=
om two disjoint parameter spaces. A whitelist validates only the URL form a= gainst ['day','week','month']. The action-argument form takes the else bran=
ch with no validation, and the value flows into PageManager::getRecentlyCha= nged(), where it is interpolated into a WHERE time >=3D '...' ORDER BY t= ime DESC clause without escaping or parameterization. UNION-based injection=
succeeds, the leaked rows render into the response page, so any visitor of=
the trigger page sees the exfiltrated data. The vulnerability provides arb= itrary read of the YesWiki database to anyone who can save the trigger page=
. On a default install (default_write_acl=3D'*'), this includes anonymous u= sers, subject to the hashcash JS check on the page-edit form. Once the trig= ger page is saved, every subsequent view fires the injection as the SQLi is=
stored. Stored SQL injection is reachable through the page-edit flow, with=
arbitrary database read. This issue has been patched in version 4.6.6.</td=
<td>2026-09-05</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52763" target=3D= "_blank" rel=3D"noopener">CVE-2026-52763</a></td>
</tr>
<td class=3D"vendor-product">Yoast SEO Premium--Yoast SEO Premium</td>
<td>The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize = control characters from redirect origins before writing them to the site's = Apache configuration file when the file-based redirect mode is enabled, and=
the redirect-creation endpoint is reachable by users with only Author-leve=
l access. This allows such users to inject arbitrary newline-delimited Apac=
he directives into the root .htaccess file. On Apache servers that honour P=
HP directives, the injection can be chained with the user's own media uploa=
d (a polyglot image carrying a PHP payload) and an auto_prepend_file direct= ive to achieve Remote Code Execution.</td>
<td>2026-09-02</td>
<td>6.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-10821" target=3D= "_blank" rel=3D"noopener">CVE-2026-10821</a></td>
</tr>
<td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Information an=
d Document Automation Program</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Yordam Information Technology Consulting, Tr= aining and Electronic Systems Industry and Trade Inc. Library Information a=
nd Document Automation Program allows XSS Targeting HTML Attributes. This i= ssue affects Library Information and Document Automation Program: before v2= 2.2.</td>
<td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19727" target=3D= "_blank" rel=3D"noopener">CVE-2026-19727</a></td>
</tr>
<td class=3D"vendor-product">Yordam Information Technology Consulting, Trai= ning and Electronic Systems Industry and Trade Inc.--Library Information an=
d Document Automation Program</td>
<td>Improper neutralization of input during web page generation ('cross-sit=
e scripting') vulnerability in Yordam Information Technology Consulting, Tr= aining and Electronic Systems Industry and Trade Inc. Library Information a=
nd Document Automation Program allows Content Spoofing. This issue affects = Library Information and Document Automation Program: from v22.1 before v22.= 2.</td>
<td>2026-09-04</td>
<td>6.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77818" target=3D= "_blank" rel=3D"noopener">CVE-2026-77818</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The Silicon Labs SiWx917 WiFi driver's transmit callback siwx91x_send()=
in drivers/wifi/siwx91x/siwx91x_wifi.c frees a network packet it does not = own. In the Zephyr TX path the net_pkt is owned by the L2/networking stack;=
the driver only borrows it to copy the frame bytes into a local net_buf. B= efore the fix, after transmitting, siwx91x_send() additionally called net_p= kt_unref(pkt) on the caller-owned packet, dropping its last reference and r= eturning it to the shared packet pool prematurely. This code path is compil=
ed in by default (CONFIG_WIFI_SILABS_SIWX91X_NET_STACK_NATIVE). The caller,=
ethernet_send() in subsys/net/l2/ethernet/ethernet.c, keeps using the pack=
et after the driver returns: it reads net_pkt_get_len(pkt), updates TX stat= istics, and then performs its own net_pkt_unref(pkt). Because the driver al= ready released the packet, these are use-after-free reads followed by a sec= ond unref (a double free). When concurrent network activity recycles the fr= eed slab slot between the two unrefs, the trailing unref decrements a diffe= rent, live packet's reference count and frees it, corrupting the net_pkt po=
ol shared by both the receive and transmit paths. The defect is exercised b=
y ordinary transmission over the native-stack SiWx917 WiFi interface, and a=
n adjacent attacker on the same WiFi network can induce transmissions (for = example ARP or ICMP echo replies, or TCP handshakes) to drive the path. The=
primary observable impact is loss of availability (transmit hangs and cras= hes from pool corruption), with race-dependent memory corruption of the ker= nel networking buffer pool. The fix removes the erroneous net_pkt_unref(pkt=
) from siwx91x_send(); the driver's receive-path unref, which correctly fre=
es a packet the driver itself allocated, is unaffected.</td> <td>2026-08-31</td>
<td>6.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14366" target=3D= "_blank" rel=3D"noopener">CVE-2026-14366</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bri= dge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides=
how each frame received on a bridge member interface is handled. For frame=
s that must also be delivered to the local stack, the code called eth_bridg= e_handle_locally() and returned NET_OK. That helper does not consume the pa= cket - it only calls bridge_iface_recv() (via virtual_recv()), which return=
s NET_CONTINUE without taking ownership of pkt. The NET_OK verdict then pro= pagates through ethernet_recv() up to processing_data() in subsys/net/ip/ne= t_core.c, where NET_OK is interpreted as "the packet was consumed, do not f= ree it." Because no consumer actually took ownership, the RX net_pkt is nev=
er returned to the pool and is leaked. The concretely reproducible leak occ= urs for frames whose EtherType has no registered L3 handler when CONFIG_NET= _ETHERNET_FORWARD_UNRECOGNISED_ETHERTYPE is set (default y when CONFIG_NET_= SOCKETS_PACKET is enabled): the fall-through L3 dispatch does not overwrite=
the NET_OK verdict, so ethernet_recv() returns NET_OK and the buffer is ne= ver released. Any device on a bridged L2 segment can emit broadcast/multica=
st frames carrying an arbitrary EtherType with no authentication. Each such=
frame permanently consumes one buffer from the finite RX pool (CONFIG_NET_= PKT_RX_COUNT), so a brief broadcast flood exhausts the pool and the device = can no longer receive traffic until it is rebooted - a persistent denial of=
service. There is no confidentiality or integrity impact. The fix makes et= h_bridge_handle_locally() propagate the real net_verdict and return NET_CON= TINUE for locally-kept frames, writing the bridge interface back through a = new dst_iface out-parameter so the packet follows the normal receive path a=
nd is unreferenced exactly once.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14696" target=3D= "_blank" rel=3D"noopener">CVE-2026-14696</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net= _pkt for a Neighbor Solicitation. When it is called with a data packet pend= ing on an unresolved neighbor and that neighbor's pending_queue is already = non-empty (an NS is already outstanding), the function appends the data pac= ket and returns early without ever sending the NS via net_send_data() or re= leasing it with net_pkt_unref(). The freshly allocated NS net_pkt and its a= ttached TX buffers are held only by a local variable and are leaked permane= ntly, never returning to CONFIG_NET_PKT_TX_COUNT / CONFIG_NET_BUF_TX_COUNT.=
The leaking branch sits on the normal IPv6 transmit path: net_ipv6_prepare= _for_send() (called from net_if.c) invokes net_ipv6_send_ns() for any outbo= und or forwarded IPv6 packet whose next hop is not yet in the neighbor cach=
e. An on-link (adjacent) attacker can drive it deterministically by sending=
a burst of request packets (for example ICMPv6 echo requests or UDP datagr= ams) that all spoof a single non-existent on-link source address: the node = generates a reply to each, the first reply queues an NS, and every subseque=
nt reply during the roughly three-second INCOMPLETE resolution window takes=
the leaking branch and loses one TX packet. Router-configured nodes forwar= ding attacker traffic toward a non-existent on-link host leak identically. = Because the leaked packets are never reclaimed and CONFIG_NET_PKT_TX_COUNT = defaults to only 4 (14 for Ethernet), a brief low-rate burst exhausts the T=
X pool. Once exhausted the node can no longer allocate any transmit packet = and cannot send TCP/UDP, ARP/ND, or any reply at all, producing a complete = and persistent network denial of service that does not self-heal until rebo= ot. The fix releases the unsent NS packet with net_pkt_unref(pkt) before th=
e early return.</td>
<td>2026-08-31</td>
<td>6.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14697" target=3D= "_blank" rel=3D"noopener">CVE-2026-14697</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m= /lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer = and NUL-terminates it. The length guard used if (string_length > buflen)=
, which accepts a string whose length is exactly buflen. After memcpy() fil=
ls the whole buffer, buf[string_length] =3D ' ' then writes one byte past t=
he end of the buffer (CWE-787). The string value and its length are taken d= irectly from the incoming CoAP payload during a LwM2M WRITE: do_write_op_js= on() parses the payload obtained from coap_packet_get_payload(), and get_st= ring() is invoked from lwm2m_write_handler() (engine_get_string() in subsys= /net/lib/lwm2m/lwm2m_message_handling.c) for a LWM2M_RES_TYPE_STRING resour= ce. The destination buf/buflen is either the resource instance's fixed data=
buffer (res_inst->data_ptr/max_data_len) or the engine validation buffe=
r (msg->ctx->validate_buf). A LwM2M server (the client's DTLS peer) c=
an therefore write a string resource with a value whose length equals the t= arget buffer size and force a one-byte overflow. The overflow is a single o= ut-of-bounds write of the constant byte 0x00 immediately past the resource =
or validation buffer, corrupting the adjacent byte in memory. It is not an = information leak and the written value is fixed, so it is not a direct code= -execution primitive, but it can corrupt adjacent state (an adjacent resour=
ce value, a length/flag field, or a struct field) and cause data corruption=
or a crash. Triggering the write is deterministic; the resulting impact de= pends on memory layout. The fix changes the guard to string_length >=3D = buflen, rejecting the exact-length case and aligning the JSON formatter wit=
h the other content formatters (lwm2m_rw_plain_text.c, lwm2m_rw_oma_tlv.c, = lwm2m_rw_senml_json.c, lwm2m_rw_cbor.c, lwm2m_rw_senml_cbor.c), which alrea=
dy used the correct boundary check.</td>
<td>2026-08-31</td>
<td>5.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14368" target=3D= "_blank" rel=3D"noopener">CVE-2026-14368</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impact=
s the function BrowserTool of the file agent/tools/browser/browser_tool.py =
of the component Browser Tool. Performing a manipulation results in denial =
of service. The attack can be initiated remotely. The exploit has been made=
public and could be used. The vendor was contacted early about this disclo= sure but did not respond in any way.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84425" target=3D= "_blank" rel=3D"noopener">CVE-2026-84425</a></td>
</tr>
<td class=3D"vendor-product">zhayujie--CowAgent</td>
<td>A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affect=
ed is an unknown function of the file agent/tools/bash/bash.py of the compo= nent Bash Tool. Executing a manipulation can lead to denial of service. The=
attack can be launched remotely. The exploit has been publicly disclosed a=
nd may be utilized. The vendor was contacted early about this disclosure bu=
t did not respond in any way.</td>
<td>2026-09-02</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84427" target=3D= "_blank" rel=3D"noopener">CVE-2026-84427</a></td>
</tr>
<td class=3D"vendor-product">ZhongBangKeJi--CRMEB</td>
<td>A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affe= cted by this vulnerability is the function eval of the file /adminapi/syste= m/crontab/save of the component Custom Scheduled Task Feature. This manipul= ation of the argument customCode causes os command injection. It is possibl=
e to initiate the attack remotely. The exploit has been made available to t=
he public and could be used for attacks. Vendor documents this as deliberat=
e debug-only behavior. But isSafePhpCode blacklist offers no real RCE conta= inment.</td>
<td>2026-09-03</td>
<td>4.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85040" target=3D= "_blank" rel=3D"noopener">CVE-2026-85040</a></td>
</tr>
<td class=3D"vendor-product">zhongyu09--OpenChatBI</td>
<td>A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0=
. Affected by this vulnerability is the function _validate_sql_safety of th=
e file openchatbi/text2sql/generate_sql.py. Performing a manipulation resul=
ts in sql injection. The attack can be initiated remotely. Versions v0.2.0 = through v0.2.2 have no SQL safety validation at all, while v0.3.0 introduce=
d a validator and v1.0.0b1/main kept the same incomplete one with an option=
al stricter mode. The vendor was contacted early about this disclosure but = did not respond in any way.</td>
<td>2026-09-01</td>
<td>6.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84061" target=3D= "_blank" rel=3D"noopener">CVE-2026-84061</a></td>
</tr>
<td class=3D"vendor-product">=C2=A0JeecgBoot-- JeecgBoot<br>=C2=A0</td>
<td>A security vulnerability has been detected in JeecgBoot up to 3.9.3. Th=
is vulnerability affects the function exportXls of the file jeecg-boot/jeec= g-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag= /llm/controller/AiragModelController.java. Such manipulation of the argumen=
t credential leads to improper access controls. It is possible to launch th=
e attack remotely. The exploit has been disclosed publicly and may be used.=
Upgrading to version 3.9.5 is able to resolve this issue. The name of the = patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the a= ffected component.</td>
<td>2026-09-06</td>
<td>4.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86228" target=3D= "_blank" rel=3D"noopener">CVE-2026-86228</a></td>
</tr>
<td class=3D"vendor-product">=C2=A0jofpin-- trape</td>
<td>A security vulnerability has been detected in jofpin trape 2.0. This vu= lnerability affects unknown code of the file core/user.py of the component = Telemetry Endpoint. Such manipulation of the argument vId leads to race con= dition. The attack can be executed remotely. Attacks of this nature are hig= hly complex. It is stated that the exploitability is difficult. The exploit=
has been disclosed publicly and may be used. The project was informed of t=
he problem early through an issue report but has not responded yet.</td> <td>2026-09-04</td>
<td>5.6</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85639" target=3D= "_blank" rel=3D"noopener">CVE-2026-85639</a></td>
</tr>
<td class=3D"vendor-product">=C2=A0jofpin-- trape<br>=C2=A0</td>
<td>A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected=
by this issue is the function join_room of the file core/sockets.py of the=
component Admin Endpoint. The manipulation results in missing authenticati= on. The attack may be launched remotely. The exploit has been released to t=
he public and may be used for attacks. The project was informed of the prob= lem early through an issue report but has not responded yet.</td> <td>2026-09-04</td>
<td>5.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85637" target=3D= "_blank" rel=3D"noopener">CVE-2026-85637</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"low_v">
<h2 id=3D"low_v_title">Low Vulnerabilities</h2>
<table class=3D"table table-style-align-center no-tablesaw" style=3D"table-= layout: fixed; width: 100%;" border=3D"1" summary=3D"Low Vulnerabilities"> <thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">AMD--AMD Radeon PRO V620 Graphics Products</td=
<td>A malicious virtual function can invoke the certain command handlers in=
the SMU, causing a denial of service due to out-of-bounds memory read.</td=
<td>2026-08-31</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-31308" target=3D= "_blank" rel=3D"noopener">CVE-2023-31308</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the web-based management interface of HPE Networking=
Fabric Composer could allow an unauthenticated remote attacker to gain ins= ight into some data handled by the affected interface. A successful exploit=
could allow an attacker to gain access to some data in a cleartext format = possibly exposing other network infrastructure to further compromise.</td> <td>2026-09-01</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73743" target=3D= "_blank" rel=3D"noopener">CVE-2026-73743</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A denial-of-service vulnerability exists in the web-based management in= terface of HPE Networking Fabric Composer that could allow an authenticated=
low privilege operator user to cause a denial of service. Successful explo= itation could allow an attacker to disrupt the availability of the affected=
interface.</td>
<td>2026-09-01</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73744" target=3D= "_blank" rel=3D"noopener">CVE-2026-73744</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the API endpoint of HPE Networking Fabric Composer c= ould allow an unauthenticated remote attacker to view some information hand= led by the affected system. Successful exploitation could allow an attacker=
to gain insight into internal services and workflows, increasing the risk =
of unauthorized access when combined with other vulnerabilities.</td> <td>2026-09-01</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73745" target=3D= "_blank" rel=3D"noopener">CVE-2026-73745</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A denial-of-service vulnerability exists in the API of HPE Networking F= abric Composer that could allow an authenticated low privilege operator use=
r to cause a denial of service. Successful exploitation could allow an atta= cker to interrupt the normal operation of the affected service.</td> <td>2026-09-01</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73746" target=3D= "_blank" rel=3D"noopener">CVE-2026-73746</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A local privilege-escalation vulnerability has been discovered in HPE N= etworking Fabric Composer. Successful exploitation could allow an authentic= ated low privilege operator user with local access to elevate their user pr= ivileges and make limited modifications on the affected system.</td> <td>2026-09-01</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73747" target=3D= "_blank" rel=3D"noopener">CVE-2026-73747</a></td>
</tr>
<td class=3D"vendor-product">arubanetworks -- fabric_composer</td>
<td>A vulnerability in the affected interface of HPE Networking Fabric Comp= oser allows an attacker with administrative privileges to access sensitive = information in a cleartext format. A successful exploit allows an attacker =
to retrieve information which could be used to potentially gain further acc= ess to network services supported by HPE Networking Fabric Composer.</td> <td>2026-09-01</td>
<td>2.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73748" target=3D= "_blank" rel=3D"noopener">CVE-2026-73748</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Employee Leave Managing System<=
<td>A security vulnerability has been detected in code-projects Employee Le= ave Managing System 1.0. Affected is an unknown function of the file /EmpMa= nageSys/editaction.php of the component Employee Profile Update. The manipu= lation of the argument Name leads to cross site scripting. The attack can b=
e initiated remotely. The exploit has been disclosed publicly and may be us= ed.</td>
<td>2026-08-31</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82622" target=3D= "_blank" rel=3D"noopener">CVE-2026-82622</a></td>
</tr>
<td class=3D"vendor-product">code-projects--Task Management System 1.0<br>= =C2=A0</td>
<td>A vulnerability was found in code-projects Task Management System 1.0. = Affected by this issue is some unknown functionality of the file /user/Upda= teUserProfile.php of the component User Profile Update. The manipulation of=
the argument lname results in cross site scripting. The attack can be laun= ched remotely. The exploit has been made public and could be used.</td> <td>2026-09-06</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86181" target=3D= "_blank" rel=3D"noopener">CVE-2026-86181</a></td>
</tr>
<td class=3D"vendor-product">Directorist: AI-Powered Business Directory, Li= stings & Classified Ads--Directorist: AI-Powered Business Directory, Li= stings & Classified Ads</td>
<td>The Directorist: AI-Powered Business Directory, Listings & Classifi=
ed Ads WordPress plugin before 8.9 does not verify that the requesting user=
owns the post being modified before writing uploaded file references to it=
s metadata, allowing users with the subscriber role and above to overwrite = image metadata on posts belonging to other users.</td>
<td>2026-09-04</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84066" target=3D= "_blank" rel=3D"noopener">CVE-2026-84066</a></td>
</tr>
<td class=3D"vendor-product">Drupal--CAPTCHA Protected Page</td> <td>Authentication Bypass Using an Alternate Path or Channel vulnerability =
in Drupal CAPTCHA Protected Page allows Functionality Bypass. This issue af= fects CAPTCHA Protected Page versions: from 0.0.0 to 1.0.2.</td> <td>2026-09-02</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81168" target=3D= "_blank" rel=3D"noopener">CVE-2026-81168</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Commerce CyberSource</td>
<td>Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSou= rce allows Brute Force. This issue affects Commerce CyberSource versions: f= rom 0.0.0 to 1.10.0.</td>
<td>2026-09-02</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81159" target=3D= "_blank" rel=3D"noopener">CVE-2026-81159</a></td>
</tr>
<td class=3D"vendor-product">Drupal--Content Moderation Notifications</td> <td>Privilege Defined With Unsafe Actions vulnerability in Drupal Content M= oderation Notifications allows Privilege Escalation. This issue affects Con= tent Moderation Notifications versions: from 0.0.0 to 3.9.0.</td> <td>2026-09-02</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81161" target=3D= "_blank" rel=3D"noopener">CVE-2026-81161</a></td>
</tr>
<td class=3D"vendor-product">elastic -- elastic_cloud_on_kubernetes</td>
<td>Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can l= ead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication = credentials persist after a cross-namespace association has been denied by = RBAC enforcement, allowing a low-privileged tenant to retain unauthorized r= ead access to the associated Elasticsearch cluster.</td>
<td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78600" target=3D= "_blank" rel=3D"noopener">CVE-2026-78600</a></td>
</tr>
<td class=3D"vendor-product">elastic -- fleet_server</td>
<td>Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial =
of service of agent upload operations via Privilege Abuse (CAPEC-122). Flee=
t Server does not correctly verify session ownership during multi-part data=
upload operations, allowing any authenticated agent to interfere with the = active upload sessions belonging to other enrolled agents.</td>
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78587" target=3D= "_blank" rel=3D"noopener">CVE-2026-78587</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Call Recording Software</td>
<td>A flaw has been found in Eleveo Call Recording Software 9.7.0. This aff= ects an unknown part of the file /callrec/roleAddAction.do. Executing a man= ipulation of the argument name/username can lead to cross site scripting. T=
he attack may be launched remotely. The exploit has been published and may =
be used. The vendor was contacted early about this disclosure but did not r= espond in any way.</td>
<td>2026-09-04</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85405" target=3D= "_blank" rel=3D"noopener">CVE-2026-85405</a></td>
</tr>
<td class=3D"vendor-product">Eleveo--Quality Management</td>
<td>A vulnerability has been found in Eleveo Quality Management 9.7.0. This=
vulnerability affects unknown code of the component Conversation Review. T=
he manipulation leads to cross site scripting. Remote exploitation of the a= ttack is possible. The exploit has been disclosed to the public and may be = used. The vendor was contacted early about this disclosure but did not resp= ond in any way.</td>
<td>2026-09-04</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85406" target=3D= "_blank" rel=3D"noopener">CVE-2026-85406</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 5.0.0, Wallos lets any authenticated user store an arbitra=
ry SMTP host - including private and cloud-metadata IP addresses - in their=
personal email notification settings, with no server-side SSRF validation.=
When the scheduled notification cron job runs, it passes the stored host d= irectly to PHPMailer, causing the Wallos server to open an outbound TCP con= nection to whatever address the attacker specified. This gives a low-privil= eged attacker a reliable mechanism to probe internal network services from = the server's perspective. This issue has been patched in version 5.0.0.</td=
<td>2026-08-31</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77351" target=3D= "_blank" rel=3D"noopener">CVE-2026-77351</a></td>
</tr>
<td class=3D"vendor-product">extension.vn--2FA Authenticator Extension</td> <td>A weakness has been identified in extension.vn 2FA Authenticator Extens= ion 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.= onMessageExternal.addListener of the component Background Service Worker. E= xecuting a manipulation of the argument sender.id can lead to information d= isclosure. The attack requires local access. The exploit has been made avai= lable to the public and could be used for attacks. The vendor was contacted=
early about this disclosure.</td>
<td>2026-08-31</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82810" target=3D= "_blank" rel=3D"noopener">CVE-2026-82810</a></td>
</tr>
<td class=3D"vendor-product">F5--BIG-IP</td>
<td>A vulnerability exists in an undisclosed BIG-IP Configuration utility p= age that may allow an attacker to spoof error messages=C2=A0 Impact: An att= acker may trick authenticated BIG-IP users into accessing malicious links a=
nd reflect a spoofed error message in the victim's BIG-IP Configuration uti= lity web browser session. This is a control plane issue; there is no data p= lane exposure. Note: Software versions which have reached End of Technical = Support (EoTS) are not evaluated.</td>
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-63020" target=3D= "_blank" rel=3D"noopener">CVE-2026-63020</a></td>
</tr>
<td class=3D"vendor-product">filamentphp--filament</td>
<td>Filament is a collection of full-stack components for accelerated Larav=
el development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth= /Pages/Login.php presents the multi-factor authentication challenge before = evaluating canAccessPanel(). For an account that canAccessPanel() denies, s= ubmitting the correct password renders the MFA challenge while an incorrect=
password returns the generic authentication failure, allowing an unauthent= icated attacker to confirm whether a candidate password is valid for that a= ccount. When email-based MFA is configured, the correct-password path also = sends a login code to the account holder. The issue applies only to account=
s that have MFA enabled and are denied panel access. Authentication is not = bypassed because canAccessPanel() still runs after the challenge, and no se= ssion is created. This issue is fixed in versions 4.12.5 and 5.7.5.</td> <td>2026-09-01</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84307" target=3D= "_blank" rel=3D"noopener">CVE-2026-84307</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Missing authorization in FileSystem in Google Chrome prior to 152.0.797= 7.75 allowed a remote attacker who had compromised the renderer process to = bypass web origin policy via a crafted HTML page. (Chromium security severi= ty: Medium)</td>
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84328" target=3D= "_blank" rel=3D"noopener">CVE-2026-84328</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.7=
5 allowed a remote attacker who had compromised the renderer process to byp= ass web origin policy via a crafted HTML page. (Chromium security severity:=
Low)</td>
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84331" target=3D= "_blank" rel=3D"noopener">CVE-2026-84331</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Incorrect authorization in Navigation in Google Chrome prior to 152.0.7= 977.75 allowed a remote attacker who had compromised the renderer process t=
o bypass web origin policy via a crafted HTML page. (Chromium security seve= rity: Medium)</td>
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84355" target=3D= "_blank" rel=3D"noopener">CVE-2026-84355</a></td>
</tr>
<td class=3D"vendor-product">google -- chrome</td>
<td>Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowe=
d a remote attacker who had compromised the renderer process to leak cross-= origin data via a crafted HTML page. (Chromium security severity: High)</td=
<td>2026-09-02</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84359" target=3D= "_blank" rel=3D"noopener">CVE-2026-84359</a></td>
</tr>
<td class=3D"vendor-product">Google--Chrome</td>
<td>Out of bounds read in CrashReporting in Google Chrome prior to 152.0.79= 77.82 allowed a remote attacker who had compromised the renderer process to=
read memory outside the sandbox via a crafted HTML page. (Chromium securit=
y severity: High)</td>
<td>2026-09-03</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85052" target=3D= "_blank" rel=3D"noopener">CVE-2026-85052</a></td>
</tr>
<td class=3D"vendor-product">GutenKit--GutenKit</td>
<td>The GutenKit WordPress plugin before 2.5.1 does not validate or escape = style settings saved against a post before using them to build the CSS it o= utputs on the front end, allowing users with the Contributor role and above=
to inject arbitrary CSS into pages served to other users and to anonymous = visitors. JavaScript execution is not possible at that role, so the impact =
is limited to defacement, interface redressing and forcing external resourc=
es to load.</td>
<td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19698" target=3D= "_blank" rel=3D"noopener">CVE-2026-19698</a></td>
</tr>
<td class=3D"vendor-product">hapijs--joi</td>
<td>joi is a schema description language and data validator for JavaScript.=
From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.re= name() implementation used by object().rename() permits a schema that renam=
es keys with a regular-expression source and a Joi.expression() or Joi.x() = target that interpolates the pattern's own match data, combined with { mult= iple: true }, to derive a target from an attacker-controlled input key. An = attacker can send x-__proto__ with an object value, causing the target to r= ender as __proto__ and set the prototype of the object returned by validate=
() instead of creating an own key. The global Object.prototype is not modif= ied, so the effect is confined to the object returned by that validation ca= ll. Static-string targets and schemas using the default { multiple: false }=
are not affected. This issue is fixed in versions 17.13.5 and 18.2.4.</td> <td>2026-09-01</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84367" target=3D= "_blank" rel=3D"noopener">CVE-2026-84367</a></td>
</tr>
<td class=3D"vendor-product">hapijs--joi</td>
<td>joi is a schema description language and data validator for JavaScript.=
From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1=
and the successor joi package contain prototype pollution in lib/messages.= js, where exports.compile() and exports.merge() reuse inherited objects for=
attacker-controlled language keys supplied through messages(), message(), = prefs({ messages }), Joi.extend({ messages }), or rule({ message }). A lang= uage key named __proto__ writes properties onto Object.prototype, and const= ructor writes to the Object function's static properties. A consuming appli= cation that gates on the presence of an inherited property can take the wro=
ng branch for every inspected object. The flaw is not reachable from data t= hat joi validates and requires an application to feed untrusted input direc= tly into schema-construction configuration. This issue is fixed in joi vers= ions 17.13.6 and 18.2.5; no fixed @hapi/joi version is available.</td> <td>2026-09-01</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84368" target=3D= "_blank" rel=3D"noopener">CVE-2026-84368</a></td>
</tr>
<td class=3D"vendor-product">HCLSoftware--Connections</td>
<td>HCL Connections is vulnerable to an information disclosure vulnerabilit=
y which could allow a user to obtain sensitive information they are not ent= itled to, caused by improper handling of request data they are not entitled=
to, caused by improper handling of request data.</td>
<td>2026-08-31</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-21827" target=3D= "_blank" rel=3D"noopener">CVE-2026-21827</a></td>
</tr>
<td class=3D"vendor-product">HKUDS--AI-Trader</td>
<td>A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ce= d735adf7c19ed8175adb1c8df. The affected element is an unknown function of t=
he file service/server/routes_agent.py of the component selfRegister API En= dpoint. Such manipulation of the argument initial_balance leads to business=
logic errors. The attack may be launched remotely. This attack is characte= rized by high complexity. The exploitability is described as difficult. The=
exploit has been disclosed to the public and may be used. This product ope= rates on a rolling release basis, ensuring continuous delivery. Consequentl=
y, there are no version details for either affected or updated releases. pr= ofit_percent_for_display() divides by INITIAL_CAPITAL + deposited, and chal= lenge scoring's return_pct also normalises against the attacker-inflated st= arting_cash. So an inflated initial_balance does not yield artificial perce=
nt returns - it inflates the absolute cash/equity column only, which is a c= osmetic/leaderboard-gaming concern in a simulated game.</td> <td>2026-09-03</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85030" target=3D= "_blank" rel=3D"noopener">CVE-2026-85030</a></td>
</tr>
<td class=3D"vendor-product">hulumi--baseline</td>
<td>@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail = selector tampering events, reducing audit logging configuration change cove= rage. Attackers can modify CloudTrail event selectors without complete dete= ction, potentially evading audit trail monitoring.</td>
<td>2026-08-31</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82863" target=3D= "_blank" rel=3D"noopener">CVE-2026-82863</a></td>
</tr>
<td class=3D"vendor-product">IBM--i</td>
<td>IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain=
information from a privileged file when using SSH.</td>
<td>2026-09-04</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18858" target=3D= "_blank" rel=3D"noopener">CVE-2026-18858</a></td>
</tr>
<td class=3D"vendor-product">Icegram Express--Icegram Express</td>
<td>The Icegram Express WordPress plugin before 5.8.6 does not properly esc= ape a list description setting before outputting it within an HTML attribut=
e, which could allow users with the Administrator role and above to perform=
Stored Cross-Site Scripting attacks.</td>
<td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15692" target=3D= "_blank" rel=3D"noopener">CVE-2025-15692</a></td>
</tr>
<td class=3D"vendor-product">IObit--Unlocker</td>
<td>A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnera= bility affects the function ZwTerminateProcess in the library IObitUnlocker= .sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads=
to improper privilege management. An attack has to be approached locally. = The vendor was contacted early about this disclosure but did not respond in=
any way.</td>
<td>2026-08-31</td>
<td>3.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82671" target=3D= "_blank" rel=3D"noopener">CVE-2026-82671</a></td>
</tr>
<td class=3D"vendor-product">itsourcecode--Online Medicine Delivery System<=
<td>A vulnerability was identified in itsourcecode Online Medicine Delivery=
System 1.0. Impacted is an unknown function of the file /index.php?q=3Dord= erdetails. Such manipulation of the argument location leads to cross site s= cripting. The attack may be launched remotely. The exploit is publicly avai= lable and might be used.</td>
<td>2026-09-03</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85207" target=3D= "_blank" rel=3D"noopener">CVE-2026-85207</a></td>
</tr>
<td class=3D"vendor-product">Jenkins Project--Jenkins</td>
<td>Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568=
.2 (both inclusive) does not correctly perform permission checks in the App= earance configuration page, allowing attackers with Overall/Manage permissi=
on to modify Appearance configuration options they should not have access t= o.</td>
<td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84653" target=3D= "_blank" rel=3D"noopener">CVE-2026-84653</a></td>
</tr>
<td class=3D"vendor-product">kyverno--kyverno</td>
<td>Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites = (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on = their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet=
32 attack (CVE-2016-2183), which, over very long-lived TLS connections carr= ying large volumes of traffic, could allow an attacker to recover small amo= unts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.</td> <td>2026-09-01</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-54356" target=3D= "_blank" rel=3D"noopener">CVE-2023-54356</a></td>
</tr>
<td class=3D"vendor-product">langgenius--dify</td>
<td>A vulnerability was identified in langgenius dify 1.13.0. Affected by t= his vulnerability is the function router.replace of the file web/app/(share= Layout)/webapp-signin/components/mail-and-password-auth.tsx of the componen=
t WebApp Sign-In. Such manipulation of the argument redirect_url leads to c= ross site scripting. The attack may be performed from remote. The exploit i=
s publicly available and might be used. The vendor was contacted early abou=
t this disclosure but did not respond in any way.</td>
<td>2026-09-03</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85022" target=3D= "_blank" rel=3D"noopener">CVE-2026-85022</a></td>
</tr>
<td class=3D"vendor-product">LatencyUtils--LatencyUtils</td>
<td>A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by=
this issue is the function LatencyStats.recordDetectedPause of the file sr= c/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetect= or. Executing a manipulation can lead to memory corruption. The attack need=
s to be launched locally. The exploit has been publicly disclosed and may b=
e utilized. The project was informed of the problem early through an issue = report but has not responded yet.</td>
<td>2026-08-31</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82596" target=3D= "_blank" rel=3D"noopener">CVE-2026-82596</a></td>
</tr>
<td class=3D"vendor-product">libxml2 -- libxml2=C2=A0<br>=C2=A0</td>
<td>In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds r= ead, aka an out-of-bounds read in the NXT macro in xmlregexp.</td> <td>2026-09-05</td>
<td>2.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86137" target=3D= "_blank" rel=3D"noopener">CVE-2026-86137</a></td>
</tr>
<td class=3D"vendor-product">libxml2 --libxml2=C2=A0<br>=C2=A0</td> <td>xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xm= lRegNewParserCtxt after a strdup failure, i.e., it does not calculate a str= ing length after NULL checking.</td>
<td>2026-09-05</td>
<td>2.9</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86141" target=3D= "_blank" rel=3D"noopener">CVE-2026-86141</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not properly verify ownership of a curriculum object before acting on it,=
allowing authenticated users with the instructor role to delete or modify = curriculum sections and materials belonging to courses owned by other instr= uctors.</td>
<td>2026-09-02</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81198" target=3D= "_blank" rel=3D"noopener">CVE-2026-81198</a></td>
</tr>
<td class=3D"vendor-product">MasterStudy LMS WordPress Plugin--MasterStudy = LMS WordPress Plugin</td>
<td>The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 doe=
s not properly verify ownership of quiz question identifiers, allowing user=
s with instructor access to read other instructors' quiz questions, includi=
ng the correct answers and explanations.</td>
<td>2026-09-02</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81196" target=3D= "_blank" rel=3D"noopener">CVE-2026-81196</a></td>
</tr>
<td class=3D"vendor-product">MongoDB--C Driver</td>
<td>A memory-handling error in the BSON-to-JSON conversion helpers of the M= ongoDB C Driver can write a small number of bytes past the end of a heap bu= ffer when a binary field is encoded and the output is cut short at a caller= -configured length limit. A party who supplies the document content, with n=
o privileges on the application that links the driver, may cause a small am= ount of data outside the intended buffer to be altered.</td>
<td>2026-09-03</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84969" target=3D= "_blank" rel=3D"noopener">CVE-2026-84969</a></td>
</tr>
<td class=3D"vendor-product">mwiede jsch --mwiede jsch=C2=A0<br>=C2=A0</td> <td>A security flaw has been discovered in mwiede jsch up to 2.28.5. Affect=
ed is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch= /KnownHosts.java. Performing a manipulation of the argument known_hosts res= ults in improper check for certificate revocation. The attack is possible t=
o be carried out remotely. The attack is considered to have high complexity=
. The exploitability is told to be difficult. The exploit has been released=
to the public and may be used for attacks. Upgrading to version 2.28.6 is = able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd= 66bcafc42d23. You should upgrade the affected component.</td> <td>2026-09-06</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86231" target=3D= "_blank" rel=3D"noopener">CVE-2026-86231</a></td>
</tr>
<td class=3D"vendor-product">OpenCart--OpenCart</td>
<td>A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted ele= ment is an unknown function of the file catalog/controller/account/address.= php of the component Autocomplete Workflow. The manipulation of the argumen=
t address_1 results in cross site scripting. It is possible to launch the a= ttack remotely. The exploit has been made public and could be used. The ven= dor was contacted early about this disclosure but did not respond in any wa= y.</td>
<td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84437" target=3D= "_blank" rel=3D"noopener">CVE-2026-84437</a></td>
</tr>
<td class=3D"vendor-product">OpenCart--OpenCart</td>
<td>A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affect=
s an unknown function of the file catalog/controller/account/edit.php of th=
e component Autocomplete Workflow. This manipulation of the argument firstn= ame causes cross site scripting. The attack can be initiated remotely. The = exploit has been publicly disclosed and may be utilized. The vendor was con= tacted early about this disclosure but did not respond in any way.</td> <td>2026-09-02</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84438" target=3D= "_blank" rel=3D"noopener">CVE-2026-84438</a></td>
</tr>
<td class=3D"vendor-product">PocketMine-MP --PocketMine-MP=C2=A0<br>=C2=A0<=
<td>PocketMine-MP before 4.0.3 does not perform case-insensitive matching w= hen removing operator entries from ops.txt. The removeOp function lowercase=
s the supplied name but only removes an exactly matching entry, so an opera= tor name stored with non-lowercase letters cannot be revoked using the deop=
command, leaving the player as an operator until the entry is removed from=
ops.txt manually.</td>
<td>2026-09-06</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-48006" target=3D= "_blank" rel=3D"noopener">CVE-2021-48006</a></td>
</tr>
<td class=3D"vendor-product">Projectwolds--Online Attendance System 1.0<br>= =C2=A0</td>
<td>A security flaw has been discovered in Projectwolds Online Attendance S= ystem 1.0. Affected by this issue is some unknown functionality of the file=
profile.php. The manipulation of the argument email results in cross site = scripting. The attack may be performed from remote. The exploit has been re= leased to the public and may be used for attacks.</td>
<td>2026-09-06</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86226" target=3D= "_blank" rel=3D"noopener">CVE-2026-86226</a></td>
</tr>
<td class=3D"vendor-product">ramon-victor--freegpt-webui<br>=C2=A0</td>
<td>A security flaw has been discovered in ramon-victor freegpt-webui up to=
098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function = getJailbreak of the file server/config.py of the component Jailbreak Mode. = The manipulation results in race condition. It is possible to launch the at= tack remotely. The attack requires a high level of complexity. The exploita= bility is assessed as difficult. The exploit has been released to the publi=
c and may be used for attacks. This product takes the approach of rolling r= eleases to provide continious delivery. Therefore, version details for affe= cted and updated releases are not available. This vulnerability only affect=
s products that are no longer supported by the maintainer.</td> <td>2026-09-04</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85704" target=3D= "_blank" rel=3D"noopener">CVE-2026-85704</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277 does not verify that = the post whose schema it renders on the front end is publicly viewable, all= owing unauthenticated visitors to disclose the schema and associated conten=
t of draft, pending, private, scheduled and password-protected posts.</td> <td>2026-09-02</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77783" target=3D= "_blank" rel=3D"noopener">CVE-2026-77783</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277 does not verify that = the requesting user is permitted to read the specific post referenced in a = request before returning its content and SEO metadata, allowing users with = the Author role and above to read the title, body and metadata of other use= rs' non-public posts.</td>
<td>2026-09-02</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77785" target=3D= "_blank" rel=3D"noopener">CVE-2026-77785</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO--Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277 does not perform a ca= pability check when bulk metadata updates target taxonomy terms, and reuses=
the supplied object identifier across object types, allowing users with th=
e Author role and above to modify the SEO metadata of terms they cannot edi=
t and to overwrite the titles of posts belonging to other users.</td> <td>2026-09-02</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77787" target=3D= "_blank" rel=3D"noopener">CVE-2026-77787</a></td>
</tr>
<td class=3D"vendor-product">Rank Math SEO-Rank Math SEO</td>
<td>The Rank Math SEO WordPress plugin before 1.0.277 does not verify that =
a user is allowed to edit the object being modified before updating its SEO=
indexing metadata, allowing users with the Author role and above to alter = that metadata on content, taxonomy terms and user profiles they do not own,=
and to remove other users' content from the site's sitemap and search engi=
ne index.</td>
<td>2026-09-02</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77784" target=3D= "_blank" rel=3D"noopener">CVE-2026-77784</a></td>
</tr>
<td class=3D"vendor-product">rpm-software-management--popt</td>
<td>A flaw was found in popt. This vulnerability allows an attacker to prov= ide specially crafted configuration content to a host, which, when loaded, = can lead to a small memory corruption issue. This occurs because of an erro=
r in how the `poptConfigFileToString` function reallocates memory for buffe= rs. Successful exploitation could result in heap metadata corruption, poten= tially causing the affected process to become unavailable (denial of servic= e).</td>
<td>2026-09-01</td>
<td>2.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18743" target=3D= "_blank" rel=3D"noopener">CVE-2026-18743</a></td>
</tr>
<td class=3D"vendor-product">runZero--Platform</td>
<td>An authorization bypass in the runZero Platform MCP service has been re= solved in version 5.1.260826.0. This issue is an instance of CWE-639: Autho= rization Bypass Through User-Controlled Key and has an estimated CVSS score=
of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).</td>
<td>2026-09-01</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81846" target=3D= "_blank" rel=3D"noopener">CVE-2026-81846</a></td>
</tr>
<td class=3D"vendor-product">sambitraj--Student Management System</td>
<td>A flaw has been found in sambitraj Student Management System up to 56ba= 287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of t=
he file aca.sql of the component Password Handler. Executing a manipulation=
of the argument Password can lead to cleartext storage of sensitive inform= ation. The attack can be executed remotely. The exploit has been published = and may be used. This product implements a rolling release for ongoing deli= very, which means version information for affected or updated releases is u= navailable.</td>
<td>2026-08-31</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82699" target=3D= "_blank" rel=3D"noopener">CVE-2026-82699</a></td>
</tr>
<td class=3D"vendor-product">sambitraj--Student-Management-System</td>
<td>A security vulnerability has been detected in sambitraj Student-Managem= ent-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted ele= ment is the function session_start. Such manipulation leads to cookie witho=
ut 'httponly' flag. The attack may be launched remotely. A high complexity = level is associated with this attack. The exploitability is regarded as dif= ficult. The exploit has been disclosed publicly and may be used. This produ=
ct operates on a rolling release basis, ensuring continuous delivery. Conse= quently, there are no version details for either affected or updated releas= es. The project was informed of the problem early through an issue report b=
ut has not responded yet.</td>
<td>2026-08-31</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82697" target=3D= "_blank" rel=3D"noopener">CVE-2026-82697</a></td>
</tr>
<td class=3D"vendor-product">sdcb--chats</td>
<td>A flaw has been found in sdcb chats up to 1.12.0. This impacts the func= tion DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileCont= roller.cs of the component Signed File Download Endpoint. This manipulation=
causes missing authentication. Remote exploitation of the attack is possib= le. The attack's complexity is rated as high. The exploitability is said to=
be difficult. The exploit has been published and may be used. The vendor w=
as contacted early about this disclosure but did not respond in any way.</t=
<td>2026-08-31</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82906" target=3D= "_blank" rel=3D"noopener">CVE-2026-82906</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in=
the question creation endpoint where the isAddingQuestionsAllowed() method=
grants access to all callers when main.enableAskQuestions is enabled, igno= ring the records.allowQuestionsForGuests setting. Unauthenticated attackers=
can submit questions via the question/create API endpoint to bypass guest = submission restrictions and inject spam into the admin moderation queue.</t=
<td>2026-09-04</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85592" target=3D= "_blank" rel=3D"noopener">CVE-2026-85592</a></td>
</tr>
<td class=3D"vendor-product">Timetics--Timetics</td>
<td>The Timetics WordPress plugin through 1.0.61 does not enforce per-objec=
t ownership when updating appointments through its REST API, allowing users=
with its custom staff role to modify, disable, or take over appointments b= elonging to other staff members.</td>
<td>2026-09-02</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14326" target=3D= "_blank" rel=3D"noopener">CVE-2026-14326</a></td>
</tr>
<td class=3D"vendor-product">ugrep --ugrep=C2=A0<br>=C2=A0</td>
<td>ugrep before 7.6.0 contains a heap buffer over-read vulnerability in th=
e LZW decompressor when processing crafted .Z archive files. Attackers can = supply malformed .Z files that cause the decompressor to read one byte past=
the allocated heap buffer, potentially crashing the process.</td>
<td>2026-09-05</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15614" target=3D= "_blank" rel=3D"noopener">CVE-2025-15614</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's retry interceptor can append the body of a ranged retry respon=
se to bytes already delivered from an earlier partial response while still = presenting the original response's status and headers. This happens when an=
upstream server delivers part of a body without a trustworthy resume check= point, for example a non-success response whose headers were already sent o=
r a partial-content response with an unusable content range, then closes th=
e connection and answers the resumed range request with more bytes. As a re= sult the response body can be longer than the Content-Length that the appli= cation observes. An application that relays such a response to a downstream=
HTTP/1.1 peer without normalizing the framing can emit a body that exceeds=
the forwarded Content-Length, and the excess bytes can be interpreted as t=
he start of a following response, which enables downstream response splitti=
ng or desynchronization. Exploitation requires an attacker-controlled upstr= eam server and an application that forwards the response through a framing-= sensitive path. This affects undici versions before 6.28.1, from 7.0.0 up t=
o 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.=
1, 7.29.1, or 8.10.2.</td>
<td>2026-09-04</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18540" target=3D= "_blank" rel=3D"noopener">CVE-2026-18540</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's dump interceptor reads and discards a response body up to a co= nfigurable maximum size. When a response declares a Content-Length that exc= eeds the maximum, the interceptor aborts cleanly, but when a response has n=
o Content-Length and is chunked, the interceptor instead signals completion=
early once the accumulated size reaches the maximum, without pausing or ab= orting the request. Because the underlying parser keeps delivering body byt= es, a second completion signal fires and trips an internal assertion, which=
aborts the request and tears down the connection. The application is left = observing a misleading successful status with an empty or truncated body wh= ile the connection has actually been disconnected. This affects undici vers= ions from 7.1.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgr= ade to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84947" target=3D= "_blank" rel=3D"noopener">CVE-2026-84947</a></td>
</tr>
<td class=3D"vendor-product">undici--undici</td>
<td>undici's cache interceptor documents that only safe HTTP methods are ca= ched, but its logic to skip caching is built by subtracting the configured = methods from the set of safe methods, so an unsafe method such as POST, PUT=
, or DELETE is never placed in the skip list and instead falls through to t=
he full cache-read path. The response-storage gate also lacked a method che= ck, so a response to an unsafe request that is heuristically cacheable or c= arries an explicit Cache-Control directive is stored and later replayed fro=
m cache. Because response headers from a remote origin are untrusted, an or= igin can answer once with a cacheable status and then have the client's own=
subsequent state-changing requests to that path served from the stale cach=
e entry without ever reaching the origin, an integrity failure that occurs = under the interceptor's default configuration. This affects undici versions=
from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade =
to undici 7.29.1 or 8.10.2.</td>
<td>2026-09-04</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85008" target=3D= "_blank" rel=3D"noopener">CVE-2026-85008</a></td>
</tr>
<td class=3D"vendor-product">valkey-io--valkey</td>
<td>A security flaw has been discovered in valkey-io valkey 9.1.0. The affe= cted element is the function handleClientsBlockedOnKey of the file src/bloc= ked.c of the component Blocked-on-keys Subsystem. The manipulation results =
in use after free. The attack may be performed from remote. A high complexi=
ty level is associated with this attack. The exploitability is described as=
difficult. The exploit has been released to the public and may be used for=
attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d2= 0b. Applying a patch is advised to resolve this issue.</td>
<td>2026-08-31</td>
<td>2.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82631" target=3D= "_blank" rel=3D"noopener">CVE-2026-82631</a></td>
</tr>
<td class=3D"vendor-product">valkey-io--valkey</td>
<td>A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is t=
he function moduleTimerHandler of the file src/module.c of the component Mo= dule Timer Subsystem. This manipulation causes double free. The attack can =
be initiated remotely. The exploit has been publicly disclosed and may be u= tilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this = issue, it is recommended to deploy a patch.</td>
<td>2026-08-31</td>
<td>2.4</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82677" target=3D= "_blank" rel=3D"noopener">CVE-2026-82677</a></td>
</tr>
<td class=3D"vendor-product">valkey-io--valkey<br>=C2=A0</td>
<td>A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. T= his affects the function kvstoreGetHashtable of the file src/kvstore.c. Thi=
s manipulation of the argument didx causes out-of-bounds read. It is possib=
le to initiate the attack remotely. The attack is considered to have high c= omplexity. It is indicated that the exploitability is difficult. The exploi=
t has been made available to the public and could be used for attacks. Patc=
h name: 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is = recommended to deploy a patch. Exploitation requires cluster mode plus atta= cker-controlled dump.rdb at startup (data-dir write access, replication fee=
d, or a stored crafted RDB) - an attacker-position DoS at boot, not network=
pre-auth. The issue report was closed stating it "is worth fixing for the = sake of memory safety=C2=A6 but I don't think it meets our bar for a securi=
ty disclosure."</td>
<td>2026-09-06</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86227" target=3D= "_blank" rel=3D"noopener">CVE-2026-86227</a></td>
</tr>
<td class=3D"vendor-product">wakujs--waku</td>
<td>Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the=
unstable_redirect() helper exported from waku/router/server (packages/waku= /src/router/define-router.tsx:156-161) accepts an arbitrary string and refl= ects it unchanged into the HTTP Location response header with no URL valida= tion, scheme restriction, or path-only enforcement. Any application that pa= sses user-controlled input to this helper - the natural pattern documented =
in the JSDoc and official fixtures - is vulnerable to open redirect attacks=
. An attacker who convinces a victim to click a crafted link can silently r= edirect the browser to an arbitrary external domain, enabling phishing, cre= dential harvesting, and OAuth token theft. Additionally, scheme-relative UR=
Ls (//evil.example/) bypass naive https?://-only allow-list filters that de= velopers might add as ad-hoc mitigations. This issue has been patched in ve= rsion 1.0.0-beta.1.</td>
<td>2026-09-03</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49456" target=3D= "_blank" rel=3D"noopener">CVE-2026-49456</a></td>
</tr>
<td class=3D"vendor-product">Weaver Show Posts--Weaver Show Posts</td>
<td>The Weaver Show Posts WordPress plugin before 1.8.1 unserialises the co= ntent of an imported file, which could lead to PHP object injections issues=
when a high privilege user import a malicious file and a suitable gadget c= hain is present on the blog.</td>
<td>2026-09-02</td>
<td>3.3</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-3360" target=3D"= _blank" rel=3D"noopener">CVE-2023-3360</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --EmbedPress<br>=C2=A0</td> <td>The EmbedPress WordPress plugin before 4.6.4 does not correctly restric=
t access to one of its Google Reviews REST routes to administrators, allowi=
ng any authenticated user with contributor-level access or above to read th=
e site administrator's email address, a value WordPress core withholds from=
that role.</td>
<td>2026-09-05</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84926" target=3D= "_blank" rel=3D"noopener">CVE-2026-84926</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --EmbedPress<br>=C2=A0</td> <td>The EmbedPress WordPress plugin before 4.6.4 does not perform a suffici= ent authorization check on one of its Google Reviews REST API routes, allow= ing users with the Contributor role and above to modify a site-wide store, = deleting entries an administrator configured and injecting their own, which=
are rendered publicly across the site.</td>
<td>2026-09-05</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84927" target=3D= "_blank" rel=3D"noopener">CVE-2026-84927</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --Joli Table Of Contents<br>= =C2=A0</td>
<td>The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanit= ise and escape some of its settings before outputting them in an admin page=
, which could allow high-privilege users such as administrators to perform = Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit=
y is disallowed, for example in a multisite setup.</td>
<td>2026-09-05</td>
<td>3.5</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15694" target=3D= "_blank" rel=3D"noopener">CVE-2025-15694</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin --My Private Site<br>=C2=A0</=
<td>The My Private Site WordPress plugin before 4.2.3 does not apply its si= te-privacy access control to certain unauthenticated front-end read surface=
s, allowing unauthenticated users to view post content, comments and post U= RLs from a site the administrator placed behind mandatory login.</td> <td>2026-09-05</td>
<td>3.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81348" target=3D= "_blank" rel=3D"noopener">CVE-2026-81348</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Events Calendar<br>=C2=A0</t=
<td>The Events Calendar WordPress plugin before 6.17.3.1 does not restrict = non-public content to the users entitled to read it on its public REST arch= ives, allowing users with a low-privilege role such as contributor to read = the full contents of every unpublished record on the site, including other = users'.</td>
<td>2026-09-05</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84745" target=3D= "_blank" rel=3D"noopener">CVE-2026-84745</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--JCH Optimize<br>=C2=A0</td> <td>The JCH Optimize WordPress plugin before 5.0.1 does not properly restri=
ct a directory path provided to one of its administrative image-browsing fe= atures to within the site, allowing high-privilege users, administrators on=
single-site and sub-site administrators on multisite, to enumerate directo= ries and file names outside the web root.</td>
<td>2026-09-05</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-15693" target=3D= "_blank" rel=3D"noopener">CVE-2025-15693</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Kirki<br>=C2=A0</td>
<td>The Kirki WordPress plugin before 6.3.0 does not check that a user is a= llowed to act on a collaboration comment before changing its state, allowin=
g users whom an administrator has granted content-level access to the page = builder to modify comments left by other users, including on pages they can= not themselves open.</td>
<td>2026-09-05</td>
<td>2.2</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84225" target=3D= "_blank" rel=3D"noopener">CVE-2026-84225</a></td>
</tr>
<td class=3D"vendor-product">WordPress Plugin--Smart Post<br>=C2=A0</td>
<td>The Smart Post WordPress plugin before 4.0.8 does not check the type, o= wnership or status of the post it is asked to duplicate, allowing users wit=
h contributor privileges and above to copy any private or password protecte=
d post into a draft of their own and read its content and metadata.</td> <td>2026-09-05</td>
<td>2.7</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78150" target=3D= "_blank" rel=3D"noopener">CVE-2026-78150</a></td>
</tr>
<td class=3D"vendor-product">yaojingang--GEOFlow</td>
<td>A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vu= lnerability affects the function unlink of the file app/Http/Controllers/Ad= min/ImageLibraryController.php of the component Image Library Cleanup. The = manipulation of the argument file_path results in path traversal. The attac=
k may be performed from remote. The exploit is now public and may be used. = Upgrading to version 2.1.1 is able to resolve this issue. The patch is iden= tified as 67abfd864a15d169a78429f3290c91cb3b93e849. It is recommended to up= grade the affected component.</td>
<td>2026-08-31</td>
<td>3.8</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82665" target=3D= "_blank" rel=3D"noopener">CVE-2026-82665</a></td>
</tr>
<td class=3D"vendor-product">zephyrproject--zephyr</td>
<td>The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statical= ly-allocated work nodes through a free-list i3c_ibi_work_nodes_free impleme= nted as a plain sys_slist_t, which provides no synchronization. The allocat= ion helpers (i3c_ibi_work_enqueue, i3c_ibi_work_enqueue_target_irq, i3c_ibi= _work_enqueue_hotjoin, i3c_ibi_work_enqueue_controller_request, i3c_ibi_wor= k_enqueue_cb) called sys_slist_get() directly from ISR context, while the w= orkqueue handler i3c_ibi_work_handler() returned nodes with sys_slist_appen= d() from the workqueue thread, with no lock on either side. Because sys_sli= st_get() and sys_slist_append() are neither atomic nor interrupt-safe, an I=
BI interrupt that fires while the workqueue thread is mid-append (or a trul=
y parallel access under CONFIG_SMP) races on the shared list. This corrupts=
the list linkage: a node may be handed to two consumers, a node may be los=
t, or the head/tail pointers may be left inconsistent so sys_slist_get() re= turns a stale or garbage pointer. In the double-hand-out case the subsequen=
t memcpy(ibi_node, ibi_work, sizeof(*ibi_node)) overwrites a node still in = flight; a garbage pointer turns the same memcpy into an out-of-bounds write=
. The race is driven by I3C bus traffic - IBIs, hot-joins, and controller-r= ole requests originate from target devices on the bus, and I3C supports hot= -joining devices. An attacker controlling an I3C peripheral on the board's = chip-to-chip bus can generate high-frequency interrupts timed to collide wi=
th the free operation. Exploitation requires physical access to the bus and=
winning a narrow timing window; the most realistic impact is a crash or ha=
ng (denial of service), with memory corruption possible but hard to control=
. The fix wraps all free-list sys_slist_get()/sys_slist_append() operations=
in the new ibi_work_alloc()/ibi_work_free() helpers, each guarded by a k_s= pinlock (ibi_work_lock), closing the race across ISR and thread contexts.</=
<td>2026-08-31</td>
<td>3.1</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-14367" target=3D= "_blank" rel=3D"noopener">CVE-2026-14367</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
<div id=3D"snya_v">
<h2 id=3D"snya_v_title">Severity Not Yet Assigned</h2>
<table id=3D"table_severity_not_yet_assigned" class=3D"table table-style-al= ign-center no-tablesaw" style=3D"table-layout: fixed; width: 100%;" border= =3D"1" summary=3D"Severity Not Yet Assigned">
<thead>
<th class=3D"vendor-product" style=3D"width: 24%;" scope=3D"col">
<span class=3D"primary-vendor">Primary</span><br><span class=3D"primary-ven= dor">Vendor</span> -- Product</th>
<th style=3D"width: 44%;" scope=3D"col">Description</th>
<th style=3D"width: 10%;" scope=3D"col">Published</th>
<th style=3D"width: 8%;" scope=3D"col">CVSS Score</th>
<th style=3D"width: 7%;" scope=3D"col">Source Info</th>
</tr>
</thead>
<tbody>
<td class=3D"vendor-product">1Hive--gardens-v2</td>
<td>Gardens v2 is a modular governance framework that enables communities t=
o create and manage multiple governance pools with customizable parameters = and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9,=
StreamingEscrow.claim() correctly rejects withdrawals while an escrow is d= isputed, but the permissionless syncOutflow() path performs the same excess= -balance transfer without checking disputed. After a streaming proposal is = challenged, anyone can call syncOutflow() to transfer escrowed SuperTokens =
to the proposal beneficiary while the dispute is pending. If the proposal i=
s later rejected, those tokens cannot be recovered by drainToStrategy(). Th=
is issue has been patched in 0xc9d4e0dacd937364793278180551e59d93cd43f9.</t=
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53924" target=3D= "_blank" rel=3D"noopener">CVE-2026-53924</a></td>
</tr>
<td class=3D"vendor-product">1Hive--gardens-v2</td>
<td>Gardens v2 is a modular governance framework that enables communities t=
o create and manage multiple governance pools with customizable parameters = and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prio=
r, normal beneficiary payout paths in StreamingEscrow preserve depositAmoun= t() while an active stream needs an escrow reserve. However, the approve-si=
de dispute resolution path drains the whole available escrow balance to the=
proposal beneficiary. At time of publication, there are no publicly known = patches.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57445" target=3D= "_blank" rel=3D"noopener">CVE-2026-57445</a></td>
</tr>
<td class=3D"vendor-product">adaltas--node-csv</td>
<td>node-csv is a full-featured CSV parser with a simple API that is tested=
against large datasets. Prior to 7.0.2, csv-parse with the columns and gro= up_columns_by_name options enabled treats a duplicate __proto__ header as a=
n existing property in packages/csv-parse/lib/api/index.js, assigns an atta= cker-controlled array through obj['__proto__'], and replaces the parsed rec= ord object's prototype. A malicious CSV header can therefore inject inherit=
ed array values into the returned record, hide those inherited values from = JSON serialization, and affect property enumeration and type or shape check=
s in applications that process the record. This issue is fixed in version 7= .0.2.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85063" target=3D= "_blank" rel=3D"noopener">CVE-2026-85063</a></td>
</tr>
<td class=3D"vendor-product">AMD--AMD Radeon Instinct MI25 Graphics Product= s</td>
<td>Release of an invalid pointer in the AMD kernel mode driver (KMD) could=
allow a privileged attacker to create a double free condition potentially = leading to arbitrary code execution.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2023-20511" target=3D= "_blank" rel=3D"noopener">CVE-2023-20511</a></td>
</tr>
<td class=3D"vendor-product">andialbrecht--sqlparse</td>
<td>sqlparse is a non-validating SQL parser module for Python. Prior to 0.6= .0, sqlparse.format(sql, reindent=3DTrue) and sqlformat --reindent route at= tacker-controlled parenthesized tuple lists through ReindentFilter._get_off= set() in sqlparse/filters/reindent.py, where _flatten_up_to_token() repeate= dly rebuilds and joins the statement prefix. Thousands of offset calculatio=
ns walk an expanding token tree, producing quadratic CPU consumption for in= puts that remain below MAX_GROUPING_TOKENS and causing request delays, redu= ced throughput, or worker starvation. This issue is fixed in version 0.6.0.= </td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84305" target=3D= "_blank" rel=3D"noopener">CVE-2026-84305</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache Allura</td> <td>Apache Allura's=C2=A0webhooks=C2=A0are vulnerable to Server-Side Reques=
t Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users a=
re recommended to upgrade to version 1.21.0, which fixes the issue.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80181" target=3D= "_blank" rel=3D"noopener">CVE-2026-80181</a></td>
</tr>
<td class=3D"vendor-product">Apache Software Foundation--Apache SkyWalking<=
<td>PagerDuty alarm hook transmits the integration routing key over clearte=
xt HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer=
plain HTTP with a redirect. That does not remove the exposure. The initial=
POST -- including the JSON body containing the routing key -- is written t=
o the socket unencrypted before any redirect response is received. Redirect= ion affects only whether the request is retried securely, not whether the f= irst copy left the host in the clear. This issue affects Apache SkyWalking:=
from 9.6.0 through 11.0.0. Users are recommended to upgrade to version 11.= 0.0, which fixes the issue.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71216" target=3D= "_blank" rel=3D"noopener">CVE-2026-71216</a></td>
</tr>
<td class=3D"vendor-product">AppNitro -- MachForm<br>=C2=A0</td>
<td>An arbitrary file upload vulnerability in AppNitro MachForm v30 allows = attackers to execute arbitrary code via uploading a crafted .phar file.</td=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78839" target=3D= "_blank" rel=3D"noopener">CVE-2026-78839</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in ash= -project ash allows an attacker to submit a non-finite decimal value that b= ypasses numeric bounds constraints or fails later operations on the value. = Ash.Type.Decimal cast input through Ecto's decimal cast in cast_input/2 and=
cast_stored/2 (lib/ash/type/decimal.ex) without checking that the resultin=
g value is finite. Elixir's Decimal represents Infinity and NaN as valid st= ructs, so a value such as "Infinity" or "NaN" passed casting and was persis= ted. Because NaN compares as false against every bound, min and max constra= ints do not reject it, and the stored special value later raises when used =
in Decimal arithmetic or is refused by the data layer, failing subsequent r= equests. The fix rejects any non-finite Decimal during casting. This issue = affects ash: from 1.28.0 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82734" target=3D= "_blank" rel=3D"noopener">CVE-2026-82734</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Uncontrolled Resource Consumption vulnerability in ash-project ash allo=
ws an attacker to force an expensive regular expression to run on input tha=
t a length constraint should have already rejected. Ash.Type.String.apply_c= onstraints/2 (lib/ash/type/string.ex) evaluated the :match regex regardless=
of the min_length and max_length constraints on the same attribute. Becaus=
e the length check did not gate the regex, an over-length value that the le= ngth constraint rejects still had the pattern applied to it, so the length = limit that would otherwise bound the work never constrained the regex input=
. Against a backtracking pattern this yields catastrophic regex evaluation =
on attacker-sized input, and even a linear pattern runs on arbitrarily larg=
e input, consuming CPU per request. The fix skips the :match regex whenever=
a length constraint is violated, making the two checks order-independent. = This issue affects ash: from 0.10.0 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82735" target=3D= "_blank" rel=3D"noopener">CVE-2026-82735</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Incorrect Behavior Order: Validate Before Canonicalize vulnerability in=
ash-project ash lets an attacker store a case-insensitive string value tha=
t violates its length or match constraints. Ash.Type.CiString.apply_constra= ints/2 (lib/ash/type/ci_string.ex) validated the max_length, min_length, an=
d match constraints against the value as submitted, while the type case-fol=
ds the string (per its casing) for storage and comparison. Because validati=
on ran before folding, an attacker can submit a value whose folded form bre= aks a constraint but whose original form passes: for example, against a mat=
ch pattern requiring uppercase, an uppercase value that is stored lowercase=
d persists a value the pattern rejects. The fix case-folds the value at the=
start of apply_constraints/2, so the constraints are checked against the f= orm that is actually stored. This issue affects ash: from 1.29.0-rc0 before=
3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82736" target=3D= "_blank" rel=3D"noopener">CVE-2026-82736</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Integer Overflow or Wraparound vulnerability in ash-project ash lets an=
attacker corrupt a stored vector and crash later reads of it by submitting=
a vector with more than 65,535 elements. Ash.Vector.new/1 (lib/ash/vector.= ex) encodes a vector as <<dim::unsigned-16, 0::unsigned-16>> fo= llowed by the element floats, packing the element count into a 16-bit field=
without checking its range. A list of more than 65,535 elements wraps the = dimension modulo 65,536, so the encoded header records a dimension that dis= agrees with the number of stored floats. from_binary/1 later reads binary-s= ize(dim)-unit(32) from the wrapped header, so every read of the corrupted v= alue misparses and raises, denying access to the affected record. The fix r= ejects any vector whose dimension exceeds 65,535. This issue affects ash: f= rom 2.14.13 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82737" target=3D= "_blank" rel=3D"noopener">CVE-2026-82737</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Improper Input Validation vulnerability in ash-project ash allows an at= tacker to persistently deny reads of a record by storing a non-version-7 UU=
ID in an Ash.Type.UUIDv7 attribute. Ash.Type.UUIDv7.cast_input/2 accepts an=
y well-formed UUID string, including non-version-7 UUIDs, and stores it as =
a 16-byte binary. On read, cast_stored/2 (lib/ash/type/uuid_v7.ex) routes t=
he stored binary back through cast_input/2, which since an input-validation=
tightening in v3.6.3 matches only version-7 (and optionally version-4) 16-= byte binaries and otherwise expects a 36-character string. A stored non-v7 = 16-byte binary matches neither clause and returns :error, so every later re=
ad of that record fails. An attacker able to set such an attribute poisons = the row permanently. The fix decodes any 16-byte stored binary directly in = cast_stored/2. This issue affects ash: from 3.6.3 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82738" target=3D= "_blank" rel=3D"noopener">CVE-2026-82738</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash discloses the stored value of a confirmed field to a=
n actor who fails its confirmation check. Ash.Resource.Validation.Confirm's=
atomic implementation (atomic/2 in lib/ash/resource/validation/confirm.ex)=
built the mismatch error with its value set to the field being confirmed. = When the actor supplies only the confirmation argument and not the field it= self, value resolves through atomic_ref/2 to the field's current stored val= ue, so the mismatch error echoes that stored value back to the actor. Again=
st a confirmation guarding a sensitive attribute, an actor can submit a del= iberately wrong confirmation and read the real value from the returned erro=
r. The fix reports the actor-supplied confirmation in the error instead of = the stored field value. This issue affects ash: from 2.17.20 before 3.32.2.= </td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82739" target=3D= "_blank" rel=3D"noopener">CVE-2026-82739</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Improper Input Validation vulnerability in ash-project ash fails to enf= orce the outer array constraints on a doubly-nested {:array, {:array, type}=
} attribute, letting invalid input pass validation. Ash.Type.apply_constrai= nts/3 (lib/ash/type/type.ex) handled the {:array, {:array, type}} case by m= apping only the inner {:array, type} constraints over each element, so cons= traints declared on the outer array (such as min_length, max_length, and ni= l_items?) were never applied. An attacker could submit an outer list that v= iolates those constraints (too many elements, or nil entries where disallow= ed) and have it accepted and persisted. The fix enforces the outer array co= nstraints and adds explicit handling for nil and non-list inputs. This issu=
e affects ash: from 2.16.1 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82740" target=3D= "_blank" rel=3D"noopener">CVE-2026-82740</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Improper Validation of Specified Type of Input vulnerability in ash-pro= ject ash lets an attacker confuse the stored type tag of an Ash.Type.Union = value that uses storage: :map_with_tag, bypassing that member's validation = and any tag-based authorization. For a union with storage: :map_with_tag, e= ach member is identified in storage by a configured tag and tag_value. Ash.= Type.Union.dump_to_native/2 (lib/ash/type/union.ex) did not force the confi= gured tag when writing the value, so a tag carried in the submitted value w=
as persisted verbatim. An attacker can therefore store a value whose data b= elongs to one member but whose tag names a different member. On read the va= lue is re-selected by its tag and treated as the incompatible member (a typ=
e confusion), bypassing the real member's constraints and any logic or poli=
cy that branches on the union tag. The fix drops any incoming tag and force=
s the configured tag value on dump. This issue affects ash: from 2.14.18 be= fore 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82741" target=3D= "_blank" rel=3D"noopener">CVE-2026-82741</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Uncontrolled Resource Consumption vulnerability in ash-project ash lets=
an attacker exhaust node memory by matching a filter that spans multiple t= o-many relationships in memory. Ash.Filter.Runtime matches a filter against=
an in-memory record by first expanding the record into combinations of its=
related rows. flatten_relationships/2 (lib/ash/filter/runtime.ex) eagerly = built the full Cartesian product across the filter's to-many relationship p= aths, so a record with K to-many relationships of M rows each materialized =
on the order of M^K scenarios before any predicate was checked. A filter or=
dataset that reaches several sizeable to-many relationships therefore allo= cates memory combinatorially and can exhaust the node. The fix streams the = expansion lazily and short-circuits on the first matching scenario, boundin=
g the work. This issue affects ash: from 1.29.0-rc0 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82742" target=3D= "_blank" rel=3D"noopener">CVE-2026-82742</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Uncontrolled Resource Consumption vulnerability in ash-project ash lets=
a slow asynchronous read spin a scheduler thread at full CPU while the fra= mework waits for it. Ash.Actions.Read.AsyncLimiter.await_at_least_one/1 (li= b/ash/actions/read/async_limiter.ex) waited for concurrent async read tasks=
by polling each with Task.yield(task, 0) in a tight loop rather than block= ing. While every outstanding task is still running (a slow related-data loa=
d or calculation), the loop returns immediately and repeats, busy-spinning = and holding a BEAM scheduler at full CPU for the whole duration of the slow=
read; concurrent slow reads tie up further schedulers. The fix waits with = Task.yield_many (a non-blocking sweep followed by a blocking wait with time= out: :infinity), so the process sleeps until a task completes instead of sp= inning. This issue affects ash: from 2.19.0 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82743" target=3D= "_blank" rel=3D"noopener">CVE-2026-82743</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Not Failing Securely (Failing Open) vulnerability in ash-project ash sk= ips an Ash.Reactor change when the guard controlling it raises, so a change=
meant to run does not. An Ash.Reactor change step can be gated by where va= lidations that decide whether the change runs. Ash.Reactor.ChangeStep (lib/= ash/reactor/steps/change_step.ex) evaluated those guards in apply_where_cla= uses/3, and apply_validation rescued any exception into {:error, error}. Th=
e reduce treated that identically to a guard whose condition was simply not=
met and bypassed the change. So when a guard raises (for example on attack= er-influenced input), a change that enforces a security-relevant modificati=
on is skipped rather than failing the step. The fix distinguishes a raised = exception (now {:raised, error}) and halts the step with an error, failing = closed. This issue affects ash: from 3.0.0-rc.17 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82744" target=3D= "_blank" rel=3D"noopener">CVE-2026-82744</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Improper Access Control vulnerability in ash-project ash lets a create = action overwrite an existing record when the ETS or Mnesia data layer is us= ed, because neither enforced primary-key uniqueness on insert. Unlike a SQL=
data layer, whose unique primary-key constraint rejects a duplicate, the E=
TS and Mnesia data layers implemented create as a keyed insert that replace=
s any existing entry with the same primary key (lib/ash/data_layer/ets/ets.= ex, lib/ash/data_layer/mnesia/mnesia.ex). An actor who can set the primary = key on a create (for example a user-supplied string or integer key) can sub= mit a create whose key matches an existing record and silently overwrite it=
, destroying and replacing another entity's data without going through the = update action or its policies. The fix rejects a create whose primary key a= lready exists with an already-taken error, and only allows duplicates for k= eyless resources. This issue affects ash: from 0.4.0 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82745" target=3D= "_blank" rel=3D"noopener">CVE-2026-82745</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Missing Authorization vulnerability in ash-project ash allows an actor =
to update records forbidden by resource policies through the atomic path of=
Ash.update_many/4. Ash.update_many/4 runs as a single atomic statement (a = data-layer update_many, for example a SQL MERGE) whenever an atomic strateg=
y is used and the data layer supports it. Ash.Actions.Update.UpdateMany (li= b/ash/actions/update/update_many.ex) took that path even under authorize?: = true without applying the resource's policies, so the statement updated eve=
ry row matched by primary key regardless of the policy filter that authoriz= ation would impose. An actor could therefore update records the policies fo= rbid, such as rows belonging to another actor or tenant. The fix restricts = the atomic path to data layers supporting changeset filters when authorizin=
g, authorizes each changeset, and merges the resulting policy filter into e= ach changeset so the statement only touches authorized rows. This issue aff= ects ash: from 3.29.0 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82746" target=3D= "_blank" rel=3D"noopener">CVE-2026-82746</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Incorrect Authorization vulnerability in ash-project ash returns record=
s that a runtime read policy denies to any actor. When a resource has an ac= cess_type :runtime read policy (a check evaluated per record rather than co= mpiled to a filter), Ash.Policy.Authorizer decides each record in check_res= ult/1 (lib/ash/policy/authorizer/authorizer.ex) by discarding impossible po= licy scenarios and inspecting what remains. When every scenario for a recor=
d was impossible, meaning no policy can authorize it and it must be forbidd= en, the empty-scenario branch instead kept the record ({[record | data], au= thorizer, any_forbidden?}) and returned it as authorized. As a result, reco= rds the runtime read policy denies are returned to any actor. The fix forbi=
ds a record whose scenarios are all impossible. This issue affects ash: fro=
m 3.4.44 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82747" target=3D= "_blank" rel=3D"noopener">CVE-2026-82747</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Incorrect Authorization vulnerability in ash-project ash authorizes an = aggregate under one read action while computing it under another, so an agg= regate can run with policies that do not match the action it was authorized=
against. Ash.Actions.Aggregate groups aggregates by their {authorize?, rea= d_action} and authorizes each group under that read action, but when buildi=
ng the data query it selected the action as opts[:action] || read_action ||=
<primary read> (lib/ash/actions/aggregate.ex). When a caller passed =
an :action option, the aggregate query ran under that action while authoriz= ation had been computed for the group's own read_action. If the run action'=
s read policies are more permissive than the authorized one, the aggregate =
(a count or sum) is computed over records the authorized action's policies = would have excluded, disclosing information about data the actor cannot rea=
d. The fix runs the aggregate under the same read_action it is authorized a= gainst. This issue affects ash: from 3.5.13 before 3.32.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82748" target=3D= "_blank" rel=3D"noopener">CVE-2026-82748</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash</td>
<td>Incorrect Authorization vulnerability in ash-project ash widens a relat= ionship's parent(...) scoping filter to match unintended records when the r= eferenced parent field cannot be resolved. Loading a relationship whose fil= ter references parent(...) resolves that expression against the parent reco= rd. resolve_parent_in_filter/3 (lib/ash/actions/read/relationships.ex) reso= lved an unresolvable parent reference (for example when the referenced fiel=
d was not selected on the source query) to nil rather than failing. A scopi=
ng predicate such as org_id =3D=3D parent(org_id) then becomes an IS NULL m= atch, and a guard like is_nil(parent(org_id)) or org_id =3D=3D parent(org_i=
d) activates its unrestricted branch, so the relationship returns records t=
he scope was meant to exclude. The fix fails the read with an error when a = parent(...) reference cannot be resolved, instead of defaulting to nil. Thi=
s issue affects ash: from 3.13.2 before 3.32.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82749" target=3D= "_blank" rel=3D"noopener">CVE-2026-82749</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Reliance on Cookies without Validation and Integrity Checking vulnerabi= lity in ash-project ash_admin lets an attacker who controls a sibling subdo= main rebind an admin's session to a different actor, tenant, or authorizati=
on mode. AshAdmin's client JavaScript read its state cookies (tenant, actor= _resource, actor_primary_key, actor_action, actor_domain, actor_authorizing=
, actor_paused) by matching the cookie name with an unanchored regular expr= ession (new RegExp(name + "=3D([^;]+)")) against the whole document.cookie.=
Any cookie whose name merely ends with the requested name therefore matche=
s, and whichever is serialized first wins. Because cookies are shared acros=
s a registrable domain, a compromised sibling subdomain can set a shadowing=
cookie (for example xactor_authorizing) with Domain=3D.example.com that fl= ows unvalidated into the admin's LiveSocket connect params. The fix matches=
cookie names by exact equality. This issue affects ash_admin: from 0.9.1 b= efore 1.3.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75757" target=3D= "_blank" rel=3D"noopener">CVE-2026-75757</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Stored Cross-site Scripting vulnerability in ash-project ash_admin exec= utes attacker-supplied record content as script in an administrator's brows= er. The relationship typeahead components AshAdmin.Components.Resource.Rela= tionshipField and AshAdmin.Components.Resource.ManagedRelationshipSelectFie=
ld highlight the matched search term by wrapping it in <b> tags and r= endering the whole string with Phoenix.HTML.raw/1. The highlighted value is=
the destination record's label_field, ordinary database content that is of= ten written by lower-privileged users. Because raw/1 disables output escapi=
ng for the entire string, a stored label such as <img src=3Dx onerror=3D= ...> runs as JavaScript in the admin's session as soon as a matching rec= ord appears in the dropdown, giving the attacker the admin's privileges ove=
r everything AshAdmin exposes. The fix HTML-escapes the label before insert= ing the highlight markup. This issue affects ash_admin: from 0.13.0 before = 1.3.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77850" target=3D= "_blank" rel=3D"noopener">CVE-2026-77850</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Use of Insufficiently Random Values vulnerability in ash-project ash_ad= min ships a hardcoded, publicly known CSP nonce, defeating nonce-based Cont= ent-Security-Policy protection. When mounted without :csp_nonce_assign_key,=
AshAdmin.Router.ash_admin/2 defaulted the img, style, and script nonces to=
the literal constant ash_admin-Ed55GFnX, which AshAdmin.Layouts wrote verb= atim into the nonce attribute of its inline <style> and <script>=
; tags on every response. The value is a compile-time constant published in=
the repository and is never rotated per request. If an application's CSP s= cript-src allow-lists that documented default, any HTML-injection sink on a=
n admin page can reuse the known nonce to run inline scripts the policy was=
meant to block. The fix generates a fresh random nonce per request. This i= ssue affects ash_admin: from 0.10.8 before 1.3.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81852" target=3D= "_blank" rel=3D"noopener">CVE-2026-81852</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Authorization Bypass Through User-Controlled Key vulnerability in ash-p= roject ash_admin turns a record-lookup URL into an equality oracle over sen= sitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the compos= ite-primary-key form (Base64 plus ETF) and returns the decoded map verbatim=
as the lookup filter, without checking that its keys are the resource's pr= imary-key fields. The deserialization guards bound size, block new atoms an=
d funs, and reject nested expressions, but none restricts which fields come=
back, and :safe still allows any already-interned attribute name. An attac= ker can therefore encode %{api_token: "guess"} and have it spliced into the=
lookup filter, brute-forcing a sensitive attribute value (API token, reset=
token) one equality guess at a time; Map.to_list/1 also accepts structs, y= ielding a bogus __struct__ key. The fix rejects any decoded key that is not=
a real primary-key field. This issue affects ash_admin: from 0.1.0 before = 1.3.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81853" target=3D= "_blank" rel=3D"noopener">CVE-2026-81853</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Improper Limitation of a Pathname to a Restricted Directory (Path Trave= rsal) vulnerability in ash-project ash_admin allows writing attacker-contro= lled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.F= orm.consume_file_uploads/1 builds the destination as Path.join([tmp_dir, en= try.client_name]) and writes it with File.cp!/2. entry.client_name is the b= rowser-supplied filename and is not sanitized, and Path.join/1 does not nor= malize ... An upload named ../../../../var/www/app/priv/static/x.png theref= ore escapes the random temp directory and lands anywhere the BEAM user can = write, enabling arbitrary file write and potentially remote code execution =
by overwriting application assets, configuration, or cron/ssh files. The on=
ly guard is an extension allowlist defaulting to :any that checks only the = extension. The fix strips path components with Path.basename/1 before joini= ng. This issue affects ash_admin: from 0.13.7 before 1.3.1.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82673" target=3D= "_blank" rel=3D"noopener">CVE-2026-82673</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Improper Encoding or Escaping of Output vulnerability in ash-project as= h_admin lets an attacker who controls a record's string primary key rewrite=
the target of AshAdmin's row-action links. The Table, DataTable, and Show = components built row-action URLs by raw string interpolation, splicing the = primary key (and table, domain, and resource names) into the query string w= ithout URL-encoding. Ash resources routinely use user-settable string prima=
ry keys (slugs, emails). Because Plug.Conn.Query resolves duplicate paramet= ers last-wins and primary_key is interpolated last, a stored key such as fo= o&action_type=3Ddestroy injects parameters that override the link, so a=
n admin clicking edit is sent to a destroy form or an arbitrary resource; a=
# truncates the query into a fragment. The fix builds every link with URI.= encode_query/1, encoding all interpolated values. This issue affects ash_ad= min: from 0.3.0-rc.0 before 1.3.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82681" target=3D= "_blank" rel=3D"noopener">CVE-2026-82681</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_admin</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in a= sh-project ash_admin lets any client that can reach the admin LiveView exha= ust the BEAM atom table and crash the entire node. Two LiveView event handl= ers interned atoms from unvalidated client input: AshAdmin.PageLive's set_a= ctor built modules from the resource/domain payload with Module.concat/1, a=
nd AshAdmin.Components.Resource.Show's calculate converted every submitted = form key with String.to_atom/1. Atoms are never garbage collected and the t= able is capped, so flooding either event with random names mints a new atom=
per request until the VM aborts, taking down every application on the node=
. The fix resolves the submitted resource/domain against the known shown re= sources and maps calculation keys to declared arguments, so no client-suppl= ied string is interned. This issue affects ash_admin: from 0.1.0 before 1.3= .1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82722" target=3D= "_blank" rel=3D"noopener">CVE-2026-82722</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash_ai discloses provider request state and credentials =
in a user-facing validation error. In AshAi.Changes.Vectorize, when the emb= edding provider call fails the change added a changeset error whose message=
inspected the raw error term (An error occurred while generating embedding=
s: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Chang= es.InvalidChanges in the :invalid class, which AshJsonApi and AshGraphql re= nder back to the caller. The embedding client's error term is not sanitized=
, so it can carry the request URL, the provider response body, and, for HTT=
P clients that keep the request in the error struct, the outbound Authoriza= tion header with the provider API key. Failures are attacker-reachable via = oversized or malformed vectorized content. The fix logs the raw error and r= eturns a generic message. This issue affects ash_ai: from 0.1.0 before 1.0.= 0.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75760" target=3D= "_blank" rel=3D"noopener">CVE-2026-75760</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Improper Control of Generation of Code (Code Injection) vulnerability i=
n ash-project ash_ai allows a remote, unauthenticated client to execute arb= itrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through E= Ex.eval_string/2. The documented prompt: fn input, context -> ... end fo=
rm lets the prompt content be built from action arguments, so when a prompt=
action's text incorporates request data, that attacker-controlled text is = compiled and run as an EEx template (Elixir source). Content such as <%=
=3D System.cmd(...) %> therefore executes on the server before any model=
request is made, requiring no authentication beyond reaching a prompt acti= on. The fix stops evaluating function-supplied prompt content as EEx; only = statically configured templates are evaluated. This issue affects ash_ai: f= rom 0.1.0 before 1.0.0.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77956" target=3D= "_blank" rel=3D"noopener">CVE-2026-77956</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Origin Validation Error vulnerability in ash-project ash_ai allows a ma= licious web page to bypass the MCP server's DNS-rebinding protection and is= sue cross-site requests to a user's local MCP server with that user's actor=
. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowe= d?/3 accepts an origin when uri.host =3D=3D conn.host and the forwarded sch= eme is https. Both values are attacker-controlled: conn.host comes from the=
Host header and the scheme is read from the raw x-forwarded-proto header w= ith no trusted-proxy check. Under DNS rebinding the browser sends the attac= ker's origin and a matching host, and page JavaScript may set X-Forwarded-P= roto: https, so the check passes with no TLS or proxy involved. The fix tru= sts only localhost origins by default; other origins require an explicit al= lowed_origins allowlist. This issue affects ash_ai: from 0.8.0 before 1.0.0= .</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81315" target=3D= "_blank" rel=3D"noopener">CVE-2026-81315</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Authorization Bypass Through User-Controlled Key vulnerability in ash-p= roject ash_ai allows a caller of an identity-configured tool to update or d= estroy records it never identified, including every row in the table. In As= hAi.Tool.Execution, identity_filter/3 built the update/destroy filter direc= tly from the raw tool arguments as [{key, Map.get(arguments, to_string(key)= )}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a pred= icate expression rather than a literal, so a caller can send {"public_ref":=
{"not_eq": "<own-ref>"}} and, combined with Ash.Query.limit(1) and A= sh.bulk_update!/Ash.bulk_destroy!, retarget the write at a record it never = identified; an omitted key yields an IS NULL filter that matches an arbitra=
ry row. The fix casts each identity value to the field type, rejecting non-= scalar inputs. This issue affects ash_ai: from 0.6.0 before 1.0.0.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82564" target=3D= "_blank" rel=3D"noopener">CVE-2026-82564</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in a= sh-project ash_ai allows an attacker who can influence a model's output to = hang the tool loop and drive unbounded, repeated model requests. AshAi.Tool= Loop classifies a model response of :tool_calls, then filters the calls thr= ough normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty th=
e list: a call missing a valid name, or one reusing a tool_call_id that alr= eady has a result in history, is dropped. With an empty list the loop appen= ded nothing and recursed with a byte-identical message list, so the convers= ation never advanced and the same request was re-sent every iteration. Unde=
r the supported max_iterations: :infinity this never terminated; otherwise =
it exhausted the full budget. Prompt-injected content can make the model re= -emit a spent tool_call_id. The fix treats an empty post-filter list as ter= minal. This issue affects ash_ai: from 0.6.0 before 1.0.0.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82579" target=3D= "_blank" rel=3D"noopener">CVE-2026-82579</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_ai</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash_ai discloses internal error text to chat users. In A= shAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool w=
as serialized verbatim with Exception.message/1 into the tool-result conten=
t. That content is appended to the conversation, emitted as a {:tool_result=
, ...} stream event, and sent back to the model, which typically relays it =
to the user. No filtering happened first, so anything raised inside a tool = callback or lifecycle hook (database constraint messages, adapter errors, q= uery fragments, policy or validation internals) was echoed as-is. A chat us=
er who can steer tool arguments into a raising code path receives the raw i= nternal text. The fix routes raised tool errors through the same safe forma= tter used for other tool errors. This issue affects ash_ai: from 0.6.0 befo=
re 1.0.0.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82580" target=3D= "_blank" rel=3D"noopener">CVE-2026-82580</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_phoenix</td>
<td>Incorrect Authorization vulnerability in ash-project ash_phoenix invoke=
s the SubdomainHook authorization callback with a nil tenant, so tenant-sco= ped access checks never see the tenant they are meant to enforce. AshPhoeni= x.LiveView.SubdomainHook.on_mount/4 attached a handle_params hook to assign=
the tenant and then immediately called handle_subdomain in the same on_mou= nt. The tenant assign is only written when LiveView later runs handle_param=
s, strictly after on_mount returns, so handle_subdomain read an unset assig=
n and ran as apply(m, f, [socket, nil | a]). A consumer gate that halts whe=
n the user does not belong to the tenant instead evaluated nil, either cras= hing or taking a permissive branch, and it was never re-run once the real s= ubdomain was assigned or on later navigations. The fix runs handle_subdomai=
n inside the handle_params hook with the real tenant on every navigation. T= his issue affects ash_phoenix: from 2.1.26 before 2.3.25.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82724" target=3D= "_blank" rel=3D"noopener">CVE-2026-82724</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_phoenix</td>
<td>Authorization Bypass Through User-Controlled Key vulnerability in ash-p= roject ash_phoenix lets an attacker who controls filter form parameters fil= ter across relationships the resource author marked non-public, turning the=
returned rows into a boolean oracle over private related data. AshPhoenix.= FilterForm resolved every relationship hop in the user-supplied path with A= sh.Resource.Info.related/2, which traverses private relationships, and only=
checked the terminal field for publicity. parse_path_and_field/2 also rewr= ote a field naming a relationship into an extra path segment, so field=3Dso= me_private_rel was accepted too. Both path and field come straight from for=
m params, and the resulting ref went to Ash.Query.do_filter/2 without the p= ublic-only enforcement of Ash.Filter.parse_input/2. The fix resolves each h=
op with Ash.Resource.Info.public_relationship/2, rejecting the first non-pu= blic hop, and requires the terminal field to be public. This issue affects = ash_phoenix: from 0.6.0-rc.1 before 2.3.25.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82725" target=3D= "_blank" rel=3D"noopener">CVE-2026-82725</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_phoenix</td>
<td>Permissive Regular Expression vulnerability in ash-project ash_phoenix = lets a remote client select the tenant an Ash application uses, or degrade = the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdo= main/2 stripped the root domain with String.replace(host, ~r/.?#{root_host}=
/, ""). The root host was interpolated raw, so each . became a wildcard and=
any metacharacter a pattern, and the replace was global and unanchored, so=
a match was removed from anywhere in the string. With root_host example.co=
m, Host: foo.exampleXcom.attacker.net returned the tenant foo.attacker.net.=
A metacharacter-bearing or nil root host degraded the pattern or raised on=
every request. The comparison was also case-sensitive, so TENANT.EXAMPLE.C=
OM and EXAMPLE.COM slipped past the root-host allowlist. conn.host comes fr=
om the client Host header. The fix matches the root host case-insensitively=
and only as an exact trailing suffix. This issue affects ash_phoenix: from=
2.1.26 before 2.3.25.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82726" target=3D= "_blank" rel=3D"noopener">CVE-2026-82726</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_phoenix</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash_phoenix writes the entire raw submitted param map in=
to an exception message, so secrets submitted alongside a union form field = leak into logs, crash reports and the dev error page. When AshPhoenix.Form.= Auto builds a union sub-form and the submitted _union_type does not match a=
configured type, both raise sites built the message with inspect(params, p= retty: true), embedding the full untrusted param map, and also inspected th=
e internal union constraints[:types]. Because the message is constructed by=
the library rather than Phoenix's parameter logger, config :phoenix, :filt= er_parameters never redacts it. An attacker controls both the trigger and t=
he contents: submitting %{"_union_type" =3D> "nope", "password" =3D> = "..."} puts the password verbatim in the raised message. The fix reports on=
ly the offending _union_type and the valid type names, dropping the param a=
nd constraints dumps. This issue affects ash_phoenix: from 1.2.17 before 2.= 3.25.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82727" target=3D= "_blank" rel=3D"noopener">CVE-2026-82727</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in a= sh-project ash_typescript allows an unauthenticated attacker to exhaust the=
BEAM atom table and abort the node via client-supplied RPC field names. As= hTypescript.FieldFormatter.convert_to_field_atom/2 in lib/ash_typescript/fi= eld_formatter.ex converts a client-supplied field name to an atom with Stri= ng.to_atom/1 when no matching atom already exists. It delegates first to pa= rse_input_field/2, which resolves the name with String.to_existing_atom/1 a=
nd falls back to returning the plain string; convert_to_field_atom/2 then m= ints an atom from that string rather than treating the name as unknown. RPC=
field selection reaches it for every requested field name through AshTypes= cript.Rpc.FieldProcessing.FieldSelector, which resolves each name before ch= ecking that the field exists, with no allowlist, length bound, or rate limi=
t. Atoms are never garbage collected, so each distinct name mints a permane=
nt one and the VM aborts once the atom table limit is reached. A field name=
over 255 characters additionally raises an uncaught SystemLimitError. This=
issue affects ash_typescript: from 0.1.0 before 0.18.0.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74837" target=3D= "_blank" rel=3D"noopener">CVE-2026-74837</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in a= sh-project ash_typescript allows an unauthenticated attacker to exhaust the=
BEAM atom table and abort the node via client-supplied typed struct field = names. resolve_typed_struct_field/2 in lib/ash_typescript/rpc/field_process= ing/field_selector.ex looks a client-supplied field name up in the typed st= ruct's reverse map and, when it finds no match, falls back to String.to_ato= m/1. Because this runs before any field-existence check, an unresolvable na=
me mints a permanent atom rather than being rejected as unknown. Atoms are = never garbage collected, so a request carrying many distinct names on a typ=
ed struct field grows the atom table until the VM aborts at its limit. This=
issue affects ash_typescript: from 0.11.0 before 0.18.0.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77856" target=3D= "_blank" rel=3D"noopener">CVE-2026-77856</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash_typescript allows an unauthenticated attacker to rec= eive unredacted internal error data by provoking an error shape the configu= red error handler does not match. apply_error_handler/3 in lib/ash_typescri= pt/rpc/errors.ex is the only hook an application has for redacting or suppr= essing errors before they reach the client, with a nil return dropping the = error entirely. Its rescue clause logs a warning and then returns the origi= nal, pre-handler error map. Error handlers are conventionally written as pa= ttern-matching functions over expected error shapes, so an unmatched shape = raises FunctionClauseError and the raw transformed error, including any sec= rets carried in vars, is emitted instead. An intent to suppress an error be= comes an intent to publish it. The rescue catches exceptions only, so a han= dler that throws or exits still propagates. This issue affects ash_typescri= pt: from 0.8.0 before 0.18.0.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77950" target=3D= "_blank" rel=3D"noopener">CVE-2026-77950</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Incorrect Authorization vulnerability in ash-project ash_typescript all= ows an unauthorized RPC caller to read attribute values that Ash field poli= cies denied. When a field policy denies an attribute, Ash substitutes %Ash.= ForbiddenField{}, which retains the real value in original_value because em= bedded resources must remain writable, and hides it from Inspect rather tha=
n removing it. AshTypescript.Rpc.ResultProcessor strips these markers to ni=
l on its template-driven paths, but normalize_primitive/1 in lib/ash_typesc= ript/rpc/result_processor.ex had no such clause, so a marker fell through t=
o the generic struct branch which calls Map.from_struct/1 and serializes ev= ery key, original_value included. The denied value is returned to the calle=
r inside the marker that represents its own denial. The simplest trigger is=
an action returning an embedded resource as a map, which routes through no= rmalize_resource_struct/2 with an empty template. normalize_value_for_json/=
1 is a public, unguarded entry point to the same path. This issue affects a= sh_typescript: from 0.11.0 before 0.18.0.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82730" target=3D= "_blank" rel=3D"noopener">CVE-2026-82730</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>URL Redirection to Untrusted Site ('Open Redirect') vulnerability in as= h-project ash_typescript allows an attacker who controls a path-parameter v= alue to redirect a generated client's request, and the credentials attached=
to it, to an unintended route or an external origin. The URL builders in l= ib/ash_typescript/typed_controller/codegen/route_renderer.ex replace each := param placeholder with a bare template interpolation and never call encodeU= RIComponent, so the value reaches executeTypedControllerRequest raw. A valu=
e containing ../ is normalised away by the fetch URL resolver and reaches a=
different route, while ? or # truncates the path and can smuggle or overri=
de query parameters. For a route whose path begins with a parameter, a valu=
e such as /evil.example.com/x yields the protocol-relative URL //evil.examp= le.com/x, sending the request and the credentials from TypedControllerConfi=
g to an attacker-controlled host. Nothing constrains the value at runtime: = get_path_param_type/2 emits only a TypeScript type, which is erased. The qu= ery-string path is unaffected, since URLSearchParams.set encodes its own va= lues. This issue affects ash_typescript: from 0.15.0 before 0.18.0.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82731" target=3D= "_blank" rel=3D"noopener">CVE-2026-82731</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Improper Input Validation vulnerability in ash-project ash_typescript a= llows a remote attacker to submit argument values outside a declared allowl= ist or bound on typed-controller routes. AshTypescript.TypedController.Requ= estHandler in lib/ash_typescript/typed_controller/request_handler.ex calls = Ash.Type.cast_input/3 and treats an {:ok, cast} result as fully validated. =
In Ash these are separate steps: cast_input/3 only coerces the term, while = every constraint declared on the argument is applied by Ash.Type.apply_cons= traints/3, which this path never calls. Constraints such as one_of, max_len= gth, min and max, and match are therefore inert, so a value outside a decla= red allowlist is accepted and passed to the route handler. Codegen renders = the same constraints into the generated TypeScript types, so an allowlist a= ppears enforced to a TypeScript caller while any other HTTP client ignores = it. Empty-string to nil normalization also lives in apply_constraints, so t=
he allow_nil?: false check accepts "" for a required argument. Where a cons= traint gates a role, a status, or a sort direction, this becomes a privileg=
e or state-machine bypass. This issue affects ash_typescript: from 0.15.0 b= efore 0.18.0.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82732" target=3D= "_blank" rel=3D"noopener">CVE-2026-82732</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash_typescript</td>
<td>Generation of Error Message Containing Sensitive Information vulnerabil= ity in ash-project ash_typescript allows an unauthenticated attacker to rea=
d internal application data from an HTTP 500 response body. When a typed-co= ntroller route handler returns anything other than a %Plug.Conn{}, dispatch=
/3 in lib/ash_typescript/typed_controller/request_handler.ex passes the val=
ue to unexpected_return/2, which interpolates inspect(value, limit: 50) dir= ectly into the response message. The limit option bounds elements per colle= ction rather than the term as a whole, so a handler falling through with a = term such as {:error, %User{}} or a changeset serialises its full field set=
, including hashed passwords, tokens, and tenant identifiers, into the JSON=
error returned to the caller. This contradicts the module's own posture el= sewhere: the rescue clause gates Exception.message/1 behind AshTypescript.t= yped_controller_show_raised_errors?/0 and otherwise returns a generic messa= ge, while this path is ungated and always echoes. This issue affects ash_ty= pescript: from 0.15.0 before 0.18.0.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82733" target=3D= "_blank" rel=3D"noopener">CVE-2026-82733</a></td>
</tr>
<td class=3D"vendor-product">ash-project--ash<br>=C2=A0</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in ash= -project ash allows an attacker to store a value of arbitrary size in an at= tribute whose length constraint should bound it. Ash measures string length=
with Elixir's String.length/1, which counts Unicode graphemes, in the max_= length and min_length constraints of Ash.Type.String (apply_constraints/2 i=
n lib/ash/type/string.ex), in Ash.Resource.Validation.StringLength, and in = the string_length expression function. A grapheme carries an unbounded numb=
er of combining marks, so a base character followed by a million combining = acute accents is one grapheme and megabytes of data, and satisfies max_leng= th: 2. Where the data layer imposes no independent limit (ETS, Mnesia, or a=
Postgres text column) the whole value is persisted, so an attacker can wri=
te an entire request body into an attribute declared with a small maximum a=
nd grow storage without bound. The counting unit also disagrees with the st= orage layer, which counts codepoints rather than graphemes, so a value acce= pted by the constraint can still be rejected or truncated by the column. A = Postgres varchar(n) column bounds the value itself and is not exposed. This=
issue affects ash: from 0.10.0 before 3.33.0.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82752" target=3D= "_blank" rel=3D"noopener">CVE-2026-82752</a></td>
</tr>
<td class=3D"vendor-product">ASUS--Control Center Enterprise (ACC)</td>
<td>Missing Authentication for Critical Function, Server-Side Request Forge=
ry (SSRF), and Use of Hard-coded Credentials in ASUS Control Center=C2=A0al= low an unauthorized user to obtain the encryption key via an HTTP request, = causing a local service to enable SSH on port 2222. The attacker can then l=
og in with the hardcode credentials=C2=A0to obtain a root shell, enabling d= irect reading, writing, and deletion of data on ASUS Control Center, as wel=
l as remote control of all servers, PCs, and workstations within the compan=
y. Refer to the 'Security Update for ASUS Control Center' section on the AS=
US Security Advisory for more information.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75754" target=3D= "_blank" rel=3D"noopener">CVE-2026-75754</a></td>
</tr>
<td class=3D"vendor-product">Authen-SASL::Perl::DIGEST_MD5<br>=C2=A0</td> <td>Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept r= eplayed authentication responses via unverified nonce in server_step. serve= r_start generates a fresh nonce and sends it in the challenge, and nothing = later compares that value against the nonce the client returns. server_step=
derives the expected digest from the client's own parameters, so a respons=
e verifies whenever its digest matches the nonce it carries. The count tabl=
e it also checks is keyed on the client-supplied nonce and starts empty in = each new server object, so a captured first response, carrying `nc=3D000000= 01`, passes that too. RFC 2831 defines the nonce in the response as the val=
ue the server sent in the preceding challenge. An attacker who observes one=
successful `qop=3Dauth` exchange can replay the captured response against =
a later session for the same service, host, realm and user, and authenticat=
e as that user without knowing the password.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86219" target=3D= "_blank" rel=3D"noopener">CVE-2026-86219</a></td>
</tr>
<td class=3D"vendor-product">Backblaze--Backblaze Client</td>
<td>A vulnerability in the Backblaze Client allows a local user to make the=
system not bootable by creating a link from Backblaze's folder to Windows =
OS system files during a backup. Successful exploitation requires an admini= strator-level system change that results in the absence of specific Windows=
OS security controls. This vulnerability is due to improper link resolutio= n.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19820" target=3D= "_blank" rel=3D"noopener">CVE-2026-19820</a></td>
</tr>
<td class=3D"vendor-product">Baserow--Baserow</td>
<td>Baserow 2.3.3 contains a SQL injection vulnerability in the index() for= mula function. A low-privileged authenticated user who can create or modify=
formula fields can provide an undocumented fourth argument that is treated=
as a SQL template and interpolated directly into a PostgreSQL expression. = The vulnerable expression is executed when Baserow recalculates formula fie=
ld values. Because the generated SQL runs through Baserow's database connec= tion, the injected SQL executes with the privileges of the Baserow PostgreS=
QL role rather than the permissions of the authenticated application user. = This issue affects Baserow: 2.3.3.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19754" target=3D= "_blank" rel=3D"noopener">CVE-2026-19754</a></td>
</tr>
<td class=3D"vendor-product">Checkmk GmbH--Checkmk</td>
<td>Improper certificate validation in Checkmk <2.5.0p10 allows a relay = and a push agent that share the same UUID to reuse each other's mTLS certif= icate to authenticate against agent receiver endpoints in either direction,=
because the endpoints do not verify that the certificate was issued by the=
ir own root certificate.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15937" target=3D= "_blank" rel=3D"noopener">CVE-2026-15937</a></td>
</tr>
<td class=3D"vendor-product">composer--composer</td>
<td>Composer is a dependency Manager for the PHP language. From 1.0 until 2= .2.30 and 2.10.3, a malicious dependency package from a custom Composer rep= ository or an untrusted composer.lock file could set source.type to perforc=
e and source.url to an rsh: or jsh: P4PORT value. When the Perforce p4 clie=
nt was installed and Composer installed the package from source through com= poser install or composer update, including --prefer-source, Composer\Util\= Perforce passed the address to p4 without validation, causing p4 to run a l= ocal command with the privileges of the user or CI account. Packagist.org d= oes not permit Perforce source metadata. This issue is fixed in versions 2.= 2.30 and 2.10.3.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84361" target=3D= "_blank" rel=3D"noopener">CVE-2026-84361</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>The vulnerability allows any authenticated user to change their own pas= sword without providing the current password or having an active elevated s= ession. It also allows the attacker to change other users' passwords if the=
attacker's account has=C2=A0Edit users=C2=A0permission (which doesn't allo=
w changing others' passwords) and lacks=C2=A0Administrate users=C2=A0permis= sion (which is required to change others' passwords).</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79989" target=3D= "_blank" rel=3D"noopener">CVE-2026-79989</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS GraphQL entry mutation resolvers (saveEntry,=C2=A0deleteEntry=
) read=C2=A0siteIddirectly from$argumentswithout passing throughArgumentMan= agerprepareArguments(), which is the function that enforces site-scope filt= ering via=C2=A0array_intersect=C2=A0against the GraphQL schema's allowed si= tes. The query path (ElementResolverprepareElementQuery) correctly calls=C2= =A0prepareArguments()`, so queries to unauthorized sites return empty. But = mutations bypass this entirely - an attacker with a token scoped to Site A = can create, modify, or delete entries in Site B by passing siteId in the mu= tations argument.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79990" target=3D= "_blank" rel=3D"noopener">CVE-2026-79990</a></td>
</tr>
<td class=3D"vendor-product">craftcms--cms</td>
<td>Craft CMS GraphQL entry mutation resolvers (saveEntry,=C2=A0deleteEntry=
) read=C2=A0siteIddirectly from$argumentswithout passing throughArgumentMan= agerprepareArguments(), which is the function that enforces site-scope filt= ering via=C2=A0array_intersect=C2=A0against the GraphQL schema's allowed si= tes. The query path (ElementResolverprepareElementQuery) correctly calls=C2= =A0prepareArguments()`, so queries to unauthorized sites return empty. But = mutations bypass this entirely - an attacker with a token scoped to Site A = can create, modify, or delete entries in Site B by passing siteId in the mu= tations argument.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79991" target=3D= "_blank" rel=3D"noopener">CVE-2026-79991</a></td>
</tr>
<td class=3D"vendor-product">CRMEB --CRMEB v6.0.0<br>=C2=A0</td>
<td>An arbitrary file deletion vulnerability in the /adminapi/file/video_da= ta_save component of CRMEB v6.0.0 allows authenticated attackers to delete = arbitrary files via crafted POST request.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79426" target=3D= "_blank" rel=3D"noopener">CVE-2026-79426</a></td>
</tr>
<td class=3D"vendor-product">curl --curl<br>=C2=A0</td>
<td>A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead=
of space (ascii code 32) immediately before the `Secure` attribute causes = curl to store the cookie without its Secure flag. The cookie might then wro= ngfully be sent over plaintext HTTP on subsequent requests to the same host= .</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80255" target=3D= "_blank" rel=3D"noopener">CVE-2026-80255</a></td>
</tr>
<td class=3D"vendor-product">dignifiedquire--async-tar</td>
<td>async-tar is a tar archive reading/writing library for async Rust. Prio=
r to version 0.6.1, async-tar mis-applies a buffered PAX size extension to =
an intermediary extension header (a GNU longname L, a GNU longlink K, or a = PAX x/g header) instead of to the next file entry. POSIX requires a PAX ext= ended-header record set to describe the next file entry, never an interveni=
ng extension header. Because poll_next_raw (src/archive.rs) threads the buf= fered PAX records into the size computation of whatever raw header it reads=
next - and that header can be an intermediary L - the stream cursor is adv= anced by an attacker-chosen amount when the L body is consumed. The parser = then desyncs relative to a POSIX-correct tar parser (e.g. GNU tar), reading=
subsequent bytes at the wrong block boundary. This issue has been patched =
in version 0.6.1.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53600" target=3D= "_blank" rel=3D"noopener">CVE-2026-53600</a></td>
</tr>
<td class=3D"vendor-product">easyadmin --easyadmin =C2=A0v2.0.2.2<br>=C2=A0= </td>
<td>easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Da= ngerous Type in the background management interface which allows authentica= ted remote attackers to execute arbitrary code and gain server privileges v=
ia a crafted file upload.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50894" target=3D= "_blank" rel=3D"noopener">CVE-2026-50894</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse aeriOS</td>
<td>In the current development version of Eclipse aeriOS, which has not yet=
had an official release, the KrakenD instance included in the API Gateway = component had the disable_jwk_security parameter hard-coded to true, with n=
o option to override it through the Helm chart configuration. This setting = disables TLS certificate verification when KrakenD retrieves the JSON Web K=
ey Set (JWKS) used to validate bearer tokens, potentially allowing an attac= ker with the ability to intercept this communication to provide a malicious=
JWKS and compromise token validation. The issue has been addressed by maki=
ng the parameter configurable through the boolean Helm value krakend.config= .disableJwkSecurity and setting its default value to false, ensuring that T=
LS certificate verification is enabled by default.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82955" target=3D= "_blank" rel=3D"noopener">CVE-2026-82955</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse aeriOS</td>
<td>In the current development version of Eclipse aeriOS, for which no offi= cial release has yet been published, the Federator component disables TLS c= ertificate validation for outbound HTTPS connections by default. When the T= LS_CERTIFICATE_VALIDATION environment variable is unset or set to false, th=
e component configures its HTTP transport to skip TLS certificate verificat= ion. As a result, an attacker able to intercept network communications betw= een the Federator and external services could impersonate those services an=
d intercept sensitive information transmitted over HTTPS, including OAuth c= lient credentials and bearer tokens. The issue has been addressed by enabli=
ng TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION en= vironment variable is now set to true in the default configuration provided=
by the Helm chart and Docker Compose deployment.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84736" target=3D= "_blank" rel=3D"noopener">CVE-2026-84736</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse aeriOS</td> <td>Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path=
traversal vulnerability in the REST API. User-controlled identifiers used =
to create, update, or delete Self-orchestrator resources were incorporated = into filesystem paths without adequate validation or sanitization. An unaut= henticated remote attacker able to access the Self-orchestrator API could t= herefore supply specially crafted identifiers containing path traversal seq= uences to write or delete JSON files outside the intended application direc= tories, subject to the filesystem permissions of the Self-orchestrator proc= ess. The impact is increased by the absence of authentication on the affect=
ed API and by the container running with elevated privileges in the affecte=
d deployment configuration. The issue has been addressed in version 1.2.1 b=
y introducing validation and sanitization of user-controlled identifiers be= fore they are used to construct filesystem paths, preventing path separator=
characters from being used to escape the intended directories.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85199" target=3D= "_blank" rel=3D"noopener">CVE-2026-85199</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Arrowhead</td>
<td>In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-author= ization gate that protects every //mgmt/ REST endpoint decides whether to a= pply its check by calling request.getRequestURL().toString().contains("/mgm= t/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's Dispatc= herServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/s= ystems (%6D =3D=3D m) therefore fails the substring check - the filter fall=
s through without authorising - yet is decoded to /serviceregistry/mgmt/sys= tems and dispatched to the management controller. Spring Security's StrictH= ttpFirewall (active via spring-boot-starter-security in arrowhead-common) o= nly rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII lett= ers pass through. Any authenticated system - regardless of privilege - can = reach every management operation, including POST /authentication/mgmt/ident= ities which creates new sysop accounts, yielding full administrative takeov=
er of the local cloud.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80515" target=3D= "_blank" rel=3D"noopener">CVE-2026-80515</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Arrowhead</td>
<td>In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is = enabled with the certificate authentication policy, CertificateMqttFilter p= arses an X.509 certificate that the client sends inside the MQTT message pa= yload (the authentication field of MqttRequestTemplate) and treats its Subj= ect DN as the authenticated identity. The certificate is decoded with Certi= ficateFactory.generateCertificate() but its signature is never verified and=
its issuer chain is never validated against any trust store. Authorisation=
is reduced to two string comparisons on attacker-supplied data: the DN-qua= lifier must equal "sy" or "op", and the cloud-name part of the CN must matc=
h the server's. Both values are public (the cloud name is in the server's o=
wn TLS certificate). An attacker who can publish to the MQTT broker can the= refore mint a self-signed certificate with CN=3DSysop.<cloud>.<org= >.arrowhead.eu, dnQualifier=3Dop, send it as the authentication field, a=
nd be authenticated as the cloud's system operator with isSysOp =3D=3D true=
. This passes the downstream ManagementServiceMqttFilter (request.isSysOp()=
=C3=A2=E2=80=A0=E2=80=99 allowed) and gives full management access over MQ= TT. The HTTP CertificateFilter is not affected - it reads the certificate f= rom jakarta.servlet.request.X509Certificate, which Tomcat populates only af= ter a successful mTLS handshake against the configured trust store.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82180" target=3D= "_blank" rel=3D"noopener">CVE-2026-82180</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Ditto</td>
<td>In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMess= ageMapper of the connectivity service builds a CreateThing command by subst= ituting placeholder values (e.g. {{ header:device_id }}) resolved from inbo= und message headers into a pre-configured JSON "thing" template as raw, un-= escaped strings, and then parses the resulting string as JSON. Because the = placeholder engine performs no JSON escaping and is unaware of the surround= ing JSON string context, a resolved value containing a double-quote charact=
er can break out of its string and inject additional JSON structure. When a=
connection is configured to use this mapper with a template that reflects =
a header whose value a publishing device can control (for example an MQTT 5=
user property, an AMQP 1.0 application property, or a Kafka record header)=
, an attacker able to publish on that connection can inject an inline _poli=
cy object. The inline policy overrides the administrator-configured policyI=
d, letting the attacker assign an arbitrary access-control policy to the ne= wly created digital twin - gaining full read/write access to it and potenti= ally revoking the legitimate owner's access, with no administrator interact= ion. Exploitation requires all of the following: the connection uses the (n= on-default) ImplicitThingCreation mapper; its template reflects an attacker= -controllable header; and, for the policy-override impact, the connection's=
authorization subjects are permitted to create policies (the default). Dep= loyments that restrict the connection's subjects to thing creation only via=
the entity-creation configuration are not affected by the policy-override = impact.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82958" target=3D= "_blank" rel=3D"noopener">CVE-2026-82958</a></td>
</tr>
<td class=3D"vendor-product">Eclipse Foundation--Eclipse Ditto</td>
<td>In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches Wo=
T (Web of Things) ThingModels over HTTP from URLs supplied by API users in = the definition field of a Thing or Feature, without validating the target h= ost, and follows HTTP redirects without re-validating the redirect target a=
nd without a hop limit. An authenticated user who is permitted to create a = Thing, or who holds WRITE permission on an existing Thing, can thereby caus=
e the Things service to issue arbitrary HTTP GET requests from inside the d= eployment's network - including to cloud instance-metadata endpoints and ot= her internal services - and can use the differing error responses returned =
to the caller to enumerate internal services. Versions 2.4.0 to 2.5.x conta=
in the same code, but are only affected where the operator explicitly enabl=
ed the WoT integration feature toggle, which is disabled by default in thos=
e versions.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84175" target=3D= "_blank" rel=3D"noopener">CVE-2026-84175</a></td>
</tr>
<td class=3D"vendor-product">elixir-mint--mint</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in e= lixir-mint mint allows a remote HTTP server to exhaust memory on the client=
host and cause a denial of service. Two HTTP/1 response-parser states accu= mulate server data without any cap. In lib/mint/http1.ex, decode_status_lin= e/4 stores the unconsumed data in conn.buffer when the status line is incom= plete, and decode_body/5 does the same for an unterminated chunk-extension = line. Both wait for a CRLF the server never has to send, and conn.buffer is=
prepended to every subsequent socket message. The :max_header_list_size bu= dget is wired only into decode_headers/5 and decode_trailer_headers/4, so n= either of these states is covered by it. A malicious server, or one reached=
through an attacker-controlled redirect or a fetched URL, streams bytes in= definitely until the BEAM node is killed by the operating system out-of-mem= ory handler. The chunk-extension variant is reached after a valid status li=
ne and a complete, valid header section, so an intermediary inspecting only=
headers sees an ordinary 200 response. This issue affects mint: from 0.1.0=
before 1.10.0.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82728" target=3D= "_blank" rel=3D"noopener">CVE-2026-82728</a></td>
</tr>
<td class=3D"vendor-product">elixir-mint--mint</td>
<td>Inefficient Algorithmic Complexity vulnerability in elixir-mint mint al= lows a remote HTTP server to exhaust CPU on the client host and cause a den= ial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each he=
x digit of a chunked response's chunk-size field into an arbitrary-precisio=
n accumulator with acc * 16 + digit and imposes no limit on the digit count=
. Because the accumulator grows without bound, the multiplication is not co= nstant time and one pass over N digits costs O(N squared). handle_data/2 pr= epends conn.buffer and re-parses from the start on every socket message, so=
a server that dribbles the digits out in small packets makes the client pa=
y that cost repeatedly. A run of roughly 512,000 hex digits costs over ten = seconds of CPU in a single pass, measured on stock defaults. The parser rea= ches this state after a valid status line and a complete, valid header sect= ion, so an intermediary inspecting only headers sees an ordinary 200 respon= se. This issue affects mint: from 1.9.3 before 1.10.0.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82729" target=3D= "_blank" rel=3D"noopener">CVE-2026-82729</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $= _SESSION['oidc_state'], but checksession.php dispatches the OIDC callback w= ithout comparing the incoming state against the session value. An attacker = can trick a victim into visiting a crafted URL, causing Wallos to exchange = the attacker's authorization code and log the victim into the attacker's ac= count. This issue has been patched in version 4.9.4.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54599" target=3D= "_blank" rel=3D"noopener">CVE-2026-54599</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.4, endpoints/db/import.php has no authentication. The = only guard is a user-table row count - if zero (fresh/unconfigured install)=
, an unauthenticated attacker can replace the entire database. This issue h=
as been patched in version 4.9.4.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-54600" target=3D= "_blank" rel=3D"noopener">CVE-2026-54600</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.6, POST /endpoints/notifications/testemailnotification= s.php accepts smtpaddress and smtpport from POST body with zero SSRF valida= tion. PHPMailer connects to attacker-supplied host:port. Every other notifi= cation endpoint uses ssrf_helper.php but email was missed. Any authenticate=
d user can probe internal network, cloud metadata. This issue has been patc= hed in version 4.9.6.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61638" target=3D= "_blank" rel=3D"noopener">CVE-2026-61638</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::ex= tractTo() without validating entry names for ../ sequences. Admin uploads c= rafted zip with entry logos/../../endpoints/shell.php to write webshell to = webroot. Extension filter only applies to post-extraction logo copy step. T= his issue has been patched in version 4.9.6.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61639" target=3D= "_blank" rel=3D"noopener">CVE-2026-61639</a></td>
</tr>
<td class=3D"vendor-product">ellite--Wallos</td>
<td>Wallos is an open-source, self-hostable personal subscription tracker. = Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url i=
n includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_in= it() with zero SSRF filtering. Unlike logo/webhook URLs which have validate= _webhook_url_for_ssrf(), OIDC URLs bypass all protections. Admin sets URL t=
o
http://169.254.169.254/latest/meta-data/ for cloud metadata access or int= ernal network pivoting. This issue has been patched in version 4.9.6.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-61640" target=3D= "_blank" rel=3D"noopener">CVE-2026-61640</a></td>
</tr>
<td class=3D"vendor-product">emlog--emlog</td>
<td>Emlog is an open source website building system. In versions 2.6.29 and=
prior, the emUnZip() function extracts all ZIP entries via ZipArchive::ext= ractTo() without validating entry paths for ../ traversal sequences. Only t=
he first entry's subdirectory structure is checked. An attacker can overwri=
te arbitrary files on the server filesystem, including config.php for immed= iate RCE. At time of publication, there are no publicly known patches.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53757" target=3D= "_blank" rel=3D"noopener">CVE-2026-53757</a></td>
</tr>
<td class=3D"vendor-product">emlog--emlog</td>
<td>Emlog is an open source website building system. In versions 2.6.29 and=
prior, article content is processed by Parsedown without enabling safe mod=
e, which means raw HTML including <script> tags embedded in Markdown =
is passed through unescaped. The output is rendered with no additional sani= tization, resulting in stored XSS visible to all site visitors. At time of = publication, there are no publicly known patches.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53758" target=3D= "_blank" rel=3D"noopener">CVE-2026-53758</a></td>
</tr>
<td class=3D"vendor-product">emlog--emlog</td>
<td>Emlog is an open source website building system. In versions 2.6.29 and=
prior, tag names in emlog are not HTML-encoded when rendered in the articl=
e editor. An attacker can create a tag containing ');alert(document.domain)= ;//. The addslashes() function does not escape HTML entities, so ' is store=
d as-is. When the browser renders the page, it decodes ' back to a literal = single quote before evaluating the JavaScript, breaking out of the string a=
nd executing arbitrary code. At time of publication, there are no publicly = known patches.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73848" target=3D= "_blank" rel=3D"noopener">CVE-2026-73848</a></td>
</tr>
<td class=3D"vendor-product">EMX Tecnologia--Gestao X</td>
<td>EMX Tecnologia Gestao X version <=3D 8.4 contains a Stored Cross-Sit=
e Scripting (XSS) vulnerability in the Help Chat functionality. Improper ne= utralization of user-controlled input during web page generation allows aut= henticated attackers to execute arbitrary JavaScript in the context of othe=
r authenticated users, potentially resulting in session hijacking, account = takeover, and unauthorized actions.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79418" target=3D= "_blank" rel=3D"noopener">CVE-2026-79418</a></td>
</tr>
<td class=3D"vendor-product">EMX Tecnologia--Gestao X</td>
<td>A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecn= ologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused=
by insufficient validation and sanitization of the mensagem parameter in t=
he /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker =
to inject arbitrary JavaScript code that is reflected and executed in the c= ontext of a victim's browser.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79419" target=3D= "_blank" rel=3D"noopener">CVE-2026-79419</a></td>
</tr>
<td class=3D"vendor-product">enchant97--note-mark</td>
<td>Note Mark is an open-source note-taking application. Prior to version 0= .19.5, Note Mark validates book and note slug values with the OpenAPI/huma = tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Patt= ern) and tests it with patternRe.MatchString(str), an UNANCHORED match. Bec= ause the pattern is not anchored (^...$), any string that merely CONTAINS o=
ne [a-z0-9-] substring passes validation. A slug such as ../../../../../../= tmp/escape is accepted and stored verbatim. The data-export CLI commands (n= ote-mark migrate export and note-mark migrate export-v1) join these unsanit= ized slugs straight into the output path with path.Join / filepath.Join, th=
en os.MkdirAll the directory and os.Create the note file. path.Join resolve=
s the ../ segments, so the note content file is written OUTSIDE the configu= red export directory. The export process commonly runs as root (default in = Docker / bare-metal admin usage), so this is a root-privilege arbitrary dir= ectory create + file write. This issue has been patched in version 0.19.5.<=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-50553" target=3D= "_blank" rel=3D"noopener">CVE-2026-50553</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>The Erlang/OTP httpc HTTP client does not enforce a limit on the total = size of response headers received from a server. The max_header_size option=
defaults to nolimit, and httpc_response:parse_headers/6 accumulates every = header into a list before the length check runs (which only fires after the=
terminating CRLF CRLF is received). A malicious or compromised HTTP server=
can send an arbitrarily large number of headers, or headers with very larg=
e values, causing the client process to allocate unbounded memory until the=
system runs out of memory or the BEAM VM crashes. A proof-of-concept serve=
r sending 100,000 headers of roughly 4000 bytes each caused the client VM t=
o allocate over 13 GB of memory in under 30 seconds. Any application using = httpc:request/4,5 to connect to untrusted servers is affected. No authentic= ation is required: any server the client connects to (including via a redir= ect or man-in-the-middle) can trigger the exhaustion. This issue affects OT=
P from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before O= TP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, correspond= ing to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.=
7 before 9.7.2. Whether OTP before OTP=C2=A017.0, corresponding to inets be= fore 5.10, is affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-55951" target=3D= "_blank" rel=3D"noopener">CVE-2026-55951</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Erl= ang/OTP stdlib allows a remote attacker to degrade availability by supplyin=
g a URI whose port component is a very long run of digits. uri_string:get_p= ort/1 passes the port substring to binary_to_integer/1 with no length bound=
, catching only error:badarg, so a syntactically valid port of up to roughl=
y 1.26 million digits converts successfully and costs the calling process h= undreds of milliseconds of arbitrary-precision arithmetic. The conversion i=
s reached from every authority-parsing path in uri_string:parse/1, includin=
g the host, registered-name, and IPv4 and IPv6 forms. parse/1 is the docume= nted interface for parsing URIs, so any application that parses an attacker= -supplied URI is exposed without further configuration. The conversion func= tion is documented to accept integers of any size, so bounding the input is=
the caller's responsibility. This issue affects OTP from OTP=C2=A021.0 bef= ore OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and fr=
om OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to stdlib from 3.5 b= efore 6.2.2.5, from 7.0 before 7.3.0.2, and from 8.0 before 8.0.4.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-59696" target=3D= "_blank" rel=3D"noopener">CVE-2026-59696</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>httpd has never implemented obs-fold (RFC 2616 =C3=82=C2=A72.2 / RFC 72=
30 =C3=82=C2=A73.2.4 header continuation lines). Every CRLF followed by a n= on-CRLF octet unconditionally starts a new header. This missing feature bec= ame a security concern as the understanding of HTTP request smuggling attac=
ks evolved. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.= 4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 b= efore OTP=C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7, fro=
m 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP=C2= =A017.0, corresponding to inets before 5.10, is affected is unknown.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66357" target=3D= "_blank" rel=3D"noopener">CVE-2026-66357</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remot=
e unauthenticated attacker to read files inside a mod_auth protected direct= ory by prefixing the request path with an extra slash. httpd_request:valida= te_uri/1 normalises the request URI with uri_string:normalize/1, which perf= orms RFC 3986 dot-segment removal but does not collapse empty path segments=
, so a doubled slash survives. mod_alias:real_name/3 concatenates the docum= ent root with that URI, and mod_auth:secret_path/3 then decides whether the=
result lies inside a protected directory block by running the configured d= irectory path as an unanchored regular expression against it. The doubled s= lash breaks the contiguous substring the regex needs, so the request is tre= ated as unprotected and no authentication challenge is issued, while mod_ge=
t opens the same path and the operating system collapses the doubled slash = and returns the protected file. The same path mismatch also evades the per-= path accounting in mod_security. This issue affects OTP from OTP=C2=A017.0 = before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and=
from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 5.1=
0 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Wheth=
er OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is affecte=
d is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66835" target=3D= "_blank" rel=3D"noopener">CVE-2026-66835</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Missing Release of Resource after Effective Lifetime vulnerability in E= rlang/OTP inets httpd allows an unauthenticated remote attacker to cause de= nial of service by sending a request with a chunked body whose chunk-size l= ine is not a hexadecimal number. The worker serving the connection is never=
released and no timeout reclaims it, so repeating the request across conne= ctions occupies every available worker and denies service to legitimate cli= ents. No authentication is required and the default configuration is affect= ed. The chunk-size line must arrive in a write separate from the headers. W= hen the body accompanies the headers, httpd_request_handler:handle_body/3 c= alls http_chunk:decode/3 inside a try ... catch throw:Error, so the {error,=
{chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 B=
ad Request. When the chunk size arrives later, the decoder is resumed throu=
gh a bare catch in httpd_request_handler:handle_info/2, which converts the = throw into a return value rather than raising it; the resulting error tuple=
is then treated as the next decoder continuation, the socket is re-armed, = and the worker waits for data that never comes. The request timeout has alr= eady been cancelled at the point the headers were accepted, and the periodi=
c byte-rate check is only armed when minimum_bytes_per_second is configured=
, which it is not by default. This issue affects OTP from OTP=C2=A018.1.4 b= efore OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and = from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 6.0.=
3 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-69664" target=3D= "_blank" rel=3D"noopener">CVE-2026-69664</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Allocation of Resources Without Limits or Throttling vulnerability in E= rlang/OTP inets httpd allows an unauthenticated remote attacker to cause de= nial of service by opening and holding open a large number of connections. = The max_clients option is documented to default to 150, and the inets harde= ning guide presents that limit as the first layer of denial-of-service defe= nce, but a server that does not set it explicitly accepts an unlimited numb=
er of simultaneous connections. Establishing the connections is sufficient;=
no valid request and no authentication are required. The accept gate in ht= tpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup= /2, which returns undefined when the key is absent, rather than the three-a= rgument form carrying the 150 default that the neighbouring get_ustate/2 us= es. Erlang term ordering places every integer before every atom, so the Cou=
nt =3D< Max guard holds for any connection count and the server never re= turns {reject, busy}. Each accepted connection occupies a worker process an=
d a socket for as long as it is held, driving the node towards process, mem= ory and file descriptor exhaustion. Servers that set max_clients explicitly=
are unaffected, because a configured value is applied as intended. This is= sue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2= =A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029= .0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.= 2.3, and from 9.7 before 9.7.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70399" target=3D= "_blank" rel=3D"noopener">CVE-2026-70399</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Erl= ang/OTP snmp allows a remote attacker to degrade availability by sending an=
SNMP message containing a BER INTEGER whose length field is arbitrarily la= rge. snmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and=
do_dec_integer_notag/2 then accumulates the value across every declared by=
te with a recursive shift and bitwise or. Work grows superlinearly in the d= eclared length because each operation acts on a progressively larger bignum=
. The size-limited variant dec_integer_notag/2 exists but is reached from o= nly one call site, dec_snmp_version/1, which bounds the version field to te=
n bytes; the request identifier, error status and index, generic and specif=
ic trap fields, engine boots and time, and every varbind value decoded by d= ec_value/1 all use the unbounded form. The decode runs before the PDU is pr= ocessed, so no valid request is required beyond what the deployment demands=
to accept the message at all. This issue affects OTP from OTP=C2=A017.0 be= fore OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and f= rom OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to snmp from 4.25.1=
before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5.=
Whether OTP before OTP=C2=A017.0, corresponding to snmp before 4.25.1, is = affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70405" target=3D= "_blank" rel=3D"noopener">CVE-2026-70405</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Erl= ang/OTP eldap allows a malicious or compromised LDAP server to degrade avai= lability by returning a referral URL whose port component is a very long ru=
n of digits. eldap:parse_port/2 passes the port substring straight to list_= to_integer/1 with no length bound. The surrounding try ... catch only rejec=
ts a value that fails to parse, so a syntactically valid port of up to roug= hly 1.26 million digits converts successfully and costs the caller hundreds=
of milliseconds of arbitrary-precision arithmetic per referral. The conver= sion function itself is documented to accept integers of any size, so bound= ing the input is the caller's responsibility. Reaching the flaw requires th=
e application to pass a server-supplied referral to eldap:parse_ldap_url/1,=
which eldap never calls itself: referral strings are returned to the calle=
r unparsed. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.= 4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 b= efore OTP=C2=A029.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, f= rom 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70409" target=3D= "_blank" rel=3D"noopener">CVE-2026-70409</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Missing Release of Resource after Effective Lifetime vulnerability in E= rlang/OTP inets httpd allows an unauthenticated remote attacker to cause de= nial of service by sending valid request headers with a large Content-Lengt=
h and then stalling before the body is complete. httpd_request_handler:hand= le_info/2 cancels the request timeout as soon as a parse step succeeds, whi=
ch includes the headers, and the clause that handles a decoder asking for m= ore data re-arms the socket with {active, once} without setting any further=
timer. httpd_request:whole_body/2 returns such a continuation whenever the=
bytes received are fewer than the announced Content-Length, so a well-form=
ed request that stops mid-body leaves the worker waiting indefinitely. The = periodic byte-rate check that would reclaim it is armed only when minimum_b= ytes_per_second is configured, which it is not by default. Repeating this a= cross connections occupies every worker permitted by max_clients and denies=
service to legitimate clients at negligible bandwidth cost. This issue aff= ects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 b= efore OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, cor= responding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and = from 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0, corresponding to i= nets before 5.10, is affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71380" target=3D= "_blank" rel=3D"noopener">CVE-2026-71380</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Erl= ang/OTP inets httpc allows a malicious or compromised HTTP server to degrad=
e availability by returning a numeric header whose value is a very long run=
of digits. httpc_handler.erl converts the server-supplied Content-Length w= ith list_to_integer/1 before comparing it against max_body_size, so the siz=
e check cannot protect the conversion, and the option defaults to nolimit i=
n any case. The same unbounded conversion appears in httpc_response:format_= response/1 for Content-Length and in httpc_response:get_ms_from_retry_after=
/1 for Retry-After, which is guarded only by a check that the first charact=
er is a digit. A value of up to roughly 1.26 million digits converts succes= sfully and costs the requesting process hundreds of milliseconds of arbitra= ry-precision arithmetic per response. The conversion function is documented=
to accept integers of any size, so bounding the input is the caller's resp= onsibility. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A027.3.= 4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 b= efore OTP=C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7, fro=
m 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP=C2= =A017.0, corresponding to inets before 5.10, is affected is unknown.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71562" target=3D= "_blank" rel=3D"noopener">CVE-2026-71562</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets=
httpd allows a remote unauthenticated attacker to read files inside a mod_= auth protected directory by requesting them with different casing, on deplo= yments whose filesystem is case-insensitive. mod_auth:secret_path/3 decides=
whether a resolved filesystem path lies inside a protected directory block=
by running the configured directory path through re:run/3 without the case= less option. A request for /secret/file against a directory configured as /= Secret therefore does not match, so the request is treated as unprotected a=
nd no authentication challenge is issued, while the filesystem resolves the=
differently cased path to the same file and mod_get serves it. Deployments=
on case-sensitive filesystems are unaffected, because there the filesystem=
itself rejects the mismatched casing. This issue affects OTP from OTP=C2= =A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.= 0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets = from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.=
2. Whether OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is=
affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73270" target=3D= "_blank" rel=3D"noopener">CVE-2026-73270</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>Gracefulness code ignored cases that should be rejected, resulting in p= ossible HTTP Request Smuggling opportunities. This issue affects OTP from O= TP=C2=A022.2 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A0= 28.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to i= nets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 befor=
e 9.7.2.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73276" target=3D= "_blank" rel=3D"noopener">CVE-2026-73276</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>httpd function check_header/3 rejects duplicate Content-Length (per CVE= -2026-23941) but never checks for the TE+CL co-presence that RFC 9112 =C3= =82=C2=A76.3 identifies as a probable smuggling attempt. handle_body/3 fram=
es by chunked and silently discards Content-Length. A CL-preferring front-e=
nd paired with chunked-preferring inets creates a classic CL.TE front-end/b= ack-end desync. This issue affects OTP from OTP=C2=A017.0 before OTP=C2=A02= 7.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, and from OTP=C2=A029=
.0 before OTP=C2=A029.0.6, corresponding to inets from 5.10 before 9.3.2.7,=
from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP= =C2=A017.0, corresponding to inets before 5.10, is affected is unknown.</td=
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-73812" target=3D= "_blank" rel=3D"noopener">CVE-2026-73812</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>The inets application HTTP server httpd fails to enforce a configured b= ody-size limit on chunked request. This issue affects OTP from OTP=C2=A017.=
0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before OTP=C2=A028.5.0.6, a=
nd from OTP=C2=A029.0 before OTP=C2=A029.0.6, corresponding to inets from 5= .10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whe= ther OTP before OTP=C2=A017.0, corresponding to inets before 5.10, is affec= ted is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74835" target=3D= "_blank" rel=3D"noopener">CVE-2026-74835</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>The mod_auth module in OTP's inets httpd server, when configured with d= ets or mnesia authentication backends and multiple directory configuration = blocks, collapses all directory blocks into a single shared user/group name= space. A user added to one protected directory is accepted as valid for all=
other protected directories on the same server instance. This issue affect=
s OTP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 befo=
re OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, corres= ponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and fro=
m 9.7 before 9.7.2. Whether OTP before OTP=C2=A017.0, corresponding to inet=
s before 5.10, is affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-74994" target=3D= "_blank" rel=3D"noopener">CVE-2026-74994</a></td>
</tr>
<td class=3D"vendor-product">Erlang--OTP</td>
<td>An attacker that connects to an open Erlang TCP port that uses the inet=
driver with {packet,4} mode can use a signed overflow in an incorrect pack=
et length calculation to overflow the receive buffer into the VM allocator = area and beyond up to about 2 GB. This would easily trash the allocated blo= ck's allocator metadata footer, and the next block, if any, and most likely=
cause the BEAM VM to crash. Utilizing this with precision enough to achiev=
e Remote Code Execution would be extremely unfeasible. This issue affects O=
TP from OTP=C2=A017.0 before OTP=C2=A027.3.4.17, from OTP=C2=A028.0 before = OTP=C2=A028.5.0.6, and from OTP=C2=A029.0 before OTP=C2=A029.0.6, correspon= ding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from=
17.0 before 17.0.6. Whether OTP before OTP=C2=A017.0, corresponding to ert=
s before 6.0, is affected is unknown.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75538" target=3D= "_blank" rel=3D"noopener">CVE-2026-75538</a></td>
</tr>
<td class=3D"vendor-product">esoTalk--esoTalk v.1.0.0g4<br>=C2=A0</td>
<td>An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbit= rary code via the core/models/ETMemberModel.class.php, core/controllers/ETM= emberController.class.php, and core/lib/ET.class.php components</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71624" target=3D= "_blank" rel=3D"noopener">CVE-2026-71624</a></td>
</tr>
<td class=3D"vendor-product">Extend Themes--Kubio AI Website Builder</td> <td>Improper input validation vulnerability in Extend Themes Kubio AI Websi=
te Builder. This issue affects Kubio AI Website Builder: before 2.9.1.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83492" target=3D= "_blank" rel=3D"noopener">CVE-2026-83492</a></td>
</tr>
<td class=3D"vendor-product">frappe--crm</td>
<td>Frappe CRM is an open-source customer relationship management tool. Pri=
or to version 1.73.0, there is an authentication bypass vulnerability via l= ogged invitation keys in crm/api. This issue has been patched in version 1.= 73.0.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53761" target=3D= "_blank" rel=3D"noopener">CVE-2026-53761</a></td>
</tr>
<td class=3D"vendor-product">Free5GC -- Free5GC v4.2.2<br>=C2=A0</td>
<td>An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial =
of service via the UPF component</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75439" target=3D= "_blank" rel=3D"noopener">CVE-2026-75439</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. From 5.0.0 until 5.5= .2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run=
the relevant upload authorization preflight in Kirby\Api\Upload::process()=
before Kirby\Api\Upload::processChunk() persisted chunk data. An authentic= ated user with the access.panel permission enabled but with files.create, f= iles.replace, and user/users.update permissions disabled could submit reque= sts with an Upload-Length header and leave unfinished chunks in site/cache/= .uploads for 24 hours. Repeating this process could consume attacker-contro= lled temporary storage, prevent other users from uploading files, or preven=
t site logic from storing data, although final permission checks still prev= ented unauthorized files from reaching the content or site/accounts directo= ries. This issue is fixed in version 5.5.2.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71415" target=3D= "_blank" rel=3D"noopener">CVE-2026-71415</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.5 and 5= .5.2, depending on the release line, Kirby's media handler used incomplete = filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/= F.php through Kirby\Filesystem\Dir::realpath() and Kirby\Filesystem\F::real= path(). The checks accepted a sibling directory whose path shared the inten= ded root's string prefix, such as /var/www/site2 next to /var/www/site, bec= ause they did not require an exact match or a DIRECTORY_SEPARATOR boundary.=
A remote attacker could use Kirby\Cms\Media::thumb() to create and access = thumbnails from image files in a PHP-readable sibling directory when that d= irectory contained a valid .json thumbnail job file, potentially exposing s= taging sites, backups, or other internal sites and deleting the job file du= ring processing. This issue is fixed in versions 4.9.5 and 5.5.2.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75592" target=3D= "_blank" rel=3D"noopener">CVE-2026-75592</a></td>
</tr>
<td class=3D"vendor-product">getkirby--kirby</td>
<td>Kirby is an open-source content management system. Prior to 4.9.5 and 5= .5.2, depending on the release line, Kirby's media handler in src/Cms/Media= .php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to =
a validated parent media directory. On nginx, PHP's built-in server, or Apa= che with AllowEncodedSlashes enabled, a remote attacker could submit encode=
d slash characters such as %2f in the filename and traverse outside the par= ent's media directory. Differences between responses for existing and nonex= istent thumbnail configurations disclosed whether an arbitrary .json file e= xisted, and a .json file containing a valid filename key could cause the re= ferenced image to be returned and the job file to be deleted. The related f= ile::version path in src/Filesystem/Asset.php also accepted ../ sequences o= utside the intended index root. This issue is fixed in versions 4.9.5 and 5= .5.2.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75594" target=3D= "_blank" rel=3D"noopener">CVE-2026-75594</a></td>
</tr>
<td class=3D"vendor-product">GitHub--Enterprise Server</td>
<td>A server-side request forgery (SSRF) vulnerability was identified in Gi= tHub Enterprise Server that allowed an unauthenticated attacker to cause th=
e Manage API to send crafted outbound requests to an attacker-controlled ho= st. An unauthenticated endpoint parsed an attacker-supplied cluster configu= ration and issued gateway-to-agent requests whose HMAC authenticated only a=
timestamp, not the request path or body. An attacker positioned to interce=
pt the outbound request could capture this token and replay it against priv= ileged management agent endpoints. High-availability deployments were not a= ffected due to a topology restriction. This vulnerability affected all vers= ions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.= 17.19, 3.18.13, 3.19.10, 3.20.6, and 3.21.4. This vulnerability was reporte=
d via the GitHub Bug Bounty program.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18730" target=3D= "_blank" rel=3D"noopener">CVE-2026-18730</a></td>
</tr>
<td class=3D"vendor-product">GitHub--Enterprise Server</td>
<td>A time-of-check time-of-use race condition vulnerability was identified=
in GitHub Enterprise Server that allowed remote code execution. Exploitati=
on required an authenticated user with write access to a repository and pre= cise timing of concurrent upload requests. This vulnerability affected all = versions of GitHub Enterprise Server prior to 3.22 and was fixed in version=
s 3.17.20, 3.18.14, 3.19.11, 3.20.7, and 3.21.5. This vulnerability was rep= orted via the GitHub Bug Bounty program.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19118" target=3D= "_blank" rel=3D"noopener">CVE-2026-19118</a></td>
</tr>
<td class=3D"vendor-product">GitHub--Enterprise Server</td>
<td>A Server-Side Request Forgery (SSRF) vulnerability was identified in Gi= tHub Enterprise Server that allowed remote code execution on the instance. = Insufficient network isolation allowed malicious pre-receive hook code to i= mpersonate an internal service and redirect trusted internal requests to a = privileged service, leading to elevated code execution. Exploitation requir=
ed pre-receive hook networking to be enabled and either site administrator = privileges or write access to a repository containing a configured pre-rece= ive hook. This vulnerability affected all versions of GitHub Enterprise Ser= ver prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20= .7, and 3.21.5. This vulnerability was reported via the GitHub Bug Bounty p= rogram.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76851" target=3D= "_blank" rel=3D"noopener">CVE-2026-76851</a></td>
</tr>
<td class=3D"vendor-product">Google Cloud--Agent Development Kit (ADK)</td> <td>A Path Traversal vulnerability in the builder endpoint in Google Cloud = Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows =
an unauthenticated remote attacker to read arbitrary files using a crafted = file_path query parameter.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79707" target=3D= "_blank" rel=3D"noopener">CVE-2026-79707</a></td>
</tr>
<td class=3D"vendor-product">Google Cloud--Google Cloud Build</td>
<td>An Incorrect Authorization vulnerability in GitHub Trigger Comment Cont= rol in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allo=
ws a remote attacker to execute unreviewed code in the build environment us= ing webhook suppression. This vulnerability was patched on 24 June 2026, an=
d no customer action is needed.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19410" target=3D= "_blank" rel=3D"noopener">CVE-2026-19410</a></td>
</tr>
<td class=3D"vendor-product">Google Cloud--Integration Connectors</td>
<td>A Missing Authorization vulnerability in HTTP Connector in Google Cloud=
Integration Connectors versions prior to 2025-12-11 on Google Cloud Platfo=
rm allows an authenticated user to escalate privileges and take over a Goog=
le Cloud Project using unauthorized service account attachment. This vulner= ability was patched on 11 December 2025, and no customer action is needed.<=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4644" target=3D"= _blank" rel=3D"noopener">CVE-2026-4644</a></td>
</tr>
<td class=3D"vendor-product">Grav API Plugin--Grav API Plugin<br>=C2=A0</td=
<td>Grav API plugin versions before 1.0.20 build password reset links from = the untrusted Host header in the forgot-password endpoint, allowing unauthe= nticated attackers to redirect reset tokens to attacker-controlled domains.=
Attackers can send password reset requests for any account with a maliciou=
s Host header, intercept the reset token from victim emails, and complete a= ccount takeover including super-admin accounts.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86196" target=3D= "_blank" rel=3D"noopener">CVE-2026-86196</a></td>
</tr>
<td class=3D"vendor-product">Grav Form Plugin--Grav Form Plugin<br>=C2=A0</=
<td>Grav Form Plugin before 9.1.22 fails to verify page authorization when = resolving forms by name across pages, allowing anonymous visitors to execut=
e form actions defined on login-restricted or unpublished pages. Attackers = can POST to any public page with a restricted form's name to trigger save, = upload, email, or call actions without authentication.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86194" target=3D= "_blank" rel=3D"noopener">CVE-2026-86194</a></td>
</tr>
<td class=3D"vendor-product">Grav--Grav<br>=C2=A0</td>
<td>Grav before 2.0.20 contains a cross-site scripting vulnerability in the=
Twig sandbox policy that allowlists addJs and addCss methods on Grav\Commo= n\Assets without proper output escaping. Page editors can inject arbitrary = script by registering malicious assets or injecting attributes, which are r= endered unescaped into document head tags and executed for all visitors inc= luding administrators.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86197" target=3D= "_blank" rel=3D"noopener">CVE-2026-86197</a></td>
</tr>
<td class=3D"vendor-product">grav-plugin-api--grav-plugin-api<br>=C2=A0</td=
<td>grav-plugin-api before 1.0.20 fails to validate group-inherited super p= ermissions in user-management guards, allowing non-super user managers to m= odify super-admin accounts. Attackers with api.access and api.users.write c=
an patch password fields on group-super accounts to gain full administrativ=
e control.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86193" target=3D= "_blank" rel=3D"noopener">CVE-2026-86193</a></td>
</tr>
<td class=3D"vendor-product">grav-plugin-api--grav-plugin-api<br>=C2=A0</td=
<td>grav-plugin-api versions before 1.0.20 contain a privilege escalation v= ulnerability in the InvitationsController where the stripSuperFlags() metho=
d only removes nested super flags but fails to strip dot-keyed equivalents = like api.super. A non-super user manager with api.access and api.users.writ=
e permissions can create an invitation with a dot-keyed super flag in the a= ccess payload that bypasses the guard and persists to the new account. Atta= ckers can accept the invitation through the public endpoint without real in= vitee interaction to create a super-admin account and immediately receive a=
valid JWT for full site control.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86195" target=3D= "_blank" rel=3D"noopener">CVE-2026-86195</a></td>
</tr>
<td class=3D"vendor-product">GROWI, Inc.--GROWI</td>
<td>GROWI contains a vulnerability with an authorization bypass through use= r-controlled key in the bookmark folder APIs. If this vulnerability is expl= oited, an authenticated attacker could retrieve, tamper with, and/or delete=
the other user's bookmark data.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53620" target=3D= "_blank" rel=3D"noopener">CVE-2026-53620</a></td>
</tr>
<td class=3D"vendor-product">GROWI, Inc.--GROWI</td>
<td>GROWI contains an incorrect authorization vulnerability. If this vulner= ability is exploited, an unauthenticated attacker could retrieve the other = user's bookmark data.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-68951" target=3D= "_blank" rel=3D"noopener">CVE-2026-68951</a></td>
</tr>
<td class=3D"vendor-product">grpc--grpc-go</td>
<td>gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the=
xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowe= rcase header matcher names in normalizeHeaderMatcher even though incoming m= etadata keys are lowercase. A DENY policy using a mixed-case name such as X= -Role or User-Agent therefore does not match and fails open, allowing reque= sts that should be rejected. The same case mismatch permits :Scheme or Grpc= -Status to evade gRFC A41 validation and prevents Host from being rewritten=
to :authority. This issue is fixed in version 1.83.1.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84303" target=3D= "_blank" rel=3D"noopener">CVE-2026-84303</a></td>
</tr>
<td class=3D"vendor-product">grpc--grpc-go</td>
<td>gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, int= ernal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a = separate recvMsg in recvBuffer, so millions of one-byte frames can consume = disproportionate heap memory even when payload bytes remain within connecti=
on and stream flow-control windows. An unauthenticated remote attacker can = use concurrent multiplexed streams to exhaust process memory and cause a ru= ntime panic or out-of-memory termination. Receive-buffer compaction is enab= led by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_= ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.</t=
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84304" target=3D= "_blank" rel=3D"noopener">CVE-2026-84304</a></td>
</tr>
<td class=3D"vendor-product">HiDPT--Weyon HiDPTAndroid</td>
<td>An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows=
a remote attacker to execute arbitrary code via the Android Debug Bridge (= ADB) daemon (adbd)</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78745" target=3D= "_blank" rel=3D"noopener">CVE-2026-78745</a></td>
</tr>
<td class=3D"vendor-product">Hitachi Energy--MicroSCADA SYS600</td>
<td>A CSV injection vulnerability exists in SYS600. Injected malicious form= ulas can add or modify data to the spreadsheet, insert links, exfiltrate da= ta, and in some cases, depending on how the user has their environment conf= igured, execute malicious code on the user's machine. To exploit this issue=
attackers would need a way to create arbitrary log messages. This could be=
achieved through normal functionality via SCIL scripts, a log injection vu= lnerability, or via the SYS600 broker. This vulnerability affects all Windo=
ws users regardless of their privilege level who can run the Notify service=
and export the log.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9852" target=3D"= _blank" rel=3D"noopener">CVE-2026-9852</a></td>
</tr>
<td class=3D"vendor-product">Hitachi Energy--MicroSCADA SYS600</td>
<td>A vulnerability exists in SYS600 which allows any user authenticated to=
the operating system of the server hosting the application to read and mod= ify application objects without being authenticated to the SYS600 system it= self. Only the SYS600 system users should be permitted to view and modify a= pplication objects.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9853" target=3D"= _blank" rel=3D"noopener">CVE-2026-9853</a></td>
</tr>
<td class=3D"vendor-product">Hitachi Energy--MicroSCADA SYS600</td>
<td>A vulnerability exists in SYS600 RBAC mechanism where users having acce=
ss to the engineering tools could elevate their privileges to administrator=
level on the underlying Windows host, granting themselves full control ove=
r the host machine.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9854" target=3D"= _blank" rel=3D"noopener">CVE-2026-9854</a></td>
</tr>
<td class=3D"vendor-product">HP Inc--HP ImageDiags</td>
<td>A potential security vulnerability has been identified in the HP ImageD= iags for versions prior to 5.0.0.36. The vulnerability could potentially al= low a local attacker to escalate privileges due to insufficient access cont= rols.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82346" target=3D= "_blank" rel=3D"noopener">CVE-2026-82346</a></td>
</tr>
<td class=3D"vendor-product">HP Inc.--HP Support Assistant</td>
<td>A potential security vulnerability has been identified in the HP Suppor=
t Assistant for versions prior to 9.53.2.0. The vulnerability could potenti= ally allow a local attacker to escalate privileges due to insufficient acce=
ss controls.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15431" target=3D= "_blank" rel=3D"noopener">CVE-2026-15431</a></td>
</tr>
<td class=3D"vendor-product">HubCore--HubCore</td>
<td>Cross-site scripting (XSS) vulnerability in the /loginController/doLogi=
n endpoint of the HubCore platform (version 14.1.1) allows a remote unauthe= nticated attacker to inject arbitrary JavaScript into the application's res= ponse via the language POST parameter.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75170" target=3D= "_blank" rel=3D"noopener">CVE-2026-75170</a></td>
</tr>
<td class=3D"vendor-product">HubCore--HubCore</td>
<td>An issue in HubCore v.14.1.1 allows a remote attacker to escalate privi= leges via the HUBCOREID session cookie handling component.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75171" target=3D= "_blank" rel=3D"noopener">CVE-2026-75171</a></td>
</tr>
<td class=3D"vendor-product">IBM--Verify Identity Access Advanced Access Co= ntrol<br>=C2=A0</td>
<td>IBM Verify Identity Access Advanced Access Control may be vulnerable to=
an information disclosure attack.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13297" target=3D= "_blank" rel=3D"noopener">CVE-2026-13297</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td>
<td>Kernel software installed and running inside a Guest VM may post improp=
er commands to the GPU Firmware to trigger a read and/or write data outside=
the Guest's virtualised GPU memory. The firmware uses data provided by the=
Guest VM to set up accesses to memory. It validated this before use, but a=
TOCTOU bug was present which allowed the earlier check results to be inval= idated.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45197" target=3D= "_blank" rel=3D"noopener">CVE-2026-45197</a></td>
</tr>
<td class=3D"vendor-product">Imagination Technologies--Graphics DDK</td>
<td>Software installed and run as a non-privileged user may conduct imprope=
r GPU driver IOCTL calls to create an allocation scenario that when freed w= ould cause double free and kernel heap corruption. Scenario caused by fabri= cating a specific combination of flags on the allocation interface that wou=
ld cause an incorrect double free event when freed.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-45200" target=3D= "_blank" rel=3D"noopener">CVE-2026-45200</a></td>
</tr>
<td class=3D"vendor-product">Italtel--NetMatch<br>=C2=A0</td>
<td>Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_I= BCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-Web= Gui/storage.jsp via the name parameter. A malicious user leveraging this vu= lnerability could inject arbitrary JavaScript. The malicious payload will t= hen be triggered every time an authenticated user browses the page containi=
ng it.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-26961" target=3D= "_blank" rel=3D"noopener">CVE-2022-26961</a></td>
</tr>
<td class=3D"vendor-product">j2commerce.com--J2Store extension for Joomla</=
<td>Joomla Extension - j2commerce.com - Unauthenticated PayPal callback for= gery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0= .21, 4.1.0-4.1.6 - The PayPal IPN listener's signature check (`_validateIPN= ()`) accepted `UNVERIFIED` and any non-`INVALID` response as valid, made it=
s verification request with `CURLOPT_SSL_VERIFYPEER` disabled, and stored i=
ts verdict in a field nothing downstream ever checked - so processing conti= nued regardless of the outcome. Separately, the paid-amount comparison only=
ran when `mc_gross` was a positive number; omitting the field from the POS=
T body (`floatval(null) =3D=3D 0`) skipped the check entirely. Combined wit=
h a merchant-configured `receiver_email` and a sequential, enumerable order=
id read from the `custom` field, an anonymous POST was enough to move a pe= nding order straight to `CONFIRMED` with no payment, or force another custo= mer's pending order to `FAILED`. `paypalv2.php` performed no amount check u= nder any circumstances.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77999" target=3D= "_blank" rel=3D"noopener">CVE-2026-77999</a></td>
</tr>
<td class=3D"vendor-product">j2commerce.com--J2Store extension for Joomla</=
<td>Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pr= icefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 -=
Four task handlers accepted a base64-encoded URL from user input and redir= ected to it without validating the destination host, enabling phishing usin=
g the shop's trusted domain. No authentication required.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78000" target=3D= "_blank" rel=3D"noopener">CVE-2026-78000</a></td>
</tr>
<td class=3D"vendor-product">j2commerce.com--J2Store extension for Joomla</=
<td>Joomla Extension - j2commerce.com - Anonymous cart-record tampering via=
inherited FOF `save` task in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1=
.6 - `fof.xml` grants the `carts` view's tasks a wildcard `true` ACL, and F=
OF only enforces CSRF tokens on back-end HTML requests, not on front-end `f= ormat=3Draw` requests. `J2StoreControllerCarts` already scoped `remove()` t=
o the caller's own session, but never overrode the generic FOF `save` task,=
so it remained reachable to insert new cart rows with an attacker-chosen `= user_id`/`session_id`, or overwrite an existing row by id.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78064" target=3D= "_blank" rel=3D"noopener">CVE-2026-78064</a></td>
</tr>
<td class=3D"vendor-product">j2commerce.com--J2Store extension for Joomla</=
<td>Joomla Extension - j2commerce.com - Guest checkout address disclosure t=
o any authenticated user (IDOR) in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.= 0-4.1.6 - `editAddress()` redirected non-owners away only when the loaded a= ddress row had a **non-empty** `user_id` belonging to someone else. Guest-c= heckout address rows have an empty `user_id`, so that check never triggered=
for them - any logged-in account guessing a small, sequential `address_id`=
got a guest customer's full name, street address, and phone number rendere=
d prefilled into the edit form.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78065" target=3D= "_blank" rel=3D"noopener">CVE-2026-78065</a></td>
</tr>
<td class=3D"vendor-product">j2commerce.com--J2Store extension for Joomla</=
<td>Joomla Extension - j2commerce.com - Missing authorization on Apps contr= oller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 -=
`J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugi=
n controllers with no ACL check anywhere in the code. It currently returns = 403 only as a side effect of `fof.xml`'s wildcard-deny resolving under the = singularised ACL key `app`, which has no explicit allow rule - not because =
of any deliberate check. Behind that path, `applocalizationdata::getInstall= erTool()` used a caller-influenced table name with no allow-list, both to s= elect a `#__j2store_*` table for truncation and to build a path to SQL file=
s it then executes - a path-traversal-capable file read/execute.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78069" target=3D= "_blank" rel=3D"noopener">CVE-2026-78069</a></td>
</tr>
<td class=3D"vendor-product">JAL Information Technology Co., Ltd.--PALLET C= ONTROL</td>
<td>PALLET CONTROL products contain an incorrect default permission vulnera= bility, which may allow a local attacker to execute arbitrary code with SYS= TEM privileges on the affected product.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81302" target=3D= "_blank" rel=3D"noopener">CVE-2026-81302</a></td>
</tr>
<td class=3D"vendor-product">jetperch--pymonocypher</td>
<td>pymonocypher uses cython to wrap the Monocypher C library. Prior to ver= sion 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks si= ze. If the caller does not provide a sufficiently large buffer based on the=
API contract, then argon2i_32 will write past the end of the buffer and po= ssibly corrupt the heap. This issue has been patched in version 4.0.2.8.</t=
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53720" target=3D= "_blank" rel=3D"noopener">CVE-2026-53720</a></td>
</tr>
<td class=3D"vendor-product">joodb.feenders.de--JooDatabase Lite extension = for Joomla</td>
<td>Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDa= tabase Lite < 5.1.0 - The cid parameter is used in queries without valid= ation, allowing SQLi vectors.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78080" target=3D= "_blank" rel=3D"noopener">CVE-2026-78080</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.com--Helix Ultimate extension for J= oomla</td>
<td>Joomla Extension - joomshaper.com - Broken Object-Level Authorization i=
n Blog Image Deletion in Helix Ultimate < 2.2.10 - `Blog::remove_image()=
` checked whether the user was authorized to edit the article ID passed in = the request, but did not verify whether the specified image path (src) belo= nged to that article. On Joomla 3 builds where physical file deletion was t= riggered, an author could supply their own article ID alongside an arbitrar=
y file path under the `/images/` directory to delete arbitrary files.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78075" target=3D= "_blank" rel=3D"noopener">CVE-2026-78075</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.com--Helix Ultimate extension for J= oomla</td>
<td>Joomla Extension - joomshaper.com - Broken Access Control & Missing=
Authorization in MegaMenu Settings in Helix Ultimate < 2.2.10 - The AJA=
X endpoint save-megamenu-settings failed to enforce item-level and menu-lev=
el edit permissions (core.edit on com_menus.item.{id} or core.admin). An au= thenticated user could submit modified layout parameters for arbitrary menu=
items without proper authorization.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78076" target=3D= "_blank" rel=3D"noopener">CVE-2026-78076</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.com--Helix Ultimate extension for J= oomla</td>
<td>Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) i=
n MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.1=
0 - Unsanitized column and item configuration values stored within the Mega= Menu layout JSON were rendered without complete contextual escaping, allowi=
ng injection of malicious HTML/JS. Stricter sanitization and tag allowlists=
via `InputFilter` and `htmlspecialchars` were implemented.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78077" target=3D= "_blank" rel=3D"noopener">CVE-2026-78077</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.com--Helix Ultimate extension for J= oomla</td>
<td>Joomla Extension - joomshaper.com - Privileged File Upload Bypass via C= ontent Spoofing in Helix Ultimate < 2.2.10 - Image uploads previously va= lidated only file extension and basic size parameters. Non-image files disg= uised with raster extensions could be uploaded. Added strict MIME verificat= ion and GD binary raster decoding (imagecreatefromstring) to reject invalid= /malformed images fail-closed.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78078" target=3D= "_blank" rel=3D"noopener">CVE-2026-78078</a></td>
</tr>
<td class=3D"vendor-product">joomshaper.com--Helix Ultimate extension for J= oomla</td>
<td>Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Par= ameter in Helix Ultimate < 2.2.10 - Return redirect parameters accepted = arbitrary Base64 strings without verifying whether the resolved target was =
an internal site URL via Uri::isInternal.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78079" target=3D= "_blank" rel=3D"noopener">CVE-2026-78079</a></td>
</tr>
<td class=3D"vendor-product">kamailio--kamailio v6.1.1</td>
<td>An issue in kamailio v.6.1.1 and before allows a remote attacker to cau=
se a denial of service via the ims_registrar_pcscf module, specifically the=
pcscf_save_pending/save_pending path and security-agreement parsing in sec= _agree.c:parse_sec_agree()</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52023" target=3D= "_blank" rel=3D"noopener">CVE-2026-52023</a></td>
</tr>
<td class=3D"vendor-product">libcurl --libcurl<br>=C2=A0</td>
<td>A flaw in libcurl's handling of HTTP/2 Server Push streams, when the pa= rent handle is set to share connections with other handles, can lead to use= -after-free in the cleanup process.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18924" target=3D= "_blank" rel=3D"noopener">CVE-2026-18924</a></td>
</tr>
<td class=3D"vendor-product">libcurl --libcurl=C2=A0<br>=C2=A0</td>
<td>A flaw in the libcurl SASL negotiation for LDAP authentication allows a=
n incomplete handshake sequence to be misinterpreted as a successful crypto= graphic verification. An attacker executing a Man-in-the-Middle (MITM) atta=
ck can inject a premature or shortcut response that bypasses complete peer = validation.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13608" target=3D= "_blank" rel=3D"noopener">CVE-2026-13608</a></td>
</tr>
<td class=3D"vendor-product">libcurl--libcurl<br>=C2=A0</td>
<td>When performing transfers via libcurl's multi interface, pooled TLS con= nections can outlive their originating easy handles. In OpenSSL 3 provider = configurations, libcurl attaches an allocated library context to the easy h= andle's state and passes it to OpenSSL without acquiring an ownership refer= ence; destroying the easy handle prematurely frees this context while the a= ctive connection retains a dangling pointer, leading to a heap-use-after-fr=
ee upon subsequent I/O or post-handshake operations.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80229" target=3D= "_blank" rel=3D"noopener">CVE-2026-80229</a></td>
</tr>
<td class=3D"vendor-product">libcurl--libcurl<br>=C2=A0</td>
<td>When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that dis= able standard peer verification (`CURLOPT_SSL_VERIFYPEER =3D 0` and `CURLOP= T_SSL_VERIFYHOST =3D 0`), libcurl fails to enforce public key pinning on co= nnections established without a presented server certificate. Bypassing the=
pinning check under these disabled-verification conditions allows unauthen= ticated connections to succeed when they should be rejected.</td> <td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80230" target=3D= "_blank" rel=3D"noopener">CVE-2026-80230</a></td>
</tr>
<td class=3D"vendor-product">libcurl--libcurl<br>=C2=A0</td>
<td>A flaw in libcurl makes it wrongly reuse an existing HTTPS connection s= etup for a given hostname even when using a different Native CA Store setti=
ng (`CURLSSLOPT_NATIVE_CA`) than when the connection was created.</td> <td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80231" target=3D= "_blank" rel=3D"noopener">CVE-2026-80231</a></td>
</tr>
<td class=3D"vendor-product">libcurl--libcurl<br>=C2=A0</td>
<td>When libpsl support is enabled, libcurl fails to enforce the Public Suf= fix List boundary check when processing a `Set-Cookie` header where the `Do= main` attribute explicitly matches an origin host that is itself a public s= uffix (e.g., `Domain=3Dco.uk` set by `co.uk`). Instead of coercing it into =
a strict host-only cookie, libcurl saves the cookie with wildcard domain sc= ope (`.co.uk`). Consequently, the cookie is inappropriately included in sub= sequent outbound requests or HTTP redirects to arbitrary sibling subdomains=
under the same public suffix (e.g., `attacker.co.uk`).</td> <td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82209" target=3D= "_blank" rel=3D"noopener">CVE-2026-82209</a></td>
</tr>
<td class=3D"vendor-product">libcurl--libcurl=C2=A0<br>=C2=A0</td>
<td>A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a=
given hostname using Negotiate authentication, when the initial request is=
done using empty credentials. This can make user B's request get sent over=
user A's previously authenticated connection.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19931" target=3D= "_blank" rel=3D"noopener">CVE-2026-19931</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerab= ility in legacy PHP template pages that render unescaped SNMP-sourced data = fields including BGP peer descriptions, VRF names, process information, and=
SLA tags. Attackers with device management access or network access to enr= oll a rogue SNMP device can inject malicious JavaScript that executes when = admins view affected routing and device pages, enabling credential theft an=
d CSRF token exfiltration.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84193" target=3D= "_blank" rel=3D"noopener">CVE-2026-84193</a></td>
</tr>
<td class=3D"vendor-product">librenms--librenms</td>
<td>LibreNMS versions >=3D 23.10.0 and < 26.2.0 (fixed in 26.4.0) con= tain an authenticated OS command injection vulnerability in libvirt discove= ry. When libvirt support is enabled (enable_libvirt=3Dtrue), the device hos= tname ($this->getDevice()->hostname) is concatenated into shell comma= nds (ssh, virsh list/dumpxml/domstate) in VminfoLibvirt.php and passed to e= xec() without escapeshellarg() or argument separation. An authenticated adm=
in can set a crafted device hostname to inject arbitrary OS commands, leadi=
ng to remote code execution in the discovery worker context.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84194" target=3D= "_blank" rel=3D"noopener">CVE-2026-84194</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86= /mce: Set up the polling timer before CMCI discovery I hit the following on=
one of my machines: mce: CPU0 BANK15 CMCI inherited storm ------------[ cu=
t here ]------------ ODEBUG: assert_init not available (active state 0) obj= ect: (____ptrval____) object type: timer_list hint: 0x0 WARNING: lib/debugo= bjects.c:632 at debug_object_assert_init+0x178/0x230, CPU#0: swapper/0/0 CP=
U: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc5 #3 PREEMPTLAZY RIP=
: 0010:debug_object_assert_init+0x18f/0x230 Call Trace: <TASK> __mod_= timer mce_timer_kick cmci_discover intel_init_cmci mce_intel_feature_init m= check_cpu_init identify_cpu identify_boot_cpu arch_cpu_finalize_init start_= kernel A second splat follows right after, from timer_setup() finding that = same timer already queued: ODEBUG: init active (active state 0) object: (__= __ptrval____) object type: timer_list hint: stub_timer+0x0/0x10 This is hap= pening because CMCI storm detection is trying to modify the timer before la= tter was properly set up. Set up the timer first. __mcheck_cpu_setup_timer(=
) only calls timer_setup(), and depends on neither the generic nor the vend=
or init. [ bp: Massage commit message. ]</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80727" target=3D= "_blank" rel=3D"noopener">CVE-2026-80727</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Rev= ert "drm/amdgpu: fix aperture mapping leak" devres teardown is LIFO. The ap= erture devres node was registered after the DRM device node, so devres_rele= ase_all() unmaps the aperture before the DRM device release callback fires = amdgpu_device_fini_sw(). IP sw_fini callbacks (e.g. vcn_v4_0_sw_fini) write=
to fw_shared through a pointer derived from aper_base_kaddr, causing a ker= nel page fault on probe failure / rollback: BUG: unable to handle page faul=
t ... PMD 0 RIP: vcn_v4_0_sw_fini+0x7b/0x170 [amdgpu] Call Trace: amdgpu_de= vice_fini_sw amdgpu_driver_release_kms devm_drm_dev_init_release devres_rel= ease_all This reverts commit d871e99879cb5fd1fa798b006b4888887e63a17a. (che= rry picked from commit 336e0cd576817ac64a4b394ca2b3680029f3e37f)</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80728" target=3D= "_blank" rel=3D"noopener">CVE-2026-80728</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm/= huge_memory: initialise workingset state before folio split xas_try_split()=
adds __GFP_ACCOUNT for page-cache xa_nodes, but __folio_split() leaves the=
xa_state's xa_lru unset. That lets a live, memcg-charged xa_node exist wit= hout being linked into the mapping's shadow_nodes list_lru; when reclaim la= ter walks the list_lru it trips VM_WARN_ON(!css_is_dying()). Use mapping_se= t_update() to install both the workingset update callback and the shadow_no= des list_lru on the xa_state.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80729" target=3D= "_blank" rel=3D"noopener">CVE-2026-80729</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: rin= g-buffer: Fix crash passing ERR_PTR to kthread_stop() In test_ringbuffer()'=
s out_free cleanup loop, the check `!rb_threads[cpu]` only catches NULL ent= ries and misses entries that hold an ERR_PTR. rb_threads[] is static, so un= assigned slots are NULL. But when kthread_run_on_cpu() fails for a cpu, it = stores ERR_PTR(-ENOMEM) (or -EINTR) in rb_threads[cpu] before the creation = loop jumps to out_free. That entry is non-NULL, so the old `!ptr` check doe=
s not break, and the cleanup proceeds to call kthread_stop() on the ERR_PTR=
. kthread_stop() then dereferences the bogus pointer, crashing the kernel d= uring the late_initcall self-test. crash logs: BUG: kernel NULL pointer der= eference, address: 000000000000001c Oops: 0002 [#1] SMP NOPTI CPU: 1 PID: 1=
Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy) RIP: 0010:kth= read_stop+0x2e/0x220 RBX: fffffffffffffff4 CR2: 000000000000001c Call Trace=
: <TASK> test_ringbuffer+0x1ec/0x650 do_one_initcall+0x6c/0x2c0 kerne= l_init_freeable+0x21d/0x420 kernel_init+0x15/0x1c0 ret_from_fork+0x21b/0x32=
0 </TASK> Kernel panic - not syncing: Fatal exception</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80730" target=3D= "_blank" rel=3D"noopener">CVE-2026-80730</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net=
: remove WARN_ON_ONCE() from sk_mc_loop() sk_mc_loop() can be called for so= ckets that are neither AF_INET nor AF_INET6 (e.g. AF_PACKET sockets when se= nding packets via raw/packet socket over virtual devices such as VRF or ipv= lan). In such cases, sk_family is not AF_INET/AF_INET6 and sk_mc_loop() fal=
ls through the switch statement and triggers WARN_ON_ONCE(1). Non-INET sock= ets do not support IP_MULTICAST_LOOP or IPV6_MULTICAST_LOOP options, so loo= pback should default to true without generating a warning.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80733" target=3D= "_blank" rel=3D"noopener">CVE-2026-80733</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /mlx5e: TC, Check if flow is PEER before acquiring devcom lock In case __ml= x5e_add_fdb_flow() fails in lower levels, the flow is deleted via mlx5e_tc_= del_flow(), and mlx5e_tc_del_flow() is acquiring ESW devcom lock without co= ndition. In addition, in case of peer_flow, __mlx5e_add_fdb_flow() is calle=
d while holding ESW devcom comp lock. This results in an AA deadlock. To fi=
x this, introduce a new PEER flag that is set on flows created as peer flow=
s (the duplicate flows on peer devices), and check it in mlx5e_tc_del_flow(=
) before acquiring ESW devcom lock. Lockdep splat: =3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D WARNING: possible recursive locking detec= ted =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Possible un= safe locking scenario: CPU0 ---- lock(&comp->lock_key#2); lock(&= comp->lock_key#2); *** DEADLOCK *** Call Trace: <TASK> dump_stack_= lvl+0x69/0xa0 print_deadlock_bug.cold+0xbd/0xca __lock_acquire+0x1671/0x2ec=
0 lock_acquire+0x10e/0x2e0 down_read+0x95/0x430 mlx5_devcom_for_each_peer_b= egin+0x4e/0xe0 [mlx5_core] mlx5e_tc_del_flow+0x11d/0xa70 [mlx5_core] mlx5e_= flow_put+0x99/0x100 [mlx5_core] __mlx5e_add_fdb_flow+0x409/0xf00 [mlx5_core=
] mlx5e_configure_flower+0x2a86/0x4100 [mlx5_core] mlx5e_rep_setup_tc_cls_f= lower+0x12f/0x1b0 [mlx5_core] mlx5e_rep_setup_tc_cb+0x153/0x750 [mlx5_core]=
tc_setup_cb_add+0x1dc/0x470 fl_change+0x2f4d/0x626d [cls_flower] tc_new_tf= ilter+0x79b/0x2310 rtnetlink_rcv_msg+0x778/0xad0 do_syscall_64+0x70/0x960 e= ntry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK></td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80739" target=3D= "_blank" rel=3D"noopener">CVE-2026-80739</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /log: Fix infinite loop when scale is too large for display When scale is l= arge enough that scaled_font exceeds the display dimensions, rows or column=
s become 0. A columns value of 0 causes an infinite loop in drm_log_draw_km= sg_record() because the loop never decrements len. Check for zero rows/colu= mns in drm_log_setup_modeset() and return an error, cleaning up the already=
allocated buffer to avoid a leak.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80740" target=3D= "_blank" rel=3D"noopener">CVE-2026-80740</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: af_= packet: Don't send zero-byte data in tpacket_snd(). syzbot reported a WARNI=
NG in __dev_queue_xmit() triggered via tpacket_snd(): skb_assert_len WARNIN=
G: at include/linux/skbuff.h:2753 skb_assert_len WARNING: at __dev_queue_xm= it+0x21bc/0x4970 net/core/dev.c:4781 Call Trace: <TASK> dev_queue_xmi=
t include/linux/netdevice.h:3448 [inline] packet_xmit+0x243/0x310 net/packe= t/af_packet.c:276 tpacket_snd net/packet/af_packet.c:2907 [inline] packet_s= endmsg+0x28d6/0x4eb0 net/packet/af_packet.c:3134 When sending 0-byte packet=
s via TPACKET ring buffer on devices with no hard header (e.g. dev->hard= _header_len =3D=3D 0), tpacket_fill_skb() populates an skb with skb->len=
=3D=3D 0 and returns 0. tpacket_snd() then forwards this empty skb to pack= et_xmit(), causing __dev_queue_xmit() to hit skb_assert_len(skb). Similar c= hecks exist in packet_snd() via commit dc633700f00f ("net/af_packet: check = len when min_header_len equals to 0") and in packet_sendmsg_spkt() via comm=
it 6a341729fb31 ("af_packet: Don't send zero-byte data in packet_sendmsg_sp= kt()."). Return -EINVAL in tpacket_fill_skb() when skb->len is zero to r= eject zero-length packets in tpacket_snd().</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80742" target=3D= "_blank" rel=3D"noopener">CVE-2026-80742</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASo=
C: xilinx: formatter_pcm: pass aud_drv_data to irq handlers The irq handler=
s take a struct device pointer and call dev_get_drvdata() to obtain the dri= ver data. However, the driver data is only set at the end of probe, after d= evm_request_irq(), so an interrupt taken in between causes the handlers to = pass a NULL pointer to readl() and crash. Pass the private data directly as=
the devm_request_irq() argument instead of the device pointer, matching wh=
at the handlers expect.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80743" target=3D= "_blank" rel=3D"noopener">CVE-2026-80743</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= filter: nf_tables_offload: suppress WARN_ON_ONCE for ENOMEM in abort path I=
n nft_flow_rule_offload_abort(), WARN_ON_ONCE(err) is triggered on every er= ror during rollback, including -ENOMEM. Memory allocation failures are expe= cted under low-memory conditions and do not indicate a kernel bug. Trace fo=
r example: nft_flow_offload_chain() // FLOW_BLOCK_BIND nft_flow_block_chain=
() nft_chain_offload_cmd() nft_block_offload_cmd() ->ndo_setup_tc() nsim= _setup_tc() flow_block_cb_setup_simple() flow_block_cb_alloc() // fails to = -ENOMEM The warning was reproduced on the 5.10 stable kernel under memory p= ressure via fault injection, but the underlying bug exists in mainline as w= ell, as demonstrated by the ENOMEM trace above. The following splat was tri= ggered during nf_tables transaction processing: WARNING: CPU: 0 PID: 8567 a=
t net/netfilter/nf_tables_offload.c:532 nft_flow_rule_offload_abort net/net= filter/nf_tables_offload.c:532 [inline] WARNING: CPU: 0 PID: 8567 at net/ne= tfilter/nf_tables_offload.c:532 nft_flow_rule_offload_commit+0x971/0xcd0 ne= t/netfilter/nf_tables_offload.c:591 Modules linked in: CPU: 0 PID: 8567 Com=
m: syz-executor.0 Not tainted 5.10.260-syzkaller #0 Hardware name: QEMU Sta= ndard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:nft_flow= _rule_offload_abort net/netfilter/nf_tables_offload.c:532 [inline] RIP: 001= 0:nft_flow_rule_offload_commit+0x971/0xcd0 net/netfilter/nf_tables_offload.= c:591 Call Trace: nf_tables_commit+0x3bd/0x4bd0 net/netfilter/nf_tables_api= .c:8604 nfnetlink_rcv_batch+0xb1e/0x1f20 net/netfilter/nfnetlink.c:509 nfne= tlink_rcv_skb_batch net/netfilter/nfnetlink.c:579 [inline] nfnetlink_rcv+0x= 3b3/0x420 net/netfilter/nfnetlink.c:597 netlink_unicast_kernel net/netlink/= af_netlink.c:1314 [inline] netlink_unicast+0x6cd/0xa00 net/netfilter/af_net= link.c:1340 netlink_sendmsg+0x906/0xe10 net/netfilter/af_netlink.c:1919 soc= k_sendmsg_nosec net/socket.c:651 [inline] __sock_sendmsg+0x155/0x190 net/so= cket.c:663 ____sys_sendmsg+0x705/0x870 net/socket.c:2379 ___sys_sendmsg+0x1= 00/0x170 net/socket.c:2433 __sys_sendmsg+0xe9/0x1c0 net/socket.c:2462 do_sy= scall_64+0x33/0x40 arch/x86/entry/common.c:46 entry_SYSCALL_64_after_hwfram= e+0x67/0xd1 Change the condition to WARN_ON_ONCE(err && err !=3D -E= NOMEM) so that warnings are only emitted for unexpected errors. This aligns=
with the common kernel practice of not warning on -ENOMEM. Found by Linux = Verification Center (linuxtesting.org) with Syzkaller.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80744" target=3D= "_blank" rel=3D"noopener">CVE-2026-80744</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: clk=
: qcom: dispcc-eliza: Fix disp_cc_mdss_mdp_clk_src RCG stall on Eliza EVK E= liza EVK (eliza-cqs-evk.dts) does not have display enabled, however its Dis= play Clock Controller is enabled and references parent clocks from DSI PHYs=
, which causes clock reparenting issues during probe (init) and warning on = Eliza EVK: disp_cc_mdss_mdp_clk_src: rcg didn't update its configuration. W= ARNING: drivers/clk/qcom/clk-rcg2.c:136 at update_config+0xd4/0xe4, CPU#1: = udevd/273 ... update_config (drivers/clk/qcom/clk-rcg2.c:136 (discriminator=
2)) (P) clk_rcg2_shared_disable (drivers/clk/qcom/clk-rcg2.c:1471) clk_rcg= 2_shared_init (drivers/clk/qcom/clk-rcg2.c:1540) __clk_register (drivers/cl= k/clk.c:3959 drivers/clk/clk.c:4368) devm_clk_hw_register (drivers/clk/clk.= c:4448 (discriminator 1) drivers/clk/clk.c:4672 (discriminator 1)) devm_clk= _register_regmap (drivers/clk/qcom/clk-regmap.c:104) qcom_cc_really_probe (= drivers/clk/qcom/common.c:418) qcom_cc_probe (drivers/clk/qcom/common.c:445=
) disp_cc_eliza_probe (dispcc-eliza.c:?) dispcc_eliza platform_probe (drive= rs/base/platform.c:1432)</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80746" target=3D= "_blank" rel=3D"noopener">CVE-2026-80746</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sel= inux: reject a permission value exceeding the class permission count perm_r= ead() bounds a permission value by SEL_VEC_MAX but never by the nprim of th=
e owning class or common, which is taken verbatim from the policy image. se= curity_get_permissions() then writes perms[value - 1] into an nprim-sized k= calloc() array, so a class declaring fewer permissions than its largest per= mission value drives an out-of-bounds heap write. The top-level symbol tabl=
es are validated this way; the nested per-class permission table is not. Re= ject a permission whose value exceeds nprim, which is already set when perm= _read() runs. Well-formed policies are unaffected. [PM: tweak comment for l= ine length]</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80755" target=3D= "_blank" rel=3D"noopener">CVE-2026-80755</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sel= inux: do not cancel a policy conversion that never started sel_write_load()=
calls selinux_policy_cancel() when sel_make_policy_nodes() fails, and that=
helper dereferences the outgoing policy to cancel its sidtab conversion. O=
n the first policy load there is no outgoing policy: security_load_policy()=
returns early for that case, before it converts anything, and state->po= licy is still NULL. A first load that fails while building the selinuxfs tr=
ee therefore takes a NULL dereference in selinux_policy_cancel(), reached f= rom a write(2) to /sys/fs/selinux/load. Skip the cancel when there is no ol=
d policy, mirroring the check security_load_policy() already makes before i=
t converts.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80756" target=3D= "_blank" rel=3D"noopener">CVE-2026-80756</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sel= inux: reject a class permission count below its inherited common security_g= et_permissions() maps an inherited common's permissions into an array sized=
by the class's own permissions.nprim, but class_read() takes that nprim ve= rbatim from the policy image and never checks that it covers the common. A = class that inherits a common of N permissions while declaring a smaller npr=
im is accepted, and on load the common's permissions are written past the c= lass-sized array -- an out-of-bounds heap write. Reject a class whose permi= ssion count is below its inherited common's. Well-formed policies, where th=
e class count already includes the inherited permissions, are unaffected.</=
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80757" target=3D= "_blank" rel=3D"noopener">CVE-2026-80757</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fut= ex: Avoid private hash use-after-free on final put futex_private_hash_put()=
drops the reference to fph before evaluating fph->mm for wake_up_var().=
futex_ref_put() enables preemption again before returning. If that put dro=
ps the final reference and the task is preempted, another task can pivot to=
the replacement hash and free the old hash after an RCU grace period. The = first task then reads fph->mm from the freed allocation when it resumes.=
KASAN reports a slab-use-after-free in futex_private_hash_put(), with the = read at offset 24 in a freed kmalloc-512 allocation. The allocation and fre=
e stacks point to futex_hash_allocate() and the RCU free path, respectively=
. Load the mm pointer while the fph reference is still held and pass the sa= ved value to wake_up_var(). wake_up_var() uses the pointer as a waitqueue k=
ey and does not dereference the mm through it.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80758" target=3D= "_blank" rel=3D"noopener">CVE-2026-80758</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: hci_aml: validate firmware segment lengths aml_download_firmware() = reads two lengths from the firmware header and uses them to build pointers = before checking that the header and segment data are present. A truncated o=
r inconsistent firmware image can make the driver read past firmware->da=
ta while constructing TCI commands. Reject images shorter than the header a=
nd ensure that the ICCM and DCCM ranges fit within the loaded firmware befo=
re downloading either segment.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80759" target=3D= "_blank" rel=3D"noopener">CVE-2026-80759</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: MGMT: reject HCI_CMD_SYNC params_len above 255 mgmt_hci_cmd_sync() = checks that the message length agrees with params_len but puts no upper bou=
nd on it. params_len is __le16 while the parameter length in the HCI comman=
d header is a u8: struct hci_command_hdr { __le16 opcode; __u8 plen; } __pa= cked; hci_cmd_sync_alloc() assigns one to the other: hdr->plen =3D plen;=
if (plen) skb_put_data(skb, param, plen); so a params_len of 256 leaves pl=
en at 0 while all 256 bytes are still appended. The frame handed to the dri= ver then declares no parameters and carries 256 of them. On a length framed=
transport such as H:4 the controller takes the trailing bytes as the start=
of the next packet. The mgmt socket MTU is HCI_MAX_FRAME_SIZE, so params_l=
en can reach about 1KB this way. Commit 03f1700b9b4d ("Bluetooth: MGMT: rej= ect malformed HCI_CMD_SYNC commands") only made params_len agree with the m= essage length, a value that fits the message but not the header field is st= ill accepted. Reject params_len that does not fit the header field.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80760" target=3D= "_blank" rel=3D"noopener">CVE-2026-80760</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: ISO: zero the sockaddr before returning it in getname iso_sock_getn= ame() fills a struct sockaddr_iso in place and returns its size without cle= aring it first, so bytes it does not write are copied to user space from th=
e kernel stack. The getsockname(2) and getpeername(2) paths both run throug=
h do_getsockname(), which hands getname() an uninitialized sockaddr_storage=
on the stack and copies back up to the number of bytes getname() returns, =
so the driver has to initialize every byte it accounts for. Two ranges are = left uninitialized: - struct sockaddr_iso is 10 bytes but only 9 are writte=
n (family, iso_bdaddr, iso_bdaddr_type), leaking the trailing pad byte on e= very call. - for a broadcast peer (BIS_LINK or PA_LINK) the returned length=
grows by sizeof(struct sockaddr_iso_bc), but only bc_sid, bc_num_bis and b= c_bis are filled; bc_bdaddr and bc_bdaddr_type, the first 7 bytes of that s= tructure, are never written. An unprivileged process can open a BTPROTO_ISO=
socket and reach the pad leak with getsockname(); the broadcast leak needs=
an established BIS/PA connection. l2cap and rfcomm already memset their so= ckaddr in getname for the same reason; do the same here.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80761" target=3D= "_blank" rel=3D"noopener">CVE-2026-80761</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: hci_sync: Fix accept list UAF during suspend hci_update_event_filte= r_sync() walks hdev->accept_list while sending a synchronous HCI command=
for each remote-wakeup device. The suspend path holds hdev->req_lock, b=
ut accept-list updates are serialized by hdev->lock. Consequently, remov= e_device() can free the current list entry during the controller wait. The = following interleaving causes the use-after-free: hci_update_event_filter_s= ync() remove_device() fetch accept-list entry hci_set_event_filter_sync() w= ait for controller response hci_dev_lock() list_del() kfree() hci_dev_unloc= k() read the freed list.next KASAN reported: BUG: KASAN: slab-use-after-fre=
e in hci_suspend_sync+0x835/0x910 Read of size 8 at addr ffff88810bec8440 b=
y task kworker/0:1/10 Workqueue: events vhci_suspend_work Call Trace: hci_s= uspend_sync+0x835/0x910 hci_suspend_dev+0x182/0x450 process_one_work+0x661/= 0x1090 worker_thread+0x45b/0xd10 Allocated by task 86: hci_bdaddr_list_add_= with_flags+0x1a8/0x400 add_device+0x381/0x820 hci_sock_sendmsg+0x1033/0x1ea=
0 Freed by task 91: kfree+0x131/0x3c0 remove_device+0x429/0xb70 hci_sock_se= ndmsg+0x1033/0x1ea0 Snapshot the remote-wakeup addresses under hdev->loc=
k. Release the lock before sending HCI commands. Clear the controller event=
filter before building the snapshot, and skip allocation and the second li=
st traversal when there are no matching entries. This preserves the origina=
l filter and scan-state updates without retaining an accept-list node acros=
s a controller wait.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80762" target=3D= "_blank" rel=3D"noopener">CVE-2026-80762</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: hci_event: validate LE Set CIG Parameters response The Command Comp= lete dispatch validates only the fixed part of the LE Set CIG Parameters re= sponse. After that part is pulled from the skb, hci_cc_le_set_cig_params() = trusts num_handles and reads each entry in the trailing handle array. Match= ing num_handles against the command's num_cis does not guarantee that the r= esponse contains the advertised handles. A truncated response from a malfun= ctioning controller can therefore make the handler read beyond the skb data=
. Validate that the remaining skb data contains all advertised handles. Inc= lude this in the existing response validation so malformed responses also f= ollow the established CIG failure handling.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80763" target=3D= "_blank" rel=3D"noopener">CVE-2026-80763</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: hci_event: fix LE list UAF on reset hci_cc_reset() clears the LE ac= cept and resolving lists without taking hdev->lock. Other command-comple=
te handlers serialize updates to these lists with that lock, and the debugf=
s readers hold it while walking them. This permits the reset completion and=
a debugfs read to interleave as follows: hci_rx_work debugfs reader ------= ----- -------------- lock hdev->lock fetch current entry list_del(entry)=
kfree(entry) read entry fields The reader then dereferences a freed list e= ntry and may follow its stale next pointer. KASAN reported: BUG: KASAN: sla= b-use-after-free in white_list_show+0x15f/0x180 Read of size 1 at addr ffff= 8881015dab16 by task poc/95 Call Trace: white_list_show+0x15f/0x180 seq_rea= d_iter+0x3ff/0x1190 seq_read+0x267/0x3d0 vfs_read+0x177/0xa20 ksys_read+0xf= 7/0x1c0 Allocated by task 91: hci_bdaddr_list_add+0x1a6/0x3a0 hci_cc_le_add= _to_accept_list+0xab/0x140 hci_cmd_complete_evt+0x26c/0x9a0 hci_event_packe= t+0x454/0xb20 hci_rx_work+0x293/0x730 Freed by task 90: kfree+0x131/0x3c0 h= ci_bdaddr_list_clear+0xd8/0x160 hci_cc_reset+0x28a/0x370 hci_cmd_complete_e= vt+0x26c/0x9a0 hci_event_packet+0x454/0xb20 hci_rx_work+0x293/0x730 Take hd= ev->lock around both list clears. This matches the existing mutation and=
traversal locking convention.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80764" target=3D= "_blank" rel=3D"noopener">CVE-2026-80764</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: hyperv: validate initial device info bounds The Hyper-V synthetic HID hos=
t supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descri= ptor followed by the report descriptor bytes. mousevsc_on_receive_device_in= fo() trusts bLength and wDescriptorLength without checking that the receive=
d packet contains both byte ranges. A malformed host or backend message can=
therefore make the guest read past the received VMBus packet while copying=
the report descriptor. Pass the received initial-device-info size into the=
parser and reject descriptor lengths that exceed the packet. Impact: A mal= icious Hyper-V host or backend can crash a guest by sending a short initial=
device-info message with an oversized HID report descriptor length.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80765" target=3D= "_blank" rel=3D"noopener">CVE-2026-80765</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: uclogic: fix use-after-free of inrange_timer on remove uclogic_remove() c= ancels the pen in-range timer and then stops the device: timer_delete_sync(= &drvdata->inrange_timer); hid_hw_stop(hdev); timer_delete_sync() onl=
y guarantees the timer is idle at that instant. uclogic_raw_event_pen() kee=
ps delivering pen reports until hid_hw_stop() stops the transport several l= ines later, and every report with pen->inrange =3D=3D UCLOGIC_PARAMS_PEN= _INRANGE_NONE re-arms the timer: mod_timer(&drvdata->inrange_timer, = jiffies + msecs_to_jiffies(100)); A report landing between the timer_delete= _sync() call and the transport teardown in hid_hw_stop() re-arms inrange_ti= mer after it was cancelled. uclogic_remove() then returns and the devm drvd= ata is freed, while hid_hw_stop() has already freed the input device drvdat= a->pen_input points at, so when the timer fires ~100 ms later uclogic_in= range_timeout() dereferences freed memory -- a use-after-free in timer-soft= irq context. Swapping the two calls is not a fix: stopping the device first=
frees drvdata->pen_input via hidinput_disconnect() while the timer may = still be pending, so a timer already armed before removal fires on the free=
d input device in the window before timer_delete_sync() runs. Use timer_shu= tdown_sync() before hid_hw_stop() instead. It cancels the timer, waits for =
a running callback while pen_input is still valid, and prevents any further=
re-arming -- a later mod_timer() from an in-flight report is silently igno= red -- so the timer is provably dead before hid_hw_stop() frees the inputs.=
This is the ordering the timer core documents for this "timer re-armed fro=
m another path" teardown case.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80766" target=3D= "_blank" rel=3D"noopener">CVE-2026-80766</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: sensor: custom: Fix use-after-free in enable_sensor enable_sensor_store()=
can call set_power_report_state(), which dereferences sensor_inst->powe= r_state and sensor_inst->report_state. These pointers refer to entries i=
n sensor_inst->fields. Create the field attributes before exposing the e= nable_sensor sysfs attribute, so enable_sensor cannot be accessed before th=
e state it depends on has been initialized. On remove, delete enable_sensor=
before freeing the field attributes, so a concurrent sysfs write cannot de= reference freed memory through power_state or report_state.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80767" target=3D= "_blank" rel=3D"noopener">CVE-2026-80767</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: ft260: fix stack-use-after-return write in I2C read race ft260_i2c_read()=
points dev->read_buf at a caller-supplied buffer (often an on-stack var= iable), arms a completion and waits up to five seconds for the device to re= turn the data. The HID input callback ft260_raw_event() runs in the input/I=
RQ path, independent of the dev->lock mutex held by the read path, and c= opies the device-supplied payload into dev->read_buf after a plain NULL = check. These two paths share read_buf, read_idx and read_len with no serial= ization. If the device delays its response until the read times out, ft260_= i2c_read() resets the controller, clears read_buf and returns, unwinding th=
e stack frame the buffer lived in. A response that arrives at that moment l= ets ft260_raw_event() pass the NULL check and then memcpy() the device-cont= rolled payload into the now-freed stack location, a bounded but attacker-in= fluenced stack-use-after-return write triggerable by malicious or malfuncti= oning hardware. Add a dedicated spinlock that serializes every access to re= ad_buf, read_idx and read_len. ft260_raw_event() now holds it across the NU=
LL check, the memcpy and the index update, while the read path takes it whe=
n arming and when clearing the buffer, so the teardown can no longer slip b= etween the check and the copy.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80768" target=3D= "_blank" rel=3D"noopener">CVE-2026-80768</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: rapoo: fix missing hid_is_usb() check to_usb_interface() can only be used=
on a hid_device whose parent is really USB; uhid can create devices that i= dentify as being on BUS_USB, but don't actually have a USB parent. Fix the = use of to_usb_interface() without a hid_is_usb() check. Add a dependency on=
USB_HID for hid_is_usb(), as other HID drivers do; the alternative would b=
e to provide a simple stub implementation on !USB_HID builds. I have verifi=
ed that it is currently possible to trigger a kernel splat due to this bug =
in an ASAN build, and that this commit fixes the issue.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80769" target=3D= "_blank" rel=3D"noopener">CVE-2026-80769</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: nintendo: stop device IO before hid_hw_stop on probe failure nintendo_hid= _probe() calls hid_device_io_start() before joycon_init() and joycon_leds_c= reate(). If either fails, the error path jumps to err_close which calls hid= _hw_close()/hid_hw_stop() without first calling hid_device_io_stop(). hid_h= w_stop() does not stop device IO, so hid_input_report() may still run and a= ccess driver data that is being torn down, resulting in a use-after-free. A=
dd an err_io_stop label that calls hid_device_io_stop() before hid_hw_close= (), and point the two post-io_start error paths at it.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80770" target=3D= "_blank" rel=3D"noopener">CVE-2026-80770</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: nintendo: register input device after capabilities are set input_register= _device() exposes the device to userspace immediately. In joycon_input_crea= te() it was called before joycon_config_rumble() configures the FF_RUMBLE c= apability and the memless force-feedback device, so a concurrent EVIOCSFF c= ould dereference a NULL dev->ff. Registering early also means the initia=
l udev event lacks button and axis information, which can make input manage=
rs ignore the device. Move input_register_device() to the end of joycon_inp= ut_create(), after all capabilities, the IMU input device and the force-fee= dback callbacks have been configured.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80771" target=3D= "_blank" rel=3D"noopener">CVE-2026-80771</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() joycon_ctl= r_read_handler() casts an incoming HID input report to struct joycon_input_= report and parses it, guarding the cast only with a 12-byte length check: i=
f (size >=3D 12) /* make sure it contains the input report */ joycon_par= se_report(ctlr, (struct joycon_input_report *)data); struct joycon_input_re= port is 49 bytes: a 13-byte header followed by a union whose IMU arm is 36 = bytes. For an IMU report joycon_parse_report() -> joycon_parse_imu_repor= t() walks that union (struct offsets 13..48), so a report of exactly 12 byt=
es with data[0] =3D=3D JC_INPUT_IMU_DATA passes the guard yet is read up to=
37 bytes past its declared length. The over-read bytes are decoded into ac= celerometer/gyroscope values and forwarded to userspace through the "(IMU)"=
input device, leaking driver-internal memory. data[0] and size are fully c= ontrolled by a malicious or spoofed Joy-Con/Pro Controller. Receive buffers=
are sized to the maximum report length, so this is an over-read within the=
allocation rather than a slab OOB, but the decoded bytes still reach users= pace. The sibling subcmd path in joycon_ctlr_handle_event() already bounds = the same cast correctly: if (size < sizeof(struct joycon_input_report) |=
| data[0] !=3D JC_INPUT_SUBCMD_REPLY) break; Use the same sizeof(struct joy= con_input_report) bound here.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80772" target=3D= "_blank" rel=3D"noopener">CVE-2026-80772</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: huawei: fix missing hid_is_usb() check to_usb_interface() can only be use=
d on a hid_device whose parent is really USB; uhid can create devices that = identify as being on BUS_USB, but don't actually have a USB parent. Fix the=
use of to_usb_interface() without a hid_is_usb() check. I have verified th=
at it is currently possible to trigger a kernel splat due to this bug in an=
ASAN build, and that this commit fixes the issue.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80773" target=3D= "_blank" rel=3D"noopener">CVE-2026-80773</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: asus: fix missing hid_is_usb() check to_usb_interface() can only be used =
on a hid_device whose parent is really USB; uhid can create devices that id= entify as being on BUS_USB, but don't actually have a USB parent. Fix the u=
se of to_usb_interface() without a hid_is_usb() check. I have verified that=
it is currently possible to trigger a kernel splat due to this bug in an A= SAN build, and that this commit fixes the issue.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80774" target=3D= "_blank" rel=3D"noopener">CVE-2026-80774</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fut= ex: Fix race on the initial mm->futex.phash.ref allocation futex_hash_al= locate() allocates mm->futex.phash.ref without any locking. Commit d9b05= 321e21e ("futex: Move futex_hash_free() back to __mmput()") moved the alloc= ation here and assumed that the process has just a single thread at this po= int. Commit ee9dce44362b ("futex: Drop CLONE_THREAD requirement for private=
default hash alloc") widened need_futex_hash_allocate_default() to cover a=
ny CLONE_VM clone, but left out vfork because the parent is suspended and c= annot race. That no longer holds once vfork is nested. If a vfork child cal=
ls vfork again and is then killed with SIGKILL, the parent is released from=
its vfork wait and runs concurrently with the grandchild in the same mm. N= either of them went through futex_hash_allocate_default(). When both call p= rctl(PR_FUTEX_HASH, PR_FUTEX_HASH_SET_SLOTS) at the same time, each one see=
s mm->futex.phash.ref as NULL and stores its own percpu counter. Only th=
e last store survives. The counter stored first is no longer reachable from=
the mm, so the references on it are not seen by __futex_ref_atomic_end(). =
A private hash that still has references is then considered dead and freed,=
and a task that still holds one of its buckets writes into freed memory in=
futex_q_lock(). Store the counter once with cmpxchg() and let the loser fr= ee_percpu() its own. The initial reference has to be taken before the store=
, otherwise another task can install a private hash while the counter is st= ill 0.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80775" target=3D= "_blank" rel=3D"noopener">CVE-2026-80775</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fut= ex: Fix race in futex_pivot_pending() during private hash resize A task per= forming a custom private hash resize can remain blocked in uninterruptible = sleep indefinitely. The hung-task detector reports: INFO: task futex-resize= r:314 blocked for more than 10 seconds. task:futex-resizer state:D stack:14= 824 pid:314 tgid:312 ppid:311 Call Trace: __schedule+0x521/0xf30 schedule+0= x22/0xa0 futex_hash_allocate+0x3db/0x490 __do_sys_prctl+0x6f5/0xbd0 do_sysc= all_64+0xf9/0x530 entry_SYSCALL_64_after_hwframe+0x77/0x7f Kernel panic - n=
ot syncing: hung_task: blocked tasks futex_pivot_pending() allows the resiz=
e request to continue when either no replacement hash is pending (hash_new = =3D=3D NULL) or the current hash reference count has reached zero. After th=
e final-reference wake, another futex task can complete the pivot between t=
he two observations: T1 T2 futex_hash_allocate() wait_var_event(mm, ...) fu= tex_pivot_pending(mm) hash_new !=3D NULL futex_hash() futex_ref_get(old) -&= gt; false futex_pivot_hash(mm) hash_new =3D NULL __futex_pivot_hash(mm, new=
) rcu_assign_pointer(hash, new) fph =3D rcu_dereference(hash) /* new */ fut= ex_ref_is_dead(fph) -> false schedule() The pivot changes the state from=
hash_new !=3D NULL with a dead current hash to hash_new =3D=3D NULL with a=
live current hash. Because futex_pivot_pending() reads hash_new and hash w= ithout serialization, the resize task can observe hash_new in the pre-pivot=
state and hash in the post-pivot state, causing futex_pivot_pending() to r= eturn false even though the pivot has completed. The task then goes to slee=
p after the wakeup has already been consumed. Serialize state reads in fute= x_pivot_pending() using futex_mm_phash::lock. This guarantees that futex_pi= vot_pending() observes hash_new and hash atomically, eliminating the race c= ondition.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80776" target=3D= "_blank" rel=3D"noopener">CVE-2026-80776</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fut= ex/pi: Plug private futex exec() race The check for private futexes whether=
the waiter's mm, which is stored in the futex_key and copied into the pi_s= tate, is the same as the owner's mm is not sufficient for exec(). exec() ha=
s a gap where the mm check fails to give the correct answer: exec() ... exe= c_release_mm() futex_exec_release() tsk::futex::exit_state =3D EXITING; cle= anup_robust_list(); 1) tsk::futex::exit_state =3D OK; ... old_mm =3D tsk::m=
m; 2) tsk::mm =3D ->mm; Between #1 and #2 the check for the mm is wrong =
as that mm is about to be swapped out and eventually freed. Plug this gap b=
y: 1) Setting tsk::futex::exit_state to FUTEX_STATE_DEAD in futex_exec_rele= ase() 2) Setting tsk::futex::exit_state to FUTEX_STATE_OK after the mm has = been switched. From a futex point of view the task is dead after it finishe=
d the robust list cleanup up to the point where it sets the state to OK aga= in.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80777" target=3D= "_blank" rel=3D"noopener">CVE-2026-80777</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fut= ex/pi: Reject cross-mm private futex owners A private futex key borrows the=
waiter's mm without taking an mm_users reference. Nevertheless, attach_to_= pi_owner() currently accepts an owner from a different address space and co= pies the private key into the owner's PI state. When that owner exits, exit= _pi_state_list() uses the saved key to find the hash bucket and acquires a = reference to the waiter's private hash. If the last user of the waiter's mm=
exits concurrently, futex_hash_free() frees the hash while the owner still=
uses its bucket and reference. Prevent this by validating in attach_to_pi_= owner() that, for private futexes, the owner mm and waiter mm are the same.=
Perform the check with the owner's pi_lock held and after validating owner= ::futex::state to serialize against a concurrent PI-state exit cleanup. [ t= glx: Amended comment ]</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80778" target=3D= "_blank" rel=3D"noopener">CVE-2026-80778</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /ionic: avoid OOB TX partner lookup for hwstamp RXQ The dedicated hardware = timestamp RX queue is allocated with q->index equal to lif->ionic->= ;nrxqs_per_lif. The normal txqcqs array only contains the regular queue pai= rs, so using that index to set rxq->partner can read one entry past txqc= qs[] and then write through the derived pointer. Only link RX/TX partners f=
or normal queue-pair indexes. Leave the hwstamp RX queue unpaired, and make=
the XDP_TX path abort cleanly if an RX queue has no TX partner.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80779" target=3D= "_blank" rel=3D"noopener">CVE-2026-80779</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: pidff: fix OOB write when hid->inputs is empty hid_pidff_init_with_qui= rks() derives its input_dev from list_entry(hid->inputs.next, struct hid= _input, list) without first checking that hid->inputs is non-empty. The = list member of struct hid_input is at offset 0, so on an empty list list_en= try() yields &hid->inputs itself and the following hidinput->inpu=
t load reads an unrelated member of struct hid_device. dev is then a type-c= onfused pointer, and force-feedback init writes through it: each set_bit(FF= _*, dev->ffbit) stores 8 bytes at dev + 192, past the end of the object = dev actually aliases, and input_ff_create() adds further writes of a heap p= ointer and two function pointers. Until hid-universal-pidff the only caller=
was hid_pidff_init() from usbhid, which runs under HID_CLAIMED_INPUT and t= herefore always has at least one hid_input. universal_pidff_probe() starts = the device with HID_CONNECT_DEFAULT & ~HID_CONNECT_FF and then calls hi= d_pidff_init_with_quirks() directly whenever the descriptor carries a PID u= sage page, bypassing that gate. A report descriptor whose only application = collection is on HID_UP_PID leaves hid->inputs empty while hid_connect()=
still succeeds through the hidraw claim, so probe reaches the unguarded li= st_entry(). The write happens in the USB probe path, on the hotplug workque= ue, so plugging in a malicious device is enough to trigger it; no attacker = software and no logged-in user are required. KASAN reports an 8-byte out-of= -bounds write in hid_pidff_init_with_quirks() reached from universal_pidff_= probe(). Check for an empty list before deriving dev and return -ENODEV, as=
the other HID force-feedback drivers already do. universal_pidff_probe() p= ropagates the error and unwinds. Discovered by XBOW, triaged by Baul Lee &l= t;
baul.lee@xbow.com></td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80780" target=3D= "_blank" rel=3D"noopener">CVE-2026-80780</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: core: fix OOB read of field->usage in hid_set_field() hid_set_field() = hands field->usage + offset to hid_dump_input() before the guard that bo= unds offset: hid_dump_input(field->report->device, field->usage + = offset, value); if (offset >=3D field->report_count) { hid_err(...); = return -1; } Under CONFIG_DEBUG_FS hid_dump_input() dereferences that point= er, with buf =3D hid_resolv_usage(usage->hid, NULL). The usage[] array i=
s allocated inline with the hid_field in hid_register_field() and holds fie= ld->maxusage entries, so an offset past it reads off the end of the kvza= lloc()ed allocation and into a neighbouring object. Had the guard run first=
, offset < report_count <=3D maxusage would already have confined the=
pointer to the array. A caller supplies such an offset today. picolcd_fb_s= end_tile() validates only report->maxfield before issuing hid_set_field(= report->field[0], 11 + i, ...) for i =3D 0..31, so its offsets are fixed=
at 11..42 and are never checked against the bound field. When the device r= egisters that field with fewer usages, the framebuffer deferred-io work dri= ves the read on every tile. KASAN reports a 4-byte slab-out-of-bounds read =
in hid_dump_input() below hid_set_field(), and the same boot logs "offset (=
1) exceeds report_count (1)" from the guard that runs only afterwards. Move=
the hid_dump_input() call below the guard. Because field->maxusage >= =3D field->report_count, the guard then establishes that field->usage=
+ offset lies inside the array before it is dereferenced, for every caller=
and without changing behaviour on the valid path. Discovered by XBOW, tria= ged by Baul Lee <
baul.lee@xbow.com></td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80781" target=3D= "_blank" rel=3D"noopener">CVE-2026-80781</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: magicmouse: do not keep a stale msc->input if no input is claimed magi= cmouse_input_mapping() caches the first hid_input's input_dev in msc->in= put while the report descriptor is parsed, and the rest of the driver treat=
s a non-NULL msc->input as proof that an input device was registered. Th=
at does not hold on the hid-input error path. If hidinput_connect() fails -=
- for instance because input_register_device() returns an error -- it unwin=
ds through hidinput_disconnect(), which frees every input_dev it created, i= ncluding the one cached in msc->input. The failure does not abort the pr= obe. hid_connect() only skips the claim: if ((connect_mask & HID_CONNEC= T_HIDINPUT) && !hidinput_connect(hdev, connect_mask & HID_CONNE= CT_HIDINPUT_FORCE)) hdev->claimed |=3D HID_CLAIMED_INPUT; and the "devic=
e has no listeners" bailout below it does not fire for this driver, which s= ets ->raw_event; on the USB Magic Mouse 2 / Magic Trackpad 2 paths hidra=
w and hiddev are claimed as well. hid_hw_start() therefore returns 0 and ma= gicmouse_probe() continues with msc->input pointing at freed memory. Bei=
ng non-NULL, it passes the "input not registered" check in probe and the NU=
LL checks in ->raw_event and ->event, so the next input report derefe= rences freed memory. Clear msc->input when the HID core did not claim an=
input device, so the existing NULL checks cover this case as well.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80782" target=3D= "_blank" rel=3D"noopener">CVE-2026-80782</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: HID=
: magicmouse: prevent unbounded recursion in magicmouse_raw_event() magicmo= use_raw_event() handles DOUBLE_REPORT_ID (0xf7) packets, which pack two tou=
ch reports into one, by splitting the packet and calling itself on each hal=
f. The only guard against runaway recursion is a "size < 1" check, which=
stops zero-sized calls but does not bound the recursion depth. A malicious=
HID device that matches this driver can send a report starting with DOUBLE= _REPORT_ID and filled with the sequence [0xf7, 0x00]. Each level consumes t=
wo bytes and recurses on the remainder, so an incoming report of up to HID_= MAX_BUFFER_SIZE (16 KiB) drives roughly 8000 nested calls. That easily exha= usts the 16 KiB kernel stack, leading to a stack overflow: a panic with CON= FIG_VMAP_STACK, or memory corruption without it. A double report only ever = wraps two normal reports; it is never legitimately nested. Refuse to re-ent=
er the DOUBLE_REPORT_ID case from a recursive call so the recursion depth i=
s bounded to two, while all valid packets keep being parsed exactly as befo= re.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80783" target=3D= "_blank" rel=3D"noopener">CVE-2026-80783</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: mpt= cp: pm: fix memory leak from alloc-during-teardown race mptcp_pm_destroy() = empties msk->pm.anno_list and msk->pm.userspace_pm_local_addr_list un= der msk->pm.lock during socket teardown, dropping the lock between the t= wo. A concurrent userspace PM genl ANNOUNCE on the same msk holds a sock re= ference via mptcp_token_get_sock() and, in mptcp_pm_nl_announce_doit(), cal=
ls mptcp_userspace_pm_append_new_local_addr() and mptcp_pm_announced_alloc(=
). Both take msk->pm.lock briefly to add to their respective lists. Beca= use the genl handler holds a sock reference, mptcp_pm_destroy() may run on = the same msk via mptcp_disconnect(), which invokes mptcp_destroy_common() w= ithout dropping the sock refcount, before the handler completes. If the loc=
k acquisitions interleave such that mptcp_pm_destroy() empties a list first=
, the later alloc adds its entry to a list head that nothing else iterates = for this msk, and the entry leaks. kmemleak reports both mptcp_pm_add_addr = objects (from mptcp_pm_announced_alloc()) and mptcp_pm_addr_entry objects (= from mptcp_userspace_pm_append_new_local_addr()) under sustained concurrent=
ANNOUNCE + close load against the userspace PM. Add an MPTCP_PM_DESTROYING=
bit in msk->pm.status, set by mptcp_pm_destroy() under pm.lock before t=
he lists are emptied and checked under pm.lock by the alloc paths. Either t=
he alloc takes pm.lock first, in which case its entry is on the list when m= ptcp_pm_destroy() frees it; or mptcp_pm_destroy() takes pm.lock first, in w= hich case the later alloc observes the bit and refuses. Found by an MPTCP p= rotocol-flow harness extending BRF (arXiv:2305.08782).</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80784" target=3D= "_blank" rel=3D"noopener">CVE-2026-80784</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fbd= ev: serialize mode sysfs access with lock_fb_info() show_mode(), show_modes= (), and store_mode() access fb_info->modelist and fb_info->mode witho=
ut holding lock_fb_info(). store_modes() takes lock_fb_info() while replaci=
ng the modelist and freeing the old one. A concurrent reader or writer can = load a pointer to an old modelist entry before store_modes() frees it, then=
dereference freed memory or store a stale freed pointer in fb_info->mod=
e. Take lock_fb_info() in show_mode(), show_modes(), and store_mode() to se= rialize with store_modes(). In show_mode(), copy the mode to the stack and = format after dropping the lock. In store_mode(), split activate() into a _l= ocked variant to avoid double-locking, and hold the locks for the modelist = walk, mode conversion, activation, and fb_info->mode assignment together= .</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80785" target=3D= "_blank" rel=3D"noopener">CVE-2026-80785</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fbd= ev: Wrap user-invoked calls to fb_set_var() in helper Handle fbcon during d= isplay updates in fb_set_var_from_user(). Check with fbcon if the mode chan=
ge is possible, update hardware state and finally update fbcon. Update all = callers. Only the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other=
mode-changes callers in sysfs and driver code are missing fbcon-related st= eps. With the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain fbc=
on state themselves.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80786" target=3D= "_blank" rel=3D"noopener">CVE-2026-80786</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() nvmet_pci_= epf_exec_iod_work() submits an I/O command with req->execute() and then = waits for the command to complete and transfers the data back to the host. = This wait is not needed for commands that do not transfer data from the dev= ice to the host. To decide whether that wait is needed, it reads iod->da= ta_len and iod->dma_dir after calling req->execute(). However, once r= eq->execute() is called, the command may complete asynchronously on anot= her CPU. For commands that do not require a device-to-host data transfer, n= vmet_pci_epf_queue_response() calls nvmet_pci_epf_complete_iod() directly, = which can free the iod before it reads iod->data_len and iod->dma_dir=
, resulting in the KFENCE use-after- free: BUG: KFENCE: use-after-free read=
in nvmet_pci_epf_exec_iod_work+0x288/0x798 [nvmet_pci_epf] Use-after-free = read at 0x00000000fdfa6d03 (in kfence-#63): nvmet_pci_epf_exec_iod_work+0x2= 88/0x798 [nvmet_pci_epf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0= x30c kthread+0x130/0x140 ret_from_fork+0x10/0x20 kfence-#63: 0x00000000e3de= 0e71-0x00000000c938ad62, size=3D712, cache=3Dkmalloc-1k allocated by task 1=
0 on cpu 0 at 73.995480s (0.005122s ago): mempool_kmalloc+0x1c/0x28 mempool= _alloc_noprof+0x40/0x9c nvmet_pci_epf_poll_sqs_work+0xd4/0x344 [nvmet_pci_e= pf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/0x= 140 ret_from_fork+0x10/0x20 freed by task 131 on cpu 3 at 73.995521s (0.008= 385s ago): mempool_kfree+0x10/0x20 mempool_free+0x44/0x64 nvmet_pci_epf_fre= e_iod+0x88/0x98 [nvmet_pci_epf] nvmet_pci_epf_cq_work+0xfc/0x280 [nvmet_pci= _epf] process_one_work+0x15c/0x4f0 worker_thread+0x18c/0x30c kthread+0x130/= 0x140 ret_from_fork+0x10/0x20 Fix this by referring to iod->data_len and=
iod->dma_dir before calling req->execute(). The remaining iod access=
es such as iod->status are only reached on the device-to-host read path.=
In this case, nvmet_pci_epf_queue_response() signals iod->done instead =
of freeing the iod, so the iod stays valid.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80787" target=3D= "_blank" rel=3D"noopener">CVE-2026-80787</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et-tcp: Do not WARN on remotely-controlled oversized SGL allocations When f= uzzing the nvme target code, I tripped a kernel warning in nvmet_tcp_map_da= ta() because the length passed into the allocator is controlled by the remo=
te initiator. A remote initiator that sends a command with an SGL claiming =
a huge number, can create a scatterlist and iovec allocation of over 1 mill= ion entries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER=
and then the page allocator will trip on a WARN_ON_ONCE_GFP() message: WAR= NING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof Workqueue: nvmet_tcp= _wq nvmet_tcp_io_work ... sgl_alloc_order nvmet_tcp_map_data nvmet_tcp_try_= recv_pdu As it's never good to trip a kernel warning remotely due to many s= ystems having panic-on-warn enabled, let's silence it by just add GFP_NOWAR=
N to the allocation flags.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80788" target=3D= "_blank" rel=3D"noopener">CVE-2026-80788</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et-tcp: bound SGL data length before allocating command buffers nvmet_tcp_m= ap_data() reads the host-controlled 32-bit sgl->length and, for the in-c= apsule offset descriptor (type 0x01), checks it against port->inline_dat= a_size before use. Any other SGL descriptor type -- including the non-inlin=
e transport SGL data-block descriptor (type (NVME_TRANSPORT_SGL_DATA_DESC &= lt;< 4) | NVME_SGL_FMT_TRANSPORT_A, the type a real host uses for out-of= -capsule writes) skips that check entirely and falls straight through to: c= md->req.sg =3D sgl_alloc(len, GFP_KERNEL, &cmd->req.sg_cnt); with=
len taken directly from the wire, unbounded up to 4 GiB. nvmet_req_init() = only parses the command and never inspects sgl->length, and nvmet_check_= transfer_len() -- the only other place transfer_len is validated -- runs la= ter, from req->execute(), after the allocation has already happened. For=
a write command the target responds with an R2T and parks the command wait= ing for the host to send the data; if the host (or an unauthenticated peer = that simply never follows up) never does, the sgl_alloc() buffer stays resi= dent for the life of the command. NVMe/TCP has no mandatory authentication =
in the default configuration, so any peer able to reach the target portal a=
nd complete a Fabrics connect can drive this with a single crafted command,=
repeatable across queues and connections for amplification. This is unboun= ded kernel memory allocation triggered by a remote, effectively unauthentic= ated peer. Validate len against the same NVMET_TCP_MAXH2CDATA ceiling this = file already uses to bound per-PDU H2C data, for every SGL descriptor type,=
before doing any allocation. This closes the gap for the non-inline descri= ptor while leaving the existing, tighter inline_data_size check in place fo=
r the in-capsule case. Runtime-verified on a v6.19 KASAN stand: with this b= ound in place, a crafted write command carrying an oversized non-inline SGL=
length is rejected before sgl_alloc() runs, where the same request previou= sly drove an unbounded ~256 MiB kernel allocation (up to 4 GiB) that stayed=
resident pending an R2T the host never satisfies.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80789" target=3D= "_blank" rel=3D"noopener">CVE-2026-80789</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() ad= vances iod while initializing the LS IOD array. If an rqstbuf allocation or=
response buffer DMA mapping fails, the unwind loop decrements iod past the=
start of the array. The final kfree(iod) therefore frees an address before=
the allocated object. This can be reproduced with nvme-fcloop and failslab=
by setting fail-nth to 6 before creating a target port. KASAN reports: BUG=
: KASAN: invalid-free in nvmet_fc_register_targetport Free of addr ffff8881= 6cf8ff48 by task nvmet_fail_nth/9552 Free the original allocation base stor=
ed in tgtport->iod instead. With this fix applied, the same sysfs write = with fail-nth=3D6 returns -ENOMEM without any KASAN report.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80790" target=3D= "_blank" rel=3D"noopener">CVE-2026-80790</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et-auth: zero the AUTH_RECEIVE response buffer nvmet_execute_auth_receive()=
allocates the response buffer with kmalloc() sized by the host-supplied AU= TH_RECEIVE allocation length, but the DH-HMAC-CHAP builders write only a fi= xed-size message into it. The full allocation length is then copied to the = wire by nvmet_copy_to_sgl(), so a remote initiator receives the bytes past = the built message -- up to nearly a page of uninitialized slab -- during th=
e pre-authentication handshake. Allocate the buffer with kzalloc() so the u= nwritten tail is zeroed before it is sent; conforming responses are unaffec= ted.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80791" target=3D= "_blank" rel=3D"noopener">CVE-2026-80791</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv=
6: fix use-after-free in ip6_finish_output2() ip6_finish_output2() caches a=
pointer to the IPv6 destination address (daddr) before invoking lwtunnel_x= mit(). The LWT-BPF transmit path or other encapsulation operations within l= wtunnel_xmit() can reallocate the skb head, freeing the memory that daddr p= oints to. When lwtunnel_xmit() returns LWTUNNEL_XMIT_CONTINUE, the function=
continues to use the stale daddr pointer to compute the nexthop and to loo=
k up or create the neighbour entry. This results in a use-after-free read, = which can leak sensitive kernel data, pollute the neighbour table with arbi= trary values, misdirect traffic, or crash the system. Fix this by re-fetchi=
ng the IPv6 header and the destination address pointer after lwtunnel_xmit(=
) returns LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop comp= utation and neighbour lookup operate on valid memory.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80792" target=3D= "_blank" rel=3D"noopener">CVE-2026-80792</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv=
4: reject undersized MTUs in ip_do_fragment() ip_do_fragment() subtracts th=
e IPv4 header length from the effective MTU and passes the resulting payloa=
d MTU to ip_frag_next(). If the effective MTU is smaller than hlen + 8, ip_= frag_next() rounds the fragment payload length down to zero. The fragmentat= ion state then never makes forward progress: state->left, state->ptr = and state->offset stay unchanged while ip_do_fragment() keeps allocating=
and transmitting header-only fragments until the softlockup detector fires=
. This is reproducible with a route installed using "mtu lock 20", but it i=
s also reproducible without route MTU lock, for example by forwarding a pac= ket to a device whose MTU is 20. Fix it in ip_do_fragment() by rejecting mt=
u < hlen + 8 with -EMSGSIZE, matching the existing IPv6 fragmentation ch= eck.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80793" target=3D= "_blank" rel=3D"noopener">CVE-2026-80793</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: nci: fix uninit-value in the RF discover/activated NTF handlers nci_rf_di= scover_ntf_packet() and nci_rf_intf_activated_ntf_packet() each parse a not= ification into an on-stack struct (nci_rf_discover_ntf / nci_rf_intf_activa= ted_ntf) that is not initialised. The RF technology-specific parameters are=
only extracted when rf_tech_specific_params_len is non-zero, so a notifica= tion that reports a zero length leaves the rf_tech_specific_params union un= initialised - and both handlers then pass it to nci_add_new_protocol(), whi=
ch reads it: - discover: nci_add_new_target() -> nci_add_new_protocol();=
- activated: nci_target_auto_activated() -> nci_add_new_protocol(). nci= _add_new_protocol() uses nfca_poll->nfcid1_len as both a branch conditio=
n and a memcpy() length and copies nfcid1/sens_res/sel_res into ndev->ta= rgets, which is later exposed to user space via NFC_CMD_GET_TARGET. BUG: KM= SAN: uninit-value in nci_add_new_protocol+0x624/0x6c0 nci_add_new_protocol+= 0x624/0x6c0 nci_ntf_packet+0x25b2/0x3c30 nci_rx_work+0x318/0x5d0 process_sc= heduled_works+0x84b/0x17a0 worker_thread+0xc10/0x11b0 kthread+0x376/0x500 L= ocal variable ntf.i created at: nci_ntf_packet+0xbc2/0x3c30 Zero-initialise=
both on-stack notifications so the union reads back as zero when no techno= logy-specific parameters are present.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80794" target=3D= "_blank" rel=3D"noopener">CVE-2026-80794</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: nci: fix out-of-bounds write in nci_target_auto_activated() nci_target_au= to_activated() appends a target to the fixed-size array ndev->targets[NC= I_MAX_DISCOVERED_TARGETS] and increments ndev->n_targets without first c= hecking the array is full; unlike its sibling nci_add_new_target(), which b= ails out when n_targets already equals NCI_MAX_DISCOVERED_TARGETS. ndev->= ;n_targets is only cleared by nci_clear_target_list(), so an NFCC that repe= atedly re-runs discovery (RF_DISCOVER_RSP, which re-enters NCI_DISCOVERY wi= thout clearing the target list) and reports an auto-activated target (RF_IN= TF_ACTIVATED_NTF) drives n_targets past the limit. The append then writes a=
struct nfc_target past the end of the array (a slab out-of-bounds write), = and nfc_targets_found() goes on to walk the array with the inflated count: = BUG: KASAN: slab-out-of-bounds in nci_add_new_protocol+0x94/0x2ac [nci] Wri=
te of size 2 at addr ffff0000c7299a18 by task kworker/u8:0/12 Workqueue: nf= c0_nci_rx_wq nci_rx_work [nci] Call trace: nci_add_new_protocol+0x94/0x2ac = [nci] nci_ntf_packet+0xddc/0x11a0 [nci] nci_rx_work+0x15c/0x1e0 [nci] proce= ss_one_work+0x2dc/0x500 worker_thread+0x240/0x460 kthread+0x1c0/0x1d0 ret_f= rom_fork+0x10/0x20 The buggy address belongs to the cache kmalloc-2k of siz=
e 2048 The buggy address is located 1024 bytes to the right of allocated 15= 60-byte region [ffff0000c7299000, ffff0000c7299618) Guard nci_target_auto_a= ctivated() with the same check used by nci_add_new_target().</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80795" target=3D= "_blank" rel=3D"noopener">CVE-2026-80795</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: nci: add data_len bound checks to activation parameter extractors nci_ext= ract_activation_params_iso_dep() and nci_extract_activation_params_nfc_dep(=
) read an inner length byte from the NCI RF_INTF_ACTIVATED_NTF payload and = use it to memcpy() into fixed kernel buffers, but neither function receives=
the caller-validated activation_params_len. A crafted NCI notification wit=
h activation_params_len=3D1 and an inner length byte of up to 20 (NFC-A) or=
50 (NFC-B) causes memcpy() to read that many bytes past the one valid byte=
in the activation params region -- a slab out-of-bounds read of kernel mem= ory adjacent to the NCI skb. The sibling nci_extract_rf_params_*() family w=
as given equivalent protection by commit 571dcbeb8e63 ("net: nfc: nci: Fix = parameter validation for packet data"), but the two activation parameter ex= tractors were not updated at that time. Add a data_len parameter to both fu= nctions, guard against an empty region before consuming the inner length by= te, decrement the remaining count after consuming it, and clamp the copy le= ngth to what is actually available. Update both call sites to pass ntf.acti= vation_params_len, which is already validated against the skb at ntf.c:801.= </td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80796" target=3D= "_blank" rel=3D"noopener">CVE-2026-80796</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: pn533: purge fragmented skbs during cleanup pn53x_common_clean() purges r= esp_q before freeing the common PN533 state, but it leaves fragment_skb unt= ouched. The fragmentation helpers queue transmit fragments there while send= ing large initiator or target-mode frames, and those skbs remain owned by t=
he driver until they are sent or discarded. If the device is removed while = fragments are still queued, the common cleanup path frees the PN533 state w= ithout releasing the queued fragment skbs, leaking them. Purge fragment_skb=
during cleanup alongside resp_q.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80797" target=3D= "_blank" rel=3D"noopener">CVE-2026-80797</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: llcp: reject PDUs shorter than the LLCP header Every LLCP PDU begins with=
a two-byte header (DSAP/SSAP + PTYPE), but the receive path never checked = that a frame is at least LLCP_HEADER_SIZE bytes before parsing it. nfc_llcp= _rx_skb() reads the header via nfc_llcp_ptype()/nfc_llcp_dsap()/ nfc_llcp_s= sap(), which dereference pdu->data[0] and pdu->data[1], and a CONNECT=
or CC PDU then computes tlv_array_len =3D skb->len - LLCP_HEADER_SIZE; =
as a size_t and hands it to the TLV walk. When the frame is shorter than th=
e header the subtraction wraps to a huge value and the walk runs far past t=
he buffer, an out-of-bounds read. A nearby NFC device can reach this withou=
t authentication; LLCP link activation happens automatically after NFC-DEP.=
Guard the common receive choke point __nfc_llcp_recv(), shared by both the=
target (nfc_llcp_data_received()) and initiator (nfc_llcp_recv()) paths, s=
o a short skb is dropped before the rx_work worker parses it. Use pskb_may_= pull() rather than a skb->len test so the two header bytes are guarantee=
d to sit in the skb linear area even for a non-linear skb, matching how the=
sibling NCI and HCI receive paths validate their headers. Reproduced with =
a KFENCE out-of-bounds read via /dev/virtual_nci on linux-next. Found by 0s=
ec automated security-research tooling (
https://0sec.ai).</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80798" target=3D= "_blank" rel=3D"noopener">CVE-2026-80798</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: llcp: fix OOB read and u8 offset wrap in TLV parsers nfc_llcp_parse_gb_tl= v() and nfc_llcp_parse_connection_tlv() contain three related bugs in their=
TLV parsing loops: 1. 'offset' is declared u8 but tlv_array_len is u16. Wh=
en TLV data advances offset past 255 it silently wraps to zero, causing inf= inite loops or double-processing of buffer data. 2. Before reading tlv[0] (= type) and tlv[1] (length) there is no check that offset+2 <=3D tlv_array= _len. A truncated TLV causes an OOB read of one byte past the buffer end. 3=
. After reading the length field, the value bytes are accessed without chec= king offset+2+length <=3D tlv_array_len. A crafted length=3D0xFF on a sh= ort buffer causes up to 255 bytes of OOB read past the buffer end. Both fun= ctions are reachable without authentication via nfc_llcp_set_remote_gb() wh= ich feeds remote LLCP general bytes directly into nfc_llcp_parse_gb_tlv() w= ith no additional validation. Fix all three issues by widening offset from =
u8 to u16 and adding bounds checks for both the TLV header and value field = before each access.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80799" target=3D= "_blank" rel=3D"noopener">CVE-2026-80799</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: llcp: bound the connect_sn TLV walk to the skb Commit 27256cdb290e ("nfc:=
llcp: bound SNL TLV parsing to the skb and add length checks") fixed the u= nbounded TLV walk in nfc_llcp_recv_snl(), and commit d8bd2dedbde5 ("nfc: ll= cp: fix OOB read and u8 offset wrap in TLV parsers") subsequently bounded n= fc_llcp_parse_gb_tlv() and nfc_llcp_parse_connection_tlv(). One sibling par= ser sharing the same pattern remains unbounded: nfc_llcp_connect_sn(). nfc_= llcp_connect_sn() walks a TLV list, reading a two-byte header (type, length=
) followed by length bytes of value, without checking that the two header b= ytes or the declared length stay within the buffer. It returns a pointer to=
a service name of up to 255 bytes that may point past the end of the skb; =
it is subsequently consumed by memcmp() in nfc_llcp_sock_from_sn(). In addi= tion tlv_array_len was computed as "skb->len - LLCP_HEADER_SIZE" in size= _t, so a CONNECT/CC frame shorter than the LLCP header underflows to a huge=
length and the walk runs far past the buffer. nfc_llcp_connect_sn() is rea= chable from nfc_llcp_recv_connect() and nfc_llcp_recv_cc(), i.e. from recei= ved CONNECT and CC PDUs. A nearby NFC device can reach this without authent= ication; LLCP link activation happens automatically after NFC-DEP, and the = nfc_llcp_rx_skb() dispatcher applies no minimum-length guard. Walk the TLV = list by pointer, bounded by skb_tail_pointer(skb), and validate each declar=
ed length before use, matching the approach already used for nfc_llcp_recv_= snl(). Starting the walk at &skb->data[LLCP_HEADER_SIZE] against the=
tail pointer also removes the size_t underflow for short frames. Found by = 0sec automated security-research tooling (
https://0sec.ai).</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80800" target=3D= "_blank" rel=3D"noopener">CVE-2026-80800</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: microread: validate target discovery payload lengths microread_target_dis= covered() parses target discovery payloads from skb->data according to t=
he HCI gate. The fixed field offsets and UID copies were checked only again=
st the destination nfc_target buffers, not against the actual skb length. V= alidate that each gate-specific payload contains the fixed fields and UID b= ytes before reading or copying them.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80801" target=3D= "_blank" rel=3D"noopener">CVE-2026-80801</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: fdp: bound the device-reported read length and fix an skb leak fdp_nci_i2= c_read() takes the next packet length from two device-supplied bytes and ne= ver validates it. The value is a u16 used as the i2c_master_recv() count in=
to a 261-byte on-stack buffer: a malicious, counterfeit or malfunctioning c= ontroller (or an i2c bus interposer) can drive it far past the buffer for a=
stack out-of-bounds write that clobbers the canary and return address, or = below the minimum frame size (directly, or by truncating the computed sum) =
so the header/LRC strip and the next length read run past a short receive. = Reject a length outside [FDP_NCI_I2C_MIN_PAYLOAD, FDP_NCI_I2C_MAX_PAYLOAD],=
as a corrupted packet already is, and force resynchronization. The same lo=
op allocates one data skb per iteration and assumes a length packet followe=
d by a data packet; a device that sends two data packets in one call leaks = the first skb when the second allocation overwrites it. Free a previously a= llocated skb before allocating the next.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80802" target=3D= "_blank" rel=3D"noopener">CVE-2026-80802</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: digital: clamp SENSF_RES length to the destination buffer digital_in_recv= _sensf_res() memcpy()s resp->len bytes from a remote NFC-F device respon=
se into the NFC_SENSF_RES_MAXSIZE-byte target.sensf_res field without an up= per-bound check. A nearby malicious NFC-F device can send an oversized SENS= F_RES response to overflow the stack-local struct nfc_target. Clamp resp-&g= t;len to NFC_SENSF_RES_MAXSIZE before the copy. Found by 0sec automated sec= urity-research tooling (
https://0sec.ai).</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80803" target=3D= "_blank" rel=3D"noopener">CVE-2026-80803</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfs=
: restore nofs context unconditionally in xfs_trans_roll When __xfs_trans_c= ommit() fails in xfs_trans_roll(), the NOFS context is cleared but only res= tored in the success path. This leaves the error path without nofs protecti= on, causing a circular lock dependency between xfs_nondir_ilock_class and f= s_reclaim: CPU0 CPU1 ---- ---- lock(&xfs_nondir_ilock_class); lock(fs_r= eclaim); lock(&xfs_nondir_ilock_class); lock(fs_reclaim); Fix this by m= oving xfs_trans_set_context() before the error check so that nofs context i=
s always restored on the new transaction.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80804" target=3D= "_blank" rel=3D"noopener">CVE-2026-80804</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfs=
: validate attr entry pointer before field access xfs_attr3_leaf_verify_ent= ry() accesses lentry/rentry fields (namelen, valuelen) before checking if t=
he entry pointer itself is within bounds. If nameidx is crafted to point ne=
ar the end of the buffer, these field accesses can read out-of-bounds befor=
e the bounds check at name_end > buf_end is performed. Add explicit boun=
ds checks for entry pointers before accessing their fields. Use offsetof() =
to check that the start of the flexible array member (nameval/name) is with=
in bounds, which ensures all preceding fields are safe to access.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80805" target=3D= "_blank" rel=3D"noopener">CVE-2026-80805</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ext=
4: don't enable DAX on new encrypted files Currently, when a new encrypted = regular file is created, the call to ext4_set_inode_flags(inode, init=3Dtru=
e) in __ext4_new_inode() is made before EXT4_INODE_ENCRYPT is set. As a res= ult, it can set S_DAX if the filesystem is mounted with "-o dax=3Dalways". = EXT4_INODE_ENCRYPT then actually gets set a bit later in __ext4_new_inode()=
, when it calls fscrypt_set_context() which calls ext4_set_context(). ext4_= set_context() sets EXT4_INODE_ENCRYPT and calls ext4_set_inode_flags(inode,=
init=3Dfalse) to set S_ENCRYPTED too. This was intended to clear S_DAX as = well. However, this was broken by commit 043546e46dc7 ("fs/ext4: Only chang=
e S_DAX on inode load"). This causes data written to the file to bypass enc= ryption, also causing xfstests failures such as generic/548 (when "-o dax= =3Dalways" is used). Fix this by simplifying the flow by making __ext4_new_= inode() set EXT4_INODE_ENCRYPT earlier. This makes it take effect in ext4_s= et_inode_flags(inode, init=3Dtrue), making S_DAX never be set. Similarly, m= ake EXT4_STATE_MAY_INLINE_DATA never be set in the first place on new encry= pted inodes. Then it doesn't need to be cleared. As a result of these simpl= ifications, ext4_set_context() no longer needs to change inode flags or sta=
te when 'handle !=3D NULL'. Remove that too.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80806" target=3D= "_blank" rel=3D"noopener">CVE-2026-80806</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nil= fs2: reject invalid block index in GC ioctl Syzbot reported list corruption=
caused by a double list_add_tail() call on bh->b_assoc_buffers within n= ilfs_lookup_dirty_data_buffers(). Analysis revealed that the root cause was=
the insertion of a page/folio with a page index of ULONG_MAX into the page=
cache via the GC ioctl. filemap_get_folios_tag(), called by nilfs_lookup_d= irty_data_buffers(), repeatedly detects a dirty folio with a page index of = ULONG_MAX due to index wrap-around, leading to duplicate processing of dirt=
y buffers. As a preparatory step, the GC ioctl loads the page/folio of the = block to be moved during GC and inserts it into the page cache based on inf= ormation in the nilfs_vdesc structure passed as an argument. Normally, this=
does not cause issues because the user-space GC library configures the nil= fs_vdesc structure properly. However, since there is no range check on the = parameters determining the page index, a request with artificially crafted = parameters -- such as those generated by Syzbot -- can result in a page/fol=
io being inserted with a page index of ULONG_MAX, triggering the above prob= lem. This resolves the issue by checking the ranges of 'vd_offset' and 'vd_= vblocknr' in the nilfs_vdesc structure that determine the page index, there=
by preventing the invalid page/folio insertions.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80807" target=3D= "_blank" rel=3D"noopener">CVE-2026-80807</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ext=
4: stop retrying saturated xattr cache entries ext4_xattr_block_set() retri=
es when a cache entry selected for reuse has a saturated reference count af= ter taking the buffer lock. The retry returns to the mbcache lookup without=
making that entry ineligible, so it can select the same unusable entry ind= efinitely. A task spinning there can hold the parent directory's i_rwsem an=
d leave concurrent rmdir callers blocked. Normally a reusable entry has a r= eference count below EXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUS= ABLE_B are updated under the same buffer lock. A corrupted filesystem can v= iolate that invariant. The syzbot reproducer reports allocator and xattr co= rruption before triggering this retry loop. Check the untrusted on-disk cou=
nt before incrementing it, avoiding overflow, and clear MBE_REUSABLE_B when=
it is already saturated. The next lookup then skips the entry that was jus=
t proven unusable. This mirrors the normal transition at EXT4_XATTR_REFCOUN= T_MAX; the release path marks the entry reusable again on the exact 1024-to= -1023 transition. Using the same QEMU harness and guest parameters, current=
unpatched Linux hung in 6 of 8 420-second trials with the do_rmdir signatu= re; representative NMI backtraces caught the owner spinning in ext4_xattr_b= lock_set(). The patched kernel completed 28 of 28 trials without a hung-tas=
k report; the final twelve trials exercised the reviewed overflow-safe form=
of the change. syzbot's patch testing also completed without reproducing t=
he hang.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80808" target=3D= "_blank" rel=3D"noopener">CVE-2026-80808</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ocf= s2: fix missing metadata reservation for large xattrs [BUG] lsetxattr() pan= ics the kernel when setting a large xattr value on a fragmented filesystem = where the file already has an external xattr block. [CAUSE] ocfs2_calc_xatt= r_set_need() never reserves metadata blocks for a new xattr value's extent = tree when the file already has an external xattr block. The not_found path = leaves meta_add at zero, so meta_ac is NULL when ocfs2_xattr_extend_allocat= ion() runs. A new value root has room for a single extent record. On a frag= mented filesystem, the allocator cannot satisfy the xattr value in one cont= iguous run, so each non-contiguous run requires its own extent record. When=
the value root's extent list is full and meta_ac is NULL, ocfs2_add_cluste= rs_in_btree() returns RESTART_META, and ocfs2_xattr_extend_allocation() hit=
s BUG_ON(why =3D=3D RESTART_META). [FIX] The case where no xattr block exis=
ts yet already calls ocfs2_extend_meta_needed(&def_xv.xv.xr_list) to re= serve value tree metadata. Add the same reservation to the case where an xa= ttr block already exists, making the two cases consistent. Replace the BUG_=
ON with a -ENOSPC return so that if RESTART_META is returned despite the re= servation, the error propagates to userspace instead of panicking the kerne= l.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80809" target=3D= "_blank" rel=3D"noopener">CVE-2026-80809</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_= uring/rsrc: fix folio size overflow in io_vec_fill_bvec() io_vec_fill_bvec(=
) computes the folio size with a plain int 1: unsigned long folio_size =3D =
1 << imu->folio_shift; imu->folio_shift is unsigned int and com=
es from folio_shift() of the folio backing the registered buffer, so it can=
be 32 or more on a 64 bit kernel. Shifting int 1 that far is undefined, an=
d on x86 and arm64 the count is taken modulo 32, so a shift of 34 yields 4 = rather than 16G. Every other folio_shift shift in this file already uses 1U=
L. The result is that the segment estimate and the fill loop disagree. io_e= stimate_bvec_size() sizes the bvec array with the real shift: max_segs +=3D=
(iov[i].iov_len >> shift) + 2; so a 1M iovec on a 16G folio is charg=
ed 2 segments, while io_vec_fill_bvec() then walks the same iovec in folio_= size chunks of 4 bytes and writes res_bvec[bvec_idx] a quarter of a million=
times, past the end of the array it was given. src_bvec is advanced once p=
er iteration as well, so imu->bvec is read past its end at the same time=
. validate_fixed_range() only checks that the range is inside the registere=
d buffer and does not bound the segment count. Reaching it needs a folio wi=
th a shift of at least 32, which means a gigantic hugetlb page: 16G on arm6=
4 with 64K pages, where CONT_PMD_SHIFT is 34 and hugetlb_add_hstate(CONT_PM= D_SHIFT - PAGE_SHIFT) registers that size, and likewise on powerpc. x86_64 = tops out at 1G, so a shift of 30, which still fits in int and is unaffected=
. Use 1UL, as the rest of the file does.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80810" target=3D= "_blank" rel=3D"noopener">CVE-2026-80810</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_= uring/cmd: fix iovec leak when the async cmd is not recycled An io_async_cm=
d carries an iovec array in ->vec.iovec, allocated when the vec has to g= row and kept across recycling through ctx->cmd_cache. On two paths nothi=
ng frees it and io_clean_op()'s kfree(req->async_data) drops the io_asyn= c_cmd without it. io_req_uring_cleanup() clears the async data flags only w= hen io_alloc_cache_put() succeeds, and the cache holds IO_ALLOC_CACHE_MAX = =3D=3D 128 entries, so once it is full the put fails and the vec is left be= hind. An NVMe passthrough workload gets there without doing anything unusua=
l: nvme_uring_cmd_io() returns -EIOCBQUEUED, so the io_async_cmd stays atta= ched for the lifetime of the command and the live object count tracks the q= ueue depth. Above 128 the puts start failing. ->cleanup is the last chan=
ce to free an inherited vec, since io_req_uring_cleanup() returns early for=
an io-wq issued command and is not called at all for one completed without=
ever being issued. But io_clean_op() calls ->cleanup only if REQ_F_NEED= _CLEANUP is set, and for uring_cmd that happens only where the vec has to g= row, so a command reusing a large enough cached vec never sets it. io_rw_al= loc_async() and io_msg_alloc_async() flag an inherited vec for exactly this=
reason; io_uring_cmd_prep() does not. Flag an inherited vec in io_uring_cm= d_prep(), and free the vec when the cache put fails, as io_req_rw_cleanup()=
does. The leak is invisible under KASAN, where io_alloc_cache_vec_kasan() = frees the vec unconditionally.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80811" target=3D= "_blank" rel=3D"noopener">CVE-2026-80811</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: dummy: Check card index validity at probe snd_dummy_probe() blindly trus=
ts that the given devptr->id value is within the proper card index range=
. It's OK for the devices the driver itself creates at the module probe tim=
e, but if the device is bound manually via sysfs interface, this could be -=
1 as "none", and this leads to OOB access for index[] and other parameters.=
Add a sanity check for the card index and warn/correct it if it's a value = out of the range.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80812" target=3D= "_blank" rel=3D"noopener">CVE-2026-80812</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et: fix NULL pointer dereference in nvmet_execute_identify_nslist() When a = host issues an Identify command with CNS 07h (Active Namespace ID List for =
a specific I/O Command Set), nvmet_execute_identify_nslist() is called with=
match_css set. The command-set filter dereferences req->ns, but this ha= ndler never calls nvmet_req_find_ns(), so req->ns is always NULL (nvmet_= req_init() resets it to NULL). As soon as an enabled namespace with an NSID=
greater than the requested value exists, req->ns->csi dereferences a=
NULL pointer and oopses. Besides the crash, the comparison is logically wr= ong: to filter the list by command set it must test the command set of the = namespace being iterated, not a single fixed value. Use the loop variable n= s->csi.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80813" target=3D= "_blank" rel=3D"noopener">CVE-2026-80813</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: rnd= is_host: add overflow check in rndis_rx_fixup() Add an overflow check to en= sure that data_offset + data_len + 8 does not wrap, which would enable an O=
OB read of the USB data buffer.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80814" target=3D= "_blank" rel=3D"noopener">CVE-2026-80814</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: scarlett2: Use a private URB for the notification endpoint scarlett2_ini= t_notify() used mixer->urb, which snd_usb_mixer_status_create() allocate=
s for the UAC2 status interrupt endpoint and mixer.c manages. On a device w= ith that endpoint, the "already in use" check fires on the status URB and r= eturns 0 for success without doing anything. No notification URB is submitt= ed, and cmd_done is left zeroed because it is initialised past that check a=
nd nowhere else. scarlett2_usb_init() then issues SCARLETT2_USB_INIT_1 and = wait_for_completion_timeout() would crash adding to the zeroed wait.head. U=
se a separate URB in scarlett2_data, as done for FCP, and initialise cmd_do=
ne in scarlett2_init_private(). mixer.c was also freeing the URB in snd_usb= _mixer_free() and resubmitting it in snd_usb_mixer_activate(), so scarlett2=
must now do both: add scarlett2_cleanup_urb(), called from private_free an=
d private_suspend, and a private_resume callback to re-establish the URB af= ter resume. scarlett2_init_notify() is reached from there, and the URB kill=
path in scarlett2_notify() completes cmd_done, leaving a stale count that = would satisfy the next command's wait before the device ACKs. Use reinit_co= mpletion() to clear it. Also free the URB if the transfer buffer allocation=
fails, and both if usb_submit_urb() fails. Move scarlett2_init_notify() up=
next to scarlett2_cleanup_urb() so scarlett2_init_private() can reference =
it without a forward declaration.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80815" target=3D= "_blank" rel=3D"noopener">CVE-2026-80815</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: FCP: Use a private URB for the notification endpoint fcp_init_notify() u= sed mixer->urb, which snd_usb_mixer_status_create() allocates for the op= tional UAC2 status interrupt endpoint and mixer.c kills, resubmits and free=
s. On a device with that endpoint, fcp_init_notify()'s "already set up" ear=
ly return fires on the status URB and returns success without doing anythin=
g. No FCP notification URB is submitted, and cmd_done is left zeroed becaus=
e it is initialised past that early return and nowhere else. fcp_init() the=
n issues init1_opcode and wait_for_completion_timeout() would crash adding =
to the zeroed wait.head. fcp_cleanup_urb() would also kill and free mixer.c=
's status URB. Use a separate URB in fcp_data, and initialise cmd_done in f= cp_init_private() where fcp_data is allocated. fcp_init_notify() is reached=
again after suspend via fcp_reinit(), and the URB kill path in fcp_notify(=
) completes cmd_done, leaving a stale count that would satisfy the next com= mand's wait before the device ACKs. Use reinit_completion() to clear it.</t=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80816" target=3D= "_blank" rel=3D"noopener">CVE-2026-80816</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: iom= mu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when raci=
ng with iopt_map_file_pages iommufd_ioas_change_process() iterates every IO=
AS area while only holding every IOAS iova_rwsem, so it assumes every area = has a non-NULL pages pointer. That assumption can be false when it runs con= currently with iopt_map_file_pages(). iopt_map_pages() executes in two phas= es. It first creates the area and inserts it into the interval tree under i= ova_rwsem, with area->pages still NULL. It then drops iova_rwsem and lat=
er fills area->pages under domains_rwsem. This leaves a window between a= rea creation and area->pages fill where a concurrent iommufd_ioas_change= _process() can observe the area and dereference a NULL area->pages point= er, leading to a NULL pointer dereference: BUG: kernel NULL pointer derefer= ence, address: 00000000000000c0 #PF: supervisor read access in kernel mode = #PF: error_code(0x0000) - not-present page PGD 4b655067 P4D 4b655067 PUD 0 = Oops: Oops: 0000 [#1] SMP NOPTI CPU: 0 UID: 0 PID: 11841 Comm: syz.1.628 No=
t tainted 7.1.0 #3 PREEMPT(full) Hardware name: QEMU Ubuntu 24.04 PC v2 (i4= 40FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 R= IP: 0010:iommufd_ioas_change_process+0x419/0xd50 drivers/iommu/iommufd/ioas= .c:538 Code: 48 89 c3 48 85 c0 0f 84 cc 00 00 00 e8 10 f5 cb fd 48 8d 7b 68=
e8 a7 b5 eb fd 48 8b 6b 68 48 8d bd c0 00 00 00 e8 17 b2 eb fd <8b> =
ad c0 00 00 00 bf 01 00 00 00 89 ee e8 85 ef cb fd 83 fd 01 74 RSP: 0018:ff= ffc90015c17d28 EFLAGS: 00010246 RAX: ffff8880186d5328 RBX: ffff88801d25e240=
RCX: 0000000080000000 RDX: 00000000000002d7 RSI: ffffffff83ba9e10 RDI: 000= 00000000000c0 RBP: 0000000000000000 R08: ffffffff8e781eb8 R09: 000000000000= 0000 R10: 00000000000000c0 R11: ffffffff83ba9e29 R12: ffff88802e216008 R13:=
ffff88802e216000 R14: 0000000000000001 R15: 0000000000000000 FS: 00007f4ae= a3f66c0(0000) GS:ffff8880b1fa1000(0000) knlGS:0000000000000000 CS: 0010 DS:=
0000 ES: 0000 CR0: 0000000080050033 CR2: 00000000000000c0 CR3: 000000004b7= 5c000 CR4: 0000000000350ef0 Call Trace: <TASK> iommufd_fops_ioctl+0x2= 87/0x400 drivers/iommu/iommufd/main.c:533 vfs_ioctl fs/ioctl.c:51 [inline] = __do_sys_ioctl fs/ioctl.c:597 [inline] __se_sys_ioctl fs/ioctl.c:583 [inlin=
e] __x64_sys_ioctl+0x120/0x170 fs/ioctl.c:583 x64_sys_call+0x1092/0x1fb0 ar= ch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry= /syscall_64.c:63 [inline] do_syscall_64+0x10a/0x680 arch/x86/entry/syscall_= 64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f4aec1a82bd C= ode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 4=
8 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0=
ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f4aea= 3f6018 EFLAGS: 00000246 ORIG_RAX: 0000000000000010 RAX: ffffffffffffffda RB=
X: 00007f4aec436090 RCX: 00007f4aec1a82bd RDX: 0000200000000180 RSI: 000000= 0000003b92 RDI: 0000000000000003 RBP: 00007f4aec250295 R08: 000000000000000=
0 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 00= 00000000000000 R13: 00007f4aec436128 R14: 00007f4aec436090 R15: 00007ffd04e= f23e0 </TASK> Modules linked in: CR2: 00000000000000c0 ---[ end trace=
0000000000000000 ]--- RIP: 0010:iommufd_ioas_change_process+0x419/0xd50 dr= ivers/iommu/iommufd/ioas.c:538 Code: 48 89 c3 48 85 c0 0f 84 cc 00 00 00 e8=
10 f5 cb fd 48 8d 7b 68 e8 a7 b5 eb fd 48 8b 6b 68 48 8d bd c0 00 00 00 e8=
17 b2 eb fd <8b> ad c0 00 00 00 bf 01 00 00 00 89 ee e8 85 ef cb fd =
83 fd 01 74 RSP: 0018:ffffc90015c17d28 EFLAGS: 00010246 RAX: ffff8880186d53=
28 RBX: ffff88801d25e240 RCX: 0000000080000000 RDX: 00000000000002d7 RSI: f= fffffff83ba9e10 RDI: 00000000000000c0 RBP: 0000000000000000 R08: ffffffff8e= 781eb8 R09: 0000000000000000 R10: 00000000000000c0 R11: ffffffff83ba9e29 R1=
2: ffff88802e216008 R13: ffff88802e216000 R14: 0000000000000001 R15: 000000= 0000000000 FS: 00007f4aea3f66c0(000 ---truncated---</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80817" target=3D= "_blank" rel=3D"noopener">CVE-2026-80817</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: iom= mu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown arm_smmu_impl_re= move() is registered as a devres action in arm_smmu_impl_probe(), before ar= m_smmu_init_queues() allocates smmu->cmdq.q.base. On a devres unwind, wh= ether a failed probe or an unbind, the queue is freed first and arm_smmu_im= pl_remove() then runs tegra241_cmdqv_remove_vintf(), whose VINTF deinit iss= ues a CMD_SYNC on the freed memory. Observed during testing with a QEMU hac=
k that makes the VCMDQ fail to enable, so the impl reset fails and probe ab= orts into the devres unwind: platform NVDA200C:00: tegra241_cmdqv: VINTF0: = VCMDQ0/LVCMDQ0: failed to enable, STATUS=3D0x00000000 platform NVDA200C:00:=
tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: GERRORN=3D0x0, GERROR=3D0x4, CONS= =3D0x0 platform NVDA200C:00: tegra241_cmdqv: VINTF0: VCMDQ0/LVCMDQ0: unclea= red error detected, resetting arm-smmu-v3 arm-smmu-v3.0.auto: failed to res=
et impl arm-smmu-v3 arm-smmu-v3.0.auto: probe with driver arm-smmu-v3 faile=
d with error -110 Unable to handle kernel paging request at virtual address=
ffff8000891e0098 ... Internal error: Oops: 0000000096000047 [#1] SMP ... C= all trace: arm_smmu_cmdq_issue_cmdlist+0x320/0x6fc (P) tegra241_vcmdq_hw_de= init+0x98/0x168 tegra241_vintf_hw_deinit+0x5c/0x1b0 tegra241_cmdqv_remove_v= intf+0x34/0xec tegra241_cmdqv_remove+0x40/0x9c arm_smmu_impl_remove+0x20/0x=
30 devm_action_release+0x14/0x20 devres_release_all+0xa8/0x110 device_unbin= d_cleanup+0x18/0x84 really_probe+0x1f0/0x29c Drop the VINTF deinit from teg= ra241_cmdqv_remove_vintf() so the unwind no longer touches the freed queue.=
Quiesce the VINTFs earlier instead. Add a device_disable() impl op and run=
it from arm_smmu_disable_action() while the CMDQ is still up. That handles=
a live unbind. A failed reset is already handled because tegra241_vintf_hw= _init() deinits the VINTF on its own error path. tegra241_cmdqv_remove_vint= f() is also used by the iommufd viommu destroy path, so quiesce there too.<=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80818" target=3D= "_blank" rel=3D"noopener">CVE-2026-80818</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: Blu= etooth: RFCOMM: take rfcomm_mutex for the deferred setup accept rfcomm_sock= _recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() withou=
t holding any RFCOMM lock: if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &= d->flags)) { rfcomm_dlc_accept(d); return 0; } and rfcomm_dlc_accept() d= ereferences the session on its first line: struct sock *sk =3D d->sessio= n->sock->sk; Every other path that touches d->session runs under r= fcomm_mutex: rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(), rf= comm_dlc_send_rpn(), and the RFCOMM thread through rfcomm_process_sessions(=
). rfcomm_connect_ind() is even documented as "called under rfcomm_lock()".=
This call site is the only one that skips it. The RFCOMM_DEFER_SETUP bit l= ooks like it serialises the accept against teardown, since __rfcomm_dlc_clo= se() returns early when it wins the test_and_clear. But rfcomm_recv_disc() = forces the state first: d->state =3D BT_CLOSED; __rfcomm_dlc_close(d, er= r); and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and BT_= CONNECT2. With the state already BT_CLOSED that switch does not match, the = bit is never consulted, and __rfcomm_dlc_close() falls through to rfcomm_dl= c_unlink(), which sets d->session =3D NULL. So a remote DISC on a deferr=
ed dlc clears the session while leaving RFCOMM_DEFER_SETUP set. The next re= cvmsg() then passes the test_and_clear and dereferences a NULL session. No = timing window is needed: once the DISC has been processed, the dereference =
is unconditional. Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_ope= n() and rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and=
re-checks the session, around a __rfcomm_dlc_accept() that the two in-core=
callers, which already hold the mutex, keep using. Reproduced on a KASAN +=
PROVE_LOCKING kernel with a BR/EDR peer emulated over /dev/vhci: the peer = brings up an ACL link, opens L2CAP on the RFCOMM PSM, starts a session, ope=
ns a dlc on a channel bound with BT_DEFER_SETUP, and sends DISC after the s= ocket is accepted. recv() on the accepted socket then hits: Oops: general p= rotection fault KASAN: null-ptr-deref in range [0x0000000000000010-0x000000= 0000000017] RIP: 0010:rfcomm_dlc_accept+0x54/0x350 Call Trace: rfcomm_sock_= recvmsg+0x1cd/0x230 sock_recvmsg+0x166/0x1c0 __sys_recvfrom+0x20d/0x300 0x1=
0 is the offset of sock in struct rfcomm_session. With this patch the same = run completes with recv() returning 0 and no report, and lockdep stays quie=
t, confirming rfcomm_mutex is still taken before lock_sock on this path as =
it is on the thread side.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80819" target=3D= "_blank" rel=3D"noopener">CVE-2026-80819</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfs=
: don't livelock in scrub on a circular unlinked list LOLLM points out that=
online fsck can livelock if an unlinked inode list contains a loop. Use a = bitmap to detect cycles.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80820" target=3D= "_blank" rel=3D"noopener">CVE-2026-80820</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= et: pci-epf: put CQ ref on create_cq mapping failure nvmet_pci_epf_create_c= q() calls nvmet_cq_create(), which takes a reference on the controller and = installs the completion queue. If the subsequent PCI address-space mapping = fails or returns a too-small partial mapping, the function jumps to err_int= ernal / err_unmap_queue without calling nvmet_cq_put(). The matching put in=
nvmet_pci_epf_delete_cq() is gated on NVMET_PCI_EPF_Q_LIVE, which is only = set after the mapping succeeds, so teardown never releases these references=
. A remote PCI host that drives Create IO CQ commands with a failing PRP1/p= ci_addr therefore leaks the CQ and a controller reference on each attempt. = Drop the CQ reference on the mapping-failure paths. The err_internal and er= r_unmap_queue labels are only reachable after nvmet_cq_create() has succeed= ed, so this pairs the create/put correctly.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80821" target=3D= "_blank" rel=3D"noopener">CVE-2026-80821</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: mai= lbox: mchp-ipc-sbi: Add null check for devm_kasprintf() Add a check to see =
if devm_kasprintf() is not NULL in mchp_ipc_get_cluster_aggr_irq(), returni=
ng -ENOMEM if the function failed.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80822" target=3D= "_blank" rel=3D"noopener">CVE-2026-80822</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nfc=
: st21nfca: validate ATR_REQ length against the received frame st21nfca_tm_= recv_atr_req() checks that the received ATR_REQ frame is at least ST21NFCA_= ATR_REQ_MIN_SIZE and that the self-declared atr_req->length is at least = sizeof(struct st21nfca_atr_req), but never checks that atr_req->length d= oes not exceed the actual received length (skb->len). st21nfca_tm_send_a= tr_res() then trusts the declared length: gb_len =3D atr_req->length - s= izeof(struct st21nfca_atr_req); ... memcpy(atr_res->gbi, atr_req->gbi=
, gb_len); so an RF peer that sends a short frame but sets atr_req->leng=
th larger than the frame makes gb_len exceed the general bytes actually pre= sent, and the memcpy reads out of bounds past the received skb. Those bytes=
are placed in the ATR_RES and sent back to the peer (kernel-memory disclos= ure to a proximity attacker); a larger declared length is an out-of-bounds = read (DoS). Reject frames whose declared length exceeds the received length=
. The adjacent nfc_tm_activated() path in the same function already derives=
its general-bytes length from skb->len rather than the declared field. = Found by 0sec (
https://0sec.ai) using automated source analysis; the missin=
g bound is evident from source. Compile-tested.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80823" target=3D= "_blank" rel=3D"noopener">CVE-2026-80823</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb=
: usbfs: fix use-after-free of usb_device in usbdev_release() usbdev_releas= e() drops its reference to the struct usb_device before draining the list o=
f completed async URBs, but that drain path reads back through the same obj= ect: free_async() calls dec_usb_memory_use_count() for any URB whose buffer=
came from the usbfs mmap() region, and its first statement is bus_to_hcd(p= s->dev->bus). After a disconnect the usbfs reference can be the last = one, in which case usb_put_dev() frees the device and the subsequent loop r= eads offset 80 of freed memory and uses the result as a struct usb_hcd *, w= hich hcd_buffer_free_pages() then dereferences. This is reachable by an unp= rivileged process that has read/write access to a /dev/bus/usb node: mmap()=
the fd, submit one URB with a buffer inside the mapping, wait for the devi=
ce to be unplugged, then munmap() and close(). It reproduces on every attem=
pt rather than being a race, because a live MAP_SHARED vma holds a referenc=
e on the struct file, so usbdev_release() cannot run until the last vma is = gone and the freeing branch of dec_usb_memory_use_count() is always taken. = BUG: KASAN: slab-use-after-free in dec_usb_memory_use_count+0x3ae/0x410 Rea=
d of size 8 at addr ffff8880122ee050 by task poc/769 CPU: 1 UID: 1000 PID: = 769 Comm: poc Tainted: G B 6.12.94 #3 Call Trace: dec_usb_memory_use_count+= 0x3ae/0x410 free_async+0x2aa/0x4f0 usbdev_release+0x375/0x460 __fput+0x3ea/= 0xb50 __x64_sys_close+0x86/0x100 Allocated by task 11: usb_alloc_dev+0x55/0= xd90 hub_event+0x2524/0x43d0 Freed by task 769: kfree+0x121/0x360 device_re= lease+0xd2/0x280 usb_put_dev+0x23/0x30 usbdev_release+0x2d8/0x460 Release t=
he device reference after the drain loop instead. Nothing between the two p= oints requires it to have been dropped.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80824" target=3D= "_blank" rel=3D"noopener">CVE-2026-80824</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: wif=
i: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb mt7925_usb_s= dio_tx_prepare_skb() pushes a TX descriptor and a USB header onto every skb=
and assumes the headroom for them is already there. That holds for locally=
generated traffic, where mac80211 reserves hw->extra_tx_headroom, but f= orwarded frames are sent through ieee80211_8023_xmit(), which does not rese= rve it. Bridge a wired interface to an mt7925u AP and the first forwarded f= rame that arrives short panics the kernel: skbuff: skb_under_panic: len:415=
put:4 tail:0x19b end:0x640 dev:wlan1 kernel BUG at net/core/skbuff.c:212! = Call trace: skb_panic+0x58/0x60 (P) skb_push+0x58/0x60 mt7925_usb_sdio_tx_p= repare_skb+0xf8/0x1b8 [mt7925_common] mt76u_tx_queue_skb+0xa0/0x1f8 [mt76_u= sb] __mt76_tx_queue_skb+0x54/0xe8 [mt76] mt76_txq_schedule.part.0+0x204/0x4=
78 [mt76] mt76_txq_schedule_all+0x50/0x80 [mt76] mt792x_tx_worker+0x68/0x10=
0 [mt792x_lib] __mt76_worker_fn+0x84/0x150 [mt76] Whether a given setup hit=
s it depends on how much headroom the ingress netdev leaves in its rx skbs.=
Reproduced on a Raspberry Pi 5 bridging onboard ethernet to a Netgear A900=
0; originally reported on an MT7986 router running OpenWrt. Nick Morrow's t= esting on a Pi 4 (bcmgenet), which leaves more headroom, helped narrow the = trigger to the ingress path. The same bug was fixed on mt7921 by commit 98c= 4d0abf5c4 ("mt76: mt7921: don't assume adequate headroom for SDIO headers")=
, but mt7925 was copied from mt7921 without the fix. Add the same guard her= e.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80825" target=3D= "_blank" rel=3D"noopener">CVE-2026-80825</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: USB=
: c67x00: fix use-after-free in c67x00_add_iso_urb() When TD creation fails=
for the last packet of an isochronous URB, c67x00_add_iso_urb() gives the = URB back before updating the endpoint scheduling state. c67x00_giveback_urb=
() frees the URB private data, and the completion callback may release the = final URB reference. The following accesses to urbp->ep_data, urb->in= terval, and urbp->cnt can therefore use freed memory. Update next_frame = and cnt before giving back the failed final packet, making the giveback the=
last operation that uses the URB and its private data.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80826" target=3D= "_blank" rel=3D"noopener">CVE-2026-80826</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: USB=
: serial: option: fix slab OOB read in interrupt URB callback The interrupt=
URB buffer is allocated in setup_port_interrupt_in() based on the endpoint=
's wMaxPacketSize: buffer_size =3D usb_endpoint_maxp(epd); port->interru= pt_in_buffer =3D kmalloc(buffer_size, GFP_KERNEL); When a USB device declar=
es wMaxPacketSize =3D 8 on its interrupt IN endpoint, the buffer is allocat=
ed from kmalloc-8 cache (exactly 8 bytes). If the device sends a short pack=
et (actual_length < wMaxPacketSize), the URB completes with status =3D=
=3D 0 and the callback proceeds to read: data[sizeof(struct usb_ctrlrequest=
)] which evaluates to data[8], accessing 1 byte beyond the allocated 8-byte=
buffer. This results in a slab out-of-bounds read. Fix this by adding the = missing bounds check: first verify that the actual length is large enough t=
o contain the struct usb_ctrlrequest header before accessing req_pkt->bR= equestType and req_pkt->bRequest, and then verify that there is an addit= ional byte for the modem signal state before reading data[sizeof(struct usb= _ctrlrequest)] inside the conditional. Use sizeof(*req_pkt) instead of size= of(struct usb_ctrlrequest) for consistency. [ johan: use dev_err(); split s= ignals declaration and initialisation ]</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80827" target=3D= "_blank" rel=3D"noopener">CVE-2026-80827</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: usb-audio: Complete cleanup after system-resume errors A failed system r= esume can leave the card unusable until reboot. usb_audio_resume() jumps to=
err_out when snd_usb_pcm_resume() or snd_usb_mixer_resume() fails. The err=
or path skips the out: block, which restores D0 and decrements chip->num= _suspended_intf. The card stays in SNDRV_CTL_POWER_D3hot, so later control = access blocks in snd_power_ref_and_wait(). USB core logs an interface resum=
e callback error. It does not retry that callback, so a later callback cann=
ot complete the skipped cleanup. usb_audio_suspend() increments num_suspend= ed_intf before returning success. A system-resume callback must consume the=
system-suspend count even if a component resume fails. Otherwise, the stra= nded count skews later suspend and resume cycles. Do not apply this cleanup=
to runtime-resume errors. Runtime PM can retry -EAGAIN or -EBUSY without a= nother suspend callback. The count must continue to describe that suspended=
interface. Other runtime-resume errors latch runtime_error in the PM core = and do not cause an immediate callback retry. Both parts of the system-resu=
me error path are longstanding. Commit 88a8516a2128a ("ALSA: usbaudio: impl= ement USB autosuspend") introduced err_out past the D0 restore. Commit 862b= 2509d157c ("ALSA: usb-audio: Fix inconsistent card PM state after resume") = later moved num_suspended_intf-- into the out: block. The error path now sk= ips both operations. No third-party code is needed to reach the error path.=
snd_usb_mixer_resume() ends in snd_usb_mixer_activate(), which returns the=
result of usb_submit_urb() for devices that have a mixer status URB. Its m= ixer->private_resume hook can also fail through scarlett2_init_notify().=
snd_usb_pcm_resume() issues a SET_CUR request to a UAC3 power domain. It c=
an return -EPIPE or -EIO when the device stalls the request. Route a compon= ent error through out: only when system_suspend is nonzero. Continue to ret= urn runtime-resume errors through err_out. Later component resume stages re= main skipped. The original error still reaches USB core. A later transfer c=
an fail if the device did not recover. I reproduced the system-resume failu=
re on an Audient iD14 MkI with an out-of-tree diagnostic mixer resume hook.=
An injected -EIO on the unpatched core left control readers in uninterrupt= ible sleep in snd_power_ref_and_wait() until a reboot. With this patch, the=
same failure restored control access. A second system suspend and resume a= lso succeeded after I disabled fault injection.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80828" target=3D= "_blank" rel=3D"noopener">CVE-2026-80828</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: usb-audio: fix OOB write in snd_usbmidi_novation_output() snd_usbmidi_no= vation_output() lays out a two-byte header at transfer_buffer[0..1] and pas= ses &transfer_buffer[2] together with a length of ep->max_transfer -=
2 to snd_rawmidi_transmit(): count =3D snd_rawmidi_transmit(ep->ports[0= ].substream, &transfer_buffer[2], ep->max_transfer - 2); ep->max_= transfer comes from the output endpoint's wMaxPacketSize via usb_maxpacket(=
). A malformed or malicious device can advertise a bulk OUT endpoint with a=
wMaxPacketSize of 1 - the USB core only clamps this value downwards - so e= p->max_transfer becomes 1 and the count argument becomes -1. snd_rawmidi= _transmit() passes the negative count on to __snd_rawmidi_transmit_peek(), = where "if (count1 > count) count1 =3D count" leaves count1 negative; get= _aligned_size() keeps it negative for a byte-stream substream, so the follo= wing memcpy(buffer, ..., count1) runs with a (size_t)-1 length and writes f=
ar past the transfer buffer, which was allocated with usb_alloc_coherent(ep= ->max_transfer). This is the same class of bug that was fixed for snd_us= bmidi_akai_output() in commit 0970274613fb ("ALSA: usb-audio: fix OOB write=
in snd_usbmidi_akai_output()"); the novation output routine was left ungua= rded. Bail out when the endpoint cannot hold the two-byte header plus at le= ast one payload byte.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80829" target=3D= "_blank" rel=3D"noopener">CVE-2026-80829</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb=
: core: Add lock to usb_wakeup_notification() Add a spin lock to usb_wakeup=
notification to prevent a race condition with dereferencing freed memory. = This could be hit by the xHCI driver as it calls this function from an IRQ = and could race with the hub_disconnect() function, which properly grabs thi=
s lock to protect the state of the device.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80830" target=3D= "_blank" rel=3D"noopener">CVE-2026-80830</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_block_crypt=
() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg=
() first. Therefore, sg_dma_len() is invalid and could return zero or a sta=
le DMA length, causing encryption and decryption to process the wrong numbe=
r of bytes when CONFIG_NEED_SG_DMA_LENGTH=3Dy. Use the original scatterlist=
length instead.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80831" target=3D= "_blank" rel=3D"noopener">CVE-2026-80831</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: qce - fix CCM AAD buffer underallocation The AAD buffer allocated in q= ce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later pro= grammed into the DMA scatterlist. The allocation size is currently calculat=
ed as: ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN while the DMA length =
is set to: ALIGN(assoclen + adata_header_len, 16) Since ALIGN() does not di= stribute over addition, the allocation can be smaller than the DMA length. = For example, when assoclen =3D 32 and adata_header_len =3D 2: allocation =
=3D ALIGN(32, 16) + 6 =3D 38 DMA length =3D ALIGN(32 + 2, 16) =3D 48 As a r= esult, the QCE hardware can read beyond the allocated buffer while computin=
g the CBC-MAC over the associated data. The extra bytes are folded into the=
authentication tag, resulting in an incorrect tag and causing CCM self-tes=
t failures such as: alg: aead: ccm-aes-qce encryption test failed (wrong re= sult) on test vector 8 Fix the allocation by adding the maximum possible AA=
D header length before alignment: ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN=
, 16) This guarantees that the allocated buffer is large enough for the ful=
ly padded AAD data for all supported header sizes.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80832" target=3D= "_blank" rel=3D"noopener">CVE-2026-80832</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: sun8i-ss - Remove crypto_rng interface Since the crypto_rng interface = for hardware PRNGs is unused and is redundant with hwrng and the actual Lin=
ux RNG, it's being phased out. Most drivers for it were already removed. Go=
ahead and remove the sun8i-ss support which is one of the only remaining o= nes. As usual for crypto_rng, this driver was also buggy: its ->generate=
() function had a use-after-free vulnerability due to using wait_for_comple= tion_interruptible_timeout() without handling shutting down the DMA operati=
on if a signal is sent. Also, it had a buffer overread bug in the line 'mem= cpy(ctx->seed, d + dlen, ctx->slen);'. There's no point in fixing the=
se bugs separately only to remove the code anyway, so this commit is marked=
with Fixes and Cc stable.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80833" target=3D= "_blank" rel=3D"noopener">CVE-2026-80833</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: sun8i-ce - Remove crypto_rng interface Since the crypto_rng interface = for hardware PRNGs is unused and is redundant with hwrng and the actual Lin=
ux RNG, it's being phased out. Most drivers for it were already removed. Go=
ahead and remove the sun8i-ce support which is one of the only remaining o= nes. Note that the sun8i-ce support for hwrng remains in place. That is the=
interface that actually matters. As usual for crypto_rng, this driver was = also buggy: its ->generate() function had a use-after-free vulnerability=
due to using wait_for_completion_interruptible_timeout() without handling = shutting down the DMA operation if a signal is sent. There's no point in fi= xing this separately only to remove the code anyway, so this commit is mark=
ed with Fixes and Cc stable.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80834" target=3D= "_blank" rel=3D"noopener">CVE-2026-80834</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: qcom-rng - Remove crypto_rng interface qcom-rng.c exposes the same har= dware through two completely separate interfaces, crypto_rng and hwrng. How= ever, the implementation of this is buggy because it permits generation ope= rations from these interfaces to run concurrently with each other, accessin=
g the same registers. That is, qcom_rng_generate() synchronizes with itself=
but not with qcom_hwrng_read(). This results in potential repetition of ou= tput from the RNG, output of non-random values, etc. Fortunately, there's a= ctually no point in hardware RNG drivers implementing the crypto_rng interf= ace. It's not actually used by anything besides the "rng" algorithm type of=
AF_ALG, which in turn is not actually used in practice. Other crypto_rng h= ardware drivers are likewise being phased out, leaving just the hwrng suppo= rt. Thus, remove it to simplify the code and avoid conflict (and confusion)=
with the hwrng interface which is the one that actually matters.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80835" target=3D= "_blank" rel=3D"noopener">CVE-2026-80835</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: virtio - bound the akcipher result length virtio_crypto_dataq_akcipher= _callback() sets the result length from the device-reported response length=
without bounding it to the destination buffer, which was allocated for the=
original request length. sg_copy_from_buffer() then reads that many bytes = from the destination buffer; a backend reporting a larger length over-reads=
adjacent kernel heap into the caller's scatterlist (an out-of-bounds read)=
. Clamp the reported length to the originally requested destination length.=
A conforming device reports no more than that, so valid results are unaffe= cted.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80836" target=3D= "_blank" rel=3D"noopener">CVE-2026-80836</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= filter: nf_tables: don't queue packet path object notifications All file:li=
ne references below are against v7.2-rc4 (ac5b0e5651b1). The trace was capt= ured on 7.2.0-rc6-kasan72rc6 (075b74841bd0), where the same lines apply. nf= t_obj_notify() is exported and reached from the packet path. Its only in-tr=
ee caller is nft_quota_obj_eval() (net/netfilter/nft_quota.c:68), which not= ifies with GFP_ATOMIC while evaluating a rule for a transiting packet, hold= ing no mutex. Since commit 67cc570edaa0 ("netfilter: nf_tables: coalesce mu= ltiple notifications into one skbuff") that notification is no longer sent = immediately. __nft_obj_notify() queues it onto nft_net->notify_list via = nft_notify_enqueue() (net/netfilter/nf_tables_api.c:1211), which is a bare = list_add_tail(). notify_list has no lock of its own (include/net/netfilter/= nf_tables.h:1951), it is serialised by commit_mutex: the six other enqueue = sites all run inside a netlink transaction, and the drain in nft_commit_not= ify() (net/netfilter/nf_tables_api.c:10746) does list_del() + kfree_skb() f= rom nf_tables_commit() with commit_mutex held. Sending packets through a ch= ain that references a depleted quota object therefore races an unlocked lis= t_add_tail() against list_del() + kfree_skb() on another CPU. The WRITE_ONC= E(prev->next, new) in __list_add() then stores through an sk_buff that h=
as already been freed: BUG: KASAN: slab-use-after-free in __nft_obj_notify+= 0x2c5/0x2d0 Write of size 8 at addr ff110001047183c0 by task poc/76 CPU: 0 = UID: 1000 PID: 76 Comm: poc Tainted: G W 7.2.0-rc6-kasan72rc6 #4 Call Trace=
: <IRQ> __nft_obj_notify (include/linux/list.h:164 include/linux/list= .h:191 net/netfilter/nf_tables_api.c:1211 net/netfilter/nf_tables_api.c:874=
3) nft_quota_obj_eval (net/netfilter/nft_quota.c:68) nft_do_chain_inet nf_h= ook_slow __ip_local_out ip_push_pending_frames udp_send_skb udp_sendmsg __x= 64_sys_sendto Allocated by task 77: __alloc_skb (net/core/skbuff.c:704) __n= ft_obj_notify (include/net/netlink.h:1055 net/netfilter/nf_tables_api.c:873=
1) nft_quota_obj_eval (net/netfilter/nft_quota.c:68) nft_do_chain Freed by = task 79: nf_tables_commit (include/linux/skbuff.h:1332 net/netfilter/nf_tab= les_api.c:10759 net/netfilter/nf_tables_api.c:11185) nfnetlink_rcv_batch (n= et/netfilter/nfnetlink.c:574) netlink_unicast netlink_sendmsg The buggy add= ress belongs to the cache skbuff_head_cache of size 232 Queueing from the p= acket path is wrong even leaving the race aside: notify_list is only draine=
d by nft_commit_notify() from nf_tables_commit() (:11185), so a notificatio=
n enqueued outside a transaction is not sent until some later netlink batch=
commits, if one ever does. The gfp argument that nft_obj_notify() still ta= kes is a leftover of the pre-67cc570edaa0 behaviour, where this path called=
nfnetlink_send() directly. Restore that: split the message construction ou=
t into nft_obj_notify_alloc() and let each caller decide what to do with th=
e skb. nft_obj_notify(), the exported one reached from the packet path, sen=
ds it straight away; nf_tables_obj_notify(), which runs under commit_mutex,=
keeps queueing it, so transaction notifications are still coalesced.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80837" target=3D= "_blank" rel=3D"noopener">CVE-2026-80837</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: vxl= an: keep the last remote linked during FDB flush A non-nexthop FDB entry is=
expected to have at least one remote while it remains reachable through th=
e FDB hash table. A filtered bulk flush violates this invariant when every = remote matches: It unlinks the last remote in vxlan_fdb_dst_destroy() and o= nly afterwards tells vxlan_flush() to destroy the parent FDB entry. An RCU = reader can find the parent during this interval. first_remote_rcu() then ap= plies list_entry_rcu() to the empty list head, producing an invalid remote = pointer that the receive learning path can read from and write to. When a m= atching remote is the sole remaining remote, leave it linked and ask the ca= ller to destroy the entire FDB entry. vxlan_fdb_destroy() keeps the remote = attached while sending the deletion notification and removing the parent fr=
om the lookup structures.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80838" target=3D= "_blank" rel=3D"noopener">CVE-2026-80838</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: bat= man-adv: reject unrepresentable multicast TVLV offsets The network and tran= sport header fields in struct sk_buff are 16-bit offsets from skb->head,=
and U16_MAX is reserved as the unset transport header value. batadv_tvlv_c= all_handler() sets both fields from a received multicast TVLV without check= ing whether the TVLV end is representable. If the end offset exceeds the fi= eld's range, skb_set_transport_header() truncates it so that the transport = header precedes the network header. The negative difference is then returne=
d by skb_network_header_len() as a large u32. batadv_mcast_forw_packet() co= nsequently accepts an oversized multicast tracker and accesses memory beyon=
d the skb data. Add skb_set_transport_header_careful(), an offset-aware cou= nterpart to skb_reset_transport_header_careful(), which validates the final=
head-relative offset before assigning it. Use the new helper in batadv_tvl= v_call_handler() and reject unrepresentable TVLVs before setting the networ=
k header.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80839" target=3D= "_blank" rel=3D"noopener">CVE-2026-80839</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv=
6: seg6: clear IPv4 control block on IPIP decapsulation End.DX4 and End.DT4=
decapsulate an IPv4 packet through decap_and_validate() and send it direct=
ly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), whic=
h normally clears IPCB before IPv4 interprets skb->cb. The skb instead r= etains IP6CB data from the outer packet. IP6CB and IPCB use the same skb-&g= t;cb storage, so IP6CB(skb)->lastopt overlaps IPCB(skb)->opt.optlen a=
nd srr, while IP6CB(skb)->nhoff overlaps rr and ts. The sender can make = the stale optlen byte nonzero with a valid outer extension-header chain. Th=
e reproducers put an eight-byte Destination Options header immediately afte=
r the 40-byte IPv6 header and before the Segment Routing Header. ipv6_desto= pt_rcv() records the sender-controlled Destination Options offset in both l= astopt and nhoff, setting them to 40. On the reproduced little-endian x86-6=
4 kernel, IPv4 therefore sees optlen =3D 40 and rr =3D 40. Both tcp_v4_save= _options() and __ip_options_echo() skip option copying when optlen is zero.=
Here optlen is 40, so the TCP SYN path allocates room for 40 bytes of opti=
on data and calls __ip_options_echo(). The stale rr value makes that functi=
on read inner packet byte 41 as the Record Route option length. The reprodu= cers set that sender-controlled byte to 255, so __ip_options_echo() copies = 255 bytes into the 40-byte option-data area. Separate End.DX4 and End.DT4 r= eproducers on the unpatched v7.2-rc5 kernel both produced: BUG: KASAN: slab= -out-of-bounds in __ip_options_echo() Write of size 255 The relevant End.DX=
4 call path is: __ip_options_echo tcp_v4_route_req tcp_conn_request tcp_v4_= conn_request tcp_rcv_state_process tcp_v4_do_rcv tcp_v4_rcv ip_protocol_del= iver_rcu ip_local_deliver_finish ip_local_deliver input_action_end_dx4_fini=
sh input_action_end_dx4 The relevant End.DT4 call path is: __ip_options_ech=
o tcp_v4_route_req tcp_conn_request tcp_v4_conn_request tcp_rcv_state_proce=
ss tcp_v4_do_rcv tcp_v4_rcv ip_protocol_deliver_rcu ip_local_deliver_finish=
ip_local_deliver input_action_end_dt4 tcp_v4_save_options() is inlined int=
o the tcp_v4_route_req() path, so it does not appear as a separate frame. W= hen decap_and_validate() handles IPPROTO_IPIP, save the ingress interface f= rom IP6CB, clear IPCB, and restore the saved value. Doing this in the commo=
n decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm. Use = IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3m= dev processing, which can replace skb_iif with the L3 master; IP6CB iif sti=
ll records the receiving interface set at IPv6 ingress.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80840" target=3D= "_blank" rel=3D"noopener">CVE-2026-80840</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /packet: defer vmalloc TX_RING free until skbs finish AF_PACKET TX_RING skb=
s keep a raw pointer to their ring frame. The skb page references preserve = page-backed ring blocks after pg_vec is freed, but they do not preserve a v= malloc mapping. tpacket_destruct_skb() currently drops the pending referenc=
e before writing the timestamp and TP_STATUS_AVAILABLE to the frame. Move t=
he decrement after those stores. The smp_wmb() in __packet_set_status() ord= ers the frame stores before the decrement. Also recheck pending TX frames u= nder pg_vec_lock before non-closing ring replacement, so a racing send cann=
ot add a pending skb between the initial check and the ring swap. Ring allo= cation can produce a mixture of page-backed and vmalloc-backed blocks. Allo= cate deferred-work storage during TX ring setup when the first vmalloc-back=
ed block is encountered, and keep its pointer in the pg_vec allocation head= er. If allocation fails, return -ENOMEM from ring setup. On socket close, a=
non-NULL pointer identifies a vmalloc-backed vector without a scan. If TX = skbs remain, defer the whole vector to system_long_wq. After pg_vec is deta= ched, a late destructor can skip the pending decrement. Use socket write-me= mory accounting as the deferred lifetime gate instead: an skb remains charg=
ed through its final sock_wfree(), after all ring-frame accesses. The delay=
ed work retains a socket reference and reschedules itself until no TX skbs = remain. Move pending_refcnt release to packet_sock_destruct() so late skb d= estructors and deferred cleanup can safely use it after packet_release(). P= age-backed teardown remains synchronous, and no lock is added to the TX com= pletion hot path.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80841" target=3D= "_blank" rel=3D"noopener">CVE-2026-80841</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net=
: bridge: mcast: fix use-after-free of a master VLAN's multicast context br= _multicast_toggle_one_vlan() clears BR_VLFLAG_MCAST_ENABLED under br->mu= lticast_lock before stopping a VLAN's multicast context. That is the teardo=
wn handshake: lockless readers gate on the flag through br_multicast_ctx_sh= ould_use() -> br_multicast_ctx_vlan_disabled(), so once it is cleared un= der the lock no reader can arm the context again. For a master VLAN the han= dshake never runs. __vlan_del() clears BRIDGE_VLAN_INFO_BRENTRY before call= ing br_vlan_put_master(), so br_multicast_toggle_one_vlan(masterv, false) r= eturns early on !br_vlan_is_brentry(vlan): the flag stays set and br->mu= lticast_lock is never taken. br_vlan_put_master() then drains the context i=
n br_multicast_ctx_deinit() and frees the VLAN through call_rcu(), while a = reader still inside rcu_read_lock() sees the context as enabled and re-arms=
it. The port and port-VLAN branch of the function has no br_vlan_is_brentr= y() test and flips the flag under br->multicast_lock, so it is not affec= ted. The reader is the bridge transmit path. For a master VLAN br_multicast= _rcv() selects brmctx =3D &vlan->br_mcast_ctx with pmctx =3D NULL, s=
o IGMP sent to the bridge device re-arms the context's timers after br_mult= icast_ctx_deinit() has already stopped them. BUG: KASAN: slab-use-after-fre=
e in detach_if_pending+0x412/0x4a0 Write of size 8 at addr ffff88810ac39918=
by task brmc/601 __mod_timer+0x51a/0xc50 br_multicast_host_join+0x25b/0x39=
0 __br_multicast_add_group+0x468/0x530 br_ip4_multicast_add_group+0x1a0/0x2=
60 br_multicast_rcv+0x2cda/0x61e0 br_dev_xmit+0x6c4/0x1540 Allocated by tas=
k 610: br_vlan_add+0x111/0xb40 br_vlan_info+0x370/0x3e0 Freed by task 0: kf= ree+0x1a7/0x4f0 rcu_core+0x7dc/0x10a0 Only test br_vlan_is_brentry() when e= nabling, like the br_multicast_ctx_vlan_global_disabled() test next to it. = Disabling then always clears BR_VLFLAG_MCAST_ENABLED under br->multicast= _lock before br_multicast_ctx_deinit() drains the context.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80842" target=3D= "_blank" rel=3D"noopener">CVE-2026-80842</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: fix xfrm_state_construct() auth-trunc leak attach_auth_trunc() can alloc= ate x->aalg while leaving x->props.aalgo at zero when the selected au=
th algorithm has no sadb_alg_id. One real case is cmac(aes). xfrm_state_con= struct() then treats !x->props.aalgo as "no auth algorithm attached yet"=
and calls attach_auth(). That overwrites x->aalg and loses the first al= location. Any later failure or teardown only frees the replacement pointer.=
Check whether x->aalg is already attached instead of inferring that sta=
te from x->props.aalgo.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80843" target=3D= "_blank" rel=3D"noopener">CVE-2026-80843</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: ah6: validate routing header segments_left AH6 rearranges routing-header=
addresses before computing or verifying the ICV. ipv6_rearrange_rthdr() as= sumes that segments_left is not larger than the number of addresses describ=
ed by the routing header's hdrlen field. That assumption does not hold for = raw IPv6 HDRINCL packets. A packet with hdrlen equal to 2 describes one add= ress, but can carry an arbitrary segments_left value. With segments_left eq= ual to 255, the function moves its address pointer 4,064 bytes backwards an=
d passes a 4,064-byte length to memmove(), resulting in an out-of-bounds ac= cess. Validate the invariant locally before modifying the routing header or=
performing any address-pointer arithmetic, and propagate malformed-header = errors to the existing AH6 input and output error paths.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80844" target=3D= "_blank" rel=3D"noopener">CVE-2026-80844</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: avoid lock inversion in nat keepalive work nat_keepalive_work() walks th=
e state table while xfrm_state_walk() holds net->xfrm.xfrm_state_lock. I=
ts callback then acquires x->lock, which conflicts with the delete path = taking the same locks in reverse order via xfrm_state_delete() and __xfrm_s= tate_delete(). This creates an AB-BA deadlock that is reported by lockdep w= hen a NAT keepalive worker races with SA deletion. Fix this by splitting th=
e keepalive walk into two phases. First, collect the candidate states while=
the walk holds xfrm_state_lock and take a reference on each state. Then, a= fter the walk completes, process each collected state and acquire x->loc=
k without nesting it under xfrm_state_lock.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80845" target=3D= "_blank" rel=3D"noopener">CVE-2026-80845</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: drop ESP-in-TCP packets with no ingress device ESP-in-TCP receives recor=
ds through the TCP strparser. handle_esp() restores skb->dev from the sa= ved skb_iif before passing the packet into the XFRM input path. Queued TCP = data can be processed after the original ingress device has been removed, f=
or example during veth or net namespace teardown. In that case dev_get_by_i= ndex_rcu() returns NULL. The XFRM IPv4 and IPv6 input paths both expect skb= ->dev to be valid while building the route lookup, so queued ESP-in-TCP = data can dereference a NULL device. Drop the packet if the saved ingress de= vice can no longer be resolved. Such a packet can no longer be routed throu=
gh the normal XFRM receive path, and this preserves the existing behaviour = for packets whose ingress device still exists.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80846" target=3D= "_blank" rel=3D"noopener">CVE-2026-80846</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: tcp=
: clamp route advmss to TCP_MIN_MSS tcp_select_initial_window() assumes tha=
t callers never pass an MSS smaller than 1, but route-derived advmss values=
can violate that assumption. A too-small explicit RTAX_ADVMSS is one way t=
o get there, but it is not the only one. The same divide-by-zero can also b=
e reached through the "default advmss" path when RTAX_ADVMSS is left at 0 a=
nd the effective advmss is later driven down by route MTU and min_adv_mss. = Introduce a tcp_dst_advmss() helper that clamps route advmss to TCP_MIN_MSS=
before TCP consumes it, and use it in the TCP paths that derive advmss fro=
m dst metrics. This keeps the effective MSS from dropping to zero before tc= p_select_initial_window() rounds the receive window.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80847" target=3D= "_blank" rel=3D"noopener">CVE-2026-80847</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: xfr=
m: espintcp: fix UAF during close ZDI reported and analyzed a race conditio=
n during close for espintcp sockets: espintcp_close() frees emsg->skb vi=
a kfree_skb() without holding any socket lock. Concurrently, the xfrm_trans= _reinject work queue invokes esp_output_tcp_finish() -> espintcp_push_sk= b() -> espintcp_push_msgs() -> skb_send_sock_locked(), which reads th=
e same skb as a data source. Fix this by adding a synchronize_rcu() call af= ter resetting sk_prot, since esp_output_tcp_finish() runs under RCU and won=
't use a socket with sk_prot =3D=3D &tcp_prot. Simply taking the socket=
lock in espintcp_close() could lead to leaks, if esp_output_tcp_finish() r= e-adds an skb in the slot we just freed. After this, the existing barrier()=
is no longer needed.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80848" target=3D= "_blank" rel=3D"noopener">CVE-2026-80848</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /tcp-ao: fix use-after-free of current_key on reconnect to another peer tcp= _inbound_ao_hash() is called before bh_lock_sock_nested() is taken, with on=
ly rcu_read_lock() held. On the fast path for established sockets, if the r= next_keyid sent by the peer differs from current_key->sndid, the key the=
peer asked for is looked up and stored in current_key. The lookup is insid=
e the RCU read side, but current_key outlives it. When the socket is discon= nected and connect() is called again for another peer, tcp_ao_connect_init(=
) unlinks every key that does not match the new peer and frees it with call= _rcu(). If current_key points at such a key, it is cleared to NULL. The fas=
t path reads sk_state only once on entry, so a softirq that got into it whi=
le the socket was still established can update current_key after that loop = has already run. The update is inside the RCU read side, so it comes before=
the call_rcu() callback, and once the callback frees the key, current_key =
is left pointing at freed memory. The next transmission picks that pointer =
up in tcp_get_current_key(). tcp_ao_transmit_skb() then reads the traffic k=
ey from the freed object, which is the use-after-free. Wait for one grace p= eriod before unlinking, and only if a key is going to be removed. By the ti=
me tcp_connect() runs the socket is already in TCP_SYN_SENT, and TCP_AO_EST= ABLISHED does not contain TCPF_SYN_SENT, so a softirq entering after the wa=
it cannot reach the fast path, and the ones already in it have finished. Th=
e existing NULL handling in the loop is then enough.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80849" target=3D= "_blank" rel=3D"noopener">CVE-2026-80849</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: tcp=
: fix AO info use-after-free in tcp_ao_connect_init() tcp_v4_connect() adds=
a SYN-SENT socket to the ehash before calling tcp_connect(). If TCP-AO is = configured, tcp_connect() first verifies that a key matches the peer and th=
e bound device's current L3 master. tcp_ao_connect_init() later resolves th=
e L3 master again and removes keys which do not match it. The socket lock d= oes not stabilize the bound device's VRF membership. Detaching the device f= rom its VRF between the initial validation and the L3-master calculation in=
tcp_ao_connect_init() can therefore make the validation succeed while init= ialization observes the default L3 domain and removes the only key. The sub= sequent AO lookup then fails, so the no-key path clears tp->ao_info and = frees it directly. The receive path can find the socket in the ehash and lo=
ad tp->ao_info under RCU before acquiring the socket lock. A reader whic=
h loaded the old pointer can thus continue into tcp_inbound_ao_hash() after=
the direct free. The issue was found during a static audit of TCP-AO objec=
t lifetime. An unprivileged reproducer in self-created user and network nam= espaces raced connect() with detaching a veth from its VRF while sending TC= P-AO segments. It triggered the same KASAN report on two fresh boots: BUG: = KASAN: slab-use-after-free in tcp_inbound_ao_hash+0x585/0x19f0 Write of siz=
e 8 at addr ffff88800bf88128 by task tcp_ao_vrf_race/232 Call Trace: tcp_in= bound_ao_hash+0x585/0x19f0 tcp_inbound_hash+0x677/0xa80 tcp_v4_rcv+0x1c3e/0= x3ab0 Allocated by task 235: tcp_ao_alloc_info+0x43/0xf0 tcp_ao_add_cmd+0xd= f7/0x13b0 do_tcp_setsockopt+0x168c/0x2640 Freed by task 235: kfree+0x1b8/0x= 550 tcp_connect+0x252/0x4f00 tcp_v4_connect+0x1114/0x1720 The bad address i=
s 40 bytes inside the freed 128-byte object, matching the tcp_ao_info count= ers.key_not_found field. The two runs used 1000 attempts each, reached the = no-key path 366 and 411 times, and produced one and two KASAN reports respe= ctively. With this change, the same reproducer reached the no-key path 366 = times in 1000 attempts without a KASAN report or oops. Use tcp_ao_destroy_s= ock() for the no-key path. It unpublishes the AO info, updates the socket m= emory and static-key accounting, and defers the free until after an RCU gra=
ce period. Also drop the WARN_ON_ONCE() and its stale comment. The VRF deta=
ch race makes the no-key state reachable during normal operation, so it is =
a handled condition rather than an impossible assertion. On panic_on_warn k= ernels the WARN would turn this handled race into a kernel panic.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80850" target=3D= "_blank" rel=3D"noopener">CVE-2026-80850</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: gtp=
: serialize PDP context updates PDP contexts can be deleted through GTP_CMD= _DELPDP or while the GTP network device is being unregistered. The latter i=
s serialized by RTNL, but the generic-netlink delete path only holds RCU. R= unning both paths concurrently can therefore make both paths delete the sam=
e PDP context. The issue was found through static analysis and reproduced o=
n a KASAN-enabled kernel by a simple two-thread program racing GTP_CMD_DELP=
DP against RTM_DELLINK: Oops: general protection fault, probably for non-ca= nonical address KASAN: maybe wild-memory-access in range [0xdead00000000012= 0-0xdead000000000127] RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp] RBP: dead0000= 00000122 The second deletion dereferenced the poisoned hlist pprev pointer.=
Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a shar=
ed mutex. Keep the mutex held until the final use of a PDP context in the N= EWPDP path, and keep the RCU read-side section around the complete PDP cont= ext use in the DELPDP path.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80851" target=3D= "_blank" rel=3D"noopener">CVE-2026-80851</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: tls=
: device: fix out-of-bounds write in tls_append_frag() Found with syzkaller=
and a local syzbot instance running on top of a netdevsim TLS offload emul= ation; tls_device.c is otherwise only reachable on a machine with a NIC tha=
t implements the offload. tls_push_data() only checks whether the open reco=
rd still has room for another frag at the bottom of its loop, and the MSG_M= ORE early break skips that check. The record survives to the next syscall w= ith the frag count it already had, and tls_append_frag() does not check eit= her, so with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or tw=
o adds a non-coalescing pipe page and num_frags walks off the end of tls_re= cord_info.frags[MAX_SKB_FRAGS]. Once the record is pushed, tls_push_record(=
) runs the same index over sg_tx_data[MAX_SKB_FRAGS] and the sg_set_page() = writes land on the destruct_work that follows it, which the workqueue then = calls. The byte limit is fine because copy drops to 0 and the loop falls th= rough to the same check; the frag count has no such feedback. Push the reco=
rd rather than keep a full one open, which is what a plain TCP socket does =
- tcp_sendmsg_locked() uses tcp_mark_push() and new_segment in both the cop=
y and the MSG_SPLICE_PAGES paths, and tls_sw already sets full_record when = the sk_msg ring fills up, MSG_MORE or not. BUG: KASAN: slab-out-of-bounds i=
n tls_append_frag ( net/tls/tls_device.c:269) Write of size 8 at addr ffff8= 881104d1530 by task tls_oob/450 CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not ta= inted 7.2.0-rc7+ #329 PREEMPT Call Trace: <TASK> dump_stack_lvl (lib/= dump_stack.c:94 lib/dump_stack.c:120) print_report (mm/kasan/report.c:378 m= m/kasan/report.c:482) kasan_report (mm/kasan/report.c:595) tls_append_frag = (net/tls/tls_device.c:269) tls_push_data (net/tls/tls_device.c:518) tls_dev= ice_sendmsg (net/tls/tls_device.c:583) inet_sendmsg (net/ipv4/af_inet.c:865=
) sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813) splice_= to_socket (fs/splice.c:884) do_splice (fs/splice.c:936 fs/splice.c:1349) __= do_splice (fs/splice.c:1431) __x64_sys_splice (fs/splice.c:1634 fs/splice.c= :1616) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall= _64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) &l= t;/TASK> and, once the record is pushed: UBSAN: array-index-out-of-bound=
s in net/tls/tls_device.c:300:24 index 18 is out of range for type 'skb_fra= g_t [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41 i= ndex 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-= of-bounds in net/tls/tls_device.c:302:39 index 18 is out of range for type = 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_device.c= :307:38 index 26 is out of range for type 'scatterlist [17]' kernel tried t=
o execute NX-protected page - exploit attempt? (uid: 0) BUG: unable to hand=
le page fault for address: ffffea000411a680 #PF: supervisor instruction fet=
ch in kernel mode #PF: error_code(0x0011) - permissions violation Oops: Oop=
s: 0011 [#1] SMP KASAN PTI Workqueue: ktls_device_destruct 0xffffea000411a6=
80 RIP: 0010:0xffffea000411a680 Call Trace: <TASK> worker_thread (ker= nel/workqueue.c:3405 kernel/workqueue.c:3486) kthread (kernel/kthread.c:436=
) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86= /entry/entry_64.S:245) </TASK></td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80852" target=3D= "_blank" rel=3D"noopener">CVE-2026-80852</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM=
: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts When {= de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled host via =
a temporary buffer, allocate a full 4KiB page for the buffer to ensure the = page containing the buffer is wholly owned by KVM, i.e. won't be concurrent=
ly allocated and accessed by other kernel code while KVM is using the buffe=
r to {de,en}crypt memory. On SNP-enabled platforms, when sending SEV/SEV-ES=
commands that trigger firmware writes to memory, the to-be-written page(s)=
must be (temporarily) assigned to Firmware (as required by the SNP archite= cture, to guard against using such commands as gadgets to attack SNP guests=
). See snp_map_cmd_buf_desc() and friends. Unfortunately, transferring owne= rship of a page to Firmware makes the page inaccessible to software, and th=
us writes generate RMP #PF violations. If KVM uses a sub-page allocation fo=
r its temporary buffer, some other actor in the kernel can allocate and use=
the other portions of the page, and thus trigger unexpected (and seemingly=
spurious) RMP #PF violations due to software attempting to access a Firmwa= re-owned page. BUG: unable to handle page fault for address: ffff906ae30f03=
00 #PF: supervisor write access in kernel mode #PF: error_code(0x80000003) =
- RMP violation PGD 6b1b80d067 P4D 6b1b80d067 PUD 100231e2063 PMD 10055a880=
63 PTE 80000100630f0163 SEV-SNP: PFN 0x100630f0 unassigned, dumping non-zer=
o entries in 2M PFN region: [0x10063000 - 0x10063200] Oops: Oops: 0003 [#1]=
SMP CPU: 70 UID: 0 PID: 10658 Comm: svw_WaiterThrea Tainted: G U W O 7.1.0= -smp--c22293789940-seanjc-next #1 PREEMPTLAZY Tainted: [U]=3DUSER, [W]=3DWA= RN, [O]=3DOOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_8=
0, BIOS 34.86.0-102 01/25/2026 RIP: 0010:memset+0xf/0x20 Call Trace: <TA= SK> __kvmalloc_node_noprof+0x2a4/0x710 do_getxattr+0x4e/0x130 path_getxa= ttrat+0x125/0x1b0 do_syscall_64+0x10a/0x480 entry_SYSCALL_64_after_hwframe+= 0x4b/0x53 RIP: 0033:0x7f3a22cb6daa </TASK> Modules linked in: kvm_amd=
kvm irqbypass vfat fat ccp k10temp sha3 libsha3 i2c_piix4 gq(O) cdc_acm xh= ci_pci xhci_hcd gsmi: Log Shutdown Reason 0x03 CR2: ffff906ae30f0300 ---[ e=
nd trace 0000000000000000 ]--- RIP: 0010:memset+0xf/0x20 Kernel panic - not=
syncing: Fatal exception Kernel Offset: 0x39e00000 from 0xffffffff81000000=
(relocation range: 0xffffffff80000000-0xffffffffbfffffff) gsmi: Log Shutdo=
wn Reason 0x02</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80853" target=3D= "_blank" rel=3D"noopener">CVE-2026-80853</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb=
: gadget: f_tcm: keep port count until LUN teardown completes tcm_usbg_drop= _nexus() permits session removal once tpg_port_count reaches zero. However,=
usbg_port_unlink() currently decrements that count from the fabric_pre_unl= ink() callback, before core_dev_del_lun() waits for active se_lun reference=
s to drain. If removal of the last LUN races a nexus removal, the latter ca=
n observe a zero port count and call target_remove_session(). This frees se= ss_cmd_map while an in-flight struct usbg_cmd, including its work item, can=
still be accessed. Overlapping the last-LUN unlink with nexus removal repr= oduces this lifetime violation as a DEBUG_OBJECTS "free active" warning for=
usbg_cmd_work, followed by a target-core BUG/Oops. The generic target-core=
unlink path has no callback after core_dev_del_lun() completes. Add an opt= ional fabric_post_unlink() callback and use it for the f_tcm port count. Th=
e count now remains nonzero until core_dev_del_lun() has finished draining = active LUN references, preventing nexus removal from freeing the session du= ring command completion.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80854" target=3D= "_blank" rel=3D"noopener">CVE-2026-80854</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: fix invalidate lock leak on open O_TRUNC DAX failure fuse_open() takes f= ilemap_invalidate_lock() for a DAX truncate (dax_truncate =3D true) and rel= eases it before the out_inode_unlock label. But when fuse_dax_break_layouts=
() fails, the goto out_inode_unlock skips the unlock and leaks the rwsem, s=
o any later fault or truncate on the file stalls on the stale lock. fuse_da= x_break_layouts() can fail with -ERESTARTSYS when a signal interrupts the w= ait for busy DAX pages to drain: open("file", O_RDWR | O_TRUNC) =C3=A2=E2= =80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC fuse_open() =C3=A2=E2=80=9D=C5=93= =C3=A2=E2=80=9D=E2=82=AC filemap_invalidate_lock() # dax_truncate =C3=A2=E2= =80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC fuse_dax_break_layouts() =C3=A2=E2= =80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC dax_break_layout() =C3=A2=E2=80=9D= =E2=80=9D=C3=A2=E2=80=9D=E2=82=AC wait_page_idle() # TASK_INTERRUPTIBLE =C3= =A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC fuse_wait_dax_page() # unlock=
, schedule, re-lock =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC signal=
=C3=A2=E2=80=A0=E2=80=99 -ERESTARTSYS goto out_inode_unlock # <- lock l= eaked Fix this by moving filemap_invalidate_unlock() below the label so tha=
t all error paths release the lock, and rename the label to out_unlock as i=
t now covers more than just the inode lock.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80855" target=3D= "_blank" rel=3D"noopener">CVE-2026-80855</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: fix invalidate lock leak on setattr writeback failure fuse_do_setattr() = takes filemap_invalidate_lock() for a DAX truncate (fault_blocked =3D true)=
and releases it at the out:/error: labels. But when a writeback flush is a= lso needed, a write_inode_now() failure returns directly and leaks the lock=
, so any later fault or truncate on the file stalls on the stale rwsem. For=
example, truncate(2) on a setuid file reaches fuse_do_setattr() with both = ATTR_SIZE and ATTR_MODE set: truncate(2) =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2= =80=9D=E2=82=AC do_truncate() =C3=A2=E2=80=9D=C5=93=C3=A2=E2=80=9D=E2=82=AC=
dentry_needs_remove_privs() # S_ISUID =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80= =9D=E2=82=AC notify_change() # KILL_SUID -> ATTR_MODE =C3=A2=E2=80=9D=E2= =80=9D=C3=A2=E2=80=9D=E2=82=AC fuse_setattr() # no killpriv: =C3=A2=E2=80= =9D=E2=80=9A # ia_valid |=3D ATTR_MODE =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80= =9D=E2=82=AC fuse_do_setattr() =C3=A2=E2=80=9D=C5=93=C3=A2=E2=80=9D=E2=82=
=AC filemap_invalidate_lock() # IS_DAX && is_truncate =C3=A2=E2=80= =9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC write_inode_now() # is_wb && A= TTR_MODE =C3=A2=E2=80=9D=E2=80=9D=C3=A2=E2=80=9D=E2=82=AC if (err) # e.g. d= aemon -> -EIO return err # <- lock leaked Fix this by adding an unloc=
k label that releases the lock before returning the error, and use it for t=
he fuse_dax_break_layouts() failure path as well.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80856" target=3D= "_blank" rel=3D"noopener">CVE-2026-80856</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: wait for FR_FINISHED on abort_on_kill to prevent use-after-free The abor= t_on_kill path in request_wait_answer() calls fuse_abort_conn() and returns=
without waiting for FR_FINISHED. If fuse_dev_do_write() is concurrently pr= ocessing the same request (FR_LOCKED set), the caller frees req->args wh= ile it is still being accessed, causing a use-after-free. Fix this by jumpi=
ng to the existing wait_event(FR_FINISHED) instead of returning early. The = wait will not hang because fuse_abort_conn() ensures all requests are ended= .</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80857" target=3D= "_blank" rel=3D"noopener">CVE-2026-80857</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: publish io-uring queues with release semantics fuse_uring_create_queue()=
initializes a fuse_ring_queue and then publishes the pointer into ring->= ;queues[qid] with WRITE_ONCE() under the fch->lock. There are several re= aders that may concurrently be fetching that pointer locklessly and then de= ferencing it. WRITE_ONCE() doesn't ensure ordering of the queue's field ini= tialization before the ring->queues[qid] pointer assignment. The queue m= ust be published with smp_store_release() so the field initialization is gu= aranteed to happen before. Readers in paths where the read may happen concu= rrently with the store need to use READ_ONCE() because any race involving a=
plain access is undefined.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80858" target=3D= "_blank" rel=3D"noopener">CVE-2026-80858</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: fix missing barrier when checking io-uring readiness fuse_block_alloc() = reads fch->initialized and then fch->io_uring. fch->io_uring is se=
t before fch->initialized, ordered by the smp_wmb() in fuse_chan_set_int= ialized(), but fuse_block_alloc() has no matching read barrier between the = two loads. This may lead a CPU to observe fch->initialized=3D1 but fch-&= gt;io_uring=3D0, and skip the check that blocks request allocation until th=
e io-uring queues are ready. This can reintroduce the lock-order inversion = deadlock that commit 3393ff964e0f prevents. Add an smp_rmb() barrier to pai=
r with the smp_wmb() in fuse_chan_set_initialized() to prevent this.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80859" target=3D= "_blank" rel=3D"noopener">CVE-2026-80859</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: fus=
e: fix race between interrupt and resend After commit f8fce75fedf7 ("fuse: = clear intr_entry in fuse_resend and fuse_remove_pending_req") the WARN_ON(!= list_empty(&req->intr_entry)) in fuse_request_free() still triggers = due to the following race: In request_wait_answer() if (test_bit(FR_SENT, &= amp;req->flags)) -> returns true In fuse_chan_resend() clear_bit(FR_S= ENT, &req->flags) In request_wait_answer() queue_interrupt(req) Fix = by: - move clearing FR_SENT inside fpq->lock - move setting FR_PENDING i= nside fiq->lock - recheck FR_SENT after acquiring fiq->lock in fuse_d= ev_queue_interrupt()</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80860" target=3D= "_blank" rel=3D"noopener">CVE-2026-80860</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb=
: xhci: bail out of setup if the controller is inaccessible xhci_gen_setup(=
) locates the operational registers using the capability length read from t=
he very first register: xhci->op_regs =3D hcd->regs + HC_LENGTH(readl= (&xhci->cap_regs->hc_capbase)); If the controller is dead or has = dropped off the bus, that read returns ~0, HC_LENGTH() truncates it to 0xff=
, and op_regs ends up 0xff bytes past the page-aligned MMIO base, i.e. unal= igned. The first access through it, xhci_halt() -> xhci_handshake() read= ing op_regs->status, is then an unaligned readl() on device memory. arm6=
4 faults on unaligned device accesses, so instead of xhci_handshake() catch= ing the all-ones value and returning -ENODEV, setup oopses: xhci-pci-renesa=
s 0005:08:00.0: Unable to change power state from D3cold to D0, device inac= cessible xhci-pci-renesas 0005:08:00.0: xHCI Host Controller xhci-pci-renes=
as 0005:08:00.0: new USB bus registered, assigned bus number 1 Unable to ha= ndle kernel paging request at virtual address ffff80030a770103 ESR =3D 0x00= 00000096000021 FSC =3D 0x21: alignment fault Internal error: Oops: 00000000= 96000021 [#1] SMP pc : xhci_halt [xhci_hcd] Call trace: xhci_halt xhci_gen_= setup xhci_pci_setup usb_add_hcd usb_hcd_pci_probe xhci_pci_common_probe xh= ci_pci_renesas_probe This was hit with a Renesas uPD720201 that failed to p= ower up ("Unable to change power state from D3cold to D0, device inaccessib= le") yet still reached the HCD probe path. Read the capability register onc=
e, and if it reads back the all-ones value (as xhci_handshake() and xhci_re= set() already test for), abort setup with -ENODEV before op_regs is derived=
from it. Reading it once also avoids re-reading a register that may change=
under a concurrent hot-removal.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80861" target=3D= "_blank" rel=3D"noopener">CVE-2026-80861</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvm= e-tcp: fix usage of page_frag_cache nvme uses page_frag_cache to preallocat=
e PDU for each preallocated request of block device. Block devices are crea= ted in parallel threads, consequently page_frag_cache is used in not thread= -safe manner. That leads to incorrect refcounting of backstore pages and pr= emature free. That can be catched by !sendpage_ok inside network stack: WAR= NING: CPU: 7 PID: 467 at ../net/core/skbuff.c:6931 skb_splice_from_iter+0xf= a/0x310. tcp_sendmsg_locked+0x782/0xce0 tcp_sendmsg+0x27/0x40 sock_sendmsg+= 0x8b/0xa0 nvme_tcp_try_send_cmd_pdu+0x149/0x2a0 Then random panic may occur=
. Fix that by serializing the usage of page_frag_cache.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80862" target=3D= "_blank" rel=3D"noopener">CVE-2026-80862</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: RDM= A/rxe: Fix OOB in free_rd_atomic_resources() free_rd_atomic_resources() ite= rates using qp->attr.max_dest_rd_atomic. Updating max_dest_rd_atomic bef= ore freeing the old array can make the free path walk past the old allocati=
on and trigger a slab out-of-bounds write catched by KASAN: =3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D BUG: KASAN: slab-out-of-bounds in free_rd= _atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline] BUG: KASAN=
: slab-out-of-bounds in free_rd_atomic_resources drivers/infiniband/sw/rxe/= rxe_qp.c:171 [inline] BUG: KASAN: slab-out-of-bounds in free_rd_atomic_reso= urces drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline] BUG: KASAN: slab-out-= of-bounds in rxe_qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_q= p.c:712 Write of size 4 at addr ffff88802b8dddb8 by task syz.3.451/11063 CP=
U: 0 UID: 0 PID: 11063 Comm: syz.3.451 Not tainted 7.1.0 #2 PREEMPT(full) H= ardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996),=
BIOS 1.16.3-debian-1.16.3-2 04/01/2014 Call Trace: <TASK> __dump_sta=
ck lib/dump_stack.c:94 [inline] dump_stack_lvl+0x10e/0x1f0 lib/dump_stack.c= :120 print_address_description mm/kasan/report.c:378 [inline] print_report+= 0xf7/0x600 mm/kasan/report.c:482 kasan_report+0xe4/0x120 mm/kasan/report.c:= 595 free_rd_atomic_resource drivers/infiniband/sw/rxe/rxe_qp.c:180 [inline]=
free_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:171 [inline] f= ree_rd_atomic_resources drivers/infiniband/sw/rxe/rxe_qp.c:163 [inline] rxe= _qp_from_attr+0x1e88/0x2150 drivers/infiniband/sw/rxe/rxe_qp.c:712 rxe_modi= fy_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_verbs.c:623 ib_security_mod= ify_qp+0x223/0xfa0 drivers/infiniband/core/security.c:625 _ib_modify_qp+0x3= 33/0xec0 drivers/infiniband/core/verbs.c:1915 modify_qp+0x13ca/0x1940 drive= rs/infiniband/core/uverbs_cmd.c:1932 ib_uverbs_modify_qp+0xcb/0x120 drivers= /infiniband/core/uverbs_cmd.c:1958 ib_uverbs_write+0xb86/0x1030 drivers/inf= iniband/core/uverbs_main.c:680 vfs_write+0x2aa/0x1070 fs/read_write.c:686 k= sys_write+0x1f8/0x250 fs/read_write.c:740 do_syscall_x64 arch/x86/entry/sys= call_64.c:63 [inline] do_syscall_64+0x116/0x800 arch/x86/entry/syscall_64.c= :94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7fefc75a70cd Code:=
ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89=
d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff =
ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fefc84950=
18 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 0= 0007fefc7835fa0 RCX: 00007fefc75a70cd RDX: 0000000000000078 RSI: 0000200000= 000240 RDI: 0000000000000007 RBP: 00007fefc764f10f R08: 0000000000000000 R0=
9: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 000000= 0000000000 R13: 00007fefc7836038 R14: 00007fefc7835fa0 R15: 00007ffcf0586aa=
0 </TASK> Allocated by task 11063: kasan_save_stack+0x33/0x60 mm/kasa= n/common.c:57 kasan_save_track+0x14/0x30 mm/kasan/common.c:78 poison_kmallo= c_redzone mm/kasan/common.c:398 [inline] __kasan_kmalloc+0xaa/0xb0 mm/kasan= /common.c:415 kasan_kmalloc include/linux/kasan.h:263 [inline] __do_kmalloc= _node mm/slub.c:5296 [inline] __kmalloc_noprof+0x32a/0x850 mm/slub.c:5308 k= malloc_noprof include/linux/slab.h:954 [inline] kzalloc_noprof include/linu= x/slab.h:1188 [inline] alloc_rd_atomic_resources drivers/infiniband/sw/rxe/= rxe_qp.c:155 [inline] rxe_qp_from_attr+0x3f8/0x2150 drivers/infiniband/sw/r= xe/rxe_qp.c:714 rxe_modify_qp+0x1e2/0x530 drivers/infiniband/sw/rxe/rxe_ver= bs.c:623 ib_security_modify_qp+0x223/0xfa0 drivers/infiniband/core/security= .c:625 _ib_modify_qp+0x333/0xec0 drivers/infiniband/core/verbs.c:1915 modif= y_qp+0x13ca/0x1940 drivers/infiniband/core/uverbs_cmd.c:1932 ib_uverbs_modi= fy_qp+0xcb/0x120 drivers/infiniband/core/uverbs_cmd.c:1958 ib_uverbs_write+= 0xb86/0x1030 drivers/infiniband/core/uverbs_ma ---truncated---</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80863" target=3D= "_blank" rel=3D"noopener">CVE-2026-80863</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: RDM= A/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp rxe_qp_from_= attr() handles IB_QP_MAX_DEST_RD_ATOMIC outside the IB_QP_STATE path, so it=
holds no state_lock and runs while the responder task rxe_receiver() (recv= _task on rxe_wq) is live. A modify_qp() setting only that attribute calls f= ree_rd_atomic_resources() then alloc_rd_atomic_resources(), swapping qp->= ;resp.resources[] while rxe_prepare_res()/find_resource() walk it; free_rd_= atomic_resources() also leaves the cached pointer qp->resp.res dangling.=
A local unprivileged user can race the free/realloc into a use-after-free =
in rxe_receiver() (local DoS). Drain recv_task around the swap with rxe_dis= able_task()/rxe_enable_task(), as rxe_qp_reset() already does when tearing = this array down, re-enabling only after alloc_rd_atomic_resources() succeed=
s so the responder never resumes against a NULL qp->resp.resources on th=
e ENOMEM path. Also clear qp->resp.res in free_rd_atomic_resources(), li=
ke the rxe_resp.c completion paths. Reproduced under KASAN; the slab-use-af= ter-free in rxe_receiver() is gone.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80864" target=3D= "_blank" rel=3D"noopener">CVE-2026-80864</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf=
: Add missing access_ok call to copy_user_syms As reported by sashiko we us=
e __get_user without prior access_ok call on the user space pointer. Adding=
the missing call for the whole pointer array. Plus removing the err check =
in the error path, because it's not needed and also we can return -ENOMEM d= irectly from the first kvmalloc_array fail path. [1]
https://lore.kernel.or= g/bpf/
20260611115503.AC16D1F00893@smtp.kernel.org/</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80865" target=3D= "_blank" rel=3D"noopener">CVE-2026-80865</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: tip=
c: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wa=
it loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to = complete: while (atomic_read(&tn->wq_count)) cond_resched(); This lo=
op can busy-wait for a long time if cond_resched() is a NOP. This typically=
happens if the netns exit is executed by a high priority task, or under ke= rnels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, i=
t wastes CPU cycles and can lead to soft lockups. Fix this by replacing the=
busy loop with wait_var_event(), allowing the thread to sleep properly unt=
il the work queue count reaches zero. Accordingly, update cleanup_bearer() =
to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when t=
he count drops to zero. This uses the global wait queue hash table, avoidin=
g the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_de= c_and_test() provides the necessary memory barrier to ensure the wakeup is = not missed.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80866" target=3D= "_blank" rel=3D"noopener">CVE-2026-80866</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: alp= ha/PCI: Add security_locked_down() check to pci_mmap_resource() Currently, = Alpha's pci_mmap_resource() does not check security_locked_down(LOCKDOWN_PC= I_ACCESS) before allowing userspace to mmap PCI BARs. The generic version h=
as had this check since commit eb627e17727e ("PCI: Lock down BAR access whe=
n the kernel is locked down") to prevent DMA attacks when the kernel is loc= ked down. Add the same check to Alpha's pci_mmap_resource().</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80867" target=3D= "_blank" rel=3D"noopener">CVE-2026-80867</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ntf= s3: Allocate iomap inline_data using alloc_page This fixes a BUG reported i=
n iomap_write_end_inline: iomap_inline_data_valid checks that the inline_da=
ta fits within a page. If the inline_data is allocated with kmemdup there's=
no guarantee that it's page-aligned, so the check sometimes fails. Allocat=
e it with alloc_page to ensure it's page-aligned.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80868" target=3D= "_blank" rel=3D"noopener">CVE-2026-80868</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ntf=
s: bound the attribute-list entry in ntfs_read_inode_mount() The $MFT attri= bute-list walk in ntfs_read_inode_mount() validates each entry only with "(=
u8 *)al_entry + 6 > al_end" and "(u8 *)al_entry + le16_to_cpu(al_entry-&= gt;length) > al_end", but then reads al_entry->lowest_vcn (an __le64 =
at offset 8) and al_entry->mft_reference (offset 16) -- fields beyond th=
e 6 bytes proven in range. al_entry->length is attacker-controlled and o= nly required non-zero, so a short entry (e.g. length 8) placed at the tail = passes both checks while the lowest_vcn / mft_reference reads fall past al_= end. al_end is ni->attr_list + attr_list_size (the on-disk size); the bu= ffer is kvzalloc(round_up(attr_list_size, SECTOR_SIZE)), so the sector roun= ding usually absorbs the over-read -- but when attr_list_size is a multiple=
of SECTOR_SIZE there is no slack and a crafted $MFT attribute list produce=
s an out-of-bounds read at mount time. Validate the entry with ntfs_attr_li= st_entry_is_valid() (added in patch 1/3) before dereferencing it, matching = the bound the other attribute-list walks now use. The validator already req= uires the length to cover the fixed header, which makes the separate "!al_e= ntry->length" check redundant, so drop it too.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80869" target=3D= "_blank" rel=3D"noopener">CVE-2026-80869</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /amdkfd: Validate CRIU-restored IDs before idr_alloc The KFD CRIU restore f= low restores previously saved object IDs from userspace. For event restore:=
kfd_criu_restore_event() -> create_signal_event() / create_other_event(=
) -> allocate_event_notification_slot() -> idr_alloc(..., *restore_id=
, *restore_id + 1, ...) For BO restore: criu_restore_memory_of_gpu() -> = idr_alloc(..., bo_priv->idr_handle, ...) In both cases, the restored ID = comes from userspace-provided CRIU data. idr_alloc() expects the ID range v= alues to fit within signed int limits. If a restored ID is larger than INT_= MAX, it can trigger a WARN in the IDR layer. A kernel WARN is undesirable b= ecause it prints a warning trace and may cause a panic or reboot on systems=
with panic_on_warn enabled. Smatch reported these paths as allowing unchec= ked userspace values to reach idr_alloc(). Add INT_MAX validation before us= ing restored IDs in: - kfd_criu_restore_event() - criu_restore_memory_of_gp= u() If the restored ID is invalid, return -EINVAL. This prevents invalid re= store data from reaching the IDR layer and avoids WARN-triggering paths, wh= ile keeping valid restore behavior unchanged.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80870" target=3D= "_blank" rel=3D"noopener">CVE-2026-80870</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: xilinx-trng - Remove crypto_rng interface Implementing the crypto_rng = interface has no purpose, as it isn't used in practice. It's being removed = from other drivers too. Just remove it. This leaves hwrng, which is actuall=
y used. Tagging with 'Cc stable' due to the bugs that this removes: - xtrng= _trng_generate() sometimes returned success even when it didn't fill in all=
the bytes. - It was possible for xtrng_trng_generate() and xtrng_hwrng_trn= g_read() to run concurrently and interfere with each other, as the locking = code in xtrng_hwrng_trng_read() was broken.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80871" target=3D= "_blank" rel=3D"noopener">CVE-2026-80871</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALS=
A: hda/tas2781: Cancel async firmware request at unbind TAS2781 HDA I2C and=
SPI queue RCA firmware loading from component bind with request_firmware_n= owait(). The firmware loader keeps the callback module pinned and holds a d= evice reference, but the callback still uses driver-private HDA state. Comp= onent unbind removes controls and DSP state immediately. Later device remov=
al tears down the TAS2781 private data, including codec_lock. If the async = firmware callback runs after unbind has started, it can operate on state th=
at is being torn down. Cancel or synchronize the async firmware request bef= ore removing controls and DSP state. A queued callback is cancelled, and an=
already-running callback is allowed to finish before unbind continues.</td=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80872" target=3D= "_blank" rel=3D"noopener">CVE-2026-80872</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM=
: arm64: nv: Write ESR_EL2 for injected nested SError exceptions kvm_inject= _el2_exception() writes ESR_EL2 for synchronous exceptions but not for SErr= or. enter_exception64() does not write ESR_ELx for any exception type, so t=
he constructed syndrome is dropped. A guest L2 hypervisor taking a nested S= Error observes stale ESR_EL2. This affects both kvm_inject_nested_serror() = and the EASE path in kvm_inject_nested_sea(). Write ESR_EL2 for except_type= _serror, matching except_type_sync.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80873" target=3D= "_blank" rel=3D"noopener">CVE-2026-80873</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: arm= 64: dts: renesas: ironhide: Describe inline ECC carveouts The DBSC5 DRAM co= ntroller protects DRAM content using inline ECC. The inline ECC utilizes ar= eas of DRAM for its operation, which are in the DRAM address range, but mus=
t not be accessed or modified. Describe the inline ECC carveout areas used =
by the DBSC5 controller on this hardware as reserved-memory, which must not=
be accessed. Include DRAM areas which are unprotected by ECC as well, thos=
e are parts of the DRAM which directly precede the ECC carveout. In case of=
high DRAM utilization, unless the inline ECC carveouts are properly reserv= ed, Linux may use and corrupt the memory used by the DBSC5 DRAM controller = for inline ECC, which would lead to the system becoming unstable.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80874" target=3D= "_blank" rel=3D"noopener">CVE-2026-80874</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv=
s: use parsed transport offset in TCP state lookup TCP state handling repar= ses the skb to find the TCP header. For IPv6 it uses sizeof(struct ipv6hdr)=
, while the surrounding IPVS code already parsed the packet with ip_vs_fill= _iph_skb() and has the real transport-header offset in iph.len. This makes = TCP state handling look at the wrong bytes when an IPv6 packet carries exte= nsion headers. Use the parsed transport offset passed down from ip_vs_set_s= tate() when reading the TCP header. For IPv4 and for IPv6 packets without e= xtension headers, the passed offset matches the previous value.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80875" target=3D= "_blank" rel=3D"noopener">CVE-2026-80875</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: rin= g-buffer: Fix event length with forced 8-byte alignment When RB_FORCE_8BYTE= _ALIGNMENT is true, rb_calculate_event_length() reserves the space of event= ->array[0] for placing the data length and rb_update_event() stores the = data length in event->array[0] accordingly. As a result the whole event = length will add extra 4 bytes for sizeof(event.array[0]) unconditionally. B=
ut ring_buffer_event_length() only subtracts the sizeof(event->array[0])=
for events larger than RB_MAX_SMALL_DATA + sizeof(event->array[0]). As =
a result, small events on architectures with RB_FORCE_8BYTE_ALIGNMENT=3Dtru=
e report a data length that is 4 bytes larger than expected. To fix it, add=
the RB_FORCE_8BYTE_ALIGNMENT as a condition to subtract the size of that l= ength field whenever RB_FORCE_8BYTE_ALIGNMENT is true. This issue is observ=
ed in a riscv64 kernel with CONFIG_HAVE_64BIT_ALIGNED_ACCESS set to y, when=
we run ftrace selftest trace_marker_raw.tc, we get the weird log: for case=
s where the id is 1..100, the number of data field is 8*N, but once id exce= eds 100, the number of data field becomes 8*N+4: # 1 buf: 58 00 00 00 80 5e=
d1 63 (number of data field is 8*1) ... # a buf: 58 ... (number of data fi= eld is 8*2) ... # 64 buf: 58 ... (number of data field is 8*13) # 65 buf: 5=
8 ... (number of data field is 8*13+4) After applying this change, the numb=
er of data field keeps being 8*N+4 consistently.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80876" target=3D= "_blank" rel=3D"noopener">CVE-2026-80876</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: afs=
: Fix vllist leak Fix a leak of the new vllist in afs_update_cell() in the = event that it is an empty list (nr_servers =3D=3D 0), in which case the old=
list isn't displaced unless the old list is also empty.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80877" target=3D= "_blank" rel=3D"noopener">CVE-2026-80877</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: afs=
: Fix leak of ungot volume Fix afs_lookup_volume_rcu() so that it doesn't l= eak a dying volume if afs_try_get_volume() fails.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80878" target=3D= "_blank" rel=3D"noopener">CVE-2026-80878</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ocf= s2: fix circular locking dependency in ocfs2_dio_end_io_write A circular lo= cking dependency involves INODE_ALLOC_SYSTEM_INODE, EXTENT_ALLOC_SYSTEM_INO= DE, and ORPHAN_DIR_SYSTEM_INODE. 1. ocfs2_mknod() acquires INODE_ALLOC then=
EXTENT_ALLOC. 2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwrit= ten extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still = holding EXTENT_ALLOC. 3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_= ALLOC via ocfs2_remove_inode. Break the cycle in ocfs2_dio_end_io_write() b=
y freeing the allocation contexts (releasing EXTENT_ALLOC) before acquiring=
ORPHAN_DIR. WARNING: possible circular locking dependency detected -------= ----------------------------------------------- is trying to acquire lock: = ffff8881e78b33a0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.= +.}-{4:4}, at: ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299 but ta=
sk is already holding lock: ffff8881e78b4fa0 (&ocfs2_sysfile_lock_key[O= RPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0xe97/0x43b0 fs= /ocfs2/inode.c:1299 the existing dependency chain (in reverse order) is: -&= gt; #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}: = inode_lock include/linux/fs.h:1029 [inline] ocfs2_del_inode_from_orphan+0x1= 2e/0x7a0 fs/ocfs2/namei.c:2728 ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.= c:2418 dio_complete+0x25b/0x790 fs/direct-io.c:281 -> #1 (&ocfs2_sys= file_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: inode_lock include/l= inux/fs.h:1029 [inline] ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/s= uballoc.c:882 ocfs2_reserve_new_metadata_blocks+0x415/0x9a0 fs/ocfs2/suball= oc.c:1078 ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351 -> #0 (&ocf= s2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}: __lock_acquire+= 0x15a5/0x2cf0 kernel/locking/lockdep.c:5237 lock_acquire+0x106/0x350 kernel= /locking/lockdep.c:5868 down_write+0x96/0x200 kernel/locking/rwsem.c:1625 i= node_lock include/linux/fs.h:1029 [inline] ocfs2_remove_inode fs/ocfs2/inod= e.c:733 [inline] ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline] ocfs2_delet= e_inode fs/ocfs2/inode.c:1157 [inline] ocfs2_evict_inode+0x1539/0x43b0 fs/o= cfs2/inode.c:1299 Chain exists of: &ocfs2_sysfile_lock_key[INODE_ALLOC_= SYSTEM_INODE] --> &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]=
--> &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE] Possible unsaf=
e locking scenario: CPU0 CPU1 ---- ---- lock(&ocfs2_sysfile_lock_key[OR= PHAN_DIR_SYSTEM_INODE]); lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYST= EM_INODE]); lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]); loc= k(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]); *** DEADLOCK ***<=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80879" target=3D= "_blank" rel=3D"noopener">CVE-2026-80879</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: IB/= mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in = the implicit ODP configuration we cannot change anything in place for the p= arent mkey. Instead the whole thing needs to be rebuilt if any change is re= quested. If the user does not specify a translation then force the implicit=
values which will then fall through the logic into mlx5_ib_reg_user_mr() t=
o allocate a completely new MR. Since implicit children were also touching = the mr->pd, this removes another case where the access was racy.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80880" target=3D= "_blank" rel=3D"noopener">CVE-2026-80880</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ocf= s2: fix buffer head management in ocfs2_read_blocks() In ocfs2_read_blocks(=
), caller should't assume that buffer head returned by 'sb_getblk()' is exc= lusively owned and so 'put_bh()' always drops b_count from 1 to 0. If it is=
not so, buffer head remains on hold and likely to be returned by the next = call to 'sb_getblk()' unchanged - that is, with BH_Uptodate bit set even if=
it has failed validation previously, thus allowing to insert that buffer h= ead into OCFS2 metadata cache and submit it to upper layers. To avoid such =
a scenario, BH_Uptodate should be cleared immediately after 'validate()' ca= llback has detected some data inconsistency.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80881" target=3D= "_blank" rel=3D"noopener">CVE-2026-80881</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: cry= pto: tegra - Return ENOMEM when input buffer allocation fails for ccm Ensur=
e the ENOMEM error value is set when the input buffer allocation fails in t= egra_ccm_do_one_req.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80882" target=3D= "_blank" rel=3D"noopener">CVE-2026-80882</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /tegra: gr2d/gr3d: Initialize address register map before HOST1X client is = registered The host1x_client_register() function is called just prior to re= gister map initialization loop, making the device available to userspace. T= his may result in userspace attempting to submits a job before the register=
map is initialized. Address this by moving register initialization before = host1x client registration.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80883" target=3D= "_blank" rel=3D"noopener">CVE-2026-80883</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ntb=
: Store original DMA address for future release The DMA API requires that d= ma_free_attrs receive the exact dma_handle originally returned by the alloc= ation function. Do not modify it.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80884" target=3D= "_blank" rel=3D"noopener">CVE-2026-80884</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: afs=
: Fix uncancelled rxrpc OOB message handler Fix AFS to cancel its OOB messa=
ge processing (typically to respond to security challenges). Also move OOB = message processing to afs_wq so that it's also waited for and make the OOB = handler just return if the net namespace is no longer live.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80885" target=3D= "_blank" rel=3D"noopener">CVE-2026-80885</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ser= ial: msm: Disable DMA for kernel console UART At the moment, concurrent wri= tes from userspace and the kernel to the console can trigger a race conditi=
on that results in an infinite loop of the same messages printed over and o= ver again. This is most likely to happen during system startup or shutdown = when the init system starts/stops a large number of system services that in= teract with various kernel code. When userspace writes to the TTY device, t=
he driver initiates an asynchronous DMA transfer and releases the port lock=
. At the same moment, the kernel printk path might grab the port lock and r= e-configure the UART controller for PIO, without waiting for the DMA operat= ion to complete. It seems like this collision results in zero progress bein=
g reported for the DMA engine, so the same text is printed to the console o= ver and over again. For the kernel console, we want a reliable output path = that will be functional even during crashes etc. So rather than implementin=
g complex code to synchronize the kernel console write routines with the us= erspace DMA write routines, simply disable DMA for the console UART instanc=
e. Similar checks exist in many other serial drivers, e.g. 8250_port.c, imx= .c, sh-sci.c etc.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80886" target=3D= "_blank" rel=3D"noopener">CVE-2026-80886</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /vmwgfx: use check_add_overflow for shader size+offset bound vmw_shader_def= ine() validates the user-supplied shader window against its backing buffer = with (u64)buffer->tbo.base.size < (u64)size + (u64)offset drm_vmw_sha= der_create_arg::offset is __u64 in the uapi; when it is near U64_MAX the un= signed addition wraps and the resulting tiny value passes the check. The un= bounded offset is then stored in res->guest_memory_offset and forwarded =
to host SVGA shader-create commands. Use check_add_overflow() to detect the=
wrap and compare the resulting endpoint against the buffer size.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80887" target=3D= "_blank" rel=3D"noopener">CVE-2026-80887</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /vmwgfx: drop dma_buf reference on foreign-fd prime import ttm_prime_fd_to_= handle() returns -ENOSYS when the imported fd's dma_buf->ops do not matc=
h the ttm_object_device's ops, but does so without releasing the reference = acquired by dma_buf_get(). Any unprivileged renderD client passing a non-vm= wgfx prime fd through the DRM_VMW_GB_SURFACE_REF{,_EXT} path leaks one dma_= buf reference per call and indefinitely pins the foreign exporter's GEM res= ources. Funnel the error path through the existing dma_buf_put() so the ref= erence is always dropped.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80888" target=3D= "_blank" rel=3D"noopener">CVE-2026-80888</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: can=
: isotp: fix timer drain order, wakeup handling and tx_gen ordering This pa= tch is a follow-up to commit cf070fe33bfb ("can: isotp: serialize TX state = transitions under so->rx_lock") which addresses following sashiko-bot fi= ndings: - isotp_sendmsg(): drain so->txfrtimer first so a stale callback=
can't re-arm echotimer after the claim - isotp_release(): wake so->wait=
after forcing ISOTP_SHUTDOWN so a sleeping sendmsg() claim isn't stranded =
- isotp_sendmsg(): have both wait_event_interruptible() calls in isotp_send= msg() also wake on ISOTP_SHUTDOWN and do not return claim to IDLE to avoid = corrupting a concurrent isotp_release() process. - isotp_sendmsg(): handle = potential claim of a new transfer when the wait_event_interruptible() call = returns in CAN_ISOTP_WAIT_TX_DONE mode. Don't touch timers and states of th=
e new transfer if a new thread incremented so->tx_gen before getting the=
lock at err_event_drop. - isotp_sendmsg(): handle a stuck can_send() and o= mit timer and state changes if a new transfer was claimed. wait_tx_done() r= eturns the error recorded in so->tx_result[], tagged with the caller's o=
wn generation. - isotp_tx_timeout(): on a claimed timeout, record the ECOMM=
error for the timed-out transfer's own generation in so->tx_result[]; s= k->sk_err is raised unconditionally, same as every other error path here=
. - isotp_tx_gen_done()/isotp_tx_timeout(): always read tx.state (acquire) = before tx_gen - the reverse order let a weakly ordered CPU pair a fresh tx.= state with a stale tx_gen/tx_result slot. - isotp_sendmsg(): wait_tx_done: = drain sk_err via sock_error() once we have read the result from so->tx_r= esult[], so an already-reported error doesn't stay latched for a later poll= ()/SO_ERROR. Also align the remaining lock-free so->tx.state/rx.state/cf= echo accesses and use skb->hash as unique loopback echo frame indicator.= </td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80889" target=3D= "_blank" rel=3D"noopener">CVE-2026-80889</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sct=
p: reject stale cookies with mismatched verification tags sctp_unpack_cooki= e() skips cookie expiration checks whenever an association already exists. = This is broader than the exception in RFC 9260 Section 5.2.4. For an existi=
ng association, Section 5.2.4 permits an expired State Cookie only when bot=
h Verification Tags in the cookie match the current association. Otherwise,=
the packet SHOULD be discarded and a Stale Cookie ERROR MUST be sent. The = broad check lets an expired Action A restart cookie reach sctp_sf_do_dupcoo= k_a(). In a runtime test with the default 60 second cookie lifetime, replay= ing such a cookie after 65 seconds returned a COOKIE-ACK and restarted the = association. Check cookie expiration unless both Verification Tags match. T= his preserves the Action D exception for a lost COOKIE ACK while rejecting = expired cookies in all other cases.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80890" target=3D= "_blank" rel=3D"noopener">CVE-2026-80890</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM=
: s390: pci: Validate AIBV and AISB before pinning guest pages The AIBV hol=
ds one bit per MSI-X vector for a given function. The size of the bit vecto=
r is derived from the NOI and the AIBVO. If the size of the AIBV exceeds a = single page boundary, then reject the request as we cannot safely pin the g= uest AIBV. Similarly reject the request if the AISB address is not 8-byte a= ligned as the architecture requires doubleword alignment for the summary bi=
t address. Since the AISBO can address up to 64 bits, the size of the AISB = can only be 8 bytes for the function. This also ensures the AISB doesn't ex= ceed a single page boundary.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80891" target=3D= "_blank" rel=3D"noopener">CVE-2026-80891</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ero= fs: cap LZMA stream pool size fs/erofs/decompressor_lzma.c sizes the module= -global MicroLZMA stream pool from num_possible_cpus() when the lzma_stream=
s module parameter is unset, then z_erofs_load_lzma_config() preallocates o=
ne image-supplied dictionary per stream, accepting dictionaries up to 8 MiB=
. On high-CPU systems, a small EROFS image can pin hundreds of MiB of vmall= oc-backed decoder state until the erofs module is unloaded. Impact: An EROF=
S image mounted by the system can pin up to 8 MiB of vmalloc memory per LZM=
A stream, either as intended or unexpectedly. Bound the default stream coun=
t by a new CONFIG_EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS option, default 16,=
so the worst-case default preallocation is 128 MiB if the number of CPUs i=
s no less than 16 while preserving the existing per-image dictionary limit.=
An explicit lzma_streams module parameter is still honoured as-is, so admi= nistrators who deliberately size the pool are not affected.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80892" target=3D= "_blank" rel=3D"noopener">CVE-2026-80892</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm/= hugetlb: fix swap entry corruption when clearing uffd-wp at fork() copy_hug= etlb_page_range() clears the uffd-wp bit of migration and hwpoison entries = with huge_pte_clear_uffd_wp(), which operates on the present-PTE bit positi= on. Swap entries keep the uffd-wp state elsewhere -- the migration branch r= eads and sets it with pte_swp_uffd_wp() and pte_swp_mkuffd_wp() -- and the = present-PTE position falls into the swap payload. On x86-64 it lands in the=
inverted swap offset, where a naturally-aligned hugetlb PFN always has the=
affected bit set, so the clear advances the encoded PFN by two pages. No u= serfaultfd needs to be involved: the clear is guarded only by the child VMA=
not being uffd-wp registered, so a plain fork() with an in-flight hugetlb = migration entry (or a poisoned hugetlb page) corrupts the entry copied into=
the child. Instrumenting the clear and forking after MADV_HWPOISON on a 2M=
B anon hugetlb page shows: offset before=3D120e00 offset after =3D120e02 Th=
e fallout is mostly latent: rmap walks match migration entries by folio ran=
ge and remove_migration_pte() rebuilds the PTE from the folio, so a within-= folio PFN skew heals once migration completes. But any path that re-encodes=
the corrupted offset -- e.g. hugetlb_change_protection() rewriting a writa= ble migration entry via make_readable_migration_entry(swp_offset(entry)) --=
propagates it. Migration entries legitimately carry uffd-wp, so clear it w= ith pte_swp_clear_uffd_wp(), matching copy_nonpresent_pte() and move_huge_p= te(). A hwpoison entry, on the other hand, never carries the uffd-wp bit: i=
t is installed fresh by make_hwpoison_entry() (try_to_unmap_one() does not = preserve uffd-wp on the hwpoison path) and hugetlb_change_protection() leav=
es hwpoison entries untouched. There was nothing to clear there, only the c= orruption, so drop the clear entirely.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80893" target=3D= "_blank" rel=3D"noopener">CVE-2026-80893</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: iom= mufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace iomm= ufd_hwpt_replace_device() calls: iommufd_auto_response_faults(hwpt, old_han= dle); passing the *new* hwpt together with the handle of the device's *old*=
domain. This should be a parameter mismatch: 1. Semantically, iommufd_auto= _response_faults(x, handle) scans x->fault's deliver list and response x= array for groups matching "handle". A group is queued under the hwpt that w=
as attached at fault-delivery time. old_handle is fetched *before* the doma=
in switch, so its group lives on old->fault, not on the new hwpt->fau= lt. 2. Historically, the first argument was "old". The routine was introduc=
ed by commit b7d8833677ba ("iommufd: Fault-capable hwpt attach/detach/repla= ce") as __fault_domain_replace_dev() in fault.c, correctly calling iommufd_= auto_response_faults(old, curr). Commit fb21b1568ada ("iommufd: Make attach= _handle generic than fault specific") moved this into iommufd_hwpt_replace_= device() in device.c and swapped it to "hwpt". This should be a refactor re= gression, not an intentional change. Fix this by passing "old" instead.</td=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80894" target=3D= "_blank" rel=3D"noopener">CVE-2026-80894</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: msh=
v: Order pt_vp_array publish against irqfd assertion path mshv_partition_io= ctl_create_vp() initialises a VP struct (allocations, mutex_init, init_wait= queue_head, page mappings) and then publishes the pointer into partition-&g= t;pt_vp_array. Several ISR paths read this array locklessly: the intercept = ISR, the two scheduler ISRs, and mshv_try_assert_irq_fast() on the irqfd fa=
st path. Of these, only mshv_try_assert_irq_fast() can structurally race th=
e publish. It runs from an eventfd waker without holding pt_mutex, and MSHV= _IRQFD does not require the target lapic_apic_id (=3D=3D vp_index) to refer=
to an existing VP at registration time. A user can therefore register an i= rqfd targeting a yet-to-be-created VP, then trigger mshv_try_assert_irq_fas= t() concurrently with MSHV_CREATE_VP for the same index. On weakly-ordered = architectures the reader can observe a non-NULL pointer in pt_vp_array befo=
re the initialising stores to the VP struct become visible, leading to use =
of partially-initialised fields (e.g. vp_register_page). The other ISR read= ers cannot reach this race: the hypervisor will not generate intercept or s= cheduler messages for a VP that has never been told to run, and the user ca=
n only call MSHV_RUN_VP on the VP fd returned by MSHV_CREATE_VP, which by c= onstruction is returned after the publish. Leave those readers as plain loa= ds. Use smp_store_release() in mshv_partition_ioctl_create_vp() to publish = the pointer, and pair it with smp_load_acquire() in mshv_try_assert_irq_fas= t(). On x86 these compile to plain accesses under TSO; on ARM64 they emit o= ne-instruction acquire/release barriers, acceptable on this fast path. The = destroy-side path (destroy_partition() clearing pt_vp_array[i] to NULL afte=
r kfree(vp)) has a separate ordering and lifetime concern that is out of sc= ope here.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80895" target=3D= "_blank" rel=3D"noopener">CVE-2026-80895</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: msh=
v: Fix race in mshv_irqfd_deassign mshv_irqfd_deactivate() and the hlist tr= aversal of pt_irqfds_list require pt->pt_irqfds_lock to be held, but msh= v_irqfd_deassign() omits it. This races with the EPOLLHUP path in mshv_irqf= d_wakeup(), which does take the lock before calling mshv_irqfd_deactivate()=
. Additionally, mshv_irqfd_deactivate() uses hlist_del() which poisons the = node pointers rather than resetting them. Since mshv_irqfd_is_active() reli=
es on hlist_unhashed() (checks pprev =3D=3D NULL), a poisoned node still ap= pears active. If a concurrent path calls mshv_irqfd_deactivate() again on t=
he same irqfd, the guard fails to prevent a double hlist_del() on poisoned = pointers. Fix both issues: - Add the missing spin_lock_irq/spin_unlock_irq = around the list traversal in mshv_irqfd_deassign(), matching mshv_irqfd_rel= ease(). - Use hlist_del_init() instead of hlist_del() so the node is proper=
ly marked as unhashed after removal, making the is_active guard reliable.</=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80896" target=3D= "_blank" rel=3D"noopener">CVE-2026-80896</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= fs: release readahead folios on iterator preparation failure netfs_prepare_= read_iterator() batches readahead folios in put_batch so that the folio ref= erences can be dropped after the I/O iterator has been prepared. If rolling= _buffer_load_from_ra() fails after earlier folios have been batched, the fu= nction returns immediately and leaves those references held. Release the ba= tch before returning the error.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80897" target=3D= "_blank" rel=3D"noopener">CVE-2026-80897</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= fs: clear PG_private_2 on copy-to-cache append failure netfs_pgpriv2_copy_t= o_cache() marks the folio with PG_private_2 before netfs_pgpriv2_copy_folio=
() appends it to the copy-to-cache rolling buffer. If the append fails, the=
folio is not queued for cache writeback, so the PG_private_2 state and its=
reference must be released immediately.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80898" target=3D= "_blank" rel=3D"noopener">CVE-2026-80898</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ero= fs: remove fscache backend entirely EROFS over fscache was introduced to pr= ovide image lazy pulling functionality. After the feature landed, the fscac=
he subsystem made netfs a new hard dependency, which is unexpected for a lo= cal filesystem and has an kernel-defined caching hierarchy which could be i= nflexible compared to the fanotify pre-content hooks. Therefore, this featu=
re has been deprecated for almost two years. As EROFS file-backed mounts an=
d fanotify pre-content hooks both upstream for a while and already providin=
g equivalent functionality (erofs-utils has supported fanotify pre-content = hooks), let's remove the fscache backend now. The main application of this = feature is Nydus [1], and they plan to move to use fanotify pre-content hoo=
ks in the near future too. I hope this patch can be merged into Linux 7.2, = which is also motivated by newly found implementation issues [2][3] that ar=
e not worth investigating given the deprecation and limited development res= ources. The associated fscache/cachefiles cleanup patch will follow separat= ely through the vfs tree (netfs) later: it seems fine since the codebase is=
isolated by CONFIG_CACHEFILES_ONDEMAND. [1]
https://github.com/dragonflyos= s/nydus/blob/v2.1.0/docs/nydus-fscache.md [2]
https://github.com/dragonflyo= ss/nydus/pull/1824 [3]
https://lore.kernel.org/r/20260619135800.1594811-1-m= ichael.bommarito@gmail.com</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80899" target=3D= "_blank" rel=3D"noopener">CVE-2026-80899</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASo=
C: SDCA: Make UMP message size check more robust If message offset was larg=
er than the buffer length the size check will pass incorrectly. Refactor th=
e check such that it is more robust to invalid sizes.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80900" target=3D= "_blank" rel=3D"noopener">CVE-2026-80900</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv=
s: fix the checksum validations ip_vs_in_icmp_v6() is missing checksum vali= dation for ICMPv6 packets from clients. In fact, as for TCP/UDP we should v= alidate the checksum for ICMP packets only when we mangle the packets on MA=
SQ or on reply for tunnel. Also, Sashiko points out that handle_response_ic= mp() being common for IPv4 and IPv6 is missing the pseudo-header calculatio=
n while validating ICMPv6 messages from real servers which is a problem if = checksum is not validated by the hardware. Fix the problems by creating ip_= vs_checksum_common_check() helper and use it for TCP/UDP/ICMP both for IPv4=
and IPv6. Rely on the nf_checksum() for validating the ICMP messages but u=
se it also for TCP and UDP. Use correct IP offset for IP_VS_DBG_RL_PKT for = TCP/UDP/SCTP. IPVS packets (TCP/UDP/SCTP/ICMP) do not need checksum validat= ion on LOCAL_OUT (local clients or local real servers) and on FORWARD (traf= fic from servers on LAN). Do it only on LOCAL_IN, in case nf_checksum() is = not called on PRE_ROUTING. Also, ip_vs_checksum_complete() can be marked st= atic.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80901" target=3D= "_blank" rel=3D"noopener">CVE-2026-80901</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: dma= engine: sun6i-dma: Fix reclaim descriptors while terminating DMA When termi= nating DMA transfers, active descriptors are not properly reclaimed. Only c= yclic descriptors were handled, leaving non-cyclic descriptors and their LL=
I chains to be permanently leaked. Fix by using vchan_terminate_vdesc() whi=
ch handles both cyclic and non-cyclic descriptors by adding them to desc_te= rminated queue for proper cleanup. Add pchan->desc !=3D pchan->done c= heck to prevent double-adding completed descriptors, which would corrupt th=
e list.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80902" target=3D= "_blank" rel=3D"noopener">CVE-2026-80902</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /xe/oa: Fix sync entry leak on OA config emit failure xe_oa_emit_oa_config(=
) releases the sync entries and the syncs array only on its success path. W= hen it fails before the point of no return (fence allocation, config buffer=
allocation or batch submission), it returns without touching stream->sy= ncs. The stream open path handles such failures in the caller, but xe_oa_co= nfig_locked() propagates the error without any cleanup, so the syncs array = and the fence references held by the parsed entries are leaked. The next co= nfig ioctl overwrites stream->syncs, making the memory unreachable for g= ood. Clean up the parsed syncs when xe_oa_emit_oa_config() fails, matching = the cleanup done by the stream open error path. (cherry picked from commit = 8af97b3da2cfce04e6b457c6eb17ed3c1daf912b)</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80903" target=3D= "_blank" rel=3D"noopener">CVE-2026-80903</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net= /tls: Fail tls_sw_splice_read() after a failed async decrypt When an async = decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.e=
rr and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() a=
nd tls_sw_read_sock() each read async_wait.err once they hold the reader lo=
ck and fail the call: a record that did not authenticate breaks the connect= ion. tls_sw_splice_read() has no such check, and sk_err does not stand in f=
or one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenev=
er a record is already parsed, and the first reader to reach sock_error() c= lears it, while async_wait.err persists. A splice therefore keeps deliverin=
g records on a connection that recvmsg() and read_sock() refuse to read. Re=
ad async_wait.err in tls_sw_splice_read() as the other two readers do.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80904" target=3D= "_blank" rel=3D"noopener">CVE-2026-80904</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net=
: tap: fix wrong transport_header when sending VLAN-tagged frame In tap_get= _user_xdp(), when processing a VLAN-tagged frame (e.g. ETH_P_8021Q), skb_se= t_network_header() is called first to advance network_header past the VLAN = tag to the inner protocol header. skb_probe_transport_header() is then call=
ed with skb->protocol still set to ETH_P_8021Q, while nhoff (derived fro=
m skb_network_offset()) already points past the VLAN tag to the inner proto= col header. In __skb_flow_dissect(), proto is initialized to ETH_P_8021Q an=
d nhoff points past the VLAN tag. When the dissector hits case ETH_P_8021Q,=
it reads a struct vlan_hdr at the current nhoff via __skb_header_pointer()=
, but that offset contains the inner protocol header (e.g. an IP header). T=
he bytes are misinterpreted as a VLAN header, yielding a garbage encapsulat=
ed EtherType that matches no known protocol. The dissector returns false, s=
o skb_probe_transport_header() never calls skb_set_transport_header(), leav= ing transport_header at its uninitialized sentinel value (~0U). Move skb_se= t_network_header() to after skb_probe_transport_header(). At the time skb_p= robe_transport_header() is called, network_header still points to the VLAN = header (offset ETH_HLEN), so nhoff is correct and the flow dissector can pa= rse the VLAN header, extract the inner EtherType, and advance nhoff to the = inner protocol header, allowing transport_header to be set correctly.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80905" target=3D= "_blank" rel=3D"noopener">CVE-2026-80905</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: net=
: packet: fix wrong transport_header when sending VLAN-tagged frame In pack= et_parse_headers(), when processing a VLAN-tagged frame, skb_set_network_he= ader() is called to advance network_header past the VLAN tag to the inner p= rotocol header. skb_probe_transport_header() is then called with skb->pr= otocol still set to the outer VLAN EtherType (e.g. ETH_P_8021Q), while nhof=
f (derived from skb_network_offset()) already points past the VLAN tag to t=
he inner protocol header. In __skb_flow_dissect(), proto is initialized to = ETH_P_8021Q and nhoff points past the VLAN tag. When the dissector hits cas=
e ETH_P_8021Q, it reads a struct vlan_hdr at nhoff via __skb_header_pointer= (), but that offset contains the inner protocol header (e.g. an IP header).=
The bytes are misinterpreted as a VLAN header, yielding a garbage encapsul= ated EtherType that matches no known protocol. The dissector returns false,=
so skb_probe_transport_header() never calls skb_set_transport_header(), le= aving transport_header at its uninitialized sentinel value (~0U). Move skb_= probe_transport_header() to before skb_set_network_header(). At the time sk= b_probe_transport_header() is called, network_header still points to the VL=
AN header, so nhoff correctly points to the VLAN header. The flow dissector=
can then parse the VLAN header, extract the inner EtherType, and advance n= hoff to the inner protocol header, allowing transport_header to be set corr= ectly.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80906" target=3D= "_blank" rel=3D"noopener">CVE-2026-80906</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /amdgpu: Fix UVD dpb min size calculation for H264 This should use actual n= umber of references from the decode message, instead of maximum derived fro=
m level. (cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e239685= 6)</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80907" target=3D= "_blank" rel=3D"noopener">CVE-2026-80907</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /amdgpu: Reject UVD message with dimensions above 4096 Fixes potential over= flow in DPB size calculations. (cherry picked from commit 05e1387d151f71569= fbe122d2c89f9db0c21dc10)</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80908" target=3D= "_blank" rel=3D"noopener">CVE-2026-80908</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm= /amdgpu: Reject UVD message with invalid number of h265 refs Same change as=
for h264, avoids overflow later when calculating min dpb size. (cherry pic= ked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80909" target=3D= "_blank" rel=3D"noopener">CVE-2026-80909</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASo=
C: codecs: lpass-wsa-macro: Fix enum kcontrol accesses EAR SPKR PA Gain" an=
d the four "WSA RX* Mux" controls are enumerated, but their get and put cal= lbacks access the value through ucontrol->value.integer.value[0] (a long=
) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This = same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC=
: codecs: rx-macro: fix accessing array out of bounds for enum type") and c= ommit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bou= nds for enum type"), but wsa-macro was missed. On 64-bit kernels with CONFI= G_SND_CTL_DEBUG this trips the elem value sanity check and every read of th= ese controls fails with -EINVAL.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80910" target=3D= "_blank" rel=3D"noopener">CVE-2026-80910</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASo=
C: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() If either = tplg_ops->dai_config or widget_kcontrol_setup fail during widget setup w=
e would double decrement the use_count of the widget because the sof_widget= _free_unlocked() would be called twice, similarly the core_put would be inv= oked twice as well. Since the use_count and core_put() is handled within th=
e widget_free function we need to return without falling through the pipe_w= idget_free label. The fixes tag is picked to the last change around this pa=
rt of the code which is adequately old enough for backporting purposes.</td=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80911" target=3D= "_blank" rel=3D"noopener">CVE-2026-80911</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sel= inux: reject an unclaimed class value in security_get_classes() security_ge= t_classes() sizes an array by p_classes.nprim and fills it at value - 1, so=
a class value the policy never defines leaves a NULL. sel_make_classes() p= asses every entry to sel_make_dir(), reaching the same d_alloc_name() deref= erence as the permission array. The class symbol table is allowed to be spa= rse (policydb_class_isvalid() exists to absorb that), but this getter build=
s its own array straight from the hash table and has no such predicate. Fai=
l the lookup when a value went unclaimed instead of handing out the NULL. C= onforming policies define every class they declare and are unaffected.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80912" target=3D= "_blank" rel=3D"noopener">CVE-2026-80912</a></td>
</tr>
<td class=3D"vendor-product">Linux--Linux</td>
<td>In the Linux kernel, the following vulnerability has been resolved: sel= inux: require every boolean value to be defined p_bools.nprim comes from th=
e policy image independently of how many booleans follow it, and cond_index= _bool() fills bool_val_to_struct[] at value - 1, so a count larger than the=
values present leaves NULL entries. Every user of that array then walks it=
by index and dereferences each entry: cond_evaluate_expr() on the access-v= ector path, security_get_bools() and security_get_bool_value() behind selin= uxfs, and security_set_bools(). A sparse class value is absorbed by policyd= b_class_isvalid() and its siblings; booleans have no such predicate, and no=
consumer that could use one. Reject a boolean value that no boolean define=
s, once, where the array is built. Conforming policies define every boolean=
they declare and are unaffected.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80913" target=3D= "_blank" rel=3D"noopener">CVE-2026-80913</a></td>
</tr>
<td class=3D"vendor-product">livewire--livewire</td>
<td>Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until=
3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history= /index.js, including fromQueryString() and insertDotNotatedValueIntoData(),=
accepts the __proto__, constructor, and prototype path segments and create=
s inherited objects. Client-side state handlers then access effects.html, e= ffects.js, effects.xjs, and effects.scripts without Object.prototype.hasOwn= Property.call(), allowing inherited attacker-controlled state to be treated=
as trusted effects. An unauthenticated attacker can craft a URL that, when=
opened by a user, executes arbitrary JavaScript in the affected applicatio= n's origin. Exploitation requires user interaction and does not bypass serv= er-side authorization or grant privileges beyond the affected user. This is= sue is fixed in versions 3.8.3 and 4.3.4.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-81887" target=3D= "_blank" rel=3D"noopener">CVE-2026-81887</a></td>
</tr>
<td class=3D"vendor-product">Lookyloo--PlaywrightCapture</td> <td>PlaywrightCapture contains a server-side request forgery (SSRF) vulnera= bility in its favicon retrieval functionality. When only_global_lookup is e= nabled, the application validates the initial favicon URL to prevent reques=
ts to localhost, loopback, or other non-public network addresses. However, = redirects followed by aiohttp were not subjected to the same validation. An=
attacker able to influence the content of a page processed by PlaywrightCa= pture could specify a publicly reachable favicon URL that responds with an = HTTP redirect to a local or otherwise restricted address, such as 127.0.0.1=
, localhost, or an internal network service. Because aiohttp automatically = followed the redirect, the resulting request could bypass the application's=
local-address restrictions and cause the PlaywrightCapture host to issue H= TTP requests to resources that should not be externally reachable. Dependin=
g on the services reachable from the PlaywrightCapture host and how retriev=
ed favicon data is subsequently exposed or processed, this could be used to=
probe internal HTTP services or potentially obtain information from otherw= ise inaccessible endpoints. The patch introduces an aiohttp request middlew= are that applies the existing local-URL validation to every request in the = redirect chain. Requests resolving to restricted/local destinations are rej= ected before they are issued.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85242" target=3D= "_blank" rel=3D"noopener">CVE-2026-85242</a></td>
</tr>
<td class=3D"vendor-product">Lutece--Lutece Core</td>
<td>A vulnerability in the Lutece Core XSL export management module up to v= ersion 7.1.7, which allows authenticated administrators to execute code rem= otely. The XML/XSLT processing configuration does not enable secure process= ing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to =
be executed from malicious XSL stylesheets. An attacker with administrator = privileges can upload a manipulated XSL transformation file and trigger its=
execution during user export operations, resulting in the execution of arb= itrary code on the server.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-4813" target=3D"= _blank" rel=3D"noopener">CVE-2026-4813</a></td>
</tr>
<td class=3D"vendor-product">malach-it--boruta-server</td>
<td>Boruta is a standalone authorization server that aims to implement OAut=
h 2.0 and Openid Connect up to decentralized identity specifications. Prior=
to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomi= zes every key of the user-supplied request body via String.to_atom/1 before=
any validation. Because String.to_atom interns atoms permanently in the BE=
AM atom table (default cap 1,048,576 atoms; ERL_MAX_ATOMS), any authenticat=
ed end user can send PUT /users/settings with a user[<fresh-key>]=3D.=
.. body containing fresh keys per request and exhaust the global VM atom ta= ble. Once the table is full, the BEAM aborts with no more index entries in = atom_tab and the entire OIDC server (auth, admin, gateway apps in the umbre= lla) crashes. The route is protected only by require_authenticated_user and=
a per-IP rate limit of 10 requests/second; a logged-in end user can hit it=
. The keys are atomized unconditionally before the downstream Accounts.upda= te_user/6 call, so even failing updates contribute to exhaustion. This issu=
e has been patched in version 0.10.0.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-49249" target=3D= "_blank" rel=3D"noopener">CVE-2026-49249</a></td>
</tr>
<td class=3D"vendor-product">Manacle Technologies--Multi-tenant ERP System<=
<td>This vulnerability exists in the ERP system due to improper authenticat= ion controls and inadequate file type validation at the API endpoint. An un= authenticated remote attacker could exploit this vulnerability by uploading=
arbitrary files to a web accessible directory on the targeted system Succe= ssful exploitation of this vulnerability could allow the attacker to execut=
e arbitrary code and compromise the targeted system.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84147" target=3D= "_blank" rel=3D"noopener">CVE-2026-84147</a></td>
</tr>
<td class=3D"vendor-product">Manacle Technologies--Multi-tenant ERP System<=
<td>This vulnerability exists in the ERP system due to improper authenticat= ion and authorization controls in the API endpoint. An unauthenticated remo=
te attacker could exploit this vulnerability by manipulating parameter whic=
h could lead to exposure of sensitive information belonging to other users =
on the targeted system.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84148" target=3D= "_blank" rel=3D"noopener">CVE-2026-84148</a></td>
</tr>
<td class=3D"vendor-product">Manacle Technologies--Multi-tenant ERP System<=
<td>This vulnerability exists in the ERP system due to exposure of reposito=
ry information through a publicly accessible .git directory. An unauthentic= ated remote attacker could exploit this vulnerability by accessing the expo= sed .git directory and retrieving repository metadata and associated files,=
which could allow reconstruction of the application's source code.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84149" target=3D= "_blank" rel=3D"noopener">CVE-2026-84149</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>An issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Soluti= ons X-Serie Gateway firmware V6_00_05 allows a remote authenticated user wi=
th the low-privileged Standard role to inject arbitrary code into the dpche=
ck system utility executed as root.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75161" target=3D= "_blank" rel=3D"noopener">CVE-2026-75161</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>An information disclosure vulnerability in the opcua-configuration meth=
od of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_0=
5 allows any remote authenticated user, including users with the low-privil= eged Standard role, to retrieve the configured OPC-UA authentication creden= tials in cleartext via the JSON API response.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75162" target=3D= "_blank" rel=3D"noopener">CVE-2026-75162</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>An issue in /cgi-bin/wwwugw.cgi of MBS-Solutions X-Serie Gateway firmwa=
re V6_00_05 allows a remote authenticated user with the low-privileged Stan= dard role to invoke hidden network diagnostic methods (ugw-ping, ugw-tracer= oute) that are not exposed in the web UI, allowing attackers to obtain sens= itive information.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75165" target=3D= "_blank" rel=3D"noopener">CVE-2026-75165</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>Insecure Permission vulnerability in MBS-Solutions X-Serie Gateway firm= ware V6_00_05 allows the low-privileged service user to execute /usr/bin/tc= pdump as root without a password. By leveraging the tcpdump -z option, an a= uthenticated attacker can achieve arbitrary command execution.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75166" target=3D= "_blank" rel=3D"noopener">CVE-2026-75166</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>A broken access control vulnerability in the ugw-usr-edit method of /cg= i-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows =
a remote authenticated user with the low-privileged Standard role to change=
the password of arbitrary accounts.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75167" target=3D= "_blank" rel=3D"noopener">CVE-2026-75167</a></td>
</tr>
<td class=3D"vendor-product">MBS-Solutions --X-Series Gateway</td>
<td>An arbitrary file upload vulnerability in /cgi-bin/ugwupload.cgi of MBS= -Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated = user with Admin role to upload files with arbitrary content to hardcoded pa= ths.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75169" target=3D= "_blank" rel=3D"noopener">CVE-2026-75169</a></td>
</tr>
<td class=3D"vendor-product">microsoft--winml-cli</td>
<td>Windows ML CLI is a command line tool for building portable, performant=
, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/= modelkit/serve/cli_api.py component exposes WinML CLI commands through a lo= calhost HTTP API without authentication and configures the allow_origins se= tting as a wildcard in both src/winml/modelkit/serve/cli_api.py and src/win= ml/modelkit/serve/app.py. A malicious website loaded by a user can send cro= ss-origin requests to /v1/cli/build or /v1/cli/config and set the trust_rem= ote_code parameter to true, which is converted to the --trust-remote-code c= ommand-line flag without validation. This reaches AutoConfig.from_pretraine=
d with trust_remote_code=3DTrue in src/winml/modelkit/loader/_autoconfig.py=
and imports Python code from an attacker-controlled model repository, resu= lting in arbitrary code execution as the server user. This issue is fixed i=
n version 0.4.0.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84452" target=3D= "_blank" rel=3D"noopener">CVE-2026-84452</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS</td>
<td>RouterOS WebFig contains an unauthenticated file-read vulnerability in = the /jsproxy path where a newly allocated session retains a stale uninitial= ized principal pointer used for file authorization. An unauthenticated atta= cker can prepare the allocator so that the file-serving path dereferences t= his pointer with sufficient rights, then supply parent-directory components=
in an encrypted URI to escape the WebFig file namespace and disclose root-= owned files, including configuration stores containing credentials.This iss=
ue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term)=C2=A0a= nd=C2=A07.24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67281" target=3D= "_blank" rel=3D"noopener">CVE-2026-67281</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS=C2=A0</td>
<td>RouterOS accepts a "related" btest connection before the corresponding = primary session has completed authentication. An unauthenticated client can=
use this state to start an IPv4 UDP test. With "random-data=3Dfalse", the = sender transmits an uninitialized tail from a kernel packet buffer. A separ= ate unchecked, inverted packet-size interval causes unsigned integer underf= low, anomalously large fragmented output, and can restart the RouterOS kern= el. This issue was fixed in versions:=C2=A06.49.21 (Long-term),=C2=A07.23.4=
(Long-term)=C2=A0and=C2=A07.24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67277" target=3D= "_blank" rel=3D"noopener">CVE-2026-67277</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS=C2=A0</td>
<td>RouterOS SSH enters the connection protocol after a client-requested re= key even though user authentication was never attempted, allowing an unauth= enticated client to open a session channel and send an exec request. On aff= ected builds the server dispatches the command, enabling unauthenticated cr= eation, overwrite, and reconstruction of files in the RouterOS managed file=
namespace, including support files containing configuration and diagnostic=
data.This issue was fixed in versions:=C2=A06.49.21 (Long-term),=C2=A07.23=
.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67279" target=3D= "_blank" rel=3D"noopener">CVE-2026-67279</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS<br>=C2=A0</td>
<td>RouterOS contains an argument-handling flaw in the SSH login path invol= ving usernames that begin with a prohibited character, allowing for the tru= sted RouterOS policy mask=C2=A0to be changed, leading to privilege escalati= on. Exploitation requires an unauthenticated SSH session to reach the Route= rOS login helper.This issue was fixed in versions:=C2=A06.49.21 (Long-term)= ,=C2=A07.23.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86060" target=3D= "_blank" rel=3D"noopener">CVE-2026-86060</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS=C2=A0<br>=C2=A0</td> <td>RouterOS does not compare the complete RSA public key when matching an = SSH authentication request to an authorized user key, checking the key type=
and modulus but omitting the exponent. Because signature verification uses=
the client-supplied key, an attacker knowing an authorized RSA modulus can=
supply a key with exponent one, forge a valid signature, and open an SSH c= ommand channel as the target user without the private key.This issue affect=
s only 7.x branch was fixed in versions: 7.23.4 (Long-term)=C2=A0and=C2=A07= .24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67276" target=3D= "_blank" rel=3D"noopener">CVE-2026-67276</a></td>
</tr>
<td class=3D"vendor-product">MikroTik--RouterOS=C2=A0<br>=C2=A0</td> <td>MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X= .509 validation. Because its trust store includes an e=3D3 root CA, an atta= cker controlling or redirecting an outbound RouterOS TLS connection can use=
the root's public certificate - without its private key - to forge a trust=
ed intermediate and issue certificates for arbitrary hostnames, enabling TL=
S server impersonation. This issue affects only 7.x branch was fixed in ver= sions: 7.23.4 (Long-term)=C2=A0and=C2=A07.24.2 (Stable)</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67278" target=3D= "_blank" rel=3D"noopener">CVE-2026-67278</a></td>
</tr>
<td class=3D"vendor-product">miniorgange.com--miniOrange Oauth Client (free=
) extension for Joomla</td>
<td>Joomla Extension - miniorgange.com - Unauthenticated arbitrary extensio=
n deinstallation via various miniOrange extensions - a missing authenticati=
on check allows unauthenticated actors to delete arbitrary installed extens= ions. Only the free versions of the miniOrange plugins are affected.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78074" target=3D= "_blank" rel=3D"noopener">CVE-2026-78074</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains an authentication bypass vulnerability in its LDAP and Li= nOTP authentication components due to insufficient validation of user-suppl= ied credentials. The custom LdapAuthenticate and LinOTPAuthenticate compone= nts replace CakePHP's FormAuthenticate implementation but did not replicate=
its credential validation checks. As a result, empty or non-string values = could reach the underlying authentication mechanisms. In the LDAP authentic= ation path, an attacker able to identify a valid directory user's email add= ress could submit an empty password. The empty credential could be passed t=
o ldap_bind(), where an LDAP server accepting unauthenticated binds may ret= urn a successful result for a valid distinguished name combined with an emp=
ty password. MISP could consequently treat the attacker as the correspondin=
g authenticated directory user without verification of the user's password.=
The issue also affected the LinOTP authentication component. Invalid crede= ntial types were not rejected before being processed, and when mixed authen= tication was enabled, an empty password could be checked against a locally = stored MISP password hash. LDAP-provisioned MISP accounts could additionall=
y be created with an empty local password because account creation skipped = normal validation, resulting in a hash corresponding to an empty password. = This could permit authentication through the local fallback mechanism when = such an account was no longer resolved through LDAP. Successful exploitatio=
n could allow a remote unauthenticated attacker to impersonate an existing = MISP user. If the targeted account has administrative or other privileged p= ermissions, the attacker could gain corresponding access to sensitive threa= t-intelligence data, modify or delete information, alter configuration, or = perform other privileged operations. The patch resolves the vulnerability b=
y requiring authentication identifiers and passwords to be valid strings, r= ejecting empty passwords where they are not explicitly permitted, and assig= ning a randomly generated local password to LDAP-provisioned accounts inste=
ad of storing a hash derived from an empty password.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85216" target=3D= "_blank" rel=3D"noopener">CVE-2026-85216</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains an improper TLS certificate validation vulnerability in C= urlClient. The CurlClient::$verifyPeer property was not explicitly initiali= zed and therefore defaulted to null. When passed to cURL, this value effect= ively disabled TLS peer verification unless the calling code explicitly ena= bled it. As a result, HTTPS connections made through affected CurlClient in= stances could accept certificates that were not issued by a trusted certifi= cate authority. An attacker capable of intercepting or manipulating network=
traffic between a MISP instance and a remote HTTPS service could impersona=
te the remote endpoint and perform a man-in-the-middle attack. Successful e= xploitation could allow an attacker to observe sensitive information transm= itted by MISP, including authentication material or exchanged threat intell= igence, and to modify responses returned to the MISP instance. The impact d= epends on the functionality using CurlClient and the data exchanged with th=
e remote service. The patch enables TLS peer verification by default while = preserving explicit support for configured self-signed certificates. It als=
o corrects the self-signed certificate handling in SyncTool so that peer ve= rification is disabled only when no pinned CA certificate is configured.</t=
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85221" target=3D= "_blank" rel=3D"noopener">CVE-2026-85221</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains an authorization flaw in the OnDemand correlation engine = where correlations were calculated solely from matching attribute values wi= thout applying the distribution, sharing group, organization, or other acce= ss-control restrictions associated with the correlated attributes and event=
s. As a result, an authenticated user could receive correlation results ref= erring to attributes or events that the user was not authorized to access. = The vulnerable correlation collection path did not take the requesting user=
into account. The patch changes the correlation collector to accept the cu= rrent user and filters the resulting attribute identifiers through MISP's e= xisting fetchAttributesSimple() authorization logic, which evaluates event-=
, attribute-, object-, distribution-, and sharing-group-level restrictions = against the live data. The issue also affected paths relying on previously = stored correlation data. Because the OnDemand engine does not maintain the = stored correlation table, its denormalized access-control information could=
be stale. The patch therefore validates correlated attribute identifiers a= gainst the current ACLs before returning them and additionally applies norm=
al event visibility conditions when retrieving related events. An authentic= ated low-privileged user could exploit this issue by querying or creating a= ttributes that correlate with restricted MISP content, potentially learning=
information about otherwise inaccessible events or attributes.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85226" target=3D= "_blank" rel=3D"noopener">CVE-2026-85226</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in t=
he event attribute filtering query builder. The taggedAttributes and galaxy= AttachedAttributes URL parameters were inserted into the query-builder rule=
s without HTML escaping before being serialized as JSON and embedded inside=
a <script> element. Because JsonTool::encode() uses JSON_UNESCAPED_S= LASHES, an attacker-controlled value containing a closing </script> s= equence could terminate the surrounding script element and inject arbitrary=
HTML or JavaScript. For example, a specially crafted viewEventAttributes U=
RL could contain malicious content in one of the affected filter parameters=
. An attacker could exploit the vulnerability by convincing an authenticate=
d MISP user to follow a crafted URL. Successful exploitation would execute = attacker-controlled JavaScript in the security context of the MISP instance=
and with the privileges of the victim's authenticated browser session. Thi=
s could allow access to information available to the victim, modification o=
f data through authenticated requests, or other actions permitted by the vi= ctim's MISP permissions. The vulnerability is addressed by applying HTML es= caping with h() to both scalar and array values before they are inserted in=
to the DOM.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85227" target=3D= "_blank" rel=3D"noopener">CVE-2026-85227</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>A persistent unsafe URL injection vulnerability exists in the MISP dash= board ButtonWidget configuration. Dashboard widget URLs were validated only=
when the widget was rendered and were not validated when the configuration=
was saved. As a result, an authenticated user able to modify dashboard wid= get settings could persist arbitrary URL values, including URLs using the j= avascript: scheme, through either of the dashboard settings persistence pat= hs. A malicious javascript: URL stored in a dashboard button could potentia= lly result in client-side script execution in the MISP security context if = the value reached a rendering or navigation path without the existing runti=
me validation. Such execution could allow an attacker to perform actions wi=
th the privileges of the affected user or access information available to t= heir MISP session. The practical exploitability of this issue is reduced by=
the fact that MISP already applied URL validation at render time, which ne= utralized known malicious values before they were presented to the user. Th=
e vulnerability therefore represents a persistence-layer validation gap and=
a defense-in-depth weakness rather than evidence of a direct bypass of the=
existing rendering protection. The patch introduces a canonical url schema=
type and validates dashboard widget configuration before it is persisted t= hrough either settings save mechanism. ButtonWidget URLs must now be string=
s resolving to an absolute path on the current MISP instance or a full URL = with the same origin. Values using javascript:, external origins, malformed=
URL forms, and non-string values are rejected at save time.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85230" target=3D= "_blank" rel=3D"noopener">CVE-2026-85230</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>A cross-site request forgery (CSRF) vulnerability existed in the cullEm= ptyEvents action of MISP. The endpoint performed a state-changing and irrev= ersible operation while accepting HTTP GET requests. Because bodyless GET r= equests are not subject to CakePHP's CSRF validation, an attacker could cau=
se an authenticated MISP user with sufficient privileges to invoke the endp= oint simply by causing their browser to load a crafted URL, for example thr= ough an embedded image or other automatically requested resource. Successfu=
l exploitation triggers the deletion of published empty events. The deletio=
n is particularly significant because the operation uses skipBlocklist, mea= ning the removed events do not leave blocklist entries that could prevent o=
r track their subsequent synchronization. This can result in unintended and=
potentially irreversible deletion of MISP event records without explicit u= ser interaction. The vulnerability was addressed by restricting cullEmptyEv= ents to HTTP POST requests, ensuring that CakePHP's normal CSRF protections=
are applied to the operation.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85236" target=3D= "_blank" rel=3D"noopener">CVE-2026-85236</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>A vulnerability in MISP's email-based one-time password (OTP) authentic= ation flow allowed an attacker to perform an unrestricted number of OTP ver= ification attempts. The email_otp() endpoint did not apply brute-force prot= ection when validating submitted OTP values. An attacker who had reached th=
e OTP verification stage, for example after successfully providing a user's=
primary authentication credentials, could repeatedly submit candidate OTP = values while the same OTP remained valid. This significantly increased the = feasibility of guessing the OTP and bypassing the additional authentication=
factor, potentially resulting in unauthorized access to the affected user'=
s account. The issue was exacerbated by the fact that the OTP is associated=
with the user rather than with an individual pending login session, allowi=
ng multiple concurrent sessions to attempt guesses against the same valid O= TP. The patch integrates the existing MISP brute-force protection mechanism=
into the email OTP flow. Failed OTP attempts are now counted against the u= ser, further attempts are rejected once the configured threshold is reached=
, and the active OTP is invalidated when the attempt budget is exhausted. B= locklisted users are also prevented from requesting the generation of a fre=
sh OTP. In addition, OTP comparison now uses hash_equals() and validates th=
at the submitted value is a string.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85237" target=3D= "_blank" rel=3D"noopener">CVE-2026-85237</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains a session fixation vulnerability in the CustomAuth authen= tication (a custom configuration) flow. When a user was successfully authen= ticated through CustomAuth, MISP stored the authenticated user identity in = the existing session without first rotating the session identifier. As a re= sult, if an attacker can cause a victim to use a session identifier known t=
o the attacker before authentication, that same session identifier remains = valid after the victim successfully authenticates. The attacker could subse= quently reuse the fixed session identifier to access the victim's authentic= ated MISP session, potentially gaining the privileges associated with the v= ictim's account. The issue occurs because __customAuthentication() wrote th=
e authenticated user into the existing CakePHP session while the call to Se= ssion->renew() had previously been disabled. The patch restores session = identifier rotation when a new authentication occurs or when the authentica= ted user changes, while avoiding unnecessary session renewal on every reque= st.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85238" target=3D= "_blank" rel=3D"noopener">CVE-2026-85238</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>A vulnerability in MISP's event template handling allowed an authentica= ted user with permission to create or modify event templates to bypass vali= dation of the template definition field. The EventTemplate::beforeValidate(=
) method only performed semantic validation when the supplied definition wa=
s already represented as an array. If a caller instead supplied a pre-encod=
ed string, including malformed JSON or JSON representing an unexpected data=
type, the value bypassed validateDefinition() and only needed to satisfy t=
he generic notBlank validation rule. As a result, an invalid event template=
definition could be stored persistently in the database. When event templa= tes were subsequently retrieved, EventTemplate::afterFind() attempted to de= code the stored definition using JsonTool::decode() without handling decodi=
ng failures. A definition containing invalid JSON could therefore trigger a=
n exception during retrieval. Because the event template index is available=
to all authenticated users, a single malicious or malformed template could=
make the event template listing and other functionality relying on EventTe= mplate queries return HTTP 500 errors until the offending database row was = manually repaired. Valid JSON representing an unexpected type, rather than = the expected JSON object, could similarly result in invalid data reaching d= ownstream consumers. The vulnerability can therefore be exploited by a user=
capable of saving event templates to persist malformed template data and c= ause a persistent denial of service against event-template functionality fo=
r other users. The patch enforces that event template definitions must be s= upplied as structured objects before saving and always applies semantic val= idation. On retrieval, malformed JSON and definitions that do not decode to=
the expected structure are caught, logged, and replaced with an empty defi= nition, preventing a malformed database entry from breaking all event templ= ate queries. =C2=A0Poisoning doesn't seem reachable according to the lead d= eveloper.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85239" target=3D= "_blank" rel=3D"noopener">CVE-2026-85239</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>An authorization flaw in MISP allowed an authenticated user to submit a=
sharing_group_id without verifying that the user was authorized to use the=
referenced Sharing Group. In several attribute and Galaxy Cluster creation=
and editing workflows, validation of the submitted Sharing Group was perfo= rmed only when the request explicitly set the distribution field to 4 ("Sha= ring Group"). An attacker could therefore craft a request containing a shar= ing_group_id while omitting the distribution parameter, or otherwise avoidi=
ng the distribution =3D=3D 4 condition, causing the Sharing Group authoriza= tion check to be skipped. This could allow a user with permission to create=
or modify the affected MISP objects to associate data with a Sharing Group=
that they are not authorized to use. Depending on the affected object's ex= isting distribution settings and subsequent processing, this could bypass i= ntended information-sharing boundaries and result in unauthorized placement=
or distribution of data to members of another Sharing Group. The issue aff= ected attribute attachment and editing operations as well as Galaxy Cluster=
creation and editing. The fix ensures that authorization is performed when= ever a non-empty sharing_group_id is submitted, independently of the distri= bution parameter. It also centralizes the authorization decision in Sharing= Group::canUse() and explicitly rejects empty Sharing Group identifiers rath=
er than allowing them to be interpreted as an unrestricted query.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85533" target=3D= "_blank" rel=3D"noopener">CVE-2026-85533</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>An incorrect authorization vulnerability in MISP allowed authenticated = users to delete attributes from events despite lacking the required perm_mo= dify or perm_modify_org permissions. The affected attribute deletion paths = relied on organization membership checks performed by MispAttribute::delete= Attribute() but did not consistently enforce MISP's event modification auth= orization rules. Consequently, a user belonging to the organization associa= ted with an event could potentially delete individual attributes or perform=
bulk attribute deletion even when their assigned role was not authorized t=
o modify the event. This created an inconsistency between attribute editing=
and deletion: editing an attribute correctly used MISP's ACL::canModifyEve= nt() authorization logic, whereas the affected deletion operations could by= pass these permission checks. An authenticated attacker with access to an a= ffected MISP instance and membership in the organization owning an event co= uld exploit this flaw to remove attributes from that event, potentially cau= sing unauthorized modification or loss of threat intelligence data. The pat=
ch introduces a common authorization check for all affected deletion paths.=
Before deletion, MISP now resolves the associated events and verifies that=
the current user is authorized to modify each event using the same authori= zation mechanism used by normal event and attribute modification operations= .</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85538" target=3D= "_blank" rel=3D"noopener">CVE-2026-85538</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>MISP contains a cross-site request forgery (CSRF) vulnerability in the = sharing group quick-edit functionality. The addOrg, removeOrg, addServer, a=
nd removeServer actions share the __initialiseSGQuickEdit() helper, where t=
he HTTP method validation intended to restrict these operations to POST req= uests was commented out. As a result, these state-changing actions could be=
invoked using GET requests. An attacker could craft a URL targeting one of=
the affected actions and cause an authenticated MISP user with sufficient = privileges to request it, for example through a malicious link or embedded = web resource. Successful exploitation could modify the membership of a MISP=
sharing group without the victim intentionally performing the operation. D= epending on the action performed, an attacker could add or remove organisat= ions or servers from a sharing group, potentially granting unintended acces=
s to information distributed through that sharing group or disrupting legit= imate information sharing. The patch restores HTTP method enforcement centr= ally in __initialiseSGQuickEdit() by calling allowMethod(['post']), ensurin=
g that all four affected quick-edit operations require POST requests and ar=
e therefore subject to the application's normal protections for state-chang= ing requests.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85546" target=3D= "_blank" rel=3D"noopener">CVE-2026-85546</a></td>
</tr>
<td class=3D"vendor-product">misp--misp</td>
<td>A cross-site request forgery (CSRF) vulnerability exists in MISP due to=
form-security and CSRF protections being disabled based on whether an inco= ming request was identified as a REST request. MISP's REST detection can be=
influenced by request properties such as the URL suffix or the HTTP Accept=
header. Because Accept: application/json can be supplied by a cross-origin=
page without requiring a CORS preflight, an attacker could cause a request=
originating from another website to be treated as REST traffic. MISP would=
consequently disable its normal form-security and CSRF validation even tho= ugh the request was authenticated using the victim's existing browser sessi= on. An unauthenticated remote attacker could exploit this behavior by convi= ncing an authenticated MISP user to visit or interact with a malicious web = page. The attacker's page could then issue crafted requests to susceptible = state-changing MISP endpoints using the victim's privileges. Depending on t=
he permissions of the victim and the targeted endpoint, this could allow un= authorized modification, creation, publication, or removal of data and othe=
r state changes. The vulnerability originates from granting the form-securi=
ty exemption based on _isRest() rather than on the authentication mechanism=
used by the request. The patch changes this behavior so that CSRF and form= -security exemptions are granted only when the request actually carries a M= ISP API key. Session-authenticated REST-style requests remain subject to CS=
RF protection. The fix also introduces support for transmitting CSRF tokens=
through the X-CSRF-Token header for legitimate same-origin AJAX requests. = Such a header cannot normally be attached by a cross-origin page without tr= iggering a CORS preflight, preventing it from being used to reproduce the o= riginal attack.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85547" target=3D= "_blank" rel=3D"noopener">CVE-2026-85547</a></td>
</tr>
<td class=3D"vendor-product">MISP--UiBeta<br>=C2=A0</td>
<td>MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections= /view.ctp) performed a secondary query of member events by UUID without app= lying the caller's access control list (ACL). The CollectionsController::vi= ew() action correctly resolved collection element UUIDs through Event::fetc= hSimpleEvents($user, ...), which enforces per-user event ACL. However, the = view template independently re-queried the same UUIDs using only an Event.u= uid IN (...) condition, omitting the createEventConditions() authorization = filter. Because collection element UUIDs are stored without server-side aut= horization against the referenced event (CollectionElementsController::add(=
) accepts whatever UUID the collection owner posts), an authenticated user = with view access to a collection could retrieve full details of events they=
are not permitted to read. The exposed data included event identifiers, in= fo, dates, timestamps, creator organization, all event tags, and galaxy clu= sters (the latter attached via a cluster-scoped rather than event-scoped AC=
L check). This constitutes an authorization bypass at the presentation laye=
r, allowing horizontal privilege escalation across event boundaries within = the MISP instance.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86283" target=3D= "_blank" rel=3D"noopener">CVE-2026-86283</a></td>
</tr>
<td class=3D"vendor-product">MojoX--MojoX<br>=C2=A0</td> <td>MojoX::Authentication versions before 0.006 for Perl allow SAML authent= ication bypass because parse_assertion builds Net::SAML2::Binding::POST wit= hout a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2=
calls Net::SAML2::Binding::POST->new with no cacert, cert_text or ancho=
rs argument, then passes the returned XML to Net::SAML2::Protocol::Assertio= n->new_from_xml with the IdP signing certificate as cacert. In Net::SAML=
2 before 0.86 that certificate guards only encrypted assertions, so the sig= nature on an unencrypted assertion is checked against the certificate the r= esponse itself carries. An attacker starts a SAML login, then posts a respo= nse signed with a certificate of their own. The audience, InResponseTo and = timestamp checks that follow are all satisfiable by the attacker, so the re= sponse authenticates any NameID it carries.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86304" target=3D= "_blank" rel=3D"noopener">CVE-2026-86304</a></td>
</tr>
<td class=3D"vendor-product">N-central --N-central<br>=C2=A0</td>
<td>A vulnerability in the N-central internal API access control filter all= ows unauthorised access to internal APIs. This is fixed in N-central 2026.3=
HF3 and 2026.4</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86206" target=3D= "_blank" rel=3D"noopener">CVE-2026-86206</a></td>
</tr>
<td class=3D"vendor-product">N-central --N-central<br>=C2=A0</td>
<td>An authentication bypass in N-central < 2026.3 HF 3 leads to authent= ication bypass in internal only APIs</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86207" target=3D= "_blank" rel=3D"noopener">CVE-2026-86207</a></td>
</tr>
<td class=3D"vendor-product">N-central --N-central<br>=C2=A0</td>
<td>N-central is vulnerable to a pre-auth remote code execution This issue = affects N-central: before 2026.3.1.14.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-86218" target=3D= "_blank" rel=3D"noopener">CVE-2026-86218</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 2.36.2 contain an expression sandbox bypass vulnera= bility where free identifiers in spread, computed-key, switch-case, or clas= s-extension positions resolve against process globals. Authenticated users = with workflow-edit permission can mutate host objects through expression ev= aluation, with changes persisting process-wide until restart.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85165" target=3D= "_blank" rel=3D"noopener">CVE-2026-85165</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential=
references in the inline workflow JSON of nodes that execute an inline sub= -workflow (e.g., the Workflow Tool node). A shared-workflow editor, or any = user creating/updating a workflow via the REST API, Public API, or MCP, can=
persist a node referencing a credential they do not own. When the workflow=
is later executed under an identity that holds the credential, the inline = sub-workflow resolves the secret and can send it to an attacker-controlled = endpoint, resulting in credential exfiltration.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85166" target=3D= "_blank" rel=3D"noopener">CVE-2026-85166</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vu= lnerability in the Elasticsearch Document Get All and Google Cloud Firestor=
e Document Query operations, which build their JSON query by interpolating = expression values directly into the query string before parsing. A value co= ntaining quote and brace characters can close the intended field and introd= uce new query operators, turning an intended single-document lookup into a = full-collection read.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85167" target=3D= "_blank" rel=3D"noopener">CVE-2026-85167</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code = execution vulnerability in the Git node. The node reset a fixed list of com= mand-bearing configuration keys before each operation, but that list did no=
t cover the content-filter and merge-driver key families. A repository with=
local configuration setting one of those keys together with a matching att= ribute pattern causes git to execute the configured command during an ordin= ary Add, Commit, Checkout, or Pull operation. The command runs as the n8n p= rocess user.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85168" target=3D= "_blank" rel=3D"noopener">CVE-2026-85168</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression = sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied p= laceholder name without requiring it to be an own property and admitted res= erved keys; against a primitive input value it returned a live host-prototy=
pe reference. An attacker with workflow-build privilege can walk the protot= ype chain to the Function constructor and compile/execute arbitrary code in=
the main n8n process, leading to remote code execution.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85169" target=3D= "_blank" rel=3D"noopener">CVE-2026-85169</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content i=
n the Gmail (v1) and Brevo nodes to the mail composer without verifying it =
is a string. An authenticated user able to run a workflow can supply an exp= ression that resolves to an object carrying a path or href property, causin=
g the composer to read a local file accessible to the n8n process or fetch =
an internal URL (SSRF) and attach the result to the outgoing message.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85170" target=3D= "_blank" rel=3D"noopener">CVE-2026-85170</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure = vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes sen=
d their decrypted credentials to the authentication endpoint via the raw le= gacy HTTP helper outside any error handling, causing the plaintext secret t=
o be persisted in execution error data. Any authenticated user can read the=
plaintext secret from their own execution through the REST API, bypassing = the blank-value redaction enforced by the credentials API.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85171" target=3D= "_blank" rel=3D"noopener">CVE-2026-85171</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 2.34.1 contain a server-side request forgery vulner= ability in the legacy request helper function exposed to Code and Function = nodes. The validation logic checks the uri property for SSRF safety while t=
he underlying HTTP client uses the url property when both are present, allo= wing attackers to bypass validation by supplying a safe uri alongside a mal= icious url to access internal addresses.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85172" target=3D= "_blank" rel=3D"noopener">CVE-2026-85172</a></td>
</tr>
<td class=3D"vendor-product">n8n-io--n8n</td>
<td>n8n versions before 2.36.2 contain a missing per-project authorization = vulnerability in the Insights API routes that allows authenticated users wi=
th insights scopes to access workflow names and execution statistics across=
projects. Attackers can supply arbitrary projectId parameters to retrieve = sensitive project and workflow information from projects they have no membe= rship in.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85173" target=3D= "_blank" rel=3D"noopener">CVE-2026-85173</a></td>
</tr>
<td class=3D"vendor-product">Netgate--Pfsense Plus/CE</td>
<td>Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate p= fSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows=
remote authenticated attackers to inject arbitrary JavaScript via maliciou=
s content in an RSS feed title. The injected script executes in the browser=
of any authenticated user who views the dashboard, due to insufficient san= itization of feed title data before rendering in the widget.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-38961" target=3D= "_blank" rel=3D"noopener">CVE-2026-38961</a></td>
</tr>
<td class=3D"vendor-product">Netgate--pfSense Plus/CE</td>
<td>Cross Site Scripting vulnerability in Netgate pfSense Plus software ver= sions <=3D 26.03 pfSense CE software versions <=3D 2.8.1 allows a rem= ote attacker to execute arbitrary code via the captive_portal_status.widget= .php file</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78849" target=3D= "_blank" rel=3D"noopener">CVE-2026-78849</a></td>
</tr>
<td class=3D"vendor-product">nodejs--node</td>
<td>A flaw in Node.js HTTP client can cause a request desynchronization for=
Node.js-based forwarding proxies that rebuild outbound headers from the vi= sible `IncomingMessage` headers while piping the original body to a reused = backend connection. Node.js can omit headers beyond `maxHeadersCount` / `ma= xHeaderPairs` from `req.headers`, `req.rawHeaders`, and `req.headersDistinc= t`, while still using those omitted headers internally for HTTP message fra= ming. In particular, `Content-Length` can be hidden from userland while the=
request body is still delivered. This vulnerability affects all supported = release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-48932" target=3D= "_blank" rel=3D"noopener">CVE-2026-48932</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. From version 1.6.19 to before version 1.17.2, Nuclio's Dashboard buil=
d pipeline does not sanitize the spec.build.tempDir field before using it t=
o construct a shell command. When the Kaniko container builder is enabled, =
a user with function-create permission can inject shell metacharacters into=
this field and achieve arbitrary command execution inside the Dashboard co= ntainer, which runs with a Kubernetes service account holding wildcard acce=
ss to Secrets, Pods, Jobs, and Deployments in its namespace. This issue has=
been patched in version 1.17.2.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79754" target=3D= "_blank" rel=3D"noopener">CVE-2026-79754</a></td>
</tr>
<td class=3D"vendor-product">nuclio--nuclio</td>
<td>Nuclio is a "Serverless" framework for Real-Time Events and Data Proces= sing. Prior to version 1.17.4, the fix for unauthenticated OS command injec= tion in the nuclio dashboard on the local/Docker platform is incomplete. Th=
e fix added validateFunctionName for function names and common.Quote() for = the named-resource shell command path, but the list-all resource path (trig= gered when no specific resource name is provided) still interpolates the re= sourceNamespace parameter unquoted into a /bin/sh -c command string. An una= uthenticated attacker can inject shell metacharacters via the X-Nuclio-Func= tion-Namespace, X-Nuclio-Project-Namespace, or X-Nuclio-Function-Event-Name= space HTTP headers to achieve arbitrary command execution inside the dashbo= ard container. This issue has been patched in version 1.17.4.</td> <td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79756" target=3D= "_blank" rel=3D"noopener">CVE-2026-79756</a></td>
</tr>
<td class=3D"vendor-product">oasdiff--oasdiff</td>
<td>oasdiff is a command-line and Go package that compares and detects brea= king changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, = oasdiff did not enforce --allow-external-refs=3Dfalse (library: openapi3.Lo= ader.IsExternalRefsAllowed =3D false) when loading a spec from a git revisi=
on (the rev:path form, e.g. main:openapi.yaml). External $refs were resolve=
d on that load path even when external refs were explicitly disabled, so th=
e mitigation silently did not apply there. This issue has been patched in v= ersion 1.18.1.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53508" target=3D= "_blank" rel=3D"noopener">CVE-2026-53508</a></td>
</tr>
<td class=3D"vendor-product">oasdiff--oasdiff-action</td>
<td>oasdiff-action is a GitHub Action that detects breaking changes in Open= API specs and post a review on every pull request. Before version 0.0.51, t=
he oasdiff actions resolved external $refs in the OpenAPI spec by default (= allow-external-refs: true). When an action runs on a pull request whose spe=
c is attacker-controlled - most importantly fork pull requests on public re= positories - a $ref in that spec is fetched/read on the runner with no inte= raction required, enabling SSRF and disclosure of structured files on the r= unner. This issue has been patched in version 0.0.51.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53507" target=3D= "_blank" rel=3D"noopener">CVE-2026-53507</a></td>
</tr>
<td class=3D"vendor-product">oasys sysoa --oasys sysoa<br>=C2=A0</td>
<td>SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote = attacker to execute arbitrary code via the outtype parameter in the /outadd= resspaging path</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-67066" target=3D= "_blank" rel=3D"noopener">CVE-2025-67066</a></td>
</tr>
<td class=3D"vendor-product">OCS Inventory NG--Ocsreports</td>
<td>Unrestricted file upload vulnerability in the CSV file upload functiona= lity of the Ocsreports admin_info endpoint. The application validates files=
solely based on the name provided by the client, without properly checking=
their content or securely restricting the permitted file types. This allow=
s a user with administrator privileges to upload PHP files to a directory a= ccessible via the web interface. If the file is subsequently processed by t=
he server, an attacker could execute arbitrary code with the privileges of = the account used by the web service.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76174" target=3D= "_blank" rel=3D"noopener">CVE-2026-76174</a></td>
</tr>
<td class=3D"vendor-product">OCS Inventory NG--Ocsreports</td>
<td>SQL injection vulnerability in the del_check parameter of the /ocsrepor= ts/?function=3Dsave_query_list endpoint. Input provided by an authenticated=
user with operator privileges is incorporated into an SQL query without pr= oper parameterisation or validation, allowing the query to be manipulated a=
nd information to be extracted from the database using SQL injection techni= ques.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76175" target=3D= "_blank" rel=3D"noopener">CVE-2026-76175</a></td>
</tr>
<td class=3D"vendor-product">OCS Inventory NG--Ocsreports</td>
<td>SQL injection vulnerability in the endpoint /ocsreports/index.php?funct= ion=3Dadmin_double due to improper processing of the values in the ID field=
included in the selected_grp_dupli[] parameter. An authenticated user with=
operator privileges can manipulate these values to alter the SQL queries e= xecuted by the application and retrieve information stored in the database.= </td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76176" target=3D= "_blank" rel=3D"noopener">CVE-2026-76176</a></td>
</tr>
<td class=3D"vendor-product">OCS Inventory NG--Ocsreports</td>
<td>Server-Side Request Forgery (SSRF) vulnerability in the /ocsreports/?fu= nction=3Dtele_activate endpoint due to insufficient validation of the HTTPS= _SERV and FILE_SERV parameters. An authenticated user with operator privile= ges can provide arbitrary values for these parameters, causing the OCS Inve= ntory server to make HTTP/HTTPS requests to external systems or internal re= sources, which could allow access to internal network services or metadata = resources of cloud services.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76177" target=3D= "_blank" rel=3D"noopener">CVE-2026-76177</a></td>
</tr>
<td class=3D"vendor-product">OCS Inventory NG--Ocsreports</td>
<td>A stored Cross-Site Scripting (XSS) vulnerability in the notification t= emplate functionality of the endpoint /ocsreports/?function=3Dnotification.=
A user with administrator privileges can input malicious HTML content whic=
h is subsequently stored and displayed without proper sanitisation when oth=
er administrators access the template customisation view, allowing JavaScri=
pt code to be executed within the application's security context and potent= ially compromising the sessions of other users with administrative privileg= es.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-76178" target=3D= "_blank" rel=3D"noopener">CVE-2026-76178</a></td>
</tr>
<td class=3D"vendor-product">omgovich--colord</td>
<td>Colord is a tiny yet powerful tool for high-performance color manipulat= ions and conversions. Prior to 2.9.4, synchronous CSS color string matchers=
in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorMo= dels/hwbString.ts, src/colorModels/lchString.ts, and src/colorModels/cmykSt= ring.ts use the ambiguous numeric regular expression ([+-]?\d*.?\d+), allow= ing the same digits to be divided between overlapping quantifiers in quadra= tically many ways when malformed input is rejected. An attacker who can sup= ply an unbounded color string to colord(), getFormat(), isEqual(), mix(), o=
r contrast(), including through a request body, JSON field, or uploaded sty= lesheet, can block the processing thread with a multi-kilobyte payload. The=
affected matchers are parseRgbaString, parseHslaString, parseHwbaString, p= arseLchaString, and parseCmykaString. This issue is fixed in version 2.9.4.= </td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85062" target=3D= "_blank" rel=3D"noopener">CVE-2026-85062</a></td>
</tr>
<td class=3D"vendor-product">Open5GS --Open5GS v2.7.7<br>=C2=A0</td>
<td>Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacke=
r to cause a denial of service via the ogs_sbi_time_parse() function</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75438" target=3D= "_blank" rel=3D"noopener">CVE-2026-75438</a></td>
</tr>
<td class=3D"vendor-product">OpenNebula Systems--OpenNebula</td>
<td>A vulnerability relating to incorrect access control in OpenNebula by O= penNebula Systems, affecting all versions prior to 7.4. This vulnerability = could allow an authenticated user with basic permissions to execute command=
s on virtual machines belonging to other users via the `one.vm.exec` functi= on, without proper verification of access permissions. To exploit the vulne= rability, it is only necessary to know the virtual machine's identifier and=
for qemu-agent to be enabled on that machine. Exploitation could allow com= mands to be executed and compromise the confidentiality, integrity and avai= lability of the affected virtual machines.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84165" target=3D= "_blank" rel=3D"noopener">CVE-2026-84165</a></td>
</tr>
<td class=3D"vendor-product">OptimiDoc--OptimiDoc Server</td>
<td>OptimiDoc Server (On-Premise) stores credentials for external services =
in cleartext. An authenticated administrator can view previously configured=
service passwords, including SMTP, FTP (for scan delivery), Active Directo=
ry (for user list import), and SharePoint credentials, in cleartext via the=
web administration panel page source, allowing exposure of sensitive third= -party authentication data. This issue was fixed in version=C2=A026.08</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-15933" target=3D= "_blank" rel=3D"noopener">CVE-2026-15933</a></td>
</tr>
<td class=3D"vendor-product">Parrot-- AR.Drone<br>=C2=A0</td>
<td>Parrot AR.Drone 1 and AR.Drone 2 are vulnerable to Denial of Service. T=
he Parrot AR.Drone platform is vulnerable to Wi-Fi deauthentication attack,=
allowing remote and unauthenticated attackers to disconnect drone from con= troller during mid-flight.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2021-44319" target=3D= "_blank" rel=3D"noopener">CVE-2021-44319</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit 673b978, a remote out-of-bounds read and write can = occur in the SDP negotiator when the remote payload-type map maintenance fe= ature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg=
.c uses payload-type numbers taken from a remote SDP offer or answer to ind=
ex fixed-size internal tables without sufficient bounds validation, so a cr= afted remote SDP can cause memory access outside those tables. The practica=
l impact is memory corruption and denial of service; code execution is not = demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOT= E_PT_MAP is enabled. The default is disabled, so default builds are not aff= ected; the feature is an interoperability option that integrating products = may enable. This issue has been patched via commit 673b978.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57159" target=3D= "_blank" rel=3D"noopener">CVE-2026-57159</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_gener= ic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serial= izes generic array headers (such as Allow, Require, Supported, and Unsuppor= ted). Under certain output-buffer boundary conditions the function can writ=
e one byte past the end of the buffer. This is reachable mainly in applicat= ions that parse and re-serialize incoming SIP requests - for example a prox=
y, SBC, or B2BUA - where a remote peer can influence the serialized message=
. The out-of-bounds write is a single fixed byte; code execution and inform= ation disclosure are not demonstrated, and in typical pool-based allocation=
s the byte falls within allocation slack. This issue has been patched via c= ommit d6a0e7f.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57160" target=3D= "_blank" rel=3D"noopener">CVE-2026-57160</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit acc03b5, a stack buffer overflow exists in PJSUA wh=
en processing Service-Route headers in a registration response (update_serv= ice_route() in pjsua_acc.c). This affects applications that register using = the PJSUA/PJSUA2 account API (the default registration path). The Service-R= oute URIs from a 2xx response to REGISTER are stored into a fixed-size arra=
y without bounding the number of headers; a registrar that returns an exces= sive number of Service-Route headers can write past the end of the array on=
the stack. The values written are internal pointers rather than arbitrary = data, so the most likely impact is unexpected application termination (deni=
al of service), though memory corruption cannot be excluded. The malicious = response may come from a compromised or malicious registrar, or - over unpr= otected transports - a spoofed response. This issue has been patched via co= mmit acc03b5.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57161" target=3D= "_blank" rel=3D"noopener">CVE-2026-57161</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP= /SDES media transport when processing a=3Dcrypto attributes during SDP offe= r/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applica= tions with SRTP enabled (use_srtp optional or mandatory, using SDES keying)=
. During media negotiation, the crypto attributes from the remote SDP are c= ollected into a fixed-size array without bounding their number; a remote pe=
er that includes an excessive number of a=3Dcrypto attributes in a single m= edia description can write past the end of that array on the stack. This is=
reachable from an incoming SIP INVITE during offer/answer, before applicat= ion-level authentication. Impact may range from unexpected application term= ination to control flow hijack/memory corruption. Applications that do not = enable SRTP are not affected. This issue has been patched via commit a1b707= c.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57162" target=3D= "_blank" rel=3D"noopener">CVE-2026-57162</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuT=
LS TLS backend when parsing the Subject Alternative Name extension of a pee=
r certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds = are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.fra= mework builds are not affected. While extracting certificate information af= ter a TLS handshake, an incorrect buffer-size value can cause an oversized = SubjectAltName entry to be written past the end of a fixed-size stack buffe=
r. A network-positioned attacker presenting a crafted certificate - a malic= ious server to a connecting client, or a malicious client to a server that = requests certificates - can trigger this during the TLS handshake, before a=
ny SIP-level authentication. Impact may range from unexpected application t= ermination to control flow hijack/memory corruption. This issue has been pa= tched via commit c4a151a.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57163" target=3D= "_blank" rel=3D"noopener">CVE-2026-57163</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB= -UTIL HTTP client (http_client.c) when buffering an HTTP response body. Thi=
s affects applications that use the PJLIB-UTIL HTTP client to receive a who=
le response body at once (a completion callback with no incremental on_data= _read callback). When growing the response buffer, an incorrect size calcul= ation based on the server-supplied Content-Length can leave the buffer too = small, causing response data to be written past the end of the allocation. =
A malicious or man-in-the-middle HTTP server can trigger this with a crafte=
d response; impact may range from unexpected application termination to mem= ory corruption. Applications that consume the response incrementally (via o= n_data_read), or that only connect to trusted servers, are not affected. Th=
is issue has been patched via commit 8d5956a.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57164" target=3D= "_blank" rel=3D"noopener">CVE-2026-57164</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLI= B-UTIL telnet CLI front-end when redrawing the command line during history = recall (handle_up_down() in cli_telnet.c). This affects only applications t= hat enable the telnet CLI front-end (same gating as the related CLI issue).=
The line-redraw sequence for a recalled history entry can accumulate more = data than a fixed-size stack buffer holds, which may lead to application te= rmination. Exploitation requires access to the unauthenticated telnet CLI, = which already permits arbitrary CLI commands, so the additional impact is l= imited. Applications that do not enable the telnet CLI front-end are not af= fected. This issue has been patched via commit 628b716.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57165" target=3D= "_blank" rel=3D"noopener">CVE-2026-57165</a></td>
</tr>
<td class=3D"vendor-product">pjsip--pjproject</td>
<td>PJSIP is a free and open source multimedia communication library writte=
n in C. Prior to commit 4472a31, a stack buffer overflow exists in the PJLI= B-UTIL telnet CLI front-end when rendering feedback for an entered command = line. Several command-line handling paths write an attacker-influenced amou=
nt of data into fixed-size buffers without sufficient bounds checking, so a=
long command line can overflow them. This affects only applications that e= nable the telnet CLI front-end (e.g. pj_cli_telnet_create() / --cli-telnet-= port). The telnet CLI is an interactive administration interface with no au= thentication, so any client able to reach it can already issue arbitrary CL=
I commands. A malformed or overly long command line can overflow a fixed-si=
ze stack buffer while rendering command-line feedback, which may lead to ap= plication termination. Because reaching this code already requires access t=
o the unauthenticated CLI, the impact beyond that existing access is limite=
d. Applications that do not enable the telnet CLI front-end are not affecte=
d. This issue has been patched via commit 4472a31.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-57166" target=3D= "_blank" rel=3D"noopener">CVE-2026-57166</a></td>
</tr>
<td class=3D"vendor-product">Power Job--PowerJob</td>
<td>PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote c= ode execution vulnerability in the /friend/process endpoint of the Server-W= orker transport layer</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75429" target=3D= "_blank" rel=3D"noopener">CVE-2026-75429</a></td>
</tr>
<td class=3D"vendor-product">pretix--venueless</td>
<td>The default docker image shipped for Venueless did not properly ensure = that uploaded SVG files could not be delivered with executable JavaScript c= ontent. A valid Content Security Policy is now set.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82838" target=3D= "_blank" rel=3D"noopener">CVE-2026-82838</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.15.=
0, an attacker can craft a PDF that causes long runtimes when the pypdf/_ut= ils.py function read_until_whitespace reads a stream containing a long run =
of bytes without whitespace. The function repeatedly performs immutable byt=
es concatenation in a one-byte loop, causing quadratic processing cost for = the long non-whitespace input. This issue is fixed in version 6.15.0.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82398" target=3D= "_blank" rel=3D"noopener">CVE-2026-82398</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.16.=
0, an attacker can craft a PDF whose cyclic tree structure causes pypdf/gen= eric/_data_structures.py TreeObject.insert_child to follow /Next links inde= finitely when a writing code path inserts a child, producing an infinite lo= op. This issue is fixed in version 6.16.0.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84309" target=3D= "_blank" rel=3D"noopener">CVE-2026-84309</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.16.=
1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outlin=
e to consume long runtimes and large amounts of memory when retrieving docu= ment outlines with large numbers of entries or deeply nested reused paths b= ecause the traversal lacked global entry-count and nesting-depth limits. Th=
is issue is fixed in version 6.16.1.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84310" target=3D= "_blank" rel=3D"noopener">CVE-2026-84310</a></td>
</tr>
<td class=3D"vendor-product">py-pdf--pypdf</td>
<td>pypdf is a free and open-source pure-python PDF library. Prior to 6.16.=
1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extra= ct_text and PageObject.extract_xform_text to traverse a directed acyclic gr= aph of reused form XObjects in which each form invokes a child multiple tim= es, creating exponentially many traversal paths and causing long runtimes a=
nd large memory consumption. This issue is fixed in version 6.16.1.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84311" target=3D= "_blank" rel=3D"noopener">CVE-2026-84311</a></td>
</tr>
<td class=3D"vendor-product">Robots--Robots</td>
<td>Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbou= nded outbound DNS queries per validation via a forward-confirmation loop th=
at does not bound the names it queries. _check_dns issues one PTR query for=
the client address, keeps the returned names matching the rule's domain, a=
nd issues a forward query for each until one resolves back to that address.=
Nothing bounds that list, and a client controls the reverse zone for its o=
wn address, so it chooses how many names the PTR answer holds. Net::DNS ref= etches a truncated answer over TCP by default, so the 512-byte UDP payload = does not cap it either. Any client whose User-Agent matches a rule with a d= omain reaches _check_dns. Each forward name is distinct and client-chosen, =
so every query misses the local cache and is resolved against the authorita= tive servers for that domain. The queries are synchronous, so the caller is=
held until all of them answer or time out.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82309" target=3D= "_blank" rel=3D"noopener">CVE-2026-82309</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--1756-ENBT Module</td>
<td>A denial-of-service security issue exists in the affected product. The = security issue stems from a crafted CIP packet being sent crashing the modu= le. The device requires a restart to recover.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84235" target=3D= "_blank" rel=3D"noopener">CVE-2026-84235</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--Arena</td>
<td>A remote code execution security issue exists in the affected products = when parsing DOE files that could allow a remote attacker to write past the=
end of an allocated object and execute code within the context of the curr= ent process. To exploit this vulnerability, a legitimate user must visit a = malicious page or open a malicious file.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-6071" target=3D"= _blank" rel=3D"noopener">CVE-2026-6071</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--ArmorStart LT</td> <td>Multiple stored cross-site scripting security issues exist within Armor= Start=C3=82=C2=AE LT. Stored XSS occurs when user input is not properly san= itized and is stored on the server, allowing an attacker to inject maliciou=
s scripts that will be executed when other users access the affected page.<=
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19471" target=3D= "_blank" rel=3D"noopener">CVE-2026-19471</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--ArmorStart LT</td>
<td>A denial-of-service security issue exists within ArmorStart=C3=82=C2=AE=
LT. The security issue stems from improper handling of a crafted HTTP PUT = request sent to the embedded web server. This can result in a loss of web s= erver availability</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-19472" target=3D= "_blank" rel=3D"noopener">CVE-2026-19472</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--CompactLogix 5380 / Contr= olLogix 5580</td>
<td>A denial-of-service security issue exists in the affected Logix platfor=
ms listed in the table above. The security issue stems from improper valida= tion of input length during CIP message processing. This can result in a ma= jor nonrecoverable fault (MNRF), requiring a power cycle to recover</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9637" target=3D"= _blank" rel=3D"noopener">CVE-2026-9637</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--ControlFLASH</td>
<td>A security issue exists within ControlFLASH=C3=A2=E2=80=9E=C2=A2, where=
the installer grants write permissions to the "Everyone" group on a produc=
t installation directory. This could allow arbitrary code execution, result= ing in an attacker being given the ability to run any commands or code of t=
he attacker's choice on a target machine at the logged-in user's permission=
level.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12663" target=3D= "_blank" rel=3D"noopener">CVE-2026-12663</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--DataEdgePlatform DataMosa=
ix Private Cloud</td>
<td>A data exposure vulnerability exists in the affected product. There are=
hardcoded links in the source code that lead to JSON files that can be rea= ched without authentication. If exploited, a threat actor could view custom=
er data.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-7952" target=3D"= _blank" rel=3D"noopener">CVE-2024-7952</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--DataEdgePlatform DataMosa=
ix Private Cloud</td>
<td>A vulnerability exists in the affected products that allows a threat ac= tor to create a project and become the administrator for it. If exploited, =
a threat actor could create, modify, and delete their own project.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-7953" target=3D"= _blank" rel=3D"noopener">CVE-2024-7953</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--DataMosaix Private Cloud<=
<td>A vulnerability exists in the affected products that allows a threat ac= tor to gain access to user's projects. To exploit this vulnerability the th= reat actor must have basic user privileges. If exploited, the threat actor = can modify and delete the project.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-7956" target=3D"= _blank" rel=3D"noopener">CVE-2024-7956</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FactoryTalk Activation Ma= nager</td>
<td>A privilege escalation security issue exists within FactoryTalk=C3=82= =C2=AE Activation Manager. The security issue stems from custom actions in = the installer that spawn visible console windows running with SYSTEM privil= eges during installation or repair operations. An authenticated attacker wi=
th Windows credentials could hijack these console windows to obtain a SYSTE= M-level command prompt, allowing full access to all files, processes, and s= ystem resources.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-16675" target=3D= "_blank" rel=3D"noopener">CVE-2026-16675</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FactoryTalk Historian Mac= hine Edition</td>
<td>A security issue exists within FactoryTalk=C3=82=C2=AE Historian Machin=
e Edition. An attacker with low-level authentication could exploit this vul= nerability to achieve remote code execution on the affected device.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2025-12768" target=3D= "_blank" rel=3D"noopener">CVE-2025-12768</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--FactoryTalk Historian Mac= hine Edition</td>
<td>A denial-of-service security issue exists within FactoryTalk=C3=82=C2=
=AE Historian Machine Edition.=C2=A0 A network adjacent attacker who is aut= henticated could send crafted requests to the web interface, resulting in b= uffer overflow conditions that may cause the device to crash and become unr= esponsive.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-12661" target=3D= "_blank" rel=3D"noopener">CVE-2026-12661</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--Redundancy Module Configu= ration Tool</td>
<td>A security issue exists within the Redundancy Module Configuration Tool=
. The RM3ConfigTool.exe binary searches directories in the system path for =
a required DLL, and one or more of these directories may be writable by sta= ndard (non-administrator) users due to incorrect default permissions. If a = local attacker places a malicious DLL in such a directory and an administra= tor subsequently runs the tool, the malicious DLL is loaded into the elevat=
ed process and executes with Administrator/SYSTEM privileges.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9633" target=3D"= _blank" rel=3D"noopener">CVE-2026-9633</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--Redundancy Module Configu= ration Tool</td>
<td>A security issue exists within the Redundancy Module Configuration Tool=
. The RMConfigTool.exe binary searches directories in the system path for a=
required DLL, and one or more of these directories may be writable by stan= dard (non-administrator) users due to incorrect default permissions. If a l= ocal attacker places a malicious DLL in such a directory and an administrat=
or subsequently runs the tool, the malicious DLL is loaded into the elevate=
d process and executes with Administrator/SYSTEM privileges.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9634" target=3D"= _blank" rel=3D"noopener">CVE-2026-9634</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--RSLinx Classic</td>
<td>A denial-of-service security issue exists within RSLinx=C3=82=C2=AE Cla= ssic. The security issue stems from improper handling of a malformed packet=
. A crafted CIP packet can cause the RSLinx=C3=82=C2=AE Classic service to = crash, requiring a restart of the service to recover</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9621" target=3D"= _blank" rel=3D"noopener">CVE-2026-9621</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--RSLinx Classic</td>
<td>A denial-of-service security issue exists within RSLinx=C3=82=C2=AE Cla= ssic. A crafted CIP packet targeting the Forward Close service can cause th=
e RSLinx=C3=82=C2=AE Classic service to crash, requiring a restart of the s= ervice to recover.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9622" target=3D"= _blank" rel=3D"noopener">CVE-2026-9622</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--RSLinx Classic</td>
<td>A denial-of-service security issue exists within RSLinx=C3=82=C2=AE Cla= ssic. A crafted CIP packet can cause the RSLinx=C3=82=C2=AE Classic service=
to crash due to insufficient data length validation, requiring a=C2=A0 res= tart of the service to recover.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9624" target=3D"= _blank" rel=3D"noopener">CVE-2026-9624</a></td>
</tr>
<td class=3D"vendor-product">Rockwell Automation--RSLinx Classic</td>
<td>A denial-of-service security issue exists within RSLinx=C3=82=C2=AE Cla= ssic. A crafted CIP packet with an oversized embedded message request can c= ause the RSLinx=C3=82=C2=AE Classic service to crash, requiring a restart o=
f the service to recover.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-9625" target=3D"= _blank" rel=3D"noopener">CVE-2026-9625</a></td>
</tr>
<td class=3D"vendor-product">Roskus--Prospero Flow CRM</td>
<td>Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET = /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 al= lows an unauthenticated attacker to confirm any order on behalf of an authe= nticated user by directing them to a crafted page. Laravel's VerifyCsrfToke=
n middleware enforces CSRF tokens only on POST, PUT, PATCH, and DELETE requ= ests; the Route::get declaration leaves this state-changing action unprotec= ted. Session cookies configured with SameSite=3DLax are automatically inclu= ded in top-level cross-site navigation, so a single link click triggers Ord= erConfirmController::confirm() and transitions the target order from pendin=
g to confirmed without user authorization. Because order numbers are sequen= tial integers, an attacker can enumerate and confirm all existing orders in=
a single automated sweep.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82911" target=3D= "_blank" rel=3D"noopener">CVE-2026-82911</a></td>
</tr>
<td class=3D"vendor-product">Sage--Employee Self Service</td>
<td>A path traversal vulnerability exists in Sage Employee Self Service's c= ustom logo functionality due to improper validation of file path parameters=
. By leveraging directory traversal sequences and their encoded variants, a=
n attacker may bypass directory restrictions and access files outside the a= pplication's intended file system scope. Successful exploitation would requ= ire knowledge of valid file names and paths. Depending on the privileges of=
the affected component, exploitation could result in the disclosure of sen= sitive information, including configuration files, environment settings, ap= plication assets, and log data. The vulnerability has been remediated throu=
gh enhanced path validation and secure path resolution controls that preven=
t access to unauthorised locations.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67395" target=3D= "_blank" rel=3D"noopener">CVE-2026-67395</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 0.12.13, MCPB File Upload Handler extracts =
a ZIP file and reads manifest.json from it. The name field in the manifest =
is directly concatenated into a file path (line 107) without any sanitizati=
on or path traversal character validation. An attacker can craft a maliciou=
s MCPB file where manifest.name is set to something like ../../../etc/malic= ious, causing the file to be extracted to an arbitrary location on the file=
system. The cleanupOldMcpbServer function (line 110) also uses the unsanit= ized name, potentially allowing deletion of arbitrary directories. This iss=
ue has been patched in version 0.12.13.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79743" target=3D= "_blank" rel=3D"noopener">CVE-2026-79743</a></td>
</tr>
<td class=3D"vendor-product">samanhappy--mcphub</td>
<td>MCPHub is a unified hub for centrally managing and dynamically orchestr= ating multiple MCP servers/APIs into separate endpoints with flexible routi=
ng strategies. Prior to version 1.0.32, MCPHub's SSRF guard in src/utils/ss= rf.ts uses a custom isBlockedIpv6 function that only checks for loopback, l= ink-local, unique-local, IPv4-mapped, and IPv4-compatible IPv6 addresses. I= Pv6 transition address families -- NAT64 (64:ff9b::/96), 6to4 (2002::/16), = and Teredo (2001::/32) -- are not checked. An attacker who can specify a UR=
L for an MCP server connection can encode a private IPv4 address inside one=
of these IPv6 forms to bypass the SSRF guard and reach internal infrastruc= ture. This issue has been patched in version 1.0.32.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79749" target=3D= "_blank" rel=3D"noopener">CVE-2026-79749</a></td>
</tr>
<td class=3D"vendor-product">Sauter--modu680-AS</td>
<td>A service running on the affected products contains a potential Time-of= -Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attac= ker could exploit this race condition to bypass intended security controls.=
This may result in the execution of unauthorized code.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78319" target=3D= "_blank" rel=3D"noopener">CVE-2026-78319</a></td>
</tr>
<td class=3D"vendor-product">Schneider Electric--EcoStruxure OPC UA Server = Expert</td>
<td>CWE-770: Allocation of Resources Without Limits or Throttling vulnerabi= lity exists that could cause denial of service of the OPC UA communication = platform when a large number of OPC UA requests are sent to the platform.</=
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2024-10085" target=3D= "_blank" rel=3D"noopener">CVE-2024-10085</a></td>
</tr>
<td class=3D"vendor-product">Schneider Electric--NetBotz 5 - 750/755</td> <td>CWE-78: Improper Neutralization of Special Elements used in an OS Comma=
nd ('OS Command Injection') vulnerability exists that could cause execution=
of Linux Operating system commands when a system back up is restored that = has been maliciously modified.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13336" target=3D= "_blank" rel=3D"noopener">CVE-2026-13336</a></td>
</tr>
<td class=3D"vendor-product">Schneider Electric--NetBotz 5 - 750/755</td> <td>CWE-564: SQL Injection: Hibernate vulnerability exists that could allow=
the injection of a malicious HQL query in the NetBotz database when a mali= cious user is logged into the NetBotz via the web-service interface or webu= i.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13337" target=3D= "_blank" rel=3D"noopener">CVE-2026-13337</a></td>
</tr>
<td class=3D"vendor-product">Schneider Electric--PowerChute Serial Shutdown= </td>
<td>CWE-307: Improper Restriction of Excessive Authentication Attempts vuln= erability exists that could allow an attacker to gain unauthorized access t=
o a user account by performing an arbitrary number of authentication attemp=
ts when redirect handling is disabled.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13348" target=3D= "_blank" rel=3D"noopener">CVE-2026-13348</a></td>
</tr>
<td class=3D"vendor-product">seacms --seacms v13.6<br>=C2=A0</td>
<td>An authenticated remote code execution (RCE) vulnerability in the admin= _config.php component of seacms v13.6 allows attackers to execute arbitrary=
code via a crafted POST request.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79423" target=3D= "_blank" rel=3D"noopener">CVE-2026-79423</a></td>
</tr>
<td class=3D"vendor-product">SEPPmail AG--Secure Email Gateway</td> <td>SEPPmail Secure Email Gateway before 15.0.7 contains a command injectio=
n vulnerability that allows authenticated administrators to execute command=
s with elevated privileges.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84830" target=3D= "_blank" rel=3D"noopener">CVE-2026-84830</a></td>
</tr>
<td class=3D"vendor-product">SEPPmail AG--SEPPmail Secure Email Gateway (SE= G)</td>
<td>SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged = session before required multi-factor authentication enrollment is completed=
. An attacker with the password for an MFA-required but unenrolled account = can access protected functionality without providing a second factor.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84831" target=3D= "_blank" rel=3D"noopener">CVE-2026-84831</a></td>
</tr>
<td class=3D"vendor-product">SEPPmail AG--SEPPmail Secure Email Gateway (SE= G)</td>
<td>SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-contr= olled data in a privileged REST import workflow without adequate validation=
. An attacker with a privileged API token can execute arbitrary commands wi=
th "nobody" privileges.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84832" target=3D= "_blank" rel=3D"noopener">CVE-2026-84832</a></td>
</tr>
<td class=3D"vendor-product">Shizen Connect Inc.--ShizenBox2 (dev-conf)</td=
<td>An improper physical access control issue exists in ShizenBox2 (dev-con= f). If exploited, an attacker with physical access to the product may execu=
te bootloader commands without authentication.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80253" target=3D= "_blank" rel=3D"noopener">CVE-2026-80253</a></td>
</tr>
<td class=3D"vendor-product">Shizen Connect Inc.--ShizenBox2 (edge-app)</td=
<td>Authorization bypass through user-controlled key issue exists in Shizen= Box2 (edge-app). If exploited, an attacker who can log in to the product ma=
y change the other user's password.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-80254" target=3D= "_blank" rel=3D"noopener">CVE-2026-80254</a></td>
</tr>
<td class=3D"vendor-product">Slack--Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. P= rior to version 0.3.7, two related authorization gaps let a host that shoul=
d no longer be trusted obtain a fresh, valid Nebula certificate, because ne= bula-mgmt does not re-evaluate revocation/authorization state at certificat=
e issuance time - only at poll time. Firstly, the blocklist is not enforced=
at sign / re-enroll time. internal/api/enroll.go:128 calls caMgr.Sign(...)=
without consulting the blocklist. The blocklist is only checked in the pol=
l path (internal/api/updates.go:57, fingerprintInBlocklist). The blocklist =
is keyed by certificate fingerprint (internal/store/sqlite.go), so a re-enr= ollment produces a new fingerprint that is not in the blocklist. Secondly, = renewal does not re-validate operator / CA status. Auto-renewal at poll tim=
e (internal/api/updates.go:285-319, signHostCert) reads host.Name, host.Gro= ups, host.NebulaIPs from the DB and re-signs without checking whether the o= wning operator is still active or the CA still valid. DisableOperator (inte= rnal/store/sqlite_operators.go) revokes sessions and API keys but does not = retire the operator's CAs, and pki/signer.go checks only CA cert time-expir=
y, not operator/CA status. This issue has been patched in version 0.3.7.</t=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53602" target=3D= "_blank" rel=3D"noopener">CVE-2026-53602</a></td>
</tr>
<td class=3D"vendor-product">Slack--Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. P= rior to version 0.3.8, Operator session tokens are stored in plaintext in t=
he operator_sessions table (the token column is the PRIMARY KEY). The sessi=
on token is a 32-byte random hex value sent directly in a cookie and valid = for 24 hours. Anyone who can read the database (backup, snapshot, file copy=
, or SQL-level disclosure) obtains every active session token and can hijac=
k operator sessions directly, with no further authentication. This issue ha=
s been patched in version 0.3.8.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53603" target=3D= "_blank" rel=3D"noopener">CVE-2026-53603</a></td>
</tr>
<td class=3D"vendor-product">Slack--Nebula mesh VPN<br>=C2=A0</td> <td>nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. P= rior to version 0.3.8, the web handler renderMobileBundle passes the real *= pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.Loa= dByID decrypts the CA's ed25519 private key into a *pki.CAManager, but Buil=
d never calls CAManager.Wipe() on any return path. As a result, when a mobi= le-bundle request goes through the web UI and Build returns - especially on=
error (missing network, invalid prefix, DB error, signing failure) - the p= laintext CA private key remains on the Go heap, unwiped, until garbage coll= ection. An attacker able to read process memory (core dump, swap, memory-sc= raping) can recover the CA signing key, which would allow minting arbitrary=
host certificates for the mesh. The API handler already does this correctl=
y: it loads the CAManager, defer caMgr.Wipe(), and wraps it in caManagerRes= olver. Only the web path is affected. This issue has been patched in versio=
n 0.3.8.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53604" target=3D= "_blank" rel=3D"noopener">CVE-2026-53604</a></td>
</tr>
<td class=3D"vendor-product">smarty-php--smarty</td>
<td>Smarty is a template engine for PHP, facilitating the separation of pre= sentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depe= nding on the release line, Smarty's {fetch} handling in libs/plugins/functi= on.fetch.php and src/FunctionHandler/Fetch.php used Security::isTrustedUri(=
) to validate only the initial remote URL against trusted_uri when a securi=
ty policy was active. For resources handled by file_get_contents(), includi=
ng HTTPS URLs, PHP followed HTTP redirects by default. An attacker who coul=
d supply or influence a fetch target and had an open redirect on a trusted = host could redirect the request to an attacker-chosen internal endpoint, by= pass the trusted_uri allowlist, and perform server-side request forgery. Th=
is issue is fixed in versions 4.5.7 and 5.8.2.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-62993" target=3D= "_blank" rel=3D"noopener">CVE-2026-62993</a></td>
</tr>
<td class=3D"vendor-product">Softing--smartLink HW-PN</td>
<td>Missing release of memory after effective lifetime vulnerability in Sof= ting smartLink allows resource leak exposure. This issue affects smartLink = HW-PN: from 1.04 before 1.10.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-13148" target=3D= "_blank" rel=3D"noopener">CVE-2026-13148</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository 3</td>
<td>A user account with permission to deploy artifacts to a hosted Maven re= pository could upload a POM file containing an oversized metadata field. Th=
is causes future attempts to list or browse that repository's components to=
permanently fail until an administrator repairs the underlying data. Only = the targeted repository is affected; other repositories and overall server = health remain unaffected.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77121" target=3D= "_blank" rel=3D"noopener">CVE-2026-77121</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository 3</td>
<td>An authorization flaw in the REST API repository details endpoint (GET = /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repositor=
y 3 allowed an account holding read or browse permission on a group reposit= ory to retrieve metadata for member repositories on which it held no direct=
permission, by requesting the endpoint directly for the member repository = name. For proxy repositories, the disclosed metadata includes the configure=
d remote URL, which may reveal internal upstream hostnames. This includes t=
he anonymous user if it has been granted this permission; whether the anony= mous user holds this permission depends on the role and permission configur= ation of the specific installation.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77122" target=3D= "_blank" rel=3D"noopener">CVE-2026-77122</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository 3</td>
<td>Nexus Repository 3 contains a sensitive information disclosure vulnerab= ility in the capability read API. An account holding the nexus:capabilities= :read privilege can retrieve the plaintext shared secret configured on a we= bhook capability, which is intended to be masked from all API responses. Th=
is issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is f= ixed in version 3.96.0.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77123" target=3D= "_blank" rel=3D"noopener">CVE-2026-77123</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository 3</td>
<td>In affected versions of Nexus Repository 3, the script execution endpoi=
nt (POST /service/rest/v1/script/{name}/run) did not verify whether script = execution had been administratively disabled. An account holding script-exe= cution permission could continue to run previously-created scripts even aft=
er an administrator set nexus.scripts.allowCreation=3Dfalse, undermining th=
e expectation that this setting fully blocks script execution.</td> <td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77124" target=3D= "_blank" rel=3D"noopener">CVE-2026-77124</a></td>
</tr>
<td class=3D"vendor-product">Sonatype--Nexus Repository 3</td>
<td>A vulnerability was identified in Sonatype Nexus Repository 3 in which = two blobstore group management REST API endpoints did not correctly enforce=
the intended authorization check. A user granted only the nexus:blobstores= :create permission could invoke these endpoints to convert an existing blob= store into a group blobstore, an action that should require the nexus:blobs= tores:update permission instead. This could result in unauthorized modifica= tion of blobstore configuration without administrator approval. The nexus:b= lobstores:create permission is a named permission that must be explicitly g= ranted by an administrator; it is not held by default.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-77125" target=3D= "_blank" rel=3D"noopener">CVE-2026-77125</a></td>
</tr>
<td class=3D"vendor-product">squirrelchat--smol-toml</td>
<td>smol-toml is a small, fast, and correct TOML parser and serializer. Pri=
or to 1.7.1, parse() can enter an infinite loop when a value inside an arra=
y or inline table is followed by a comment with no trailing newline. In src= /util.ts, skipUntil() calls indexOfNewline(), receives -1 at the end of inp= ut, and resets the cursor to the beginning of the string instead of leaving=
the structure scan. The parser then hangs indefinitely and can consume a s= ervice's processing capacity when an application parses attacker-controlled=
TOML. This issue is fixed in version 1.7.1.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85730" target=3D= "_blank" rel=3D"noopener">CVE-2026-85730</a></td>
</tr>
<td class=3D"vendor-product">sulu--sulu</td>
<td>Sulu is an open-source PHP content management system based on the Symfo=
ny framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint=
and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.p=
hp do not enforce VIEW permission for the target resource in PreviewLinkMan= ager::generate() or PreviewLinkManager::revoke(). An authenticated administ= ration user who knows a target resource identifier can create or revoke a p= review link for any page, article, or snippet, including content in a websp= ace or area the user cannot view. A generated preview URL is public and res= olves content by an opaque token, allowing the user or anyone receiving the=
link to read restricted content without authentication. This issue is fixe=
d in versions 2.6.25 and 3.0.8.</td>
<td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82394" target=3D= "_blank" rel=3D"noopener">CVE-2026-82394</a></td>
</tr>
<td class=3D"vendor-product">sulu--sulu</td>
<td>Sulu is an open-source PHP content management system based on the Symfo=
ny framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint d= erives its permission check from the client-supplied collection value inste=
ad of the media item's actual source collection, and src/Sulu/Bundle/MediaB= undle/Media/Manager/MediaManager.php allows MediaManager::move() to reassig=
n the item without checking that source. An authenticated backend user with=
edit permission on one collection and knowledge of a target media identifi=
er can name the allowed collection in the request, move an item out of a re= stricted collection, and then view or download content the user was not per= mitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82395" target=3D= "_blank" rel=3D"noopener">CVE-2026-82395</a></td>
</tr>
<td class=3D"vendor-product">SUSE--Fleet</td>
<td>A security vulnerability was discovered in Fleet's Helm template prepro= cessing where templates evaluated by the Fleet controller could reach netwo=
rk resources outside the management cluster. A user who can supply bundle c= ontent to a repository referenced by a `GitRepo` resource can cause the Fle=
et controller to: - Disclose cluster metadata available to the templating c= ontext. - Reveal information about hosts reachable from the controller's ne= twork position. Because the disclosure channel is name resolution, it may r= emain effective in environments where outbound traffic is otherwise restric= ted. The disclosed information is limited to values exposed to the Fleet te= mplating context and to name resolution results. Integrity and availability=
of managed clusters are not affected. This issue affects Fleet: from 0.12.=
0 before 0.12.19, from 0.13.0 before 0.13.15, from 0.14.0 before 0.14.10, f= rom 0.15.0 before 0.15.6, and from 0.16.0 before 0.16.1.</td> <td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-75036" target=3D= "_blank" rel=3D"noopener">CVE-2026-75036</a></td>
</tr>
<td class=3D"vendor-product">ThinkSNS+ --ThinkSNS+ v2.4<br>=C2=A0</td>
<td>An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to es= calate privileges via the ResetPasswordController.php component</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71625" target=3D= "_blank" rel=3D"noopener">CVE-2026-71625</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ versions before 4.1.8 fail to validate CAPTCHA when the store = parameter is set to 'now' in question submission requests. Unauthenticated = attackers can bypass CAPTCHA protection and submit unlimited questions dire= ctly, causing database pollution and triggering outgoing mail notifications= .</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85586" target=3D= "_blank" rel=3D"noopener">CVE-2026-85586</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.8 enforces incorrect permission checks on admin con= tent pages, allowing lesser-privileged editors to read draft and inactive c= ontent. Attackers with only add permissions can access news edit and FAQ tr= anslate endpoints to view unpublished content invisible to the public.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85587" target=3D= "_blank" rel=3D"noopener">CVE-2026-85587</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plai= ntext within user data export ZIP files. Attackers obtaining exported archi= ves can extract the TOTP seed and generate valid one-time codes to bypass t= wo-factor authentication.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85588" target=3D= "_blank" rel=3D"noopener">CVE-2026-85588</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerab= ility in the admin dashboard API endpoints searches and content-health that=
enforce only authentication without permission checks. Any authenticated u= ser can access these endpoints to read site-wide search statistics and cont= ent-health counters regardless of their privilege level.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85589" target=3D= "_blank" rel=3D"noopener">CVE-2026-85589</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ before 4.1.8 contains an authentication bypass vulnerability i=
n its two-factor authentication (TOTP) disable functionality. The removeTwo= factorConfig() handler (reachable via POST /api/user/remove-twofactor) veri= fies only that the user is logged in and that a valid CSRF token is supplie=
d, then disables TOTP without requiring password re-entry or a current TOTP=
code. The same downgrade is also reachable inline via PUT /api/user/data/u= pdate, which accepts a plain twofactor_enabled form field under the same se= ssion+CSRF-only guard. An attacker who has hijacked a user's session can si= lently strip two-factor protection from any account, including administrato=
r accounts, after which password-only authentication succeeds.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85590" target=3D= "_blank" rel=3D"noopener">CVE-2026-85590</a></td>
</tr>
<td class=3D"vendor-product">thorsten--phpMyFAQ</td>
<td>phpMyFAQ versions before 4.1.8 contain an authentication bypass vulnera= bility in the user control panel API endpoint that allows authenticated att= ackers to change account passwords without verifying the current password. = Attackers with session access can submit a PUT request to the user data upd= ate endpoint with only a CSRF token to silently change any user's password,=
including administrators, causing irreversible account takeover and victim=
lockout.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85591" target=3D= "_blank" rel=3D"noopener">CVE-2026-85591</a></td>
</tr>
<td class=3D"vendor-product">TP-Link Systems Inc.--Archer AX55 v4</td>
<td>A stack-based buffer overflow vulnerability exists in the EasyMesh modu=
le of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may=
submit crafted input that causes the easymesh daemon to crash and may pote= ntially achieve remote code execution on the device. Successful exploitatio=
n may cause the EasyMesh daemon to crash and may potentially allow remote c= ode execution when Mesh mode is enabled. This may result in high impact to = the confidentiality, integrity, and availability of the affected device.</t=
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18167" target=3D= "_blank" rel=3D"noopener">CVE-2026-18167</a></td>
</tr>
<td class=3D"vendor-product">TP-Link Systems Inc.--Archer AX55 v4</td>
<td>A hard-coded cryptographic key vulnerability exists in the=C2=A0web mod= ule of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login se= ssion may use the known shared RSA private key to decrypt the=C2=A0administ= rator=C2=A0password; the weakened AES session key further reduces the effor= t=C2=A0required=C2=A0to compromise session confidentiality. Successful expl= oitation may disclose the administrator password captured from an HTTP logi=
n session and compromise session confidentiality.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-18330" target=3D= "_blank" rel=3D"noopener">CVE-2026-18330</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces re= strictions on the traefik.ingress.kubernetes.io/service.middlewares Service=
annotation in the Kubernetes Ingress provider. A namespace-limited tenant = excluded from the allowlist can attach an operator-owned middleware to its = Service, and if that middleware injects backend credentials, recover them a=
t a controlled backend.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85594" target=3D= "_blank" rel=3D"noopener">CVE-2026-85594</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 co= ntain an authentication bypass vulnerability in the digestAuth middleware w= here unknown usernames receive an empty secret instead of rejection. Attack= ers can compute a valid digest response using the empty secret and arbitrar=
y credentials to bypass authentication on any digestAuth-protected route wi= thout a valid username or password.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85595" target=3D= "_blank" rel=3D"noopener">CVE-2026-85595</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik versions >=3D v3.7.0 and <=3D v3.7.10 contain an authenti= cation bypass in the Kubernetes Ingress NGINX provider. The TLS option gene= rated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secr=
et annotation was named after the Ingress namespace and name. As a result, = two Ingress objects sharing the same host, the same client CA secret, and t=
he same client-authentication mode produced two distinct TLS option names f=
or that host. Traefik treats this as a TLS options conflict and falls back =
to the entry point's default TLS configuration, which does not request a cl= ient certificate, so a route configured with nginx.ingress.kubernetes.io/au= th-tls-verify-client: "on" becomes reachable without a client certificate. = Only the v3.7 line is affected; the issue is fixed in v3.7.11.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85596" target=3D= "_blank" rel=3D"noopener">CVE-2026-85596</a></td>
</tr>
<td class=3D"vendor-product">traefik--traefik</td>
<td>Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option=
conflict resolution vulnerability that allows unauthenticated attackers to=
bypass client-certificate authentication by creating conflicting TLS optio=
ns on multi-host routers. Attackers can reach protected backends by exploit= ing shared TLS resolution across multiple hostnames in a single router rule=
, causing the strict mTLS requirement to fall back to default options for a=
ll hosts.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85597" target=3D= "_blank" rel=3D"noopener">CVE-2026-85597</a></td>
</tr>
<td class=3D"vendor-product">Trimble --TM4WEB</td>
<td>In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with sessio=
n identifiers, it is possible to recover valid session cookies via reflecte=
d cross-site scripting affecting the external document viewer endpoint.</td=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2022-35497" target=3D= "_blank" rel=3D"noopener">CVE-2022-35497</a></td>
</tr>
<td class=3D"vendor-product">Trueview --Trueview 6.0.23.4<br>=C2=A0</td>
<td>No authentication exists in the MQTT service of Trueview 6.0.23.4. The = MQTT broker accepts client connections on TCP port 1883 without requiring a= uthentication, allowing a remote attacker with network access to establish =
an MQTT session and perform unauthorized publish or subscribe operations.</=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79391" target=3D= "_blank" rel=3D"noopener">CVE-2026-79391</a></td>
</tr>
<td class=3D"vendor-product">Trueview--T18161 S 6.0.23.4<br>=C2=A0</td>
<td>Trueview T18161 S 6.0.23.4 contains an improper verification in MQTT co= mmand processing. An attacker with network access can replay or modify capt= ured MQTT messages, including security-related nonce, timestamp, and signat= ure fields, and the device accepts the modified messages and executes the a= ssociated commands.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79389" target=3D= "_blank" rel=3D"noopener">CVE-2026-79389</a></td>
</tr>
<td class=3D"vendor-product">Trueview--T18161 S 6.0.23.4<br>=C2=A0</td>
<td>Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to=
the transmission of MQTT communications in plaintext over TCP port 1883. A=
n unauthenticated attacker with access to the same network segment can inte= rcept MQTT traffic and obtain sensitive device information and operational = data, including device identifiers, message metadata, and control-related i= nformation.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-79390" target=3D= "_blank" rel=3D"noopener">CVE-2026-79390</a></td>
</tr>
<td class=3D"vendor-product">Twig--Twig=C2=A0<br>=C2=A0</td>
<td>Twig is a template language for PHP. From version 1.0.0 to before versi=
on 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists = all method calls on instances of Twig\Markup. Twig\Markup is not final, so = subclasses inherit the bypass. An application that passes an object of a Ma= rkup-derived class into a sandboxed template (typically to mark a chunk of = HTML as safe) inadvertently exposes every public method of that subclass to=
template authors, regardless of the configured allowedMethods list. This i= ssue has been patched in version 3.27.0.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-46636" target=3D= "_blank" rel=3D"noopener">CVE-2026-46636</a></td>
</tr>
<td class=3D"vendor-product">vbpf--prevail</td>
<td>PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpr= etation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTr= ansformer::add() silently skips offset-variable updates when the destinatio=
n register carries a non-singleton typeset (two or more simultaneously poss= ible pointer types). Subsequent bounds checks use the stale offset and acce=
pt out-of-bounds memory accesses, so a crafted BPF program passes verificat= ion even though it would corrupt memory at runtime. This issue has been pat= ched in version 0.2.4.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53670" target=3D= "_blank" rel=3D"noopener">CVE-2026-53670</a></td>
</tr>
<td class=3D"vendor-product">vbpf--prevail</td>
<td>PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpr= etation Layer. Prior to version 0.2.4, the abstract transformer in prevail = treats writes through a T_CTX-typed base register as a silent no-op: do_mem= _store in src/crab/ebpf_transformer.cpp only models T_STACK stores, and the=
checker's T_CTX bounds arm never tests AccessType::write. An attacker can = craft an eBPF program that overwrites a context field (e.g., ctx->data),=
reload that field typed as T_PACKET, and dereference an attacker-controlle=
d address - and prevail will report the program as safe. This issue has bee=
n patched in version 0.2.4.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53671" target=3D= "_blank" rel=3D"noopener">CVE-2026-53671</a></td>
</tr>
<td class=3D"vendor-product">vbpf--prevail</td>
<td>PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpr= etation Layer. Prior to version 0.2.4, the prevail eBPF verifier accepts AL= U32 ADD and SUB instructions that operate on pointer-typed registers withou=
t checking the is64 flag. Because ALU32 arithmetic zero-extends the 32-bit = result, the upper half of any pointer is silently destroyed at runtime, yet=
prevail marks the program as verified safe. Any caller that can submit an = eBPF program for verification - including unprivileged users on kernels tha=
t permit BPF program loading - can produce a program that passes verificati=
on but faults or misbehaves at runtime. This issue has been patched in vers= ion 0.2.4.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-53706" target=3D= "_blank" rel=3D"noopener">CVE-2026-53706</a></td>
</tr>
<td class=3D"vendor-product">WebPros--ConfigServer Security & Firewall<=
<td>An insecure Apache configuration in ConfigServer Security & Firewal=
l maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host=
. A remote unauthenticated attacker whose address is blocked can request a = mapped executable and run arbitrary commands as the Apache user. The vulner= ability affects installations where CSF Messenger v3 and its HTTPS mode are=
enabled. WebPros addressed the vulnerability in version 16.31.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67402" target=3D= "_blank" rel=3D"noopener">CVE-2026-67402</a></td>
</tr>
<td class=3D"vendor-product">WebPros--Plesk</td>
<td>A critical local privilege escalation via OS command injection vulnerab= ility has been discovered in Plesk for Linux, affecting all versions from 1= 8.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer =
or reseller with shell access (or allowed to change their own shell access)=
to elevate privileges to the root account on the hosting server.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67394" target=3D= "_blank" rel=3D"noopener">CVE-2026-67394</a></td>
</tr>
<td class=3D"vendor-product">WebPros--Plesk</td>
<td>Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.= 80.5 allows local users to execute arbitrary code as root.</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67397" target=3D= "_blank" rel=3D"noopener">CVE-2026-67397</a></td>
</tr>
<td class=3D"vendor-product">WebPros--WHMCS</td>
<td>Missing authorization vulnerability has been discovered in 2Checkout pa= yment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, = all other EOL versions from 4.5.0. The vulnerability allows an unauthentica= ted user to get WHMCS customer's data via 2Checkout payment gateway's endpo= int under specific conditions.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-67398" target=3D= "_blank" rel=3D"noopener">CVE-2026-67398</a></td>
</tr>
<td class=3D"vendor-product">withastro--astro</td>
<td>Astro is a web framework for content-driven websites. Prior to 7.2.4, A= stro stripped a configured non-root base path from request pathnames using =
a string-prefix check without verifying a path-segment boundary. With base = "/app", a request to "/appX/admin" resolved internally to the protected "/a= dmin" route while middleware observed "/appX/admin" in context.url.pathname=
. In applications that authorize base-prefixed routes by inspecting context= .url.pathname, an unauthenticated remote attacker could bypass pathname-bas=
ed middleware authorization and reach protected routes. This issue is fixed=
in version 7.2.4.</td>
<td>2026-09-02</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84376" target=3D= "_blank" rel=3D"noopener">CVE-2026-84376</a></td>
</tr>
<td class=3D"vendor-product">wolfSSL--wolfSSL<br>=C2=A0</td>
<td>With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SS= L_CTX_FUNCTION` callback replaces the trust store, libcurl can silently rei= nstall the cached store after the callback returns. A certificate trusted b=
y the cached store but rejected by the callback-selected store is then inco= rrectly accepted.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82208" target=3D= "_blank" rel=3D"noopener">CVE-2026-82208</a></td>
</tr>
<td class=3D"vendor-product">WWBN--AVideo</td>
<td>WWBN AVideo through 30.0 contains an information disclosure vulnerabili=
ty in the MobileManager plugin getConfiguration endpoint that returns sensi= tive configuration data to unauthenticated visitors. Attackers can send an = unauthenticated GET request to plugin/MobileManager/getConfiguration.json.p=
hp to obtain TLS private key file paths, socket configuration details, plat= form version, and debug flags enabling further targeted attacks.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-84481" target=3D= "_blank" rel=3D"noopener">CVE-2026-84481</a></td>
</tr>
<td class=3D"vendor-product">Xing Inc.--XING CPTrans-ME-X</td>
<td>XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenti= cated OS command may be injected.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-62928" target=3D= "_blank" rel=3D"noopener">CVE-2026-62928</a></td>
</tr>
<td class=3D"vendor-product">Xing Inc.--XING CPTrans-ME-X</td>
<td>XING CPTrans-ME-X contains an Exposure of Sensitive System Information =
to an Unauthorized Control Sphere (CWE-497). Sensitive system information m=
ay be leaked.</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-66840" target=3D= "_blank" rel=3D"noopener">CVE-2026-66840</a></td>
</tr>
<td class=3D"vendor-product">Xing Inc.--XING CPTrans-ME-X</td>
<td>XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone=
with the knowledge of the credential may log in to the affected device.</t=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-69657" target=3D= "_blank" rel=3D"noopener">CVE-2026-69657</a></td>
</tr>
<td class=3D"vendor-product">Xing Inc.--XING CPTrans-ME-X</td>
<td>XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyo=
ne with the knowledge of the credential may log in to the affected device.<=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-70403" target=3D= "_blank" rel=3D"noopener">CVE-2026-70403</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 = and 0.9.11, and in xmldom version 0.6.0 and earlier, Element.setAttribute()=
calls the private _createAttribute(name) path without validating the attri= bute name, while Document.createAttribute(name) validates against QName. XM= LSerializer.serializeToString() emits attribute names verbatim, and require= WellFormed: true did not validate them, so a crafted name can terminate the=
intended attribute and inject additional attributes, including event handl= ers, into browser-consumed output; synthesized xmlns:PREFIX declarations ex= pose the same unchecked-name boundary. This issue is fixed in @xmldom/xmldo=
m versions 0.8.14 and 0.9.11; no fixed version is available for xmldom.</td=
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83605" target=3D= "_blank" rel=3D"noopener">CVE-2026-83605</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.9.0-beta.9 until 0.9.11, the proc= essing-instruction production in lib/grammar.js lets the greedy S+ separato=
r and lazy Char*? data group repeatedly repartition a long whitespace tail = when the required closing ?> is absent. Both parsePI and parseProcessing= Instruction apply the expression to the entire remaining source, causing qu= adratic backtracking during DOMParser.parseFromString() under default optio=
ns and allowing a small unauthenticated XML input to stall the Node.js even=
t loop. This issue is fixed in @xmldom/xmldom version 0.9.11.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83606" target=3D= "_blank" rel=3D"noopener">CVE-2026-83606</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.14 = and 0.9.11, and in xmldom version 0.6.0 and earlier, Document.createElement= (tagName) stores an unvalidated element name and XMLSerializer.serializeToS= tring() emits that name verbatim. The requireWellFormed: true path did not = validate the element qualified name or synthesized xmlns:PREFIX declaration=
, so attacker-controlled tag names could inject attributes, elements, or pr= ocessing instructions into serialized XML or HTML and could cause cross-sit=
e scripting when browser-consumed. The unchecked values violate the XML QNa=
me constraint, and default serialization and creation-time createElement() = behavior remain permissive. This issue is fixed in @xmldom/xmldom versions = 0.8.14 and 0.9.11; no fixed version is available for xmldom.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83607" target=3D= "_blank" rel=3D"noopener">CVE-2026-83607</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, the DOCUMENT_TYPE_NODE=
branch in lib/dom.js validates publicId, systemId, and internalSubset unde=
r requireWellFormed: true but emits DocumentType.name verbatim. A name cont= aining > or whitespace can terminate the <!DOCTYPE ...> declaratio=
n and inject sibling markup; the value can be supplied through createDocume= ntType() on the 0.8.x and unscoped lines or through a direct DocumentType.n= ame property write on every affected line. The default path and legacy crea= tion-time behavior remain permissive, while the vulnerable strict path fail=
s to enforce an XML Name. This issue is fixed in @xmldom/xmldom versions 0.= 8.15 and 0.9.12; no fixed version is available for xmldom.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83608" target=3D= "_blank" rel=3D"noopener">CVE-2026-83608</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.9.0 until 0.9.12, the shared reg(=
) builder in lib/grammar.js compiles the anchored QName_exact validator wit=
h the multiline flag, so ^ and $ validate only one line instead of the comp= lete name. createElementNS, createAttributeNS, createDocumentType, and crea= teAttribute consequently accept a malformed XML name whose first line is va= lid and whose later text injects markup when serialized through either the = default path or requireWellFormed: true. The triggering ECMAScript line ter= minators are U+000A, U+000D, U+2028, and U+2029. This issue is fixed in @xm= ldom/xmldom version 0.9.12.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83609" target=3D= "_blank" rel=3D"noopener">CVE-2026-83609</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createEntityR= eference(name) accepts an invalid name and the ENTITY_REFERENCE_NODE serial= izer emits the resulting nodeName directly in &name; form. Directly ser= ializing the node or fragment with XMLSerializer.serializeToString() and re= quireWellFormed: true can therefore break the entity-reference boundary and=
produce attacker-controlled XML markup when reparsed. The parser does not = ordinarily create these nodes, and element-child insertion is rejected, so = exploitation requires an application to create and directly serialize an En= tityReference. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.= 9.12; no fixed version is available for xmldom.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83610" target=3D= "_blank" rel=3D"noopener">CVE-2026-83610</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMParser.parseFromStr= ing() can silently accept an end tag such as </a\njunk>, close the el= ement, and discard the trailing content. On 0.9.x, the lib/sax.js end-tag v= alidator inherits the multiline flag from reg(), allowing the first line to=
satisfy the anchored XML ETag production; older lines have no equivalent r= esidue validation. This parser differential can bypass a parse-before-trust=
well-formedness gate, although it does not inject the discarded content; o= nError on 0.9.x and errorHandler on 0.8.x are the relevant reporting interf= aces. This issue is fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no = fixed version is available for xmldom.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83611" target=3D= "_blank" rel=3D"noopener">CVE-2026-83611</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.9.0-beta.1 until 0.9.12, HTML-mod=
e parsing through DOMParser.parseFromString() mishandles a mixed-case closi=
ng tag for the script, style, textarea, or title raw-text elements. parseHt= mlSpecialContent, selected by isHTMLRawTextElement or isHTMLEscapableRawTex= tElement, uses a case-sensitive indexOf() and then calls substring() with a=
missing-close result of negative one, causing unstable parser progression = and quadratic output amplification. A small untrusted text/html document ca=
n consequently consume disproportionate CPU and memory when parsed and seri= alized. This issue is fixed in @xmldom/xmldom version 0.9.12.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83612" target=3D= "_blank" rel=3D"noopener">CVE-2026-83612</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, DOMHandler.startElemen=
t in lib/dom-parser.js inserts every parsed attribute through setAttributeN= ode, while NamedNodeMap.setNamedItem in lib/dom.js calls the linear getName= dItem or getNamedItemNS lookup for each insertion. A well-formed element wi=
th many distinct attributes therefore requires quadratic comparisons during=
DOMParser.parseFromString() and can stall a Node.js event loop before appl= ication validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 a=
nd 0.9.12; no fixed version is available for xmldom.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83613" target=3D= "_blank" rel=3D"noopener">CVE-2026-83613</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom versions 0.3.0 through 0.6.0, two independent qua= dratic paths can cause denial of service. In lib/sax.js, parseElementStartP= art repeatedly rescans a malformed tag name to the next > during single-= character recovery; in lib/dom.js, normalize() repeatedly removes and appen=
ds adjacent text nodes, causing quadratic reindexing and string rebuilding.=
The first path is reachable through default DOMParser.parseFromString() pr= ocessing, while the second is also reachable through a direct normalize() c= all on a programmatically constructed DOM, and endDocument invokes that nor= malization after parsing. This issue is fixed in @xmldom/xmldom versions 0.= 8.15 and 0.9.12; no fixed version is available for xmldom.</td> <td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83614" target=3D= "_blank" rel=3D"noopener">CVE-2026-83614</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom versions 0.1.5 through 0.6.0, appendElement in li= b/sax.js uses _copy to clone the complete currentNSMap for each nested elem= ent that declares a new namespace prefix. Keeping every ancestor map live o=
n the parse stack creates quadratic peak namespace-map storage, so a small = highly compressible XML document can exhaust the process heap before applic= ation validation. This issue is fixed in @xmldom/xmldom versions 0.8.15 and=
0.9.12; no fixed version is available for xmldom.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83615" target=3D= "_blank" rel=3D"noopener">CVE-2026-83615</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. Prior to @xmldom/xmldom versions 0.8.15 = and 0.9.12, and in xmldom version 0.6.0 and earlier, Document.createProcess= ingInstruction(target, data) in lib/dom.js accepts an unvalidated target, w= hile the requireWellFormed: true serializer checks only for a colon and the=
reserved case-insensitive xml name on 0.9.x and performs no target check o=
n 0.8.x. Because serialization emits <?target data?>, a target contai= ning >, ?, whitespace, or another invalid XML-name character can break t=
he processing-instruction boundary and inject XML structure. This issue is = fixed in @xmldom/xmldom versions 0.8.15 and 0.9.12; no fixed version is ava= ilable for xmldom.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83616" target=3D= "_blank" rel=3D"noopener">CVE-2026-83616</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.9.11 until 0.9.12, the requireWel= lFormed: true element and attribute name checks use the anchored QName_exac=
t expression produced by reg() in lib/grammar.js, which inherits the multil= ine flag. A name with a valid first line followed by U+000A, U+000D, U+2028=
, or U+2029 and breakout markup therefore passes validation and is emitted = verbatim in element start and end tags or attribute names. This bypasses th=
e strict-serialization checks introduced for the earlier element-name and a= ttribute-name injection advisories, while the default serialization path re= mains outside the strict guarantee. This issue is fixed in @xmldom/xmldom v= ersion 0.9.12.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83617" target=3D= "_blank" rel=3D"noopener">CVE-2026-83617</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.9.10 until 0.9.12, the requireWel= lFormed: true serializer validates DocumentType.publicId and DocumentType.s= ystemId with PubidLiteral_match and SystemLiteral_match expressions produce=
d by reg() in lib/grammar.js, which inherit the multiline flag. A complete = valid literal on the first line can therefore satisfy the matcher while U+0= 00A, U+000D, U+2028, or U+2029 and breakout markup remain in the emitted &l= t;!DOCTYPE ...> declaration. This bypasses the strict-serialization miti= gation for the earlier DocumentType injection advisory; creation and direct=
property assignment remain unvalidated by design. This issue is fixed in @= xmldom/xmldom version 0.9.12.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83618" target=3D= "_blank" rel=3D"noopener">CVE-2026-83618</a></td>
</tr>
<td class=3D"vendor-product">xmldom--xmldom</td>
<td>xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) D= OMParser and XMLSerializer module. From 0.7.0 until 0.8.15, the release-0.8=
.x parser in lib/sax.js trims captured end-tag names with the unanchored gl= obal expression /[ \t\n\r]+$/g. For an end tag containing a long whitespace=
run followed by a non-whitespace character, the expression retries from ea=
ch possible starting position and backtracks quadratically before failing i=
ts end anchor. DOMParser.parseFromString() reaches the path under default o= ptions, allowing a small unauthenticated XML input to stall the Node.js eve=
nt loop; the 0.9.x and unscoped npm lines do not contain this expression. T= his issue is fixed in @xmldom/xmldom version 0.8.15.</td>
<td>2026-09-01</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-83619" target=3D= "_blank" rel=3D"noopener">CVE-2026-83619</a></td>
</tr>
<td class=3D"vendor-product">Xpdf--Xpdf</td>
<td>Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 fon=
t has a zero height.</td>
<td>2026-09-03</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-85458" target=3D= "_blank" rel=3D"noopener">CVE-2026-85458</a></td>
</tr>
<td class=3D"vendor-product">YesWiki -- YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWik=
i Bazar contains a stored Server-Side Template Injection (SSTI) vulnerabili=
ty in the semantic template feature that can be escalated to confirmed Remo=
te Code Execution (RCE). An authenticated administrator can place arbitrary=
Twig expressions into the Semantic template (Twig) field (bn_sem_template)=
, and that content is later executed server-side when public semantic endpo= ints are requested. This issue has been patched in version 4.6.6.</td> <td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52762" target=3D= "_blank" rel=3D"noopener">CVE-2026-52762</a></td>
</tr>
<td class=3D"vendor-product">YesWiki--YesWiki<br>=C2=A0</td>
<td>YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there =
is an authenticated PHP object injection vulnerability in BazarImportAction=
via unserialize. This issue has been patched in version 4.6.6.</td>
<td>2026-09-05</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-52777" target=3D= "_blank" rel=3D"noopener">CVE-2026-52777</a></td>
</tr>
<td class=3D"vendor-product">z-galaxy--zbus_polkit</td> <td>Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry=
of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type=
u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a=
signed 32-bit integer (D-Bus type i). Because of this type mismatch, polki=
t silently discards the caller-supplied UID and instead determines the subj= ect's owner itself by looking up the PID in /proc, a lookup that is inheren= tly subject to a time-of-check/time-of-use race. Consequently, an applicati=
on that passes a UID obtained from a trustworthy source - for example SO_PE= ERCRED Unix socket peer credentials - in order to defend against PID reuse = receives no protection, and the supplied UID has no effect on the authoriza= tion decision. A local unprivileged attacker who can cause an authorized pr= ocess to terminate and then win the race to have their own process assigned=
the same PID can be authorized under the identity of the terminated proces=
s, bypassing the polkit authorization check and performing actions the atta= cker is not entitled to. This issue affects zbus_polkit before 5.1.0.</td> <td>2026-08-31</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-78422" target=3D= "_blank" rel=3D"noopener">CVE-2026-78422</a></td>
</tr>
<td class=3D"vendor-product">ZenHive--ZenHive mpp</td>
<td>Improper Validation of Specified Quantity in Input in ZenHive mpp allow=
s an unauthenticated remote client to inflate the fee-payer's gas cost per = sponsored payment by a large multiplier and to have the sponsor pay for pro= visioning an access key on the client's own account. When the server sponso=
rs Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/me= thods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the = validity window and the access list of the client-signed 0x76 envelope, but=
does not check whether the envelope carries the optional key_authorization=
field. A client can attach a fully signed key authorization, provisioning =
a new access key with token spending limits on its own account, alongside t=
he normal payment call. The key and each limit entry are persistent storage=
writes billed as intrinsic gas to the sponsor, bounded only by the gas_lim=
it ceiling. At the reporter's default of one key with three token limits th=
e sponsored cost rises from about 46,587 gas to about 1,808,700 gas, and th=
e client keeps a valid access key it paid nothing for. This issue affects m= pp: from 0.2.0 before 0.16.1.</td>
<td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82751" target=3D= "_blank" rel=3D"noopener">CVE-2026-82751</a></td>
</tr>
<td class=3D"vendor-product">ZenHive--ZenHive mpp<br>=C2=A0</td>
<td>Improper Validation of Specified Quantity in Input in ZenHive mpp allow=
s an unauthenticated remote client to inflate the fee-payer's gas cost per = sponsored payment by a large multiplier and to have the sponsor pay for EIP= -7702 account delegations of the client's choosing. When the server sponsor=
s Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/met= hods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the v= alidity window and the access list of the client-signed 0x76 envelope, but = never reads its aa_authorization_list field. Every signed delegation in tha=
t list is charged as intrinsic gas before the payment call runs, so a clien=
t attaching delegations from throwaway authority keys makes the sponsor pay=
for them within the default gas_limit ceiling. At the reporter's default o=
f seven entries the sponsored cost rises from about 46,575 gas to about 1,8= 84,087 gas. Because each entry is applied as a persistent set-code delegati= on, a client can also upgrade its own accounts to delegated code at the spo= nsor's expense. This issue affects mpp: from 0.2.0 before 0.16.1.</td> <td>2026-09-06</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-82750" target=3D= "_blank" rel=3D"noopener">CVE-2026-82750</a></td>
</tr>
<td class=3D"vendor-product">Zhao-github--ApiAdmin v.5.0.1<br>=C2=A0</td> <td>File Upload vulnerability in Zhao-github ApiAdmin v.5.0.1 allows a remo=
te attacker to execute arbitrary code via a crafted .php file</td> <td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71620" target=3D= "_blank" rel=3D"noopener">CVE-2026-71620</a></td>
</tr>
<td class=3D"vendor-product">Zhao-github--ApiAdmin v.5.0.1<br>=C2=A0</td> <td>SQL injection vulnerability in Zhao-github APiAdmin v.5.0.1 allows a re= mote attacker to obtain sensitive information via the User.php component</t=
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71622" target=3D= "_blank" rel=3D"noopener">CVE-2026-71622</a></td>
</tr>
<td class=3D"vendor-product">=C2=A0Invoice Ninja-- Invoice Ninja v5.13.24<b= r>=C2=A0</td>
<td>An issue in Invoice Ninja v5.13.24 allows a remote attacker to obtain s= ensitive information via the StoreWebhookRequest.php, UpdateWebhookRequest.= php, and WebhookSingle.php components</td>
<td>2026-09-04</td>
<td>not yet calculated</td>
<td><a href=3D"
https://www.cve.org/CVERecord?id=3DCVE-2026-71626" target=3D= "_blank" rel=3D"noopener">CVE-2026-71626</a></td>
</tr>
</tbody>
</table>
<p><a href=3D"#top">Back to top</a></p>
</div>
</div>
</div>
<style>body {
font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: norma=
l; font-style: normal; color: #333333;
}
</style>
=20
<div id=3D"mail_footer">
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; colo=
r: #757575;">Having trouble viewing this message?=C2=A0</span><a href=3D"ht= tps://content.govdelivery.com/accounts/USDHSCISA/bulletins/428f9a0" target= =3D"_blank" rel=3D"noopener">View it as a webpage</a>.=C2=A0<a href=3D"http= s://content.govdelivery.com/accounts/USDHS/bulletins/292141e" target=3D"_bl= ank" rel=3D"noopener"></a><span style=3D"font-size: 10.0pt; color: #757575;= "></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">You are subscribed to updates from the </span><a href=3D"
https://w= ww.cisa.gov"><span style=3D"font-size: 10.0pt;">Cybersecurity and Infrastru= cture Security Agency</span></a><span style=3D"font-size: 10.0pt; color: #7= 57575;"> (CISA)<br></span><a href=3D"
https://public.govdelivery.com/account= s/USDHSCISA/subscriber/edit?preferences=3Dtrue#tab1" target=3D"_blank" rel= =3D"noopener"><span style=3D"font-size: 10.0pt; color: #00568c;">Manage Sub= scriptions</span></a>=C2=A0=C2=A0<span style=3D"font-size: 10.0pt; color: #= 757575;">|=C2=A0=C2=A0</span><a href=3D"
https://www.cisa.gov/privacy-policy=
" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; colo=
r: #00568c;">Privacy Policy</span></a><span style=3D"font-size: 10.0pt; col= or: #757575;">=C2=A0=C2=A0|=C2=A0 <a href=3D"
https://subscriberhelp.granicu= s.com/s/article/Subscriber-Help-Center" target=3D"_blank" rel=3D"noopener">= Help</a><a href=3D"
https://insights.govdelivery.com/Communications/Subscrib= er_Help_Center" target=3D"_blank" rel=3D"noopener"></a></span><span style= =3D"font-size: 10.0pt; color: #757575;"></span></p>
<p style=3D"text-align: center;"><span style=3D"font-size: 10.0pt; color: #= 757575;">Connect with CISA: <br></span><a href=3D"
https://www.facebook.com/= CISA" target=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; = color: #00568c;">Facebook</span></a><span style=3D"font-size: 10.0pt; color=
: #757575;">=C2=A0 |=C2=A0 </span><a href=3D"
https://twitter.com/CISAgov" t= arget=3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: = #00568c;">Twitter</span></a><span style=3D"font-size: 10.0pt; color: #75757= 5;">=C2=A0 |=C2=A0 </span><a href=3D"
https://Instagram.com/cisagov" target= =3D"_blank" rel=3D"noopener"><span style=3D"font-size: 10.0pt; color: #0056= 8c;">Instagram</span></a><span style=3D"font-size: 10.0pt; color: #757575;"= >=C2=A0 |=C2=A0 </span><a href=3D"
https://www.linkedin.com/company/cybersec= urity-and-infrastructure-security-agency" target=3D"_blank" rel=3D"noopener= "><span style=3D"font-size: 10.0pt; color: #00568c;">LinkedIn</span></a><sp=
an style=3D"font-size: 10.0pt; color: #757575;">=C2=A0 |=C2=A0=C2=A0 </span= ><a href=3D"
https://www.youtube.com/channel/UCxyq9roe-npgzrVwbpoAy0A" targe= t=3D"_self"><span style=3D"font-size: 10.0pt; color: #00568c;">YouTube</spa= n></a><span style=3D"font-size: 10.0pt; color: #757575;"></span></p>
</div>
<div id=3D"tagline">
<hr>
<table style=3D"width: 100%;" border=3D"0" cellspacing=3D"0" cellpadding=3D=
<tbody>
<td style=3D"color: #757575; font-size: 10px; font-family: Arial;" width=3D= "89%">This email was sent to
cisa@toolazy.synchro.net using Granicus Commun= ications Cloud, on behalf of: Cybersecurity and Infrastructure Security Age= ncy =C2=B7 707 17th St, Suite 4000 =C2=B7 Denver, CO 80202</td>
<td align=3D"right" width=3D"11%"><a href=3D"
https://granicus.com/solution/= digital-communication-engagement/" target=3D"_blank" rel=3D"noopener"><img = src=3D"
https://content.govdelivery.com/images/govd-logo-dark.png" border=3D= "0" alt=3D"Granicus Communications logo" width=3D"115"></a></td>
</tr>
</tbody>
</table>
<style type=3D"text/css">body .abe-column-block { min-height: 5px; } table.= gd_combo_table img {margin-left:10px; margin-right:10px;} table.gd_combo_ta= ble div.govd_image_display img, table.gd_combo_table td.gd_combo_image_cell=
img {margin-left:0px; margin-right:0px;}</style>
</div>
</td>
</tr>
</table>
<img alt=3D"" src=3D"
https://links-2.govdelivery.com/CI0/010101a082abc183-f= 330510c-984c-43ab-b10b-12d1fe8f79aa-000000/drg0CoM2dX_U5p-LWSv2CIqm3JDfeWl_= oAU5m8Fd_vU=3D452" style=3D"display: none; width: 1px; height: 1px;">
</body>
</html>
--===============0436581685986125891==--
--===============8050327280383293692==--